Download NGFW - Data Sheet - Dragon Technology Distribution

Survey
yes no Was this document useful for you?
   Thank you for your participation!

* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project

Document related concepts
no text concepts found
Transcript
SANGFOR
Next Generation
Firewall
(NGFW)
Next-Generation security for your business
SANGFOR Next-Generation Firewall is designed with application control,
intrusion prevention and web security in mind to deliver excellent visibility
over users, applications and contents. SANGFOR NGFW ensures the entire
security from layer 2 to layer 7 at multi-gigabit speed and distinguishes itself
from the traditional firewall, making it the ideal choice for customers.
Entire application security protection
Bidirectional content inspection
Intelligent security defense system
Application layer high performance
Product Features
Entire security
Firewall
Authentication & Visibility
Static and dynamic package filtering.
User
Mapping by IP, MAC, IP/MAC binding, hostname and USB-Key.
authentication User account import from CSV file and LDAP Server.
Inspection on well-known protocols of FTP, HTTP, SMTP, RTSP,
H.323 (Q.931, H.245, RTP/RTCP), SQLNET, NMS, PPTP, TCP,
UDP…
Seamless integration with AD and LDAP,
Policy based SSO integration with AD domain, proxy, POP3
and WEB,
Protection against attacks of Land, Smurf, Fraggle, WinNuke,
Ping of Death, Tear Drop, IP spoofing, SYN/ICMP/UDP flood,
HTTP GET flood, DNS query flood, ARP cheating, ICMP
redirection, static and dynamic black list, etc.
Intrusion
Prevention
Scanning based on signature, protocol or applications.
Intelligent analysis of unknown threats with correlation
analysis.
Application
control
Identify applications based on application signatures database.
URL filtering
On-disk URL database,Anti-proxy technology.
Support application based control policy.
Support URL category and group based policy.
Up-to-date CVE Compatibility certificated IPS database of
3000+ signatures.
Server and terminal group signature database flexible for
policy deployment.
HW&SW
Visibility
Real-time monitor on CPU, memory, disk, session, online users and
network interface information.
BM Visibility
Bandwidth usage ranking by IPs, applications and users.
Security
Visibility
Detailed real-time information on security issues for servers or
terminals, including source/destination IP, attack category and
URL, etc.
Policy based IPS protection on source/destination IP and
subnet.
Block worms, Trojans, spyware, scanning, DoS, DDoS,
vulnerability exploits, buffer overflow attacks, abnormal
protocol and attacks with evasive tactic employed.
Networking and optimization
Deployment
Gateway, Bridge, Bypass mode, virtual wire and mix mode.
Detailed log message and in-cloud threats analysis.
Networking
Support ARP, DNS, IP UNNUMBERED.
Support policy routing, static routing, RIP v1/2 and OSPF.
Anti-virus
Stream-based anti-virus for HTTP, FTP, SMTP and POP3
protocols, etc.
Up-to-date anti-virus database with 300,000+ signatures
updated manually or automatically.
Build-in SOPHOS anti-virus database and engine.
Web
Application
Security
Support application policy-based forwarding.
,
Up-to-date application signature database of 2000+ web
application threats.
NAT
Build-in
IPsec VPN
Built-in route-based IPsec VPN for secure, fast and cost-effective
deployment of remote office network.
Bandwidth
management
Support multiplexing and intelligent routing
Weak password protection for ftp and telnet, etc.
Server information invisibility for web server and ftp server,
etc.
DLP
Management
Build-in sensitive information signature database and support
user-defined sensitive information, such as username, password,
mailbox, ID and MD5 keys.
Configuration
Port and service scanning for certain IP and assess the security risk
for the server or terminal.
Support weak password for FTP, MYSQL, ORACLE, MSSQL, SSH,
RDP, NetBIOS and VNC services, etc.
Automatically generate the cross-module security policy for FW,
IPS and WAF module to ensure the entire security.
Support Web GUI with SSL encryption;
Support SNMP.
Alarm
Ensure high security for sensitive information of the database
against leakage.
Risk Assess
Management
File uploading scanning and filtering based on signatures
Prevent information leakage through HTTP connections.
Advanced P2P control.
Qos policy based on users, applications, IPs, file types,
website types and schedules, etc.
Black list and exclusion list of URL.
Protect web application against the top ten threats defined by
OWASP, including SQL injection, XSS attack and CRSF, etc.
1:1 NAT, n:n NAT, m:n NAT, time based NAT policy.
Support NAT ALG, including DNS, FTP, H.323 and SIP, etc.
Support E-mail, MSM alarms on sign-in, virus, IPS, web attack
and hardware issues.
Support graphical tools for trouble shooting
Support template configuration for easier maintenance.
Reporting
Risk Report
Support security risk report based on port, service, vulnerability
and weak password providing guideline for IT administrator.
Security Logs
Detailed loges for security events as DOS attack, web attack,
IPS, viruses, website access, application control, user login
and OS configuration.
Support schedule based trend report.
Trend Report
Support user defined statistics report based on IP, group,
Statistics
users, application in flexible report schedule
Report
Report Format Support XML, PDF format and automatically send to specified
email list.
www.sangfor.com
SANGFOR
Next Generation Firewall
(NGFW)
NGFW
Product Family
Model
S5000-F-I
M5000-F-I
M5100-F-I
M5200-F-I
M5300-F-I
M5400-F-I
M5500-F-I
M5600-F-I
M5800-F-I
Profile
Mini
1U
1U
1U
1U
1U
2U
2U
2U
2U
2G
2G
2G
2G
2G
4G
4G
8G
16G
24G
HD Capacity
320GB
320GB
320GB
320GB
320GB
320GB
500GB
500GB
500GB
500GB
Firewall throughput
1 Gbps
1 .5Gbps
2 Gbps
3 Gbps
5 Gbps
8 Gbps
12 Gbps
18 Gbps
20 Gbps
25 Gbps
RAM
Firewall throughput
M5900-F-I
50 Mbps
100 Mbps
200 Mbps
400 Mbps
500 Mbps
700 Mbps
1 Gbps
2 Gbps
5 Gbps
10 Gbps
IPS & WAF
throughput
35 Mbps
70 Mbps
100 Mbps
150 Mbps
300 Mbps
500 Mbps
650 Mbps
1.3Gbps
3.8Gbps
6.8Gbps
New sessions
per second
10,000
11,000
13,000
20,000
30,000
50,000
90,000
150,000
200,000
300,000
500,000
1,000,000
1,200,000
1,500,000
1,800,000
2,100,000
2,300,000
6,000,000
8,000,000
(APP & URL enabled)
Max concurrent
session
15,000,000
Power and Physical Specifications
Dual Power
Supplies
N/A
N/A
N/A
N/A
N/A
N/A
√
√
√
√
Power [Watt]
(Typical)
60W
60W
60W
100W
100W
250W
300W
300W
500W
500W
Temperature
0~ 40℃
0~ 40℃
0~ 40℃
0~ 40℃
0~ 40℃
0~ 40℃
0~ 40℃
0~ 40℃
0~ 40℃
0~ 40℃
Relative
Humidity
5%~95%
5%~95%
5%~95%
5%~95%
5%~95%
5%~95%
5%~95%
5%~95%
5%~95%
5%~95%
non-condensing non-condensing non-condensing non-condensing non-condensing non-condensing non-condensing non-condensing non-condensing non-condensing
System
Dimensions
(W×L×H mm3)
275x175x
44.5
430x300x
44.5
430x300x
44.5
430x300x
44.5
430x300x
44.5
430x430x
44.5
440x500x
89
440x500x
89
440x500x
89
440x600x
90
System Weight
1.5 Kg
3.9 Kg
4.0 Kg
4.2 Kg
4.25 Kg
7.0 Kg
10.9 Kg
18.0 Kg
19.0 Kg
20.0 Kg
NA
NA
1 pair
1 pair
1 pair
1 pair
2 pair
3 pair
4 pair
4 pair
10/100/1000
3
4
4
6
4
8
8
10
8
8
1G Fiber SFP
-
-
-
-
2
-
2
4
4
-
10G Fiber SFP
-
-
-
-
-
-
-
-
-
2
Network Interfaces
Bypass (copper)
SANGFOR TECHNOLOGIES CO., LTD
[email protected]
www.sangfor.com
Global Service Center: +60 12711 7129 (7511)
Related documents