Net-Gateway nTMG Business Security Series Threat Management

Post on 03-Feb-2022

4 views 0 download

transcript

7

6

5

4

www.nappliance.com

Integrated Business Security Gateway• High performance Unified-Threat-Management security appliance

platform• Firewall, IPS, remote access, Web caching, secure application

publishing, URL and anti-malware filtering and Email protection functionalities

• Cost effective, designed for Small and Mid-Sized Businesses

Net-Gateway nTMG Business Security Series

Threat Management Gateway Appliance

• nApplianceNet-GatewaynTMGnetworksecurityappliancedeliverscomprehensive,multi-layereddefenseagainstthreatstonetworksandMicrosoftapplications,contentacceleration,intuitivemanagement,andscalability-fullyintegrated,withturnkey“outofthebox”convenience.

• AttheheartofthenTMGisMicrosoftForefrontEdgeTMG2010StandardEdition,anadvancedStatefulpacketandapplication-layerinspectionfirewall,virtualprivatenetwork(VPN)andaWebcachesolutionthatenablesallsizebusinesscustomerstoeasilymaximizeexistinginformationtechnology(IT)investmentsbyimprovingnetworksecurityandperformancewithseamlessActiveDirectoryService(ADS)Support.

nTMG Turn-Key Appliance Platform Highlights

• IntegratedBusinessGatewaySecuritysolutionforbusinessesofallsizes• FourModelstochoosefrom• MaximumReliabilitythroughRedundantHotswapDisksandPSModules• LargeNetworkPortDensity&RemoteKVMSupport• Oneface™ApplianceManagementSystem• PoweredbyForefrontThreatManagementGateway2010–StandardEdition

Multi-Layer Stateful Firewall Support:

Securely Publish Business Application for Remote Access:

•Increasedwebperformancewithacceleratedwebcaching

•Activecontentcachingofpopularcontent,con-tentdistributionandmirroring,andscheduledcontentdownload.

•URLfilteringforcompliancewithcorporatepolicy

•Preventingmalwareoutbreakscausedbyinadvertentemployeevisitstomalicioussitesorbydownloadsofinfectedfiles.

•Preventingthelatestviruses,spam,worms,andinappropriatecontentfromreachinginboxeswithe-mailprotectionatthenetworkperimeter.

•Monitoringtoolstohelptracknetworkstatuscreatealertstogetstatusonfirewallbehavior,configureandviewlogsgraphicallytotrackTMGactivity,andcreatereportstocustomizeandsummarizeloginformation.

•SupportsstandarddataformatssuchasW3CandODBC

1•Offersallthreefunctionality,packet-filtering,

statefulfilteringanddeepapplication-levelcontentfiltering

•Statefulfilteringsupportsdynamicpacketfilteringwhichopensportsonlywhennecessary,itexaminedatacrossingthefirewallinthecontextofitsprotocolandthestateoftheconnectionandprotectagainstnumberofsub-applicationlayerattacks,suchassessionhijacking

•Floodresiliencyfeatureprotectfrombeingpermanentlyunavailable,compromised,orunmanageableduringafloodattack

Smart Application-Layer Firewall Support:

2

•Fullfeaturedapplicationawarefirewallcomprehensivelyhelpsprotectfrombothexternalandinternalthreats.ItperformsdeepinspectionofInternetprotocolssuchasHTTP,FTP,SMTP,steamingmediaapplications,H.323,IDS,RPC,SOCKSandWebProxyfilterswhichenablesittodetectmanythreatsthattraditionalfirewallscannotdetect

VPN – Secure Remote Client Access and Regional Office Connectivity:

3

•IntegratedVPNclientaccessIntegratedbasedonWindowsServer2008functionality

•VPNClientstatefulfiltering,deepinspectionandquarantine,helpingprotectnetworksfromattacksthatenterthroughaVPNconnection

•Site-SiteIPSecConnectivitybetweentwoseparateoffices,statefulfilteringandinspectionofremoteofficeresourceaccess

•Secureaccesstoremoteusersoutsidethecorporatenetwork,protectswebapplicationbehindthefirewallsuchasWebServers,Share-PointPortal,IIS,E-mailserverapplicationslike“outlookanywhere”accesstoExchangeusingOutlookWebandMobileAccess(OWA/OMA),ActiveSyncandRPCoverHTPS.

High Performance Web Caching and Bandwidth Optimization:

Secure Web and Messaging Protection:

Monitoring, Logging and Reporting:

Secure Web Gateway for Corporate Networks

Microsoft®Forefront™ThreatManagementGateway2010isasecureWebgatewaythatenablesemployeestousetheInternetsafelyandproductivelywithoutworryingaboutmalwareandotherthreats.TohelpblockthelatestWeb-basedthreats,itprovidesmultiplelayersofcontinuouslyupdatedprotectionsincludingURLfiltering,malwareinspection,andintrusionprevention.

Forefront Threat Management Gateway (TMG) 2010 is designed to increase the security of corporate Web usage by:•Preventingmalwareoutbreakscausedbyinadvertentemployeevisitstomalicioussitesorbydownloadsofinfectedfiles.•EnforcingWebsecuritypolicyforapplicationprotection,malwareinspection,andURLfiltering

Unified Web Security Interface: SingleinterfaceformanagingWebsecuritypolicy

Forefront nTMG delivers comprehensiveprotectionagainstWeb-basedthreats,integratedintoaunifiedgatewaythatreducesthecostandsimplifiesthecomplexityofWebsecurity.

Comprehensive Protection:•Blocksmalicioussitesmoreeffectively•PreventsExploitationofvulnerabilities•CatchesWeb-basedmalware•Deliverscorenetworkprotectionfeatures•Extendsenforcementtoencryptedweb-traffic

Integrated Security:•Deliversasinglesourceforwebsecurity•ReducesCosts•Leveragesexistinginfrastructureinvestments

Simplified management:•Centralizesmanagementinasingle,easy-to-

useconsole•Deliverscomprehensivecustomreports

The secure Web gateway solution includes four components:•TheForefrontTMG2010server,whichprovides

multipleinspectiontechnologies,includingapplication-andnetwork-layerfirewall,intrusionprevention,andmalwarefilteringtokeepuserssafefromWeb-basedattacks.ItconnectstotheForefrontTMGWebProtectionService*forURLfilteringandanti-malwareupdates.ForefrontTMGWebProtectionService,whichdeliversanti-malwareupdatesandprovidesareal-timeconnectiontocloud-basedURLfilteringtechnologiesthatcanbeusedtomonitororblockemployeeWebusage.

•Themanagementconsole,whichofferslocalpolicymanagementfornTMGserver

•Amanagementserver(onlyavailablewithpurchaseofForefrontnTMGEEnterpriseEdition),whichenablesthecreationofenterprise-widepoliciesthatcanbeassignedtoanarrayofnTMGservers.

•ForefrontnTMGcanscaleperformancewhenadministratorsdeploymultipleForefrontnTMGatindividualsites.

Better Protection Against Web-Based Threats

ForefrontTMG2010protectsemployeesfromWeb-basedthreatsbyintegratingmultiplelayersofsecurityintoaneasy-to-managesolution.Deployedoncorporatenetworksasaunifiedgateway,ForefrontTMG2010inspectsWebtrafficatthenetwork,application,andcontentlayerstohelpensureasingle,consistentWebpolicy.Inadditiontocomprehensiveprotection,italsohelpsimprovefirewallperformancebyoffloadingprocessor-intensivefunctionslikeinspectionformalware.

Key Features and Benefits

www.nappliance.com

nTMG Series: Secure Remote Office Gateway FunctionalityHelps connect remote-site regional offices

OrganizationscanusenTMGseriesappliancetoconnecttoandsecuretheirregionalofficesordepartments.Itoffersacost-effectivesolutionforsite-to-sitevirtualprivatenetwork(VPN)connectivity.

•LowCost,EasytoDeploy,Non-managedRegionalofficeconnectivitysolution

•FourModelstochoosefrom,custom-builtforSmall,MidandLargeBusinesses

•RedundantHotswapDisksandPowerSupplyModules

•LargeNetworkPortDensity&RemoteKVMSupport

•Built-inDualNodeHighAvailabilityNLBSupport

•PoweredbyMicrosoftForefrontTMG2010–StandardEdition.

nTMGB, when used in conjunction with nTMGE series of appliances offers advance centralized management of large number of remote offices and efficient network bandwidth by providing HTTP compression and caching of content - including software updates. Please visit nTMGE Series on our website for more information.

Net-Gateway nTMG Business Series: Integrated Security Gateway Appliance

InternetsuchasOutlookWebAccess,SharePoint,WebserverandTerminalservices.

Anywhere VPN Remote Access Solution:

Securelyextendaccesstopartners,customers,consultantsandremoteemployeestoapplications,documents,anddatafromanyPCordevicefromoutsidethecorporatenetwork.

Site-to-Site VPN Connectivity Solution:

AsanalternativetonTMGBseries

appliances,itofferseasy,LowCostcorporatenetworkexpansion.Idealsolutionfordepartmentsandlargenumberofremoteofficesofallsizesatmultiplelocations.

Intelligent Content Caching and Acceleration:

Activecontentcachingandschedulingenhancebandwidthefficiency.

Deployment Scenarios:ThenAppliancenTMGisafullyintegrated“’all-in-one”securitygatewayappliance,itiseasytodeploywithout-of-boxturnkeyconvenience.Itprovides:

Unified Gateway Security Solution:

Purpose-built,robust,standalone,multi-purpose,fullyfeaturedcorporateapplicationFirewall,IPS,VPN,CachingandUnifiedThreatManagement(UTM)capability.Itisoneplatformwhichfitsallbusinesssecurityneeds,providesbusinesscontinuitythroughmultiplelinkmanagement,singlesign-onandseamlessActiveDirectoryServiceintegration.

Web and Email Content Filtering Solution:

Comprehensiveemployeeaccesscontrolandprotectionagainstexternalandinternalweb-basedthreads.ItprovidescontinuousupdatesforURLfiltering,anti-virus&anti-malware,anti-spamandExchangeemailsecurityserviceforbusinessesofallsizes.

Secure Web Application Publishing Solution:

Streamlineremoteaccessbyprovidingsecurityforcorporateapplicationsaccessedoverthe

www.nappliance.com

2

1

3

4

5

6

nAppliance Networks, Inc.540 Dado Street, San Jose, CA 95131, USAPhone: 1-408-895-5000 (Local) 1-877-895-nAPP (6277) (US-Toll Free) 011-408-895-5000 (International)Fax: 1-408-943-8222/8101 Email: info@nappliance.com Website: http//www.nappliance.com

nApplianceNetworks,NetGateway,nTMG,nTMGE,nUAG,Sonavault,Oneface,ARRMSaretrademarksofnApplianceNetworks,Inc.Allotherbrands,productnames,tradenames,trademarksandservicemarksusedhereinarethepropertyoftheirrespectiveowners.Copyright©1996-2010nApplianceNetworks,Inc.Allrightsreserved.

3rd Party Add-On Integration:

Offers Comprehensive ISV security application support

nApplianceForefrontapplianceplatformsarepurpose-built,highperformancehardwaredevicesintegratedwithnAppliancedesignedOneface™systemmanagementtoolsandMicrosoftForefrontEdgeSecuritySoftwareSolutions.nApplianceForefrontSecurityproductsarepre-integratedwithanumberofadditionalindustryleadinganduseful3rdpartysecuritysoftwaremodulestogreatlyincreasethecapabilitiesof

Microsoft Forefront TMG Appliance Editions ComparisonForefront Gateway Appliance Platform Benefits

• Intelligent Application Gateway Platform.Integratedappliancefornetworkperimeterdefense,remoteaccess,application-layerprotection,webcontentcaching,emailandwebprotectionforMicrosoftbasedInfrastructures

•Centralized Policy Based Access Control.Centralizespolicymanagement,controllingaccessbyprotocolorapplicationtypeandbyuser,group,roles,schedules,contenttypetiedtoActiveDirectory

•Easy Windows MMC based Manageability. Traditionally,enterprise-classfirewallshavehadareputationforbeingdifficulttolearn,configureandmaintain.Net-GatewaynTMGseriesoffersindustrymostadvancefeatureandfamiliarwindowsinterfaceandisthemostcompleteproductinitsclass

•Lowest Total Cost of Ownership. ExceptionaleaseofimplementationenablesITleaderstobeconfidentthattheirnetwork,users,clientdevices,andapplicationareprotectedwiththeleadingMicrosoftsecurityappliancefamilycelebratedforassuredperformanceandlowestTCO

•Centralized Appliance Management through ONEface™. OurIntuitiveWebGUImanagementtoolofferseasynetworksetup,configuration,backup/restore,updates,logging,reporting,3rdpartysecurityapplicationsadd-onandcentralizedappliancemanagement

•Appliance Recovery and Remote Management (ARRMS™).OurrecoverysystemcombinedwithadvancedLCDfunctionalityoffersappliancerecoverytofactorydefaultsenablesmultiplesystemimagecopiesbackuptolocaldiskornetwork,andinstantrestoretolastgoodknownstate.

•Superior Product Technology, Value and Support.Stateoftheartsystemandapplicationintegration,bestprice-to-performance-ratiosintheindustry,deploymentassistanceforMicrosoftForefrontGatewaytechnologies,globaltechnicalsupport,efficientappliancelifecyclemanagementandupgrades,andaboveallfutureproofingwithMicrosoftsecurityarchitecture. nAppliance delivers Integrated Appliance “Turnkey” Solutions:

nApplianceNetworks,an ISO9001:2000 isaproviderofmissioncriticalnetworkedgesecu-rityinfrastructureprovider.Unlikealternativesthataresimplybasedongeneral-purposeserverhardware, our appliances are designed for highest reliability, optimized for maximum perfor-mance,andmanufacturedtoexactqualityspecifications.TrustnApplianceNet-GatewayFore-frontapplianceseriestodeliverreliableandcomprehensivesolutions.

eachoftheappliance.Theseoptional-packagesaretested,pre-loadandmadeavailableasaninstalloptionsforyourconvince.Customerscanchooseneededoptional-packagesforinstallationmanuallyandpurchaseasoftwarelicenseforactivation.Allsecuritysoftwareapplicationpackagesrunonahardenedoperatingsystem,securelymanagedandupdatedviaONEface,thenApplianceappliancemanagementservicesinterface.

“Best-of-the-Breed”ISVAdd-OnSecurityApplicationSupport.These3rdpartyadd-onsincludeQoS,BandwidthandWANOptimization,ContentManagement,Multi-FactorAuthentication,Single-Sign-OnandAdvanceReportingsoftwarecomponents.nApplianceComponentManager,aMMCbasedsnap-intoolallowsthecustomerstoaddandremoveadditionalcomponentsasdesired.

TOTAL SECURITY: Purpose-Built, Microsoft Forefront TMG Optimized Appliance

Comprehensive ISV Support

nApplianceIntegrated3rdPartySecurityComponents

•WANOptimization•QoS,TrafficShaping•Multi-FactorAuthentication•Single-Sign-On