Connect and Secure Retail Tomislav Tucibat, Major accounts Manager Adriatic February 2016 Copyright Fortinet Inc. All rights reserved.
2014: Year of the Retail Data Target 40 million card numbers, 70 million records Home Depot 56 million card numbers, 53 million records Michaels 2.6 million card numbers Staples 1.6 million card numbers Goodwill Industries 868,000 card numbers Breach 2 / 25
Technology Demands on Retail Networks New retail technologies Wireless POS, sales tablets, guest Wi-Fi, smart digital signage, presence analytics Compliance requirements PCI, regional data privacy compliance Security threats Advanced Persistent Threats Multiplied by many locations 3 / 25
Software Features Hardware Features Fortinet Connect and Secure Solution Wired Net PoE 3G/4G Management/ Reporting FortiSwitch FortiGate FortiExtender FortiManager WAN FortiAnalyzer Wireless Net FortiAP WAN/VPN FortiPresence FW & VPN Web Filtering WAN Optimization PoE Interfaces SSL Inspection User/Device ID Hybrid WAN 3G/4G connectivity IPS DLP WiFi Controller Space & Energy Saving Application Control Vuln. Scanning Endpoint Control AV/Sandbox Anti-spam Token Service 4 / 25
Network Security
Retail Store Device Proliferation INTERNET SaaS Gateway Management Multiple Management Consoles Web Filtering WAN Acceleration VPN Application Control Inconsistent Networking Functions Firewall Advanced Threat Protection IPS Slower Threat Response Antivirus WiFi Controller Potential Gap in Protection 6 / 25
FortiGate Device Consolidation Management INTERNET Single Management Console Firewall VPN Application Control IPS Web Filtering Antivirus WAN Acceleration Data Leakage Protection WiFi Controller Advanced Threat Protection SaaS Gateway FortiGate DCFW NGFW UTM Integrated Networking & Security Faster Threat Response FortiGate consolidates networking and security technologies into a single high performance appliance Consolidated Security Policy 7 / 25
Performance & Scalability FortiGate Entry Level Family FG-98D-POE FG-94D-POE FG-60D/-POE FWF-90D/-POE FWF-60D/-POE FG/FWF-60D- 3G4G FG-90D/-POE FGR-60D SoC2 FG-70D SoC2 FG-30D/-POE FG/FWF-92D FWF-30D/-POE FG-80D CPU SoC2 CPU FW <1G 1G 2G 2G 4G NGF W <250Mbps 250MB 1G 275MB 1G Ports 1 5 GE 1 10 GE 1 48 GE 8 / 25
Secure in-store Connectivity Wireless LAN, Wired LAN, Wireless WAN
FortiWiFi Overview FortiWiFi INTERNET Small Deployments - Up to 300 sq meters or 3,000 sq feet FortiWiFi 10 / 25
FortiWiFi Family FWF-30D/30D- POE FWF-60D/60D- POE FWF-90D/90D- POE Thick AP Number of radios 1 1 1 IEEE 802.11 standards a/b/g/n a/b/g/n a/b/g/n 802.11n support 2x2 MIMO 2x2 MIMO 2x2 MIMO Max client association rate 300Mbps 300Mbps 300Mbps Max number of SSIDs 8 8 8 Max Managed FortiAP (Total/ Local Bridge) 2/2 10 / 5 32 / 16 11 / 25
FortiAP overview FortiAP INTERNET Larger Deployments - More than 300 sq meters or 3,000 sq feet FortiGate/FortiWiFi WLAN Controller 12 / 25
Single Radio Dual Radio Dual Band FortiAP Family 3x3:3 FAP-320C FAP-321C 802.11ac 802.11ac FAP-222C 802.11ac FAP-223C 802.11ac 2x2:2 FAP-224D FAP-221C 802.11ac FAP-28C FAP-25D FAP-24D 1x1:1 FAP-21D FAP-14C FAP-112D FAP-11C Remote Outdoor Indoor 13 / 25
Fortinet Wireless Features for Retail Wireless IDS Rogue AP Suppression Layer 7 Application Control Integrated Guest Captive Portal 14 / 25
Non-PoE PoE FortiSwitch Secure Access Family FS-108D-POE FS-324B-POE FS-224D-POE FSR-112D-POE FS-124D-POE FS-448B FS-28C FS-124D FS-348B 8 port 24 port 48 port 15 / 25
Switch Segmentation for PCI Compliance FortiGate Switch Management Uses modified CAPWAP protocol like FortiAP View port speed, status, etc. Apply security policy Authentication via 802.1x or captive portal Segment Network 16 / 25
Problems with 3G/4G WAN in Retail Modems connected directly to CPE CPE usually located in a wiring closet Poorly located for optimal 3G/4G reception 17 / 25
FortiExtender Wireless WAN Solution Houses a 3G/4G modem Can be installed for optimal coverage Connects to FortiGate via Ethernet cable 18 / 25
FortiExtender family FortiExtender-20B FortiExtender-100B FortiExtender-100A-VZW (Band 13) Indoor w/ Security Lock USB Modem PoE or AC powered Outdoor, IP55 Rated USB Modem Ruggedized Construction PoE Powered Outdoor, IP55 Rated Internal Verizon 4G Modem Ruggedized Construction PoE powered 19 / 25
Retail Presence Analytics FortiPresence
Components: FortiPresence Solution Overview FortiAP or FortiWiFi: Detects Wi-Fi signal from smartphones FortiGate: Aggregates signal information from multiple APs FortiPresence: Processes data and presents analytics on dashboard FortiPresence 21 / 25
Measure FortiPresence: Measure. Connect. Total/New/Repeat Dwell time duration A/B store comparison VIP Alert Real-time Heat maps And more Influence Connect» Social Wi-Fi Login» Marketing Opt-in» Push coupon Influence» Analyzes Wi-Fi traffic» Detect product search» API can trigger:» Smart digital signs» Instant price cuts» Push Coupons 22 / 25
Case Study - Bobbejaanland Theme Park Retail Theme Park Located in Flanders, Belgium 56 acres, 50 attractions, 750,000+ visitors per year Challenge Growing attendance and improving profitability Increasing utilization of rides and attractions Connecting wireless Point-of-Sale systems Enabling guest Wi-Fi for visitors Solution FortiGate Deployed as Security Appliance and Wireless Controller 30+ FortiAP Access Points FortiPresence Analytics Service 23 / 25
Local case study - Plodine Plodine Located in Croatia 75 supermarkets across Croatia Challenge Protecting the local network Network segmentation Enabling guest Wi-Fi for visitors Solution 2xFortiGate 500D Deployed as Security Appliance and Wireless Controller 50+ FortiAP Access Points FortiAnalyzer 24 / 25
Thank you! ttucibat@fortinet.com