Komplettschutz für den Mittelstand 26.04.2007 Paderborn Clemens Guttenberger System Engineer DACH
Agenda Produktüberblick LiveDemo Fireware 9.0 SecurityServices Fireware Edge 8.5 Fragen
Über uns : Gründungsjahr 1996, Hauptsitz in Seattle, Washington ~300 Mitarbeiter weltweit Der erste Hersteller mit deep application inspection auf einer Appliance (1997) 2006 Unified threat management (UTM) für alle Modelle: Edge, Core, Peak. Mehr als 350,000 appliances ausgeliefert Kunden in mehr als 150 Ländern
Fireware 9.0 verfügbar seit 17. April 2007
Firebox X e-series Produktübersicht Peak Fireware Pro Core Fireware Fireware Pro - optional Edge Fireware Edge
Produktdetails Firebox X Peak:
What s New to 9.0 X550e VPN Enhancements 9.0 Upgrade 8.3 Bundled MUVPN Max MUVPN BOVPN X550e 5 10 75 35* 1* *Upgradeable to to 45 10
What s New to 9.0 Faster Core & Peak Throughput 9.0 Update 8.3 Firebox Core X550e X750e X1250e Firewall Throughput 300+ 125 300+ 200 300+ Firebox Peak X5500e X6500e X8500e Firewall Throughput 900 1.5gbps 2.0+gbps 2.0+gbps 2.0+gbps 2.0+gbps
What s New to 9.0 Features of Core & Peak 9.0 Update Feature Fireware Fireware Pro VPN Failover Internet Key Exchange (IKE) 3rd Party Certificates Drag-and-Drop Tunnels with Firewall Rules Quality of Service Enhancements Traffic Shaping Load Balancing Multi-WAN Enhancements Virtual Local Area Network (VLAN) Policy-based Routing
LIVEDEMO
Neu in WSM 9.0 Firewall and BOVPN policy configuration have been merged on to a single tab in the Policy Manager Firewall rules apply to VPN tunnels
Neu in Fireware 9.0 DHCP mit MAC-Address Reservierung WAN failover control: Fireware can now monitor up to two destinations for network status using Ping, TCP-handshake, or both.
Neu in Fireware Pro 9.0 new multi-wan, load balancing algorithms for outbound traffic have been expanded to include: weighted round-robin interface bandwidth threshold Policy-based routing for outbound traffic, including interface failover, is now supported. VPN failover is now supported full traffic management and QoS, including: Minimum guaranteed bandwidth configuration options in each policy 8 priority levels for QoS Flexible QoS queuing to support strict queuing, weighted fair queuing, and weighted round-robin DSCP support, (Differentiated Service Code Point)
Neu in Fireware Pro 9.0 VLANs are now supported IKE 3rd party certificates for BOVPN: Verisign Microsoft Entrust RSA KEON High Availability: You can configure any licensed interface as a HA-interface.
WatchGuard System Manager Intuitive, easy-to-use management software Intuitive graphical interface Easy to learn; easy to use Unified management console No need to maintain separate software for multiple point solutions Interactive real-time monitoring Immediately see and understand what's happening in your network Drag-and-drop VPN Create secure branch office VPN tunnels quickly and easily Secure, flexible logging and comprehensive reporting Real-time VPN creation
WatchGuard UTM Security Services
Firebox X e-series UTM Bundles Lieferumfang 1 Firebox X e-series: 1 Jahr Gateway AV/IPS 1 Jahr spamblocker 1 Jahr WebBlocker 1 Jahr LiveSecurity Service Ein Artikel, ein Preis, eine Lösung
COMBINED PROTECTION With Security Services Gateway AV (e-mail, network, clients) IPS (e-mail, network, clients) URL (clients) Anti-Spam (e-mail) Anti-Spyware (e-mail, network, clients)
Comprehensive UTM Capabilities Security Services spamblocker WebBlocker Gateway AV/IPS) Full UTM available across all Firebox Appliances Edge, Core and Peak
Security Service: SpamBlocker Einfachste Konfiguration Realtime Erkennung von Massenausbrüchen #? Internet Realtime Detection Center Ja/Nein
Security Service: WebBlocker Einfachste Konfiguration URL Filter Optimierung von Webzugriffen 40 Kategorien Benutzer und Benutzergruppenabhängig Zeitabhängig
Security Service: GAV / Intrusion Prevention Einfachste Konfiguration Kontrolle über IM und P2P Gateway Antivirus für HTTP und SMTP Spyware Erkennung
MORE CONTROL
Fireware Edge 8.5.1
New Features of 8.5 Release HTTP, FTP, POP3 Proxies GAV/IPS Services SpamBlocker for POP3 mail Enhanced Help content Enhanced logging options Port Address Translation for policies Web-based debug utilities
Proxies for Edge
Edge 8.5 Proxies HTTP, FTP and POP3 proxies, similar to Fireware proxy functionality Edge proxies apply to outgoing (client) connections only Custom policies using proxies can be created
Edge 8.5 Proxy configuration Configure proxies in Firewall menu, as with other policies Click Edit button to configure proxy settings
POP3 PROXY
POP3 Proxy configuration Configurable time-out values Custom deny message for e-mail
POP3 Proxy filtering Restrict specific MIME types Restrict file pattern names
Security Services on Edge
Proxy-related services for Edge The Edge 8.5 release adds support for some features previously restricted to Core/Peak Fireware products: GAV IPS SpamBlocker for POP3
GAV/IPS Configuration
GAV/IPS Configuration Enable for each proxy Separate GAV/IPS settings Configurable size limit for scanning to improve performance
GAV/IPS Updates Automatic updates, manual updates, and signature status available License expiration details listed
SpamBlocker for POP3 proxy SpamBlocker configuration from new menu link For POP3 proxy, not SMTP, fitting Edge market
SpamBlocker settings Same categories as CommTouch product used in Fireware Configurable exceptions
LOGGING CHANGES
Per-policy logging options Logging can be enabled or disabled for each policy
Verbose proxy logs When enabled, proxy logs can be substantially more verbose than packet filter logs, but contain more detailed information
NEW HELP SYSTEM
In-line help system New help system provides greater depth and ease of access to information
In-line help system Detailed guides lead administrator through common tasks
PORT ADDRESS TRANSLATION
Port Address Translation Incoming firewall policies can now include port redirection
Port Address Translation After configuring the port a policy allows in at the External interface, you can configure port redirection for that policy s connections to an internal host
DEBUG UTILITY PAGE
debug.htm Helpful debug utilities can be reached by browsing to https://[firebox IP]/debug.htm View/edit configuration properties Ping targets Capture proxied packet traces Capture IPSEC debug information
Fragen?
Vielen Dank für Ihre Aufmerksamkeit!