NetDefend UTM Firewall Series



Similar documents
NetDefend UTM Firewall Series

NetDefend UTM Firewall Series

NetDefend UTM Firewall Series

Network Security Firewall

Unified Services Routers

NetDefend Firewall UTM Services

Unified Services Routers

NetDefend Firewall UTM Services

How To Protect Your Network From Attack From A Virus And Attack From Your Network (D-Link)

Unified Services Routers

Wireless Controller DWC-1000

Cisco RV082 Dual WAN VPN Router Cisco Small Business Routers

Gigabit Multi-Homing VPN Security Router

Cisco RV 120W Wireless-N VPN Firewall

SonicWALL Clean VPN. Protect applications with granular access control based on user identity and device identity/integrity

Cisco RV180 VPN Router

How To Use A Cisco Wvvvdns4400N Wireless-N Gigabit Security Router For Small Businesses

Gigabit Content Security Router

Cisco WRVS4400N Wireless-N Gigabit Security Router: Cisco Small Business Routers

Gigabit SSL VPN Security Router

Network Security. Protective and Dependable. Pioneer of IP Innovation

Total solution for your network security. Provide policy-based firewall on scheduled time. Prevent many known DoS and DDoS attack

ZyWALL USG100-PLUS Unified Security Gateway. Security on a New Level. Benefits. - The Future Is Ahead. Stay Ahead with ZyXEL USG100-PLUS

Firewall Defaults and Some Basic Rules

The Ultimate WLAN Management and Security Solution for Large and Distributed Deployments

Deploy and Manage a Highly Scalable, Worry-Free WLAN

Firewall Defaults, Public Server Rule, and Secondary WAN IP Address

Network Security. Protective and Dependable. 52 Network Security. UTM Content Security Gateway CS-2000

Gigabit Multi-Homing VPN Security Router

Cisco ASA 5500 Series IPS Solution

IREBOX X. Firebox X Family of Security Products. Comprehensive Unified Threat Management Solutions That Scale With Your Business

Huawei Eudemon200E-N Next-Generation Firewall

Intelligent WLAN Controller with Advanced Functions

How To Set Up A Cisco Rv110W Wireless N Vpn Network Device With A Wireless Network (Wired) And A Wireless Nvv (Wireless) Network (Wireline) For A Small Business (Small Business) Or Remote Worker

SonicWALL Advantages Over WatchGuard

USG6600 Next-Generation Firewall

Cisco RV220W Network Security Firewall

Cisco RV215W Wireless-N VPN Router

Public Internet Access Done the Right Way

Cisco SR 520-T1 Secure Router

Network Security. Network Security. Protective and Dependable. > UTM Content Security Gateway. > VPN Security Gateway. > Multi-Homing Security Gateway

Cisco RV110W Wireless-N VPN Firewall

Cisco RV110W Wireless-N VPN Firewall

Security on a New Level -The Future Is Ahead. Stay Ahead with ZyXEL USGs.

Extreme Security Threat Protection G2 - Intrusion Prevention Integrated security, visibility, and control for next- generation network protection

Security Gateway 10er Serie

White Paper. ZyWALL USG Trade-In Program

WATCHGUARD FIREBOX VCLASS

Fortigate Features & Demo

Cisco RV220W Network Security Firewall

Secure your Informations efficiently. SECURITY: FIREWALL & VPN CLIENTS Trends Features Products and Solutions jfrancis@dlink.de

Load Balance Router R258V

DrayTek Vigor High Performance Firewall Router. - VPN - Up to 200 concurrent tunnels. - Load Balancing & Failover between WAN ports

USG6300 Next-Generation Firewall

Chapter 9 Firewalls and Intrusion Prevention Systems

Managed 24/48-Port 10/100Mbps plus 2 Gigabit Copper Ports and 2 Combo SFP Slots

ZyWALL USG 20/20W/50/ 100/200 Unified Security Gateway. Security on a New Level. Benefits. -The Future Is Ahead. Stay Ahead with ZyXEL USGs.

Ixia Director TM. Powerful, All-in-One Smart Filtering with Ultra-High Port Density. Efficient Monitoring Access DATA SHEET

Cisco RV180W Multifunction VPN Router

Simple security is better security Or: How complexity became the biggest security threat

Unpacking the Product. Rack Installation. Then, use the screws provided with the equipment rack to mount the firewall in the rack.

Gigabit Multi-Homing VPN Security Gateway

Ultra-fast Performance for Tomorrow s VPN Deployments

Enterprise Wireless LAN. Key Features. Benefits. Hotspot/Service Gateway Series

Securing Networks with PIX and ASA

UTT Technologies offers an effective solution to protect the network against 80 percent of internal attacks:

LB Intelligent Multi-WAN Router

ProSecure Unified Threat. UTM Series. Unified Gateway Security for Smart IT Networks Without Compromise

McAfee Network Security Platform A uniquely intelligent approach to network security

ENHWI-N n Wireless Router

Introduction of Quidway SecPath 1000 Security Gateway

Security+ Guide to Network Security Fundamentals, Fourth Edition. Chapter 6 Network Security

Firewalls, Tunnels, and Network Intrusion Detection

1. Built-In SPI Firewall to Protect Your Enterprise Network 2. Multi-Spam-Filtering Function Providing High Spam-Filtering Accuracy

/ /Res Dated INVITATION FOR BIDS

CaptIO Policy-Based Security Device

- Introduction to PIX/ASA Firewalls -

UNIFIED THREAT MANAGEMENT SOLUTIONS AND NEXT-GENERATION FIREWALLS NETWORK SECURITY NETWORK SECURITY I ENDPOINT SECURITY I DATA SECURITY

Move over, TMG! Replacing TMG with Sophos UTM

Firewalls, Tunnels, and Network Intrusion Detection. Firewalls

Cisco SA 500 Series Security Appliances

Content Scanning for secure transactions using Radware s SecureFlow and AppXcel together with Aladdin s esafe Gateway

How NETGEAR ProSecure UTM Helps Small Businesses Meet PCI Requirements

SonicOS 5.9 / / 6.2 Log Events Reference Guide with Enhanced Logging

Secure and Always Online Networking for Small- to Medium-sized Businesses

Product Factsheet MANAGED SECURITY SERVICES - FIREWALLS - FACT SHEET

Cisco Small Business ISA500 Series Integrated Security Appliances

Network protection and UTM Buyers Guide

IBM Security Network Protection

Cyberoam Next-Generation Security. 11 de Setembro de 2015

The All-in-One, Intelligent WLAN Controller

Securing the Small Business Network. Keeping up with the changing threat landscape

Transcription:

Product Highlights Increased Security Integrated Firewall/VPN and UTM provides protection from viruses, intrusions and harmful content. Reduced Cost of Ownership Subscription service per firewall rather than per user reduces licensing cost and simplifies management. Easily Manage and Control Internet Usage Fast, efficient web content filtering helps administrators monitor and control employee Internet usage. DFL-260E/860E/1660/2560/2560G NetDefend UTM Firewall Series Features Integrated Firewall/VPN Powerful Firewall Engine Virtual Private Network (VPN) Security Granular Bandwidth Management 802.1Q VLAN Tagging and Port-based VLAN D-Link End-to-End Security Solution (E2ES) Integration with ZoneDefense 9 High Availability 11 Advanced Functions Stateful Packet Inspection (SPI) Detect/Drop Intruding Packets Server Load Balancing Policy-based Routing Unified Threat Management Optional Service Subscriptions Intrusion Prevention System (IPS) Antivirus (AV) Protection Web Content Filtering (WCF) Virtual Private Network (VPN) IPSec NAT Traversal VPN Hub and Spoke IPSec, PPTP, L2TP DES, 3DES, AES, Twofish, Blowfish,CAST-128 Encryption The D-Link NetDefend Unified Threat Management (UTM) firewalls provide a powerful security solution to protect business networks from a wide variety of threats. UTM Firewalls offer a comprehensive defense against virus attacks, unauthorized intrusions, and harmful content, successfully enhancing fundamental capabilities for managing, monitoring, and maintaining a healthy network. Unified Threat Management NetDefend UTM Firewalls integrate intrusion detection and prevention, gateway antivirus, and content filtering for superior Layer 7 content inspection protection. The real-time update service keeps the IPS information, antivirus signatures, and URL databases current. Combined, these enhancements help to protect office networks from application exploits, network worms, malicious code attacks, and provide everything a business needs to safely manage employee Internet access. Powerful VPN Performance NetDefend UTM Firewalls offer an integrated VPN Client and Server allowing remote offices or trusted partner to securely connect to a head office. Mobile users working remotely from home or on the road can also safely connect to the office network to access company data and e-mail. NetDefend UTM Firewalls incorporate hardware-based VPN engines to support and manage a large number of VPN configurations.

Automated Key Management via IKE/ISAKMP Aggressive/Main/Quick Negotiation Multiple WAN Interfaces for Traffic Load Sharing 6 Enhanced Network Services DHCP Server/Client/Relay IGMP V3 H.323 NAT Traversal Robust Application Security ALGs OSPF Dynamic Routing Protocol 9 Run-Time Web-Based Authentication DFL-260E Firewall Throughput: 150 Mbps VPN Performance: 45 Mbps (3DES/AES) 1 10/100/1000 Ethernet WAN Port 5 Switched 10/100/1000 Ethernet LAN Ports 1 10/100/1000 Ethernet DMZ Port DFL-860E Firewall Throughput: 200 Mbps VPN Performance: 60 Mbps (3DES/AES) 2 10/100/1000 Ethernet WAN Ports 8 Switched 10/100/1000 Ethernet LAN Ports 1 10/100/1000 Ethernet DMZ Port DFL-1660 Firewall Throughput: 1.2 Gbps VPN Performance: 350 Mbps (3DES/AES) 6 Configurable Gigabit Ethernet Ports DFL-2560(G) Firewall Throughput: 2 Gbps VPN Performance: 1 Gbps (3DES/AES) 10 Configurable Gigabit Ethernet Ports 4 SFP Ports (DFL-2560G) Advanced VPN configuration options include: DES/3DES/AES/Twofish/Blowfish/CAST-128 encryption Manual or IKE/ISAKMP key management Quick/Main/Aggressive Negotiation modes VPN Authentication support using Radius server or user database Enterprise-Class Firewall Security NetDefend UTM Firewalls provide a complete set of advanced security features to manage, monitor, and maintain a healthy and secure network. Network management features include: Remote Management and Access Policies Bandwidth Control Policies URL Blacklists and Whitelists UTM Services Maintaining an effective defense against the various threats originating from the Internet requires that all three databases used by the NetDefend UTM Firewalls are kept up-to-date. In order to provide a continuous defense, D-Link offers optional UTM Service subscriptions which include updates for each defense: Intrusion Prevention Systems (IPS) Antivirus Protection (AV) Web Content Filtering (WCF). NetDefend UTM Subscriptions ensure that each of the firewall s service databases are complete and effective. Robust Intrusion Prevention 10 The NetDefend UTM Firewalls employ component-based signatures, a unique IPS technology which recognizes and protects against all varieties of known and unknown attacks. This system can address all critical aspects of an attack or potential attack including payload, NOP sled, infection, and exploits. The IPS database includes attack information and data from a global attack sensor-grid and exploits collected from public sites such as the National Vulnerability Database and Bugtrax. The NetDefend UTM Firewalls constantly create and optimize NetDefend signatures via the D-Link Auto-Signature Sensor System without overloading existing security appliances. These signatures ensure a high ratio of detection accuracy and a low ratio of false positives. Stream-based Virus Scanning 10 The NetDefend UTM Firewalls examine files of any size, using a stream-based virus scanning technology which eliminates the need to cache incoming files. This zero-cache scanning method not only increases inspection performance but also reduces network bottlenecks. NetDefend UTM firewalls use virus signatures from Kaspersky Labs to provide systems with reliable and accurate antivirus protection, as well as prompt signature updates. Consequently, viruses and malware can be effectively blocked before they reach desktops or mobile devices.

Fast, Efficient Web Content Filtering 10 Web Content Filtering helps administrators monitor, manage, and control employee Internet usage. The NetDefend UTM Firewalls implement multiple global index servers with millions of URLs and real-time website data to enhance performance capacity and maximize service availability. These firewalls use granular policies and explicit blacklists and whitelists to control access to certain types of websites for any combination of users, interfaces, and IP networks. The firewall can actively handle Internet content by stripping potential malicious objects, such as Java Applets, JavaScripts/VBScripts, ActiveX objects, and cookies. NetDefend UTM Subscription The standard NetDefend UTM Subscription provides your firewall with UTM service updates for 12 months starting from the day you activate or extend your service.2 The NetDefend UTM Subscription can be renewed regularly to provide your firewalls with the most up-to-date security service available from D-Link. NetDefend Center: http://security.dlink.com.tw Powerful VPN Engine Hardware-based data encryption and authentication for IPSec, PPTP, L2TP, and SSL in Client/Server mode enable fast and safe handling of VPN traffic. 1 Professional Intrusion Prevention System (IPS) Automatic updates from a comprehensive IPS signature database focus on attack payloads to protect the network against zero-day attacks. Real-Time Antivirus Inspection (AV) The antivirus engine scans using the most complete, most up-to-date antivirus signature database. Streaming-based pattern matching provides effective protection against viruses. Secure Network Implementation Using NetDefend UTM Firewalls Licensed for Unlimited Users Optional subscription services for IPS, Antivirus Scanning, and Web Content Filtering are priced per firewall rather than per user, thus reducing the total cost of ownership for licensing. WAN Link Load-Balancing and Fault-Tolerance Multiple WAN ports support traffic load balancing and failover, thus guaranteeing Internet availability and bandwidth. D-Link End-to-End Security (E2ES) Solutions 9 The ZoneDefense mechanism, operating in conjunction with D-Link xstack switches, automatically quarantines infected workstations and prevents them from flooding the internal network with malicious traffic. D-Link Green Certified The D-Link Green certified DFL-1660 and DFL-2560(G) are built with an 80 PLUS internal power supply. 80 PLUS certified power supplies offer increased reliability due to greater efficiency, and provide a reduced cost of ownership through longer equipment life. Additionally, 80 PLUS power supplies help prevent pollution by limiting energy consumption, and run at a lower temperature reducing cooling costs. The DFL-260E and DFL-860E save energy automatically through cable length and link status detection. By detecting the length of cables connected to a port, the amount of power used for the port can be adjusted, only using as much as is needed. The DFL-260E/860E also detect if a port is not in use, and can automatically reduce the power used for that port, cutting energy used for it by a substantial amount. D-Link Green certified devices comply with RoHS (Restriction of Hazardous Substances) and WEEE (Waste Electrical and Electronic Equipment) directives. RoHS directives restrict the use of specific hazardous materials during manufacturing, while WEEE implements standards for proper recycling and disposal. Together, these considerations make D-Link Green firewall products the environmentally responsible choice.

Technical Specifications DFL-260E DFL-860E DFL-1660 DFL-2560(G) Ethernet Ports 1 10/100/1000 DMZ port (configurable) 1 10/100/1000 WAN port 5 Switched 10/100/1000 LAN ports 1 10/100/1000 DMZ port (configurable) 2 10/100/1000 WAN port 8 Switched 10/100/1000 LAN ports 6 configurable 10/100/1000 ports 10 configurable 10/100/1000 ports SFP 4 SFP ports (DFL-2560G ONLY) 7 USB 2 USB ports (reserved) Console RS-232 DB-9 RS-232 System Performance 1 Firewall Throughput 2 150Mbps 200Mbps 1.2Gbps 2Gbps VPN Throughput 3 45Mbps 60Mbps 350Mbps 1Gbps IPS Throughput 4 60Mbps 80Mbps 400Mbps 600Mbps Antivirus Throughput 4 35Mbps 50Mbps 225Mbps 450Mbps Concurrent Sessions 25,000 40,000 600,000 1,500,000 New Sessions (per second) 2,000 4,000 15,000 20,000 Policies 500 1,000 4,000 6,000 Firewall System Dynamic Routing Protocol Proactive End-Point Security Transparent Mode NAT, PAT H.323 NAT Traversal Time-Scheduled Policies Application Lyer Gateway OSPF ZoneDefense Networking DHCP Server/Client DHCP Relay Policy-Based Routing Port-based VLAN IEEE 802.1q VLAN 8 16 1024 2048 IP Multicast IGMP v3 Virtual Private Network (VPN) Encryption Methods (DES/3DES/AES/Twofish/Blowfish/ CAST-128) PPTP/L2TP Server SSL VPN Hub and Spoke IPSec NAT Traversal Dedicated VPN Tunnels 100 300 5 2,500 5,000 Traffic Load Balancing Outbound Load Balancing Traffic Redirect at Fail-over Outbound Load Balancing Traffic Redirect at Fail-over Server Load Balancing Outbound Load Balance Algorithems Round-robin, Weight-based Round-robin, Destination-based, Spill-over

Bandwidth Management Policy-Based Traffic Shaping Guaranteed Bandwidth Dynamic Bandwidth Balancing Maximum Bandwidth Priority Bandwidth High Availability WAN Fail-Over WAN Fail-Over Active-Passive Mode Device Failure Detection Link Failure Detection FW/VPN Session SYN Intrusion Detection & Prevention System (IDP/IPS) Automatic Pattern Update DoS, DDoS Protection Attack Alarm via E-mail Advanced IDP/IPS Subscription Automatic Pattern Update DoS, DDoS Protection Attack Alarm via E-mail Advanced IDP/IPS Subscription IP Blacklist by Threshold or IDP/IPS Content Filtering Antivirus Physical & Environmental HTTP Type: URL Blacklist/Whitelist Script Type: Java, Cookie, ActiveX, VB Real Time AV Scanning Unlimited File Size Scans VPN Tunnels Email Type: E-mail Blacklist/Whitelist External Database Content Filtering Supports Compressed Files Automatic Pattern Update Signature Licensor: Kaspersky Power Supply Internal Power Supply 80 PLUS Internal Power Supply Dimensions 11.02 x 7.08 x 1.73 (280 x 180 x 44mm) 11 Racket Mount 12.99 x 7.08 x 1.73 (330 x 180 x 44mm) 13 Rack-Mount 17.32 x 15.75 x 1.73 (440 x 400 x 44mm) 19 Standard Rack-Mount Operating Temperature Storage Temperature Operating Humidity 32 F to 104 F (0 to 40 C) -40 F to 158 F(-20 to 70 C) 5% to 95% non-condensing EMI FCC Class A CE Class A C-Tick VCCI Safety UL LVD (EN60950-1) LVD (EN60950-1) cul, CB MTBF 186,614 Hours 140,532 Hours 400,000 Hours 310,000 Hours Warranty Warranty Limited Lifetime Ordering Information Part Number DFL-260E-NB DFL-260-IPS-12 DFL-260-AV-12 DFL-260-WCF-12 DFL-860E-NB DFL-860-WCF-12 DFL-860-IPS-12 DFL-860-AV-12 Description NetDefend Network Security UTM Firewall, 1 Gigabit WAN, 1 Gigabit DMZ, 5T LAN (90-Day IPS Subscription) NetDefend IPS 1-Year Subscription for DFL-260/DFL-260E NetDefend AV 1-Year Subscription for DFL-260/DFL-260E NetDefend WCF 1-Year Subscription for DFL-260/DFL-260E NetDefend Network Security UTM Firewall, 2 Gigabit WAN, 1 Gigabit DMZ, 8 Gigabit LAN (90-Day IPS Subscription) NetDefend WCF 1-Year Subscription for DFL-860/DFL-860E NetDefend IPS 1-Year Subscription for DFL-860/DFL-860E NetDefend AV 1-Year Subscription for DFL-860/DFL-860E

Ordering Information Part Number DFL-1600 DFL-1660-AV-12 DFL-1660-IPS-12 DFL-1660-WCF-12 DFL-1660-NB DFL-1600-AV-12 DFL-1600-IPS-12 DFL-1600-WCF-12 DFL-2560-NB DFL-2560G-NB DFL-2560-AV-12 DFL-2560-IPS-12 DFL-2560-WCF-12 Description NetDefend Network Security Firewall, 6 User-Configurable Gigabit Ports (90-Day IPS Subscription) NetDefend AV 1-Year Subscription for DFL-1660 NetDefend IPS 1-Year Subscription for DFL-1660 NetDefend WCF 1-Year Subscription for DFL-1660 NetDefend Network UTM Firewall, IU, 6GbE, 90 day IPS/AV/WCF NetDefend AV 1-Year Subscription for DFL-1600 NetDefend IPS 1-Year Subscription for DFL-1600 NetDefend WCF 1-Year Subscription for DFL-1600 NetDefend Network UTM Firewall, IU, 10GbE, 90 day IPS/AV/WCF NetDefend Network UTM Firewall, IU, 6GbE, 4SFP, 90 day IPS/AV/WCF NetDefend AV 1-Year Subscription for DFL-2560/2560G NetDefend IPS 1-Year Subscription for DFL-2560/2560G NetDefend WCF 1-Year Subscription for DFL-2560/2560G 1 Actual performance may vary depending on network conditions and activated services. 2 The maximum Firewall plaintext throughput is based on RFC2544 testing methodologies. 3 VPN throughput is measured using UDP traffic at 1420 byte packet size adhering to RFC 2544. 4 IPS and Anti-Virus performance test is based on HTTP protocol with a 1Mb file attachment run on the IXIA IxLoad. Testing is done with multiple flows through multiple port pairs. 5 Performance based on firmware 2.27.00 and above 6 Available when DMZ port is configured as WAN port 7 Compatible with D-Link SFP module transceivers: DEM-310GT, DEM-311GT, DEM-312GT2, DEM-314GT, DEM-315GT, DGS-712 8 Sold seperatley 9 For DFL-860E, DFL-1660, and DFL-2560(G) only 10 With optional subscription services 11 For DFL-1660 and DFL-2560(G) only Updated 12/7/11 DFL-260E DFL-860E DFL-1660 DFL-2560 DFL-2560G For more information U.S.A. 17595 Mt. Herrmann Street Fountain Valley, CA 92708 800.326.1688 dlink.com Canada 2525 Meadowvale Blvd Mississauga, ON L5N 5S2 800.361.5265 dlink.ca 2011 D-Link Corporation/D-Link Systems, Inc. All rights reserved. D-Link, the D-Link logo, and D-ViewCam are trademarks or registered trademarks of D-Link Corporation or its subsidiaries in the United States and/or other countries. Other trademarks or registered trademarks are the property of their respective owners. Visit www.dlink.com for more details. Building Networks for People