Replacing Microsoft Forefront Threat Management Gateway with F5 BIG-IP. Dennis de Leest Sr. Systems Engineer Netherlands



Similar documents
Protect your internal users on the Internet with Secure Web Gateway. Richard Bible EMEA Security Solution Architect

F5 Secure Web Gateway Services Reference Architecture

F5 Identity and Access Management (IAM) Overview. Laurent PETROQUE Manager Field Systems Engineering, France

Filling the Threat Management Gateway Void with F5

MANAGE SECURE ACCESS TO APPLICATIONS BASED ON USER IDENTITY. EMEA Webinar July 2013

Top 10 Reasons Enterprises are Moving Security to the Cloud

WHAT S NEW IN WEBSENSE TRITON RELEASE 7.8

Presented by Philippe Bogaerts Senior Field Systems Engineer Securing application delivery in the cloud

Post-TMG: Securely Delivering Microsoft Applications

+ web + DLP. Secure 1, 2, or all 3 with one powerful solution. The best security you can get for one or for all.

GET MORE OUT OF YOUR MICROSOFT APPLICATION INVESTMENTS. Jeppe Koefoed, F5 Networks

Web Security Gateway Anywhere

Security F5 SECURITY SOLUTION GUIDE

Comprehensive real-time protection against Advanced Threats and data theft

Fight Malware, Malfeasance, and Malingering with F5

Enabling Business Beyond the Corporate Network. Secure solutions for mobility, cloud and social media

Quick Start 5: Introducing and configuring Websense Cloud Web Security solution

Fidelis XPS Power Tools. Gaining Visibility Into Your Cloud: Cloud Services Security. February 2012 PAGE 1 PAGE 1

Deploying F5 to Replace Microsoft TMG or ISA Server

Enterprise Buyer Guide

WEBSENSE TRITON SOLUTIONS

Achieve Unified Access Control and Scale Cost-Effectively

TRITON AP-WEB COMPREHENSIVE REAL-TIME PROTECTION AGAINST ADVANCED THREATS & DATA THEFT

Cisco ASA and Cloud Web Security: Best-in-Class Network Security Combined with Best-in-Class Web Security

Secure Web Gateways Buyer s Guide >

Security Services. 30 years of experience in IT business

The Advantages of Security as a Service versus On-Premise Security

全 球 資 安 剖 析, 您 做 確 實 了 嗎? Albert Yung Barracuda Networks

Websense Web Security Solutions. Websense Web Security Gateway Websense Web Security Websense Web Filter Websense Express Websense Hosted Web Security

Dell SonicWALL Portfolio

Hayri Tarhan, Sr. Manager, Public Sector Security, Oracle Ron Carovano, Manager, Business Development, F5 Networks

APERTURE. Safely enable your SaaS applications.

Achieve Unified Access Control and Scale Cost-Effectively

How To Secure Your Employees Online With Zscaler.Com And Your Website From Being Infected With Spyware Or Malware

Achieve Unified Access Control and Scale Cost-Effectively

Achieve Unified Access Control and Scale Cost-Effectively

Websense Web Security Solutions. Websense Web Security Gateway Websense Web Security Websense Web Filter Websense Hosted Web Security

NetScaler: A comprehensive replacement for Microsoft Forefront Threat Management Gateway

Extending Threat Protection and Control to Mobile Workers with Cloud-Based Security Services > White Paper

Deliver Secure and Accelerated Remote Access to Applications

Intelligent, Scalable Web Security

Secure iphone Access to Corporate Web Applications

Key Findings. Websense Triton Security Gateway Anywhere

Putting Web Threat Protection and Content Filtering in the Cloud

Stop advanced targeted attacks, identify high risk users and control Insider Threats

Web Security Gateway Solutions

Infrastructure for more security and flexibility to deliver the Next-Generation Data Center

Data Sheet: Endpoint Security Symantec Protection Suite Enterprise Edition Trusted protection for endpoints and messaging environments

Check Point submitted the SWG Secure Web Gateway for

Cisco Cloud Web Security

Secure Cloud Computing

TRITON APX. Websense TRITON APX

The first agentless Security, Virtual Firewall, Anti- Malware and Compliance Solution built for Windows Server 2012 Hyper-V

DUBEX CUSTOMER MEETING

Achieve Unified Access Control and Scale Cost-Effectively

Symantec Protection Suite Add-On for Hosted and Web Security

WEBSENSE SECURITY SOLUTIONS OVERVIEW

Lab Testing Summary Report

How to use mobilecho with Microsoft Forefront Threat Management Gateway (TMG)

EXTENDING THREAT PROTECTION AND CONTROL TO MOBILE WORKERS

Cisco Virtualization Experience Infrastructure: Secure the Virtual Desktop

Cisco Web Security: Protection, Control, and Value

F5 PARTNERSHIP SOLUTION GUIDE. F5 and VMware. Virtualization solutions to tighten security, optimize performance and availability, and unify access

Multi-Layer Security for Multi-Layer Attacks. Preston Hogue Dir, Cloud and Security Marketing Architectures

Security Administration R77

Data Security on the Move. Mark Bloemsma, Sr. Sales Engineer Websense

Cyan Networks Secure Web vs. Websense Security Gateway Battle card

Managing Web Security in an Increasingly Challenging Threat Landscape

V1.4. Spambrella Continuity SaaS. August 2

Mobile, Cloud, Advanced Threats: A Unified Approach to Security

Lab Testing Detailed Report DR January Competitive Testing of Web Security Devices

MOVING SECURITY TO THE CLOUD. pandasecurity.com

Office 365 Cloud App Security MARKO DJORDJEVIC CLOUD BUSINESS LEAD EE TREND MICRO EMEA LTD.

Mitigating Web Threats with Comprehensive, Cloud-Delivered Web Security

Reverse Proxy for Trusted Web Environments > White Paper

Cisco Cloud Web Security Key Functionality [NOTE: Place caption above figure.]

How To Sell Security Products To A Network Security Company

UNIFIED CONTENT SECURITY: Securing the Borderless Enterprise

Network protection and UTM Buyers Guide

Securing Virtual Applications and Servers

INCREASINGLY, ORGANIZATIONS ARE ASKING WHAT CAN T GO TO THE CLOUD, RATHER THAN WHAT CAN. Albin Penič Technical Team Leader Eastern Europe

Deliver Secure and Fast Remote Access to Anyone from Any Device

The Fortinet Secure Health Architecture

Transcription:

Replacing Microsoft Forefront Threat Management Gateway with F5 BIG-IP Dennis de Leest Sr. Systems Engineer Netherlands

Microsoft Forefront Threat Management Gateway (TMG) Microsoft Forefront Threat Management Gateway (TMG) was Microsoft s comprehensive security solution Microsoft Forefront TMG has been widely deployed in Microsoft customers to serve a variety of functions: Delivering forward proxy as a secure web gateway Enabling reverse proxy As a firewall in some instances F5 Networks, Inc 2

Why customers need a Microsoft Forefront TMG replacement Microsoft discontinued Forefront TMG, requiring customers to find a new solution to secure corporate access to the web December 1, 2012: Microsoft Forefront TMG 2010 reached End-of-Sales Maintenance and support is to continue through April 14, 2015 Microsoft does not have a successor product for Forefront TMG as a secure web gateway Your need to protect against web-based threats is only increasing! F5 Networks, Inc 3

Web access is a necessary part of any employee s day F5 Networks, Inc 4

IT must architect for all types of web access Social Cloud Internet F5 Networks, Inc 5

Web access exposes your enterprise to sophisticated attacks Watering Hole Attacks Drive-by Downloads Spearphishing F5 Networks, Inc 6

Web-based threat trends 23% 1 out of 8 websites has a vulnerability 2 Web-based attacks up 23% 2 Estimated 37.3 million Internet users worldwide experienced phishing attacks from May 1, 2012 to April 30, 2013 1 1 https://devcentral.f5.com/articles/protecting-against-mobile-and-web-security-threats; 2 Symantec s 2014 Internet Security Threat Report; F5 Networks, Inc 3 Symantec s 2014 Internet Security Threat Report 7

Migrating from Microsoft s Threat Management Gateway to F5 BIG-IP F5 Networks, Inc 8

Before: Typical Microsoft TMG deployment Delivered web-based malware protection, URL filtering, and content filtering Deployed with application delivery controller for scalability and high-availability Complex infrastructure F5 Networks, Inc 9

After: F5 replaces TMG and does more Built in scalability, high availability and performance with BIG-IP Platform Delivers comprehensive forward-proxy with F5 Secure Web Gateway Services Enables extremely granular access and security policies with remote/mobile access through F5 Access Policy Manager (APM) Eases access and security policy creation and management with Visual Policy Editor (VPE) Consolidates and simplifies infrastructure firewall, load balancer/adc, proxy servers, and more F5 Networks, Inc 10

Benefits of F5 replacing Microsoft Forefront TMG Significantly streamlines web proxy deployments Consolidation increases ROI Enhances functionality and security Comprehensive security for Microsoft deployments F5 Networks, Inc 11

F5 Access Policy Manager (APM) and Secure Web Gateway Services F5 Networks, Inc 12

F5 s Unified Identity and Access Management (IAM) Secure Web Gateway Internet Internet Apps Internet Apps Web Access Management Remote Access and Application Access Enterprise Apps Virtual Edition Appliance Chassis Mobile Apps Enterprise Mobility Gateway Federation Cloud, SaaS, and Partner Apps F5 Networks, Inc 13

Application authentication, authorization, and identity federation with F5 Application Policy Manager (APM) Context-aware policy enforcement Scalability and performance Access control over third-party SaaS Simplified, granular policy creation and management F5 Networks, Inc 14

How BIG-IP APM is different Most scalable solution available Scales 10X over other competitive offerings Industry s only access solution with a simple GUI for creating/modifying contextaware policies (VPE) One access appliance, one policy engine Native VDI support And much more! F5 Networks, Inc. F5 CONFIDENTIAL INTERNAL USE ONLY 15

F5 Visual Policy Editor (VPE) Endpoint Inspection F5 Networks, Inc 16

F5 Secure Web Gateway Services Context-Aware Web Security Bandwidth Controls Acceptable Use Policy Controls Compliance F5 Networks, Inc 17

F5 Secure Web Gateway Services architecture URL categorization and filtering Web application controls Advanced web-based and embedded malware protection Fast SSL inspections and bypass Fast and effective threat detection (based on Websense ThreatSeeker) Server Server Contractors Employees Active Directory PCI CDE Server Server Corporate Network Kerberos NTLM Basic Auth 407 Wireless Guest Network Web Application Firewall NGFW and/or IPS Inspection DMZ Secure Web Gateway Malware Detection URL Categorization DDoS/ Perimeter Firewall Cloud Based Threat Intelligence Internet Remote Users Salesforce.com Update Server B2B Server Web APIs E-Commerce Facebook YouTube Malicious Server Facebook Games Viral Video Policy- Violatio n Sites Detailed reporting and logging Strategic Point of Control Malware F5 Networks, Inc. 18

Extends visibility and control into the cloud Headquarters Visibility and Control Home Visibility and control for web activities on-premises, offpremises, and in the cloud through a single management view F5 Networks, Inc. 19

Global real-time threat detection from Websense Global Threat Awareness Unifies 900M+ endpoints Analyzes 3-5B requests/day Master URL database classifies 60M websites Comprehensive and granular social web application control Largest intelligence network Real-time Threat Detection URL classification Real-time content classification Malware detection and protection FULLY INTEGRATED BIG-IP APM policy management and reporting Integrated engines from Websense Support by F5 URL CLASSIFICATION CONTENT AND MALWARE USER-ID POLICY MANAGEMENT AND ENFORCEMENT REPORTS/LOGGING SSL FORWARD PROXY TMOS F5 Networks, Inc 20

Flexible licensing models SWG Option Features F5 Product Components URL Filtering URL filtering Web application controls User identification and context-based policy Visual policy, reporting and logging Connection to Threatseeker for updates BIG-IP Access Policy Manager (APM) 1 or 3 Yr. URL Filtering Subscription GBB: Best + URL Filtering Subscription Secure Web Gateway URL filtering Web application controls User identification and context-based policy Visual policy, reporting and logging Connection to Threatseeker for updates BIG-IP Access Policy Manager (APM) 1 or 3 Yr. SWG Subscription GBB: Best + Secure Web Gateway Services Malware detection and protection Real-time content classification F5 Networks, Inc 21

F5 Secure Web Gateway Services benefits and differentiation First one-stop shop for all access policy, inbound and outbound Superior scale and performance Only web gateway to secure against inbound and outbound threats Ensures regulatory and organizational compliance Lowest TCO and quickest ROI BACKED BY WORLD-CLASS SUPPORT AND PROFESSIONAL SERVICES F5 Networks, Inc 22

Why replace Microsoft Forefront TMG with F5 Streamlines and simplifies Consolidates Enhances security 1 Superior scale and peformance One appliance, one policy engine, one stop F5 Networks, Inc 23

Next Steps For more information, visit: www.f5.com/architectures