Sophos Roadshow Complete Security Vision
Reconized leader Over 25 years of experience Data protection experts Global company with local presence 100 million users trust Sophos Reputation for highest quality From the three major security vendors the fastest growing one In the last years a growth of 20% / year Leader in the Gartner Magic Quadrant for Endpoint Protection Leader in the Gartner Magic Quadrant for Mobile Data Protection Leader in the Gartner Magic Quadrant for Unified Threat Management
Sophos Portfolio Overview Protect every part of your business
Complete Security Vision We provide comprehensive protection that fits your security budget. Our Complete Security protects everywhere, from your network, to your servers, endpoints, and mobile devices too. And because it s all from Sophos - it works better together and it s so simple to use you ll actually turn it on. It s better protection that saves you money.
Complete Security Vision Sophos UTM Everything managed from a single appliance Network Protection Firewall Intrusion Prevention, VPN Wireless Web and Email Protection Additional security features on your perimeter Endpoint Protection and Mobile Control Securing your endpoints and mobile devices
Complete Security Vision Where will Sophos UTM go Astaro Secure Gateway Active Protection Anti malware Web reputation checking Anti spam Data features SPX Email Encryption Data control for web and email Sophos Endpoint Managed in Astaro Secure Gateway Application Control Client Firewall Full Disk Encryption Device and media Encryption Manage Sophos Endpoint clients Anti malware Device Control Web Protection
UTM 9 major news «ASG» appliance rebranding to «SophosUTM» GUI in new white / blue Sophos coloring HTML5 VPN WLAN hotspot / Captive portal Endpoint protection
UTM 9 additional news Network Security 1:1 NAT Rules Reorganize NAT Tab Multiple Objects in firewall rules Make user VPN configs available to admin SSL VPN Client without admin rights Update OpenSSL to > 1.0 UTF8 support SSL-VPN username/password Ship Snort engine as a pattern IPv6 NAT NAT: Show rule numbers for "log initial packets" IPv6 Support for GeoIP Web Security AppAccuracy Program 'Youtube for Schools' Support Mail Security Improve Listbox Widget Notifications for blocked outgoing mail Wireless Security Time Based access Transmit Power Adjustment Added usage and error reporting Web Application Security Site Path Routing Hot-Standby support for backend servers Form hardening: check HTTP request method Logging/Reporting Show license info in Executive Report Improve performance of userlog_read for the Management tab Networking DHCP Options Support DHCP Server "Relay Mode" Network Definition Ranges Export of Netflow/IPFIX Records Interface Groups in Multi-Path rules IPv6 Support for Dynamic Interfaces DHCPv6: Clients with static mappings only Improved 3G Modem Support Load Sharing between multiple BGP uplinks QoS Improvements (Shape downloads) Spanning Tree for Bridge Mode WebAdmin/GUI Customize Title for WebAdmin Add + expanders to customization GUI Add constant Live-Log button to WebAdmin TOP Show active sessions and logged in users Customizable Dashboard Global Object Search LCD4Linux Improvements HA/Cluster Keep unit on old version during Up2Date (Cold-rollback) Sync conntrack node id Kernel Kernel Update Performance: AFC low hanging fruits Performance: MMAPed nfnetlink Drop uniprocessor kernels Installer Improve SSD support Up2Date Support installation of newer revisions of the same version
New hardware design
UTM 9 GUI New «Sophos style» coloring
UTM 9 HTML5 VPN clientless SSL VPN Pure HTML5! (No Java or ActiveX) Support for RDP, VNC, SSH, Telnet, and WebApps Support for mobile devices (Apple ios, Android) Part of the network protection subscription #1 feature request in http://feature.astaro.com EndUser Portal
UTM 9 HTML5 VPN clientless SSL VPN
UTM 9 Endpoint Protection Always connected and up2date location independent UTM 9.2 Global Connect Service Policies, Events, Updates Außenstelle Mobile User Policies, Events, Updates Internet Policies Roadwarrior Zentrale
UTM 9 Endpoint Protection Computer Management Computer Management
UTM 9 Endpoint Protection Status
UTM 9 Endpoint Protection Antivirus Device Control
UTM 9 Hotspot support Guest WLAN aka Captive Portal 3 different modi: Terms of use Password of the day Voucher Customizeable captive page Part of the Wireless Subscription #2 Feature Request in http://feature.astaro.com
Hotspot configuration Setup
Voucher Management Management of vouchers in the EndUser-Portal
Roadmap Sophos NSG products
Sophos UTM 9 Roadmap 2012 2013 Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May Jun UTM 9.0 UTM 9.1 UTM 9.2 UTM 9.0 GUI in Sophos Design SAV Integration UTM Endpoint Protection Device Control AV & HIPS Clientless SSL VPN Hotspot support UTM 9.1 Erweiterte Endpoint Protection Web Filtering (policy sync.) Client Firewall (policy sync.) DLP Full Disk Encryption MAC OS support Erweiterte Wireless Protection Repeater, Wireless IDS, Rogue AP detection UTM 9.2 Erweiterte Endpoint Protection App.Ctrl (client/gw comm.) Device & Media Encryption VPN client UTM Mobile Control Remote Lock & Wipe Central App. Mgt. Email Access Mgt. 21
Sophos UTM Manager Roadmap 2012 2013 Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May Jun ACC 4.0 ACC 4.0 / Sophos UTM Manager GUI in Sophos Design / new Name Import of definitions from UTM devices More efficient bandwidth usage Better scalability Central licence management Global policy management for endpoints
SophosAccess Points Roadmap AP 50 Supports 2,4 and 5GHz bands GE Interface POE+ Injector available AP 5 USB Access Point Adds WIFI functionality to RED10 v2/v3 Centrally managed via SophosUTM Price < 100 Q3
Remote Ethernet Device «RED» Roadmap RED 10 rev.3 Sophos branded RED 10 RED 50 For medium offices (~50 User) 1 USB, 4 GE LAN ports 2 GE WAN ports for Load Balancing and Failover >150 Mbps throughput VRED 10 Virtual RED10 For connecting virtual enviroments VMware Image Available Q2/Q3 On request