Anda di halaman 1dari 2

Unified Threat Management CR 2500iNG

Future-ready

Future-ready Security for Large Enterprise networks CR 2500iNG Data Sheet

The Cyberoam NG series for enterprises offer Next-Generation Firewall (NGFW) capabilities with high
performance required for future enterprise networks. These Next-Generation Network security
appliances offer inline application inspection and control, HTTPS inspection, Intrusion
Prevention System, malware protection, secure remote access via VPN (IPSec and SSL) and
granular bandwidth controls. The inline Layer 8 Identity-based controls with on-appliance
reporting offer complete control & real-time visibility over user and network activities.
The ‘Next-Generation’ Series for Large
Based on best-in-class hardware along with software to match, the NG series Enterprises:
enables unprecedented throughput speeds for future-ready security in large Offering Next-Generation Firewall protection
enterprise networks. to large enterprises

Cyberoam NG series for large enterprises offer assured Security,


Connectivity and Productivity. Its Extensible Security Architecture
Cyberoam's Layer 8 Technology treats
(ESA) supports feature enhancements that can be developed
“User Identity” as the 8th Layer in the
rapidly and deployed with minimum efforts, offering future- protocol stack
ready security to organizations.

VPNC
L8 USER
CERTIFIED
SSL
Portal
SSL
Exchange
L7 Application
SSL
Firefox
VPNC
CERTIFIED
Basic
SSL
JavaScript

SSL Basic
L6 Presentation ASCII, EBCDIC, ICA
Interop Network Extension

www.check-mark.com
AES
Interop
SSL Advanced
Network Extension Cyberoam UTM offers security
L5 Session L2TP, PPTP
across Layer 2-Layer 8 using
L4 Transport TCP, UDP Identity-based policies
L3 Network 192.168.1.1

L2 Data Link 00-17-BB-8C-E3-E7

L1 Physical

Cyberoam UTM features assure Security, Connectivity, Productivity

Security Connectivity Productivity


Network Security Business Continuity Employee Productivity
- Firewall - Multiple Link Management - Content Filtering
- Intrusion Prevention System - High Availability - Instant Messaging Archiving & Controls
- Web Application Firewall
Network Availability IT Resource Optimization
Content Security - VPN - Bandwidth Management
- Anti-Virus/Anti-Spyware - 3G/4G/WiMAX Connectivity - Traffic Discovery
- Anti-Spam (Inbound/Outbound)## - Application Visibility & Control
- HTTPS/SSL Content Security Future-ready Connectivity
- “IPv6 Ready” Gold Logo Administrator Productivity
Administrative Security - Next-Gen UI
- Next-Gen UI
- iView- Logging & Reporting
Specification
Interfaces - Block High Availability
Copper GBE Ports 14 - P2P applications e.g. Skype - Active-Active
1GbE SFP (Mini GBIC) Ports 4 - Anonymous proxies e.g. UItra surf - Active-Passive with State Synchronization
10GbE SFP (Mini GBIC) Ports 2 - “Phone home” activities - Stateful failover
Configurable Internal/DMZ/WAN Ports Yes - Keylogger - Alerts on appliance status change
Console Ports (RJ45) 1 - Layer 7 (Applications) & Layer 8 (User - Identity)
USB Ports 2 Visibility Administration & System Management
Hardware Bypass Segments 2# - Web-based configuration wizard
RAID 1 (with two disk) Yes Web Application Firewall - Role-based access control
- Positive Protection model - Firmware Upgrades via Web UI
System Performance* - Unique "Intuitive Website Flow Detector" technology - Web 2.0 compliant UI (HTTPS)
Firewall throughput (UDP) (Mbps) 40,000 - Protection against SQL Injections, Cross-site Scripting - UI Color Styler
Firewall throughput (TCP) (Mbps) 28,000 (XSS), Session Hijacking, URL Tampering, Cookie - Command Line Interface (Serial, SSH, Telnet)
New sessions/second 200,000 Poisoning - SNMP (v1, v2c)
Concurrent sessions 3,500,000 - Support for HTTP 0.9/1.0/1.1 - Multi-lingual support: Chinese, Hindi, French, Korean
IPSec VPN throughput (Mbps) - Extensive Logging & Reporting - Cyberoam Central Console (Optional)
8,000
No. of IPSec Tunnels 3,000 - NTP Support
SSL VPN throughput (Mbps) Virtual Private Network
1,000
WAF throughput (Mbps) - IPSec, L2TP, PPTP User Authentication
1,000
Anti-Virus throughput (Mbps) - Encryption - 3DES, DES, AES, Twofish, Blowfish,
6,000 - Internal database
IPS throughput (Mbps) 6,000 Serpent
- Hash Algorithms - MD5, SHA-1 - Active Directory Integration
UTM throughput (Mbps) 4,500 - Automatic Windows Single Sign On
- Authentication - Preshared key, Digital certificates
- IPSec NAT Traversal - External LDAP/RADIUS database integration
Stateful Inspection Firewall
- Layer 8 (User - Identity) Firewall - Dead peer detection and PFS support - Thin Client support - Microsoft Windows Server 2003
- Multiple Security Zones - Diffie Hellman Groups - 1,2,5,14,15,16 Terminal Services and Citrix XenApp - Novell
- Access Control Criteria (ACC) - User - Identity, Source & - External Certificate Authority support eDirectory
Destination Zone, MAC and IP address, Service - Export Road Warrior connection configuration - RSA SecurID support
- UTM policies - IPS, Web Filtering, Application Filtering, - Domain name support for tunnel end points - External Authentication - Users and Administrators
Anti-Virus, Anti-Spam and Bandwidth Management - VPN connection redundancy
- Overlapping Network support
- User/MAC Binding
- Layer 7 (Application) Control & Visibility - Multiple Authentication servers
- Access Scheduling - Hub & Spoke VPN support
- Policy based Source & Destination NAT Logging/Monitoring
- H.323, SIP NAT Traversal SSL VPN
- TCP & UDP Tunneling - Graphical real-time and historical monitoring
- 802.1q VLAN Support
- Authentication - Active Directory, LDAP, RADIUS, - Email notification of reports, gateway status, viruses
- DoS & DDoS Attack prevention
- MAC & IP-MAC filtering and Spoof prevention Cyberoam and attacks
- Multi-layered Client Authentication - Certificate, - Syslog support
Gateway Anti-Virus & Anti-Spyware Username/Password - Log Viewer - Firewall, IPS, Web filter, Anti Virus, Anti
- Virus, Worm, Trojan: Detection & Removal - User & Group policy enforcement Spam, Authentication, System and Admin Events
- Spyware, Malware, Phishing protection - Network access - Split and Full tunneling
- Automatic virus signature database update - Browser-based (Portal) Access - Clientless access On-Appliance Cyberoam-iView Reporting Cyberoam TM

- Scans HTTP, HTTPS, FTP, SMTP, POP3, IMAP, IM, - Lightweight SSL VPN Tunneling Client - Integrated Web-based Reporting tool - VIEW
VPN Tunnels - Granular access control to all the Enterprise Network Cyberoam-iView
- Customize individual user scanning resources - 1000+ drilldown reports
- Self Service Quarantine area - Administrative controls - Session timeout, Dead Peer - 45+ Compliance Reports
- Scan and deliver by file size Detection, Portal customization - Historical and Real-time reports
- Block by file types - TCP- based Application Access - HTTP, HTTPS, RDP, - Multiple Dashboards
- Add disclaimer/signature TELNET, SSH - Username, Host, Email ID specific Monitoring
Dashboard
Gateway Anti-Spam Instant Messaging (IM) Management - Reports - Security, Virus, Spam, Traffic, Policy violations,
- Inbound/Outbound Scanning - Yahoo and Windows Live Messenger VPN, Search Engine keywords
- Real-time Blacklist (RBL), MIME header check - Virus Scanning for IM traffic - Multi-format reports - tabular, graphical
- Filter based on message header, size, sender, recipient - Allow/Block Login - Exportable formats - PDF, Excel
- Subject line tagging - Allow/Block File Transfer - Automated Report Scheduling
- IP address Black list/White list - Allow/Block Webcam
- Redirect Spam mails to dedicated email address - Allow/Block one-to-one/group chat IPSec VPN Client**
- Image-based Spam filtering using RPD Technology - Content-based blocking - Inter-operability with major IPSec VPN Gateways
- Zero hour Virus Outbreak Protection - IM activities Log - Supported platforms: Windows 2000, WinXP 32/64-bit,
- Self Service Quarantine area - Archive files transferred Windows 2003 32-bit, Windows 2008 32/64-bit, Windows
- Spam Notification through Digest - Custom Alerts Vista 32/64-bit, Windows 7 RC1 32/64-bit
- IP Reputation-based Spam filtering - Import Connection configuration
Wireless WAN
Intrusion Prevention System - USB port 3G/4G and Wimax Support Certification
- Signatures: Default (4500+), Custom - Primary WAN link - ICSA Firewall - Corporate
- IPS Policies: Multiple, Custom - WAN Backup link - Checkmark UTM Level 5 Certification
- User-based policy creation - VPNC - Basic and AES interoperability
- Automatic real-time updates from CRProtect networks Bandwidth Management - “IPv6 Ready” Gold Logo
- Protocol Anomaly Detection - Application and User Identity based Bandwidth
- DDoS attack prevention Management Hardware Specifications
- Guaranteed & Burstable bandwidth policy
Memory 6GB
- Application & User Identity based Traffic Discovery
Web Filtering HDD (HOT Swappable) 250GB or higher
- Multi WAN bandwidth reporting
- Inbuilt Web Category Database
- Category-based bandwidth restriction
- URL, keyword, File type block Compliance
- Categories: Default(82+), Custom CE / FCC / UL
User Identity and Group Based Controls
- Protocols supported: HTTP, HTTPS
- Access time restriction
- Block Malware, Phishing, Pharming URLs Dimensions
- Time and Data Quota restriction
- Schedule-based access control H x W x D (inches) 3.54 x 17.52 x 23.23
- Schedule based Committed and Burstable Bandwidth
- Custom block messages per category H x W x D (cms) 9 x 44.5 x 59
- Schedule based P2P and IM Controls
- Block Java Applets, Cookies, Active X Weight 19kg, 41.8lbs
- CIPA Compliant
Networking
- Data leakage control via HTTP, HTTPS upload Power
- Failover - Automated Failover/Failback, Multi-WAN
Input Voltage 90-260 VAC
failover, 3GModem failover
Application Filtering - WRR based load balancing
Consumption 258 W
- Inbuilt Application Category Database Total Heat Dissipation (BTU) 881
- Policy routing based on Application and User
- 11+ Application Categories: e.g. Gaming, IM, P2P, Redundant Power Supply Yes
- IP Address Assignment - Static, PPPoE, L2TP, PPTP &
Proxy
- Schedule-based access control DDNS Client, Proxy ARP, DHCP server, DHCP relay Environmental
- Support for HTTP Proxy Operating Temperature
- Dynamic Routing: RIP v1& v2, OSPF, BGP, Multicast 0 to 40 °C
Storage Temperature -25 to 75 °C
Forwarding Relative Humidity (Non condensing)
- Parent Proxy support with FQDN 10 to 90%
- “IPv6 Ready” Gold Logo

#
If Enabled, will bypass traffic only in case of power failure. *Antivirus, IPS and UTM performance is measured based on HTTP traffic as per RFC 3511 guidelines.
##
Actual performance may vary depending on the real network traffic environments. **Additional Purchase Required. Inbound and Outbound Spam filtering cannot be used simultaneously.

Toll Free Numbers C o p y r i g h t © 1999-2013 Cyberoam Te c h n o l o g i e s Pvt. L t d. A l l R i g h t s R e s e r v e d.


Cyberoam and Cyberoam logo are registered trademark of Cyberoam Technologies Pvt. Ltd. Although
USA : +1-800-686-2360 | India : 1-800-301-00013 Cyberoam has attempted to provide accurate information, Cyberoam assumes no responsibility for
accuracy or completeness of information neither is this a legally binding representation. Cyberoam has the
APAC/MEA : +1-877-777-0368 | Europe : +44-808-120-3958 right to change,modify, transfer or otherwise revise the publication without notice. PL-10-1000252-100718 Unified Threat Management

www.cyberoam.com I sales@cyberoam.com

Anda mungkin juga menyukai