
8878ad5481eacfeb021e7b95868e6f4c.ppt
- Количество слайдов: 35
Gigabit Content Security Router CS-5800
Presentation Outline u Product Overview u Product Feature u Product Application u Product Comparison u Appendix 2 / 34
Overview u What is the Content filter? ü Content filtering is the technique whereby content is blocked or allowed based on analysis of its content, rather than its source or other criteria. It is most widely used on the Internet to filter email and web access. 3 / 34
Overview u What is IPv 6 ? ü IPv 6 is the next-generation Internet Protocol version designated as the successor to IPv 4, the first implementation used in the Internet that is still in dominant use currently. ü It is an Internet Layer protocol for packet-switched internetworks. The main driving force for the redesign of Internet Protocol was the foreseeable IPv 4 address exhaustion. ü IPv 6 has a vastly larger address space than IPv 4. This results from the use of a 128 -bit address, whereas IPv 4 uses only 32 bits. u Why IPv 6 ? ü Nowadays, lots of electronic products or mobile devices can browse the Internet, which means the need of IP Address increases. However, the current IPv 4 network infrastructure is not capable enough to provide IP Address to each single users / Clients. ü The situation forces the ISP to build up the IPv 6 network infrastructure speedily. 4 / 34
Product Overview u PLANET Security Product Classification CS-1000 Enterprise UTM /Content Security Gateway Multi-Homing Security Gateway CS-2001 CS-5800 MH-2001 MH-3400 SMB VPN Security Gateway SOHO VPN Security Wireless Router SG-1000 SG-4800 VRT-402 N VRT-420 N 5 / 34
Product Overview u PLANET Security Product Difference CS-5800 l. Multi-WAN load balance l. VPN function l. SPI / Do. S Firewall Content filter l. Qo. S l. Dual stack IPv 6 l. Full Ports Gigabit Security SSL VPN SG-4800 3 G/3. 5 G MH-3400 6 / 34
Product Overview u Front Panel of CS-5800 ü 8 -LAN Port 10/1000 Base-T RJ-45 • Port 1 configurable with LAN 1(Mirror Port) ü 4 -WAN Port 10/1000 Base-T RJ-45 ü 1 -DMZ Port 10/1000 Base-T RJ-45 • ü u Configurable with WAN 5 1 -Reset Button Power Consumption ü Reset Button 100~240 VAC, 50~60 Hz, max 0. 8 A 1 x 10/1000 Base-T, RJ-45 19” Rack-mountable 8 x 10/1000 Base-T RJ-45 4 x 10/1000 Base-T, RJ-45 7 / 34
Product Benefits u Multi-WAN ü Multi-WAN auto line backup (Fail Over) ü Realizing inbound / outbound load balancing with Multi-WAN u Performance ü All Gigabit Ethernet port improve Network Efficiency u Smart Qo. S ü Smart Qo. S control the P 2 P and video downloading easily ü Guaranteed bandwidth for Qo. S Schedule and Priority Qo. S 8 / 34
Product Benefits u Strong Protection for Network Security ü 60 PPTP/200 IPSec VPN tunnel ensure security information transmission* ü The built-in SPI/policy-based firewall/Do. S prevent many known hacker attack u Online Behavior management ü Flexible for Content filter include Web Filtering and Application Blocking u Abundant IPv 6 Support ü Meet the need for larger addressing and higher security ü IPv 4 / IPv 6 Dual Stack helps to connect to IPv 6 network now and in the future 9 / 34
Product Key Features Content Filter Full Ports Gigabit DOS prevent SPI Firewall Multi-WAN Load balance CS-5800 60 PPTP 200 IPSec VPN tunnel Smart Qo. S IPv 6 / IPv 4 Dual Stack 10 / 34
Product Features – Multi WAN u Hardware ü 8 -LAN Port 10/1000 Base-T RJ-45 • Port 1 configurable with LAN 1(Mirror Port) ü 4 -WAN Port 10/1000 Base-T RJ-45 • Inbound / outbound load balancing and auto line fail-over with Multi-WAN ü 1 -DMZ Port 10/1000 Base-T RJ-45 • Configurable with WAN 5 ü Support HA (High Available) 11 / 34
Product Features u 1/14 Multi-WAN Fail over When WAN 1 Fail, the user can access Internet through the Multi-WAN 1 WAN 2~4 DMZ Group LAN Group 12 / 34
Product Features Outbound Load Balancing WAN 1 Loading 2/14 u WAN 1 WAN 2~4 Loading WAN 2~4 Multi WAN 2~4 - WAN Ports Network Traffic Enable over loading Load Balancing LAN Group DMZ Group 13 / 34
Product Features Inbound Load Balancing WAN 1 Loading 3/14 u WAN 2~4 Loading Clients Multi - WAN Ports Network Traffic WAN 2~4 Network Traffic over loading Enable Load Balancing WAN 1 WAN 2~4 DMZ (WEB/ FTP sever) 14 / 34
Product Features u 4/14 HA (High Available) High Availability is adopted in the network that requires fault tolerance and backup mechanism. Two similar devices are used to be the backup for each other. ISP 1 ISP 2 Slave Master 15 / 34
Product Features – Security & Qo. S u Bandwidth Management ü Guaranteed Bandwidth ü Max. Bandwidth ü Session Limit ü Port-Based Qo. S u Security ü SPI (Stateful Packet Inspection) Firewall ü Do. S (Denial of Service) prevention ü IP & Port filtering ü DMZ Host ü Prevents ARP Attack on LAN 16 / 34
Product Features 5/14 Bandwidth Management According to the IP and service (port) to ensure the important application. u E-Mail: 3 Mbps Set different bandwidth VIP: 5 Mbps ERP: 10 Mbps Other: 2 Mbps 17 / 34
Product Features u 6/14 Smart Qo. S When the bandwidth usage over the set percent, the smart Qo. S will enabled automatically to limit each users bandwidth. 20 Mbps 10 Mbps Over the preset usage!! 2 Mbps 5 Mbps Each user be limited 1 Mbps 18 / 34
Product Features u 7/14 SPI Firewall/Do. S Prevent The SPI firewall have check and filter the abnormal packet , the Do. S prevent will protect the user avoid the Do. S / DDo. S attack. Cracker Web / FTP server Internet User Group 19 / 34
Product Features – VPN & VLAN u VPN Feature* ü IPSec, PPTP and L 2 TP Pass through ü Supports IPSec • • • IPSec Hardware acceleration IPSec Encryption DES / 3 DES / AES 128 / AES 192 / AES 256 IPSec Authentication MD 5 / SHA 1 ü VPN Hub u Support VLAN ü IEEE 802. 1 Q Tagged VLAN on WAN port* ü Port VLAN 20 / 34
Product Feature u 8/14 IPSec VPN (Site to Site) Headquarter Cause the data via the VPN tunnel will be encrypt, so even the hacker intercept this data still can’t read this information. VP N Tu nn Hacker el Branch Office !@#$%^&*())_ ? ? ? ? ? 21 / 34
Product Features u 9/14 VPN Hub VPN Tunnel Firewall Gateway No need to create the Firewall Gateway new VPN tunnel Secured VPN Connection 22 / 34
Product Features u 10/14 Port VLAN The manager can via the Port VLAN feature collocate with the multiple subnet to manage the network. VLAN 1 VLAN 2 VLAN 3 23 / 34
Product Features - Management u Full Management ü IPv 4 / IPv 6 Dual Stack ü Standard-based Management • • • WEB-based SNMP v 1 and v 2 c Remote management ü Content Filter • • • Restrict Application Download/Upload blocking URLs/Scripts Filter ü Statistic • • Traffic Graphic statistic Monitoring, Logging, and Alarms of system activities 24 / 34
Product Features u 11/14 IPv 6 / IPv 4 Dual Stack WEB Load Balance Application Log ICMP DMZ DHCP Transport Layer Remote Management IPv 4 Stack IPv 6 Stack IPv 4 network IPv 6 network CS-5800 IPv 4 Host IPv 6 Host 25 / 34
Product Features u 12/14 Content Filter* The content filter feature can block the P 2 P , IM software and the specified file extension as. exe or. pdf. X 26 / 34
Product Features 13/14 Traffic Statistic Network manager can observe the user’s traffic usage and the behavior , u It help the manager to make the bandwidth of the network distribute easily. Inbound/ Outbound Statistic Physical port Statistic Service Statistic Client traffic Statistic 27 / 34
Product Features 14/14 u. Management The CS-5800 provide the SNMP and http web management, the manager can supervise this device easily. TCP/IP SNMP v 1 / v 2 c Compliant with many web browser. TCP/IP HTTP Web Management (IPv 4/IPv 6) 28 / 34
Product Feature-summary Security VPN Tunnel connection Remote management via VPN Tunnel Multi-ISP improve the bandwidth Content Filter SPI Firewall/ DOS Prevent Fast access for full Gigabit port 29 / 34
Product Application u Headquarter-Branch Office Remote Multi Service Solution ü A company locates in Taipei , Taiwan and its branch office is in New York, US. The two places needs many service like Vo. IP, Video conference, data transmission and IP surveillance to communicate with each other. The MIS manager needs some product to accord with those demand: • Extend the bandwidth and make a cost-effective network • Stable network connection( fail over) • The reliable VPN connection • Use the bandwidth management mechanism (Qo. S) to ensure the average bandwidth for each user 30 / 34
Product Application u Multi Service Solution Branch Office Vo. IP Phone Multi-WAN connect with Multi-ISP improve the bandwidth and cost savings IP Camera Server Internet ISP 2 ISP 1 HTTP / video Traffic CMS/Data Via the VPN tunnel to established the secure and High efficiency network Vo. IP Traffic Vo. IP Phone Headquarter 31 / 34
Product Comparison u External Comparison Model PLANET CS-5800 Draytek Vigor 3300 Hardware Processor Cavium CN 3120 -500 MHz Unknow RAM 1 G DDR 2 MB Unknow Flash 32 MB Unknow Desktop/19 inch rack 5 x WAN(1 x configurable for DMZ) 8 x LAN (All Giga ports) 3 x WAN 10/100 Ethernet (1 x configurable for DMZ) 4 x LAN 10/100 Ethernet 1 x Console Port System Performance Firewall performance 1 Gbps Unknow 3 DES performance 154 Mbps Unknow Concurrent Session 40, 000 Unknow Product Photo Dimension Network port 32 / 34
Product Comparison u External Comparison Model PLANET CS-5800 Draytek Vigor 3300 Content Filtering Yes Policy-based Firewall Yes SPI Firewall Yes VPN Feature VPN Tunnel IPSec : 200 PPTP : 60 IPSec : 200 PPTP : Unknow Yes - Outbound / Inbound Outbound Yes Traffic statistic - SNMP v 1, v 2 c Yes Qo. S Yes Alert by email Yes IPv 6 Yes - VLAN Port VLAN, 802. 1 Q VLAN tag RIPv 1/2 , Strategic Route RIPv 1/2 , Static Routing Firewall VPN Hub Management WAN Load balancing High Availability Statistics SNMP Dynamic routing 33 / 34
Appendix - Sales Target u Target Markets ü ü u SMB/ Enterprise Office Security Reseller Target Customers ü Who buy our Security Gateway • ü Who buy our Multi-Homing Security Gateway • • ü SG-1000/SG-4800 MH-3400/MH-2001 VRT-420 N Who buy our UTM Content Security Gateway • CS-1000/CS-2001 34 / 34
35 / 34
8878ad5481eacfeb021e7b95868e6f4c.ppt