Next-Generation Firewalls (NGFW)
Overview
AhnLab TrusGuard is the NGFW with multiple security features including IPS, application control, VPN, C&C detection, Anti-Virus/Anti-Spam, and DLP.
TrusGuard ensures high performance with its multi-core-based hardware and optimized software architecture. TrusGuard’s key features are as below.
- Providing firewall, signature-based IPS, and web filtering
- Securing visibility and controlling the behavior of local and global applications exploited to pose security threats
- Real-time C&C server blacklist updates and detecting/blocking malicious connections by AhnLab Smart Defense
- Supporting safe and fast internal network connection via IPSec / SSL VPN
- Supporting DLP(Data Loss Prevention) to cope with internal data leakage threats
- Offering outstanding DDoS protection with our patented technology
Features
Feature | Description |
Firewall |
Stateful packet inspection methods
|
IPS |
|
Application Control | Global/local application detection and block
|
C&C Detection/Block |
Cloud-based detection and block of C&C server access
|
Anti-Virus/Anti-Spam
|
|
Web Filtering |
Detecting / blocking global and local website access
|
DDoS Mitigation | Mitigating TCP, UDP, ICMP, HTTP flooding DDoS attacks
|
IPSec VPN |
Using Hub & Spoke/Star/Mesh topology
|
SSL VPN | Gateway-to-Client VPN
|
Interoperation with
Endpoint Solution |
Anti-Virus(V3) interoperation
|
Log & Monitoring
|
Saving logs / internal HDD
|
Advantages
AhnLab TrusGuard fully reflected the market demand and technology of AhnLab, which solidified its position as the security leader of South Korea for more than two decades.
Integration of Reliable Network & Content Security Technologies
- Network technology accumulated for decades and verified from over 6,000 sites
- Database and expertise in malware response for over 20 years
High Performance
- Stable network operation powered by a high-performance multi-core platform and optimized architecture
- Supporting high-performance firewall, VPN, and application control – outstanding multi-function
Application Control
- Behavior control of internal users such as access and login to the major global/local applications
- Supporting unknown application control
C&C Server Detection & Prevention
- Unmatched detection and prevention capabilities for C&C server connection (cloud-based)
VPN with Enhanced Threat Response between HQ-Branch / PC- Office
- Supporting a safe communication via public network fundamentally with IPSec VPN
- Restraining malware propagation by interoperating firewall and IPS feature with VPN traffic
- Enhancing the security of branches by providing IPS, application control, AV and mal-site prevention
- Establishing a flexible VPN network by simultaneously supporting IPSec VPN and SSL VPN
Engine Specialized for DDoS Mitigation
- Effectively preventing DDoS attacks by applying phased detection & prevention mechanism
- Response to TCP, UDP, ICMP, and HTTP Flooding attacks
Interoperation with AhnLab Endpoint Solutions
- Device-based control via EPP interoperation(agentless)
- EPP agent redirection
- Controlling SSL VPN connection based on ESA vulnerability scan
Response to the Latest APT
- Detecting unknown files by interoperating with APT-exclusive AhnLab MDS
- Blocking suspicious unknown URL/IP classified as level 10 by MDS
Central Configuration, Monitoring, and Reporting via AhnLab TMS
- Providing various features to efficiently manage multiple security appliances with AhnLab TMS
Emergency Response Capability of ASEC – Global Threat Response Group
- 24/7 emergency response by ASEC(AhnLab Security Emergency response Center) expertise
- Supporting regular signature updates three times a day as well as an emergency update
Customers can enjoy the following benefits by using AhnLab TrusGuard
Integration of Reliable Network & Content Security Technologies
- Properly handling growing network traffic with the optimized high-performance multicore
Unparalleled Threat Detection and Response Technology
- Multi-engine architecture specialized in threat detection
- Differentiated threat detection with AhnLab’s security intelligence
Perfectly Covering IPv6 Network Environment
- Supporting IPv6 applicable to the actual network environment
TCO Reduction
- Lessening the financial burden of purchasing different security solutions such as firewall, IPS, application control and DLP
- Addressing management complexity and resource burden caused by the operation of different security solutions
Improving Business Productivity and Network Efficiency
- Eliminating unnecessary traffic with Anti-Spam, P2P & messenger control, and mal-site access control
- Saving network costs by traffic optimization
Establishing VPN with Stronger Threat Response
- Enhancing the security of VPN traffic from branches inflowing to the HQ
- Fixing and quarantining infected PC by interoperating with AhnLab Policy Center
- Providing mobile SSL VPN
- Coping with IoT/M2M environment by providing SSL VPN interconnected to the embedded device
Interoperation with AhnLab Endpoint Solutions
- Device-based control via EPP interoperation(agentless)
- EPP agent redirection
- Controlling SSL VPN connection based on ESA vulnerability scan
Enhanced Protection for Branch Offices
- Reinforcing the prevention of inflowing attacks and malware to branches with IPS, AV, and mal-site block features
Specifications
Concept Map
Specifications
SMB/Branch Office
Category | TrusGuard 40B | TrusGuard 50B | TrusGuard 70B | TrusGuard 80B | TrusGuard 100B | TrusGuard 400B | |
---|---|---|---|---|---|---|---|
CPU | 2 Core | 4 Core | 4 Core | 8 Core | 8 Core | 4 Core | |
RAM | 4GB | 8GB | 8GB | 8GB | 8GB | 8GB | |
System Storage | 4GB | 4GB | 4GB | 4GB | 4GB | 4GB | |
Log Storage | – | SATADOM 120GB
(Option) |
SATADOM 120GB
(Option) |
SATADOM 120GB | HDD 1TB
or SSD 240GB/1TB |
HDD 1TB
or SSD 240GB/1TB |
|
NIC | 1GC | 8 | 8 | 8 | 8 | 8 | 8 |
1GF | – | – | – | 2 | 2
(Max 6) |
4 | |
10GF | – | – | – | – | – | – | |
FW | 4G | 6G | 8G | 8G | 10G | 12G | |
IPS | – | 1.5G | 2.5G | 3G | 3.5G | 4G | |
VPN | 1G | 1.2G | 1.4G | 1.6G | 1.6G | 1.8G | |
VPN Tunnel | 2,500 | 5,000 | 5,000 | 10,000 | 10,000 | 20,000 | |
Concurrent Session | 1,000,000 | 1,500,000 | 2,000,000 | 3,000,000 | 3,000,000 | 5,000,000 | |
Size(WxHxD) | 220x44x194.5 | 430x44x193 | 430x44x193 | 430x44x340 | 430x44x340 | 430x44x429.8 | |
Power | Single | Single | Single | Single | Single | Redundant |
※ TrusGuard 40B model supports only firewall/IPSec VPN.
Enterprise/Data Center and for Headquarter
Category | TrusGuard 500B | TrusGuard 2000B | TrusGuard 5000B | TrusGuard 10000B | TrusGuard 20000B | |
CPU |
4 Core
|
8 Core | 20 Core | 32 Core |
48 Core |
|
RAM |
16GB |
16GB |
64GB |
64GB |
256GB |
|
System Storage |
4GB |
SSD 64GB |
SSD 64GB |
SSD 64GB |
SSD 64GB |
|
Log Storage |
HDD 2TB or SSD 240GB/1TB |
HDD 2TB/4TB or SSD 1TB/2TB (RAID-1/0) |
HDD 2TB/4TB or SSD 1TB/2TB (RAID-1/0) |
HDD 2TB/4TB or SSD 1TB/2TB (RAID-1/0) |
HDD 2TB/4TB or SSD 1TB/2TB (RAID-1/0) |
|
NIC |
1GC |
8 |
10 (Max 34) |
10 (Max 50) |
10 (Max 50) |
10 (Max 50) |
1GF |
8 |
8 (Max 32)
|
8 (Max 48) |
8 (Max 48) |
8 (Max 48) |
|
10GF |
0 (Max 4)
|
0 (Max 12) |
4 (Max 28) |
4 (Max 28) |
4 (Max 28) |
|
40GF |
– |
– |
0 (Max 8) |
0 (Max 12) |
0 (Max 12) |
|
FW |
16G
|
60G |
120G |
200G |
240G |
|
IPS |
5G
|
20G |
30G |
50G |
70G |
|
VPN |
2G |
10G |
13G |
19G |
19G |
|
VPN Tunnel |
30,000 |
40,000 |
50,000 |
60,000 |
60,000 |
|
Concurrent Session |
8,000,000 |
10,000,000 |
30,000,000 |
40,000,000 |
60,000,000 |
|
Size(WxHxD) |
450x44x429.8 |
438x88x571 |
438x88x571 |
438x88x571 |
438x88x571 |
|
Power |
Redundant |
Redundant |
Redundant
|
Redundant
|
Redundant |
Đánh giá
Chưa có đánh giá nào.