Bỏ qua đến nội dung
0
Giỏ hàng 0 sản phẩm

Chưa có sản phẩm trong giỏ hàng.

Tư vấn giải pháp

AhnLab TrusGuard 40B

Liên hệ Hóa đơn VAT Bảo hành chính hãng
THÔNG TIN SẢN PHẨM

Chi tiết và thông số kỹ thuật

AhnLab TrusGuard 40B là giải pháp tường lửa thế hệ tiếp theo (Next-Generation Firewall – NGFW) được phát triển bởi AhnLab, nhà cung cấp giải pháp an ninh mạng hàng đầu Hàn Quốc.

TrusGuard 40B cung cấp khả năng bảo vệ toàn diện cho mạng lưới của bạn khỏi các mối đe dọa mạng tiên tiến nhất hiện nay.

Thông số cơ bản:
  • Throughput: 1.5 Gbps
  • VPN throughput: 300 Mbps
  • Số lượng giao diện mạng: 8
  • Cổng Gigabit Ethernet: 8
  • Cổng SFP: 2
  • Kích thước: 1U rackmount
  • Nguồn điện: AC 100-240V, 50/60Hz
Tính năng chính:
  • Ngăn chặn các cuộc tấn công mạng tiên tiến: TrusGuard 40B sử dụng công nghệ Deep Learning tiên tiến để phát hiện và ngăn chặn các cuộc tấn công mạng tiên tiến như ransomware, zero-day attack, và APT.
  • Ngăn chặn các hành vi vi phạm dữ liệu: TrusGuard 40B cung cấp các tính năng bảo mật dữ liệu tiên tiến như DLP (Data Loss Prevention) để ngăn chặn việc rò rỉ dữ liệu nhạy cảm.
  • Quản lý truy cập mạng (NAC): TrusGuard 40B cho phép bạn kiểm soát chặt chẽ truy cập vào mạng lưới của bạn, giúp bảo vệ các tài nguyên mạng khỏi truy cập trái phép.
  • Bảo vệ chống lại các mối đe dọa mạng mới nổi: TrusGuard 40B liên tục được cập nhật để bảo vệ bạn khỏi các mối đe dọa mạng mới nổi.
Lợi ích khi sử dụng AhnLab TrusGuard 40B:
  • Bảo vệ toàn diện mạng lưới của bạn khỏi các mối đe dọa mạng tiên tiến.
  • Ngăn chặn các hành vi vi phạm dữ liệu.
  • Kiểm soát chặt chẽ truy cập vào mạng lưới của bạn.
  • Hiệu suất cao và dễ dàng sử dụng.
  • Được hỗ trợ bởi đội ngũ chuyên nghiệp của SMNET.
Hãy liên hệ SMNET để bảo vệ mạng lưới của bạn an toàn với AhnLab TrusGuard 40B!
Physical
Main Processor 2 Core 1.6Ghz * 1ea
Main Memory 4GB (since ’21 Jan)
System Storage (CF / SSD) 4GB
Log Storage
Log Storage (Option)
Type Small Size, 1U
Dimension(WxHxD mm) 220x44x194.5
Weight Weight : 1.3
Boxed : 2.6
Double Boxed : 11.9
Power (External Power Supply) 40W Single Power
Power Consumption (W) 17W
Redundant Power No
Operating Temperature 0~40 deg C
Storage Temperature -20~70 deg C
BTU/h (MAX) 58
QRNG
CC Certification EAL 4
(Intrusion Prevention Protection Profile)
GS Certification ○ (3.0)
IPv6 Certification IPv6 Ready Logo Phase-2(Router)
Electro-Magnetic Compatibility FCC/ KC
Interfaces
Slots
Console Interface 1 (RJ-45)
10/100 Switch
10/100/1000 Switch Port (Copper)
10/100/1000 Base-T (Copper) 8
1G Base-X (Fiber – SFP)
10G Base-X
40G Base-X
100G BASE-X
Option module
Bypass X
System Performance
Session
Max Concurrent Sessions (CC) 1.000.000
Connection Per Second (CPS) 35.000
Performance
Firewall Throughput (Max) 4G
Firewall Throughput (64bytes) 1G
IPS Throughput (Max)
VPN Throughput 1G
VPN Tunnels 2.500
SSL VPN Users (PC, Mobile for each)
Q-VPN Users
System Policies
by Feature
Firewall Policies 1024
Network Features
OS Inhouse Developed ○ (ANOS)
Mode
Route mode
Transparent(Bridge) Mode
Interface
Static, DHCP Interface
802.1Q VLAN
802.3ad Port Aggregation
  – Port Active-Standby
  – Port Active-Active
  – Traffic Transfer Mode Round-robin (L2/ L2+L3/ L3+L4)
Multi-line (Load-balancing/ Fail-over)
Routing
Static Routing
Source Routing ○ (Source & Destination Based)
Dynamic Routing ○ (RIPv1/v2, OSPF, BGP)
Multicast Routing
  – Routing ○ (PIM-SM, IGMP)
  – Channel japping (Join/ Leave)
  – Static RP(Rendezvous Point)
  – SPT (Short Path Tree)
High Availability
Full-Mesh Network Configuration (without L2)
High-Availability
 – Active-Active, Active-Standby (with/ without L4)
 – Policy Sync./ Session Sync.
 – VLAN Interface High-Availability
 – Heart Beat Interface Aggregation ○ (Active-Active/ Active-Standby)
 – Packet Divert ○ (Active-Active/ Active-Standby)
VRRP (Virtual Router Redundancy Protocol)
Bypass function(Transparent mode) X
QoS
Firewall Policy/ IP/ Port QoS
Policy Based/ Schedule Based QoS
QoS Rating, Detail Setting ○ (7 Level)
Max Bandwidth Limit/ Min Bandwidth Guarantee
Mass Web Traffic Control
QOS Directionality Setting Control
Rollback Configuration Rollback/ Firmware Rollback
Configuration Changes Hostory Comparison with Previous Settings
Other
DHCP Server/ Client
DHCP Relay (in Bridge Mode)
DNS/ Split DNS
SNMP ○ (SNMP v1/ v2/ v3)
NTP Server (Primary/ Secondary)
SIMS Interlock
VoIP Dynamic Port (H.323, SIP)
Service/ Protocol Session Timeout Control
Virtual System
IPv6
Dual Stack
IPv4 & IPv6 Simultaneous Processing
IPv6 Networking
Dual Stack ○ (Static, Bridge, aggregation, VLAN)
IPv6 Static IP
IPv6 DHCP Server
IPv6 Bridge
IPv6 Static Routing
IPv6 Dynamic Routing ○ (RIPv6, OSPFv6, BGPv6)
IPv6 RA
IPv6 Tunneling ○ (6to4)
IPv6 Translation ○ (NAT46 / NAT64/ NAT66/ DNS64)
IPv6 LogServer
IPv6 Packet Filtering
Stateful Inspection
Firewall
Features
Stateful Packet Inspection
Independent Performance Related to Number of Policies
Independent Performance Related to Number of Sessions
Realtime Apply for New Policies
Validation Check for Policies (1) ○ (Day/ Week/ Month Hit Counting)
Validation Check for Policies (2) ○ (Last Hit Time)
Virtual Packet Simulation
Searching for Expiring Policies
Bi-directional Policies
Zone-based policy management function
Alarm when Total Number of Sessions Exceeded Threshold
Alarm when Limit Number of Sessions per Firewall Policy
Alarm when Total Number of Dropped Packets Exceeded Threshold
Alarm when HA State Changed
Alarm when HA Disconnected
Categorization for HA Sync. List
Filtering
Black List
White List
Schedule Based Policy
Limit for Session Count per Policy
Limit for Session Count per Source IP Address
NAT
NAT (Network Address Translation)
Static/ Dynamic NAT, Excluded NAT, NAT Traversal,
Load-Sharing NAT, Twice NAT
Security Profile IPS/ App. control/ Web Filter/ Etc. N/A
User-ID / Device User-Based Firewall Policy Setting & Management
Device-Based Control (OS, Patch, S/W)
External Auth. Server ○ (LDAP/AD/RADIUS/MS SQL/TACACS+)
Domain Name Object Domain Name-Based Firewall Policy Setting & Management
Etc.
Firewall Policy Export/ Import
URL Categorized Filter N/A
Automatic creation of log based policies/objects
Encrypted Traffic Control N/A
SSL Inspection SSL Traffic Inspection
White List function (inspection exception)
Regional Block
Regional Block Policy Block for Regional IP address ○ (Country/Continet)
Custom Region ○ (Max 10)
Application Control N/A
Application-Based Control
Number of Applications
Number of Signatures
Signature Update for Closed Network
Application Information
Custom Application
QoS for Application
Unknown Application Control
Application Mapping
IPS N/A
Features
Security Threat Monitoring Analysis, Signature Detection
24hr Monitoring/ Response Service
Emergency Response System
Zero-Day Attack Defense
Cloud Based Real-Time Malcious Code Detection
Microsoft Security Patch, Share Past Vulnerability Info
Signature Update Cycle
Signature Update History
Signature Help
AST/ CDN Update Service
Signature Update in Air-gapped
Web Help in Air-gapped
Safe Update Service
IPS Policy Profiling
Signature Based Prevention
Intrusion Prevention Signatures
Prevent attack over vulnerabilities
   Web vul Prevention (OWASP 10)
      – SQL/PHP Injection, XSS (Cross-Sites Scripting)
      – IIS/ CGI/ MISC/ PHP related vulnerabilities
   Application  Prevention
      – OS vulnerabilities/ Internet Explorer
      – ARP Spoofing
      – Shell code
      – Script
Network Intrusion
   Various Scanning Intrusion
   NetBios
   RPC
   DoS
   BackDoor
   TCP Reassembly, IP Defragmentation
   DNS
   Exploit  (SSH, WINS, ISAKMP)
   Protocol Anomaly
Malware Prevention
   Worm
   Trojan
   Spyware
   Downloader
   Dropper
   Massmailer
   Vulnerability
   Shell Code
APT Attack Defense
  Recent APT hack tool/ method/ malicious code
source/ block
   Block Trojan sources
   Block Spyware sources
   Block Various mal code sources
Block suspicious activities over vulnerabilities
Behavior Based Prevention
Anomaly Based Prevention
DoS, Scan Prevention (TRINOO, JOLT, WINNUKE )
User Defined Rules
User Defined Signature
IP/ Port/ source/ dest Based Rule, exceptions
Bot/ BotNet Detection & Prevention
Bot mal code inflow control
DDoS Protection
TCP Flooding
 – SYN Flooding (Spoofing), ACK Flooding (Spoofing)
 – NULL Flooding (Spoofing), SYN-ACK Flooding
 – IP Random Fragment Flag, RST Flooding
UDP Flooding
 – UDP Flooding (Spoofing)
ICMP Flooding
 – ICMP Echo Flooding (Spoofing)
 – ICMP Echo Reply Flooding (Spoofing)
Application
 – HTTP GET Flooding Attack
 – Rudy Attack
 – CC (Cache-Control) Attack
Other
 – Confuse TCP/UDP/ICMP Flooding
Response
Allow, Block, Log
Session Drop
Quarantine (infected PCs)
Limit Bandwidth(Auto Throttling)
IAC (Internet Access Control)
PC Security Status Check & Control
Preventing Malicious Code Proliferation
Auto Cure for Infection PC
Malicious Code Auto Extraction
Update
Update
C&C Server Detect/Block
C&C BlackList Based N/A
Cloud Based C&C Server Database
C&C Server Detection/ Control (IRC/ HTTP)
VPN
SSL VPN N/A
Gateway to Client
User level Access Control
Center SSL VPN Active-Stand By HA
Center SSL VPN L4 Switch VPN Load-Balancing
User Auth. using ID/PW
Designated Network(Server) for User & User Group
Virtual IP Assign when SSL VPN Connection
Redirection Page when SSL VPN Connection
SSL VPN Main Page Customizing (Logo)
SSL VPN Idle Session Timeout
SSL VPN User Login Time Control
Forced User Block & User Login Lock
User Password Initiation (by admin)
Client PC Security Pre-Check
Client PC Security Post-Check
Internal Server Access Control
Real-time User Monitoring
PC Client Supported OS (32bit/ 64bit)
SSL VPN Tunnel – IPSec VPN Tunnel Interlock
SSL VPN Traffic IPS Interlock
Mobile SSL VPN
Embedded ternminal linkage support
SSL VPN User Authentication
ID/ Password Auth.
Login Fail Count Setting
External Auth. Server (SSL VPN)
Private Certificate
Public Certificate
IPsec VPN
VPN Network Deployment Hub & Spoke/ Star/ Mesh
Gateway-to-Gateway/ Gateway-to-Client
Bridge over IPSec
Key Exchange Way ○ (IKE v1/ IKE v2/ Manual)
Key Exchange Auth. ○ (Shared Key/ Certificate)
Encryption Algorithm ○ (3DES, AES(128,192,256), SEED, ARIA)
Certificated Encryption Algorithm ○ (ARIA)
Hash Function ○ (SHA1, SHA2, HAS160)
Dead Peer Detection
IPSec Traffic Bypass
PFS (Perfect Forward Secrecy)
NAT Traversal
Split Tunnel
Prevent Replay Attack
Center VPN L2/ L3 Switch VPN HA ○ (A-A, A-S)
Center VPN L4 Switch VPN Load-Balancing
Branch VPN L2 environment Load-Balancing
Multi-line for Branch ○ (Load-balancing, Fail-over, Over 2 lines)
Multi-line Load Balancing (1) Per Session/ Per Packet/ Weight Based
Multi-line Load Balancing (2) Active-Active/ Active-Standby
Traffic-Tunnel Pairing ○ (Sourec/ Destination Based)
DR Network Backup ○ (Auto/ Manual Backup)
Router Auto Backup
VPN Traffic QoS
GRE over IPSec
Firewall / IPS Interlock
Malicious Code Block in VPN Tunnel IPS Signature Based
VPN Network Monitoring ○ (Malfunction, Traffic, VPN Status)
Policy Batch Distribution for VPN Network
Colsed Branch Control/ Prevention of Thefts
Anti-Virus / Anti-Spam / Content Filtering
Anti-Virus N/A
Inhouse Signature Create Organization
24hr Monitoring & Response
Emergency Response System
Signature Periodic Update
Stable Update Service using CDN
Services Scanned
e-mail Virus Pre-cure (Outbreak Prevention)
AV Engine
Max File Size for Inspection
Compressed File Inspection
File Extension Filtering
Packet Based Anti-Virus (Stream Based AV)
Anti-Spam N/A
Scans SMTP, POP3
RBL(Real-Time Black List)
Global Spam Engine
Custom Keyword(Title, Contents)
Regular Expression/ WildCard
Max Mail Size for Inspection
Whitelist
Spam Mail Quarantine
Mail Receiver Limit
Mass Mail Transfer Limit
Mail Size Limit
Website Filtering N/A
URL Filtering(HTTP)
URL Filtering DB
Custom URL Filtering
WildCard
Exception on policy
   Malicious Code Distribution Site Filtering N/A
Block for Malicious Code Distribution Site
Block for Phishing Site
Malicious Site Filtering DB
   Anti-APT N/A
Unknown Malicious Suspicious File Detection
Other Proxy N/A
Supported Proxy
Proxy & IPS Interlock (IPS, AV, AS Scanning)
Block for Java Applet, Active X
Block for Command (FTP, SMTP)
Block for Mail Relay (SMTP)
Private IP Address Prevention
DNS Response Inspection
DNS Safe Search
Update
Update
Data Loss Prevention (DLP) N/A
Data Loss Prevention
Data Loss Prevention
File Extension Filtering
File Name Filtering
Block & Detect for Personal Information
DLP Directionality Setting Control
Admin Auth.
Admin Auth.
ID/ Password Auth.
Admin Login Fail Count
Admin Session Idle Timeout
Trusted Host Setting ○ (IPv4/IPv6 Address)
External Auth. Server ○ (RADIUS/ LDAP/ Active Directory/ TACAS+/ OTP)
Management
user-friendly GUI
HTTPS (WebUI), SSH
Multi-language Korean
admin privilege
* detail privilege settings
Open API
Logging / Monitoring
Log Type
Log Type system/ network/ admin log/ security event log
Log Leveling (Leveling) 5 levels
Real-time Monitoring
System Realtime Monitoring
Network Realtime Monitoring ○ (traffic amt, packets, connections)
Abnormal devices Monitoring
(system resource, usage threshold/ power error/ connection error/system/ admin login/ license/update fail)
abnormal device event level
view sessions realtime
Top 50 monitoring
IPS realtime monitoring
Virus realtime monitoring
Spam mail realtime monitoring
Website filter realtime monitoring
FW filter log monitoring
FW policy monitoring
Detail event log analysis
detail security policy log
main services ○ (Protocol, service, usage statistics)
log store method ○ (user-defined log, save method)
event alert ○ (e-mail/ SMS/ PoP-Up)
central monitoring (standalone)
central monitoring on multiple devices
device status monitoring
log search & reporting (embed/standalone) standalone
system/ traffic/ security event statistics
system/ traffic/ security event detail view
attack analysis
Drill-Down analysis
harmful traffic correlation
fast reporting
various types of reporting
daily, weekly, monthly report