Bỏ qua đến nội dung
0
Giỏ hàng 0 sản phẩm

Chưa có sản phẩm trong giỏ hàng.

Tư vấn giải pháp

AhnLab TrusGuard 40B

Liên hệ Hóa đơn VAT Bảo hành chính hãng
THÔNG TIN SẢN PHẨM

Chi tiết và thông số kỹ thuật

AhnLab TrusGuard 40B là giải pháp tường lửa thế hệ tiếp theo (Next-Generation Firewall – NGFW) được phát triển bởi AhnLab, nhà cung cấp giải pháp an ninh mạng hàng đầu Hàn Quốc.

TrusGuard 40B cung cấp khả năng bảo vệ toàn diện cho mạng lưới của bạn khỏi các mối đe dọa mạng tiên tiến nhất hiện nay.

Thông số cơ bản:
  • Throughput: 1.5 Gbps
  • VPN throughput: 300 Mbps
  • Số lượng giao diện mạng: 8
  • Cổng Gigabit Ethernet: 8
  • Cổng SFP: 2
  • Kích thước: 1U rackmount
  • Nguồn điện: AC 100-240V, 50/60Hz
Tính năng chính:
  • Ngăn chặn các cuộc tấn công mạng tiên tiến: TrusGuard 40B sử dụng công nghệ Deep Learning tiên tiến để phát hiện và ngăn chặn các cuộc tấn công mạng tiên tiến như ransomware, zero-day attack, và APT.
  • Ngăn chặn các hành vi vi phạm dữ liệu: TrusGuard 40B cung cấp các tính năng bảo mật dữ liệu tiên tiến như DLP (Data Loss Prevention) để ngăn chặn việc rò rỉ dữ liệu nhạy cảm.
  • Quản lý truy cập mạng (NAC): TrusGuard 40B cho phép bạn kiểm soát chặt chẽ truy cập vào mạng lưới của bạn, giúp bảo vệ các tài nguyên mạng khỏi truy cập trái phép.
  • Bảo vệ chống lại các mối đe dọa mạng mới nổi: TrusGuard 40B liên tục được cập nhật để bảo vệ bạn khỏi các mối đe dọa mạng mới nổi.
Lợi ích khi sử dụng AhnLab TrusGuard 40B:
  • Bảo vệ toàn diện mạng lưới của bạn khỏi các mối đe dọa mạng tiên tiến.
  • Ngăn chặn các hành vi vi phạm dữ liệu.
  • Kiểm soát chặt chẽ truy cập vào mạng lưới của bạn.
  • Hiệu suất cao và dễ dàng sử dụng.
  • Được hỗ trợ bởi đội ngũ chuyên nghiệp của SMNET.
Hãy liên hệ SMNET để bảo vệ mạng lưới của bạn an toàn với AhnLab TrusGuard 40B!
Physical
Main Processor 2 Core 1.6Ghz * 1ea
Main Memory 4GB (since ’21 Jan)
System Storage (CF / SSD) 4GB
Log Storage –
Log Storage (Option) –
Type Small Size, 1U
Dimension(WxHxD mm) 220x44x194.5
Weight Weight : 1.3
Boxed : 2.6
Double Boxed : 11.9
Power (External Power Supply) 40W Single Power
Power Consumption (W) 17W
Redundant Power No
Operating Temperature 0~40 deg C
Storage Temperature -20~70 deg C
BTU/h (MAX) 58
QRNG –
CC Certification EAL 4
(Intrusion Prevention Protection Profile)
GS Certification ○ (3.0)
IPv6 Certification IPv6 Ready Logo Phase-2(Router)
Electro-Magnetic Compatibility FCC/ KC
Interfaces
Slots –
Console Interface 1 (RJ-45)
10/100 Switch –
10/100/1000 Switch Port (Copper) –
10/100/1000 Base-T (Copper) 8
1G Base-X (Fiber – SFP) –
10G Base-X –
40G Base-X –
100G BASE-X –
Option module –
Bypass X
System Performance
Session
Max Concurrent Sessions (CC) 1.000.000
Connection Per Second (CPS) 35.000
Performance
Firewall Throughput (Max) 4G
Firewall Throughput (64bytes) 1G
IPS Throughput (Max) –
VPN Throughput 1G
VPN Tunnels 2.500
SSL VPN Users (PC, Mobile for each) –
Q-VPN Users –
System Policies
by Feature
Firewall Policies 1024
Network Features
OS Inhouse Developed ○ (ANOS)
Mode
Route mode ○
Transparent(Bridge) Mode ○
Interface
Static, DHCP Interface ○
802.1Q VLAN ○
802.3ad Port Aggregation
  – Port Active-Standby ○
  – Port Active-Active ○
  – Traffic Transfer Mode Round-robin (L2/ L2+L3/ L3+L4)
Multi-line (Load-balancing/ Fail-over) ○
Routing
Static Routing ○
Source Routing ○ (Source & Destination Based)
Dynamic Routing ○ (RIPv1/v2, OSPF, BGP)
Multicast Routing
  – Routing ○ (PIM-SM, IGMP)
  – Channel japping (Join/ Leave) ○
  – Static RP(Rendezvous Point) ○
  – SPT (Short Path Tree) ○
High Availability
Full-Mesh Network Configuration (without L2) ○
High-Availability
 – Active-Active, Active-Standby (with/ without L4) ○
 – Policy Sync./ Session Sync. ○
 – VLAN Interface High-Availability ○
 – Heart Beat Interface Aggregation ○ (Active-Active/ Active-Standby)
 – Packet Divert ○ (Active-Active/ Active-Standby)
VRRP (Virtual Router Redundancy Protocol) ○
Bypass function(Transparent mode) X
QoS
Firewall Policy/ IP/ Port QoS ○
Policy Based/ Schedule Based QoS ○
QoS Rating, Detail Setting ○ (7 Level)
Max Bandwidth Limit/ Min Bandwidth Guarantee ○
Mass Web Traffic Control ○
QOS Directionality Setting Control ○
Rollback Configuration Rollback/ Firmware Rollback ○
Configuration Changes Hostory Comparison with Previous Settings ○
Other
DHCP Server/ Client ○
DHCP Relay (in Bridge Mode) ○
DNS/ Split DNS ○
SNMP ○ (SNMP v1/ v2/ v3)
NTP Server (Primary/ Secondary) ○
SIMS Interlock ○
VoIP Dynamic Port (H.323, SIP) ○
Service/ Protocol Session Timeout Control ○
Virtual System
IPv6
Dual Stack
IPv4 & IPv6 Simultaneous Processing ○
IPv6 Networking
Dual Stack ○ (Static, Bridge, aggregation, VLAN)
IPv6 Static IP ○
IPv6 DHCP Server ○
IPv6 Bridge ○
IPv6 Static Routing ○
IPv6 Dynamic Routing ○ (RIPv6, OSPFv6, BGPv6)
IPv6 RA ○
IPv6 Tunneling ○ (6to4)
IPv6 Translation ○ (NAT46 / NAT64/ NAT66/ DNS64)
IPv6 LogServer ○
IPv6 Packet Filtering
Stateful Inspection ○
Firewall
Features
Stateful Packet Inspection ○
Independent Performance Related to Number of Policies ○
Independent Performance Related to Number of Sessions ○
Realtime Apply for New Policies ○
Validation Check for Policies (1) ○ (Day/ Week/ Month Hit Counting)
Validation Check for Policies (2) ○ (Last Hit Time)
Virtual Packet Simulation ○
Searching for Expiring Policies ○
Bi-directional Policies ○
Zone-based policy management function ○
Alarm when Total Number of Sessions Exceeded Threshold ○
Alarm when Limit Number of Sessions per Firewall Policy ○
Alarm when Total Number of Dropped Packets Exceeded Threshold ○
Alarm when HA State Changed ○
Alarm when HA Disconnected ○
Categorization for HA Sync. List ○
Filtering
Black List ○
White List ○
Schedule Based Policy ○
Limit for Session Count per Policy ○
Limit for Session Count per Source IP Address ○
NAT
NAT (Network Address Translation) ○
Static/ Dynamic NAT, Excluded NAT, NAT Traversal,
Load-Sharing NAT, Twice NAT
Security Profile IPS/ App. control/ Web Filter/ Etc. N/A
User-ID / Device User-Based Firewall Policy Setting & Management ○
Device-Based Control (OS, Patch, S/W) ○
External Auth. Server ○ (LDAP/AD/RADIUS/MS SQL/TACACS+)
Domain Name Object Domain Name-Based Firewall Policy Setting & Management ○
Etc.
Firewall Policy Export/ Import ○
URL Categorized Filter N/A
Automatic creation of log based policies/objects ○
Encrypted Traffic Control N/A
SSL Inspection SSL Traffic Inspection
White List function (inspection exception)
Regional Block
Regional Block Policy Block for Regional IP address ○ (Country/Continet)
Custom Region ○ (Max 10)
Application Control N/A
Application-Based Control
Number of Applications
Number of Signatures
Signature Update for Closed Network
Application Information
Custom Application
QoS for Application
Unknown Application Control
Application Mapping
IPS N/A
Features
Security Threat Monitoring Analysis, Signature Detection
24hr Monitoring/ Response Service
Emergency Response System
Zero-Day Attack Defense
Cloud Based Real-Time Malcious Code Detection
Microsoft Security Patch, Share Past Vulnerability Info
Signature Update Cycle
Signature Update History
Signature Help
AST/ CDN Update Service
Signature Update in Air-gapped
Web Help in Air-gapped
Safe Update Service
IPS Policy Profiling
Signature Based Prevention
Intrusion Prevention Signatures
Prevent attack over vulnerabilities
   Web vul Prevention (OWASP 10)
      – SQL/PHP Injection, XSS (Cross-Sites Scripting)
      – IIS/ CGI/ MISC/ PHP related vulnerabilities
   Application  Prevention
      – OS vulnerabilities/ Internet Explorer
      – ARP Spoofing
      – Shell code
      – Script
Network Intrusion
   Various Scanning Intrusion
   NetBios
   RPC
   DoS
   BackDoor
   TCP Reassembly, IP Defragmentation
   DNS
   Exploit  (SSH, WINS, ISAKMP)
   Protocol Anomaly
Malware Prevention
   Worm
   Trojan
   Spyware
   Downloader
   Dropper
   Massmailer
   Vulnerability
   Shell Code
APT Attack Defense
  Recent APT hack tool/ method/ malicious code
source/ block
   Block Trojan sources
   Block Spyware sources
   Block Various mal code sources
Block suspicious activities over vulnerabilities
Behavior Based Prevention
Anomaly Based Prevention
DoS, Scan Prevention (TRINOO, JOLT, WINNUKE )
User Defined Rules
User Defined Signature
IP/ Port/ source/ dest Based Rule, exceptions
Bot/ BotNet Detection & Prevention
Bot mal code inflow control
DDoS Protection
TCP Flooding
 – SYN Flooding (Spoofing), ACK Flooding (Spoofing)
 – NULL Flooding (Spoofing), SYN-ACK Flooding
 – IP Random Fragment Flag, RST Flooding
UDP Flooding
 – UDP Flooding (Spoofing)
ICMP Flooding
 – ICMP Echo Flooding (Spoofing)
 – ICMP Echo Reply Flooding (Spoofing)
Application
 – HTTP GET Flooding Attack
 – Rudy Attack
 – CC (Cache-Control) Attack
Other
 – Confuse TCP/UDP/ICMP Flooding
Response
Allow, Block, Log
Session Drop
Quarantine (infected PCs)
Limit Bandwidth(Auto Throttling)
IAC (Internet Access Control)
PC Security Status Check & Control
Preventing Malicious Code Proliferation
Auto Cure for Infection PC
Malicious Code Auto Extraction
Update
Update
C&C Server Detect/Block
C&C BlackList Based N/A
Cloud Based C&C Server Database
C&C Server Detection/ Control (IRC/ HTTP)
VPN
SSL VPN N/A
Gateway to Client
User level Access Control
Center SSL VPN Active-Stand By HA
Center SSL VPN L4 Switch VPN Load-Balancing
User Auth. using ID/PW
Designated Network(Server) for User & User Group
Virtual IP Assign when SSL VPN Connection
Redirection Page when SSL VPN Connection
SSL VPN Main Page Customizing (Logo)
SSL VPN Idle Session Timeout
SSL VPN User Login Time Control
Forced User Block & User Login Lock
User Password Initiation (by admin)
Client PC Security Pre-Check
Client PC Security Post-Check
Internal Server Access Control
Real-time User Monitoring
PC Client Supported OS (32bit/ 64bit)
SSL VPN Tunnel – IPSec VPN Tunnel Interlock
SSL VPN Traffic IPS Interlock
Mobile SSL VPN
Embedded ternminal linkage support
SSL VPN User Authentication
ID/ Password Auth.
Login Fail Count Setting
External Auth. Server (SSL VPN)
Private Certificate
Public Certificate
IPsec VPN
VPN Network Deployment Hub & Spoke/ Star/ Mesh
Gateway-to-Gateway/ Gateway-to-Client ○
Bridge over IPSec ○
Key Exchange Way ○ (IKE v1/ IKE v2/ Manual)
Key Exchange Auth. ○ (Shared Key/ Certificate)
Encryption Algorithm ○ (3DES, AES(128,192,256), SEED, ARIA)
Certificated Encryption Algorithm ○ (ARIA)
Hash Function ○ (SHA1, SHA2, HAS160)
Dead Peer Detection ○
IPSec Traffic Bypass ○
PFS (Perfect Forward Secrecy) ○
NAT Traversal ○
Split Tunnel ○
Prevent Replay Attack ○
Center VPN L2/ L3 Switch VPN HA ○ (A-A, A-S)
Center VPN L4 Switch VPN Load-Balancing ○
Branch VPN L2 environment Load-Balancing ○
Multi-line for Branch ○ (Load-balancing, Fail-over, Over 2 lines)
Multi-line Load Balancing (1) Per Session/ Per Packet/ Weight Based
Multi-line Load Balancing (2) Active-Active/ Active-Standby
Traffic-Tunnel Pairing ○ (Sourec/ Destination Based)
DR Network Backup ○ (Auto/ Manual Backup)
Router Auto Backup ○
VPN Traffic QoS ○
GRE over IPSec ○
Firewall / IPS Interlock ○
Malicious Code Block in VPN Tunnel IPS Signature Based
VPN Network Monitoring ○ (Malfunction, Traffic, VPN Status)
Policy Batch Distribution for VPN Network ○
Colsed Branch Control/ Prevention of Thefts ○
Anti-Virus / Anti-Spam / Content Filtering
Anti-Virus N/A
Inhouse Signature Create Organization
24hr Monitoring & Response
Emergency Response System
Signature Periodic Update
Stable Update Service using CDN
Services Scanned
e-mail Virus Pre-cure (Outbreak Prevention)
AV Engine
Max File Size for Inspection
Compressed File Inspection
File Extension Filtering
Packet Based Anti-Virus (Stream Based AV)
Anti-Spam N/A
Scans SMTP, POP3
RBL(Real-Time Black List)
Global Spam Engine
Custom Keyword(Title, Contents)
Regular Expression/ WildCard
Max Mail Size for Inspection
Whitelist
Spam Mail Quarantine
Mail Receiver Limit
Mass Mail Transfer Limit
Mail Size Limit
Website Filtering N/A
URL Filtering(HTTP)
URL Filtering DB
Custom URL Filtering
WildCard
Exception on policy
   Malicious Code Distribution Site Filtering N/A
Block for Malicious Code Distribution Site
Block for Phishing Site
Malicious Site Filtering DB
   Anti-APT N/A
Unknown Malicious Suspicious File Detection
Other Proxy N/A
Supported Proxy
Proxy & IPS Interlock (IPS, AV, AS Scanning)
Block for Java Applet, Active X
Block for Command (FTP, SMTP)
Block for Mail Relay (SMTP)
Private IP Address Prevention
DNS Response Inspection
DNS Safe Search
Update
Update –
Data Loss Prevention (DLP) N/A
Data Loss Prevention
Data Loss Prevention
File Extension Filtering
File Name Filtering
Block & Detect for Personal Information
DLP Directionality Setting Control
Admin Auth.
Admin Auth.
ID/ Password Auth. ○
Admin Login Fail Count ○
Admin Session Idle Timeout ○
Trusted Host Setting ○ (IPv4/IPv6 Address)
External Auth. Server ○ (RADIUS/ LDAP/ Active Directory/ TACAS+/ OTP)
Management
user-friendly GUI ○
HTTPS (WebUI), SSH ○
Multi-language Korean
admin privilege
* detail privilege settings
○
Open API ○
Logging / Monitoring
Log Type
Log Type system/ network/ admin log/ security event log
Log Leveling (Leveling) 5 levels
Real-time Monitoring
System Realtime Monitoring ○
Network Realtime Monitoring ○ (traffic amt, packets, connections)
Abnormal devices Monitoring ○
(system resource, usage threshold/ power error/ connection error/system/ admin login/ license/update fail)
abnormal device event level ○
view sessions realtime ○
Top 50 monitoring ○
IPS realtime monitoring –
Virus realtime monitoring –
Spam mail realtime monitoring –
Website filter realtime monitoring –
FW filter log monitoring ○
FW policy monitoring ○
Detail event log analysis ○
detail security policy log ○
main services ○ (Protocol, service, usage statistics)
log store method ○ (user-defined log, save method)
event alert ○ (e-mail/ SMS/ PoP-Up)
central monitoring (standalone)
central monitoring on multiple devices ○
device status monitoring ○
log search & reporting (embed/standalone) standalone
system/ traffic/ security event statistics ○
system/ traffic/ security event detail view ○
attack analysis ○
Drill-Down analysis ○
harmful traffic correlation ○
fast reporting ○
various types of reporting ○
daily, weekly, monthly report ○