|
 |
|
|
|
|
|
|
سری Z
VPN 2500
VPN 2500 برای ایجاد ارتباطی سریع و ایمن بین شعبات سازمان و یا به عنوان VPN gateway برای تا ۲۰۰۰کاربر VPN طراحی شده است.
شتابدهنده رمزنگاری VPN باعث افزایش نرخ انتقال اطلاعات و کارایی می گردد. با توجه به سخت افزار دستگاه و امکان HotSwap و همچنین هارددیسک های 24/7 سرور، منبع تغذیه یدکی، کارایی و دسترسی بالا، دستگاه ها تا 99.97 در مقابل خرابی ایمن هستند. امکاناتی نظیر HA، xUA با single sign-on، traffic shaping &، QoS و load balancing دستگاه VPN 1000 گیت پروتکت را به انتخابی عالی برای زیرساخت های VPN در سازمان هایی با دفاتر متعدد و کارمندان راه دور تبدیل ساخته است.
|
|
|
Special Features
Extended
User Authentication |
|
The majority of today's Firewall systems support a proxy based
user-authentication. That means that only the services, which work with proxies
e.g. at http or ftp, it can be assigned user specific.The gateProtect Firewall
decrees over a rule-based extended user-authentication. Here it is possible to
assign as many services as you need individually for a user or a user group.
These services can be provided with all well-known additional options like proxy
or web-filter.Now, if a user log on a computer at the Firewall, all assigned
services for the concerning computer will be activating.
|
Extended
VPN Gateway (SSL with X.509 Certificates + IPSec) |
|
gateProtect offers the most usual forms of today's site-to-site and road warrior
vpn connections via IPSEC and SSL. The administration and creation is supported
by Wizards and the eGUI-technology. Additionally the Firewall provides external
configuration files during the creation of vpn connections. These can be used
for the creation of single-click-connections and for the import on remote
firewalls for site-to-site connections.
In addition gateProtect offers a SSL site-to-site solution with X.509
certificates, which can work optionally also in the bridge-mode. With a normal
bridge two or several network interfaces were connected so that they form a
logical network. gateProtect allows this not only for network interface, but
also for vpn over ssl connections. It is possible to handle computers at other
locations exactly the same as if they would be in the local network.
|
Traffic
shaping & QoS
|
|
The Traffic Shaping of gateProtect is one of the most extensive implementations
at the market. For each object on the desktop maximum and minimum bandwidth can
be specified. Thereupon constructing the traffic for the individual services can
be affected. Thus the distribution of the bandwidth can be configured into each
degree of detail.
A further characteristic of the gateProtect solution is the prioritisation of
data packets in the VPN tunnel using QoS. This is important for time-critical
applications, where a delay is unwanted. So you are able to telephone
trouble-free over a VPN tunnel by using VoIP independently of the efficiency of
the tunnel e.g. by RDP or downloads.
|
Load
Balancing |
|
With its load balancing gateProtect allows to divide the data traffic to the
Internet on different internet connections. The firewall takes the decision
which internet connection will be used for every connection.
Such segmentation is normally made according to protocols. gateProtect allows to
allocate the traffic to several internet connection. In this way the usage of
the internet connections detail can be planned and optimized into smallest
detail.
|
High
availability
|
|
The high availability of gateProtect firewall systems is based on an
active/passive system. In this configuration a secondary firewall is installed
parallel to the primary firewall. The secondary firewall continual synchronizes
over dedicated connections with the primary Firewall. So it is able to assume
the work of the primary Firewall in case of failures smoothly and without manual
interference.
Furthermore the condition of the primary firewall is monitored by different
systems. If the monitoring detects any problems within the firewall, the
firewall will shutdown by itself. After this the secondary firewall gives free
the synchronized configuration and will continue working directly in place of
the primary firewall. The down-times will minimize and the occurred problems can
be eliminated unhurriedly.
|
|
|
|
|
|
|
Short facts VPN 2500 |
|
The essentials in brief |
|
User license |
unlimited |
|
|
|
|
LAN (accumulated) |
5 |
|
|
|
VPN - Crypto acceleration
|
Yes |
Redundant -
HDD (Raid) |
Yes |
Redundant -
Power supply |
Yes |
|
|
|
Throughput (Mbps) |
|
Firewall |
9 000 |
|
VPN (IPSec) |
2 500 |
|
IDS/IPS |
2 500 |
|
Concurrent Sessions |
2 500 000 |
|
|
Features |
|
Firewall |
|
Layer function |
|
Single Sign On (xUA)
|
|
Zoom function |
|
Paket filter |
|
IDS |
|
NAT |
|
Bridging |
|
|
|
Internet |
|
Failover |
|
Concurrent connections
|
|
Load Balancing
|
|
Traffic shaping |
|
|
|
|
|
|