63
Security
NetDefend Firewall Selection Matrix
iPS Firewalls
utM Firewalls
DFL-210
DFL-800
DFL-1600
DFL-2500
DFL-260
DFL-860
DFL-1660
DFL-2560
DFL-2560G
interface
ethernet WAN Port
1
2
-
-
1
2
-
-
-
Ethernet DMZ Port
1
1
-
-
1
1
-
-
-
ethernet LAN Port
4
7
-
-
4
7
-
-
-
User-Configurable Gigabit RJ-45 Port
-
-
6
8
-
-
6
10
6
user-configurable Gigabit SFP Port
-
-
-
-
-
-
-
-
4
System Performance
Firewall throughput (Mbps)
80
150
320
600
80
150
1,200
2,000
2,000
VPN throughput (Mbps)
25
45
120
300
25
45
350
1,000
1,000
concurrent Sessions
10K
20K
400K
1,000K
10K
20K
600K
1,500K
1,500K
Policies
500
1,000
2,500
4,000
500
1,000
4,000
6,000
6,000
Firewall System
transparent Mode
yes
yes
yes
yes
yes
yes
yes
yes
yes
Network & Port Address Translation (NAT,
PAt)
yes
yes
yes
yes
yes
yes
yes
yes
yes
OSFP Dynamic Routing Protocol
No
yes
yes
yes
No
yes
yes
yes
yes
time-Scheduled Policies
yes
yes
yes
yes
yes
yes
yes
yes
yes
Proactive Network Security (ZoneDefense)
No
yes
yes
yes
No
yes
yes
yes
yes
icSA Firewall corporate Level certified
yes
yes
yes
yes
yes
yes
yes
yes
yes
Networking
DHCP Server / Client
yes
yes
yes
yes
yes
yes
yes
yes
yes
DHCP Relay / Policy-based Routing
yes
yes
yes
yes
yes
yes
yes
yes
yes
ieee 802.1Q Virtual LAN (VLAN)
8
16
128
1,024
8
16
1,024
2,048
2,048
iP Multicast (iGMPv3)
yes
yes
yes
yes
yes
yes
yes
yes
yes
Virtual Private Network (VPN)
DeS/3DeS/AeS/twofish/Blowfish/cASt-128
yes
yes
yes
yes
yes
yes
yes
yes
yes
Dedicated VPN tunnels
100
200
1,200
2,500
100
200
2,500
5,000
5,000
PPtP/L2tP Server / iPSec NAt traversal
yes
yes
yes
yes
yes
yes
yes
yes
yes
Hub and Spoke
yes
yes
yes
yes
yes
yes
yes
yes
yes
icSA iPSec 1.3 enhanced certified
yes
yes
yes
yes
yes
yes
yes
yes
yes
System Management
Web-Based User Interface (HTTP/HTTPS)
yes
yes
yes
yes
yes
yes
yes
yes
yes
Command Line/SSH
yes
yes
yes
yes
yes
yes
yes
yes
yes
configuration Backup/restore
yes
yes
yes
yes
yes
yes
yes
yes
yes
user Authentication
Built-in Database
yes
yes
yes
yes
yes
yes
yes
yes
yes
External RADIUS / LDAP (IPSec only) Server
yes
yes
yes
yes
yes
yes
yes
yes
yes
External Microsoft IAS Server
yes
yes
yes
yes
yes
yes
yes
yes
yes
XAUTH for IPSec Authentication
yes
yes
yes
yes
yes
yes
yes
yes
yes
Logging and Monitoring
Internal / External Log (Syslog Server)
yes
yes
yes
yes
yes
yes
yes
yes
yes
Email Notification, Event Log & Alarm
yes
yes
yes
yes
yes
yes
yes
yes
yes
SNMP v1, v2c
yes
yes
yes
yes
yes
yes
yes
yes
yes
traffic Load Balancing
Outbound Traffic Load Balancing
yes
yes
yes
yes
yes
yes
yes
yes
yes
Server Load Balancing
No
yes
yes
yes
No
yes
yes
yes
yes
Algorithms for Outbound Traffic Load Balancing
round-robin, Destination-Based, Spillover
yes
1
yes
1
yes
1
yes
1
yes
1
yes
1
yes
yes
yes
Bandwidth Management
Policy-Based traffic Shaping
yes
yes
yes
yes
yes
yes
yes
yes
yes
Guaranteed / Maximum / Priority Bandwidth
yes
yes
yes
yes
yes
yes
yes
yes
yes
Dynamic Bandwidth Balancing
yes
yes
yes
yes
yes
yes
yes
yes
yes
Bandwidth Management in VPN tunnel
yes
yes
yes
yes
yes
yes
yes
yes
yes
High Availability (HA)
WAN Fail-Over / Traffic Redirect at Fail-Over
yes
yes
yes
yes
yes
yes
yes
yes
yes
Device / Link Failure Detection
No
No
yes
yes
No
No
yes
yes
yes
Intrusion Detection & Prevention System (IDP/IPS)
Automatic Pattern update
yes
yes
yes
yes
yes
yes
yes
yes
yes
DoS, DDoS Protection
yes
yes
yes
yes
yes
yes
yes
yes
yes
iP Blacklist by threshold or iPS/iDP
No
yes
yes
yes
No
yes
yes
yes
yes
content Filtering
HTTP / Script / Email Type
yes
yes
yes
yes
yes
yes
yes
yes
yes
External Database Content Filtering
yes
2
yes
2
No
No
yes
yes
yes
yes
yes
Anti-Virus
real time AV Scanning / unlimited File Size
yes
2
yes
2
No
No
yes
yes
yes
yes
yes
Scans VPN tunnels / compression File
yes
2
yes
2
No
No
yes
yes
yes
yes
yes
Signature Licensor (Kaspersky)
yes
2
yes
2
No
No
yes
yes
yes
yes
yes
Automatic Pattern update
yes
2
yes
2
No
No
yes
yes
yes
yes
yes
email Security
SMTP & POP3 Protocol Support
yes
yes
yes
yes
yes
yes
yes
yes
yes
MIME Header Check for File Extension
Filtering
yes
yes
yes
yes
yes
yes
yes
yes
yes
Email Rate & Size Protection (SMTP Protocol
only)
yes
yes
yes
yes
yes
yes
yes
yes
yes
Anti-Spam (for SMtP Protocol only)
yes
yes
yes
yes
yes
yes
yes
yes
yes
iM/P2P Blocking
yes
yes
yes
yes
yes
yes
yes
yes
yes
NetDefend Firewall Selection Matrix
1
Available in Firmware 2.25.01
2
Available in Firmware 2.26.00
70
Summary of Contents for DES-7200
Page 1: ...Business Solutions Guide...