Sophos XG Firewall - Zones

Transcription

Sophos XG FirewallUnrivalled simplicity, security and insightSophos XG Firewall brings a fresh new approach to the way youmanage your firewall, respond to threats, and monitor what’shappening on your network. Get ready for a whole new level ofsimplicity, security and insight.

Sophos XG FirewallSophos XG Firewall – The next thing in next-genXG Firewall is optimized for today’s business, delivering all the protection andinsights you need in a single, powerful appliance that’s easy to mange.Advanced protection made simplePotent, powerful fastMost firewall products make you set up and manage policiesacross multiple modules or screens. Not Sophos. We providea powerful unified policy model that allows you to manage,view, filter, and sort all your user, application and networkpolicies on a single screen.We’ve engineered XG Firewall to deliver outstandingperformance. Our appliances are built using Intel multicore technology, solid-state drives, and accelerated inmemory content scanning. In addition Sophos FastPathpacket optimization technology ensures you’ll always getmaximum throughput.More-in-one protectionYou get all the next-gen firewall features you need plusfeatures you can’t get anywhere else – including ourrevolutionary Security Heartbeat , full web applicationfirewall, and complete email anti-spam, encryption and DLP.No extra hardware. No extra cost. Simply choose what youwant to deploy.On-box reports included as standardWith hundreds of built-in reports you’ll know exactly what’shappening with your users and your network. You get detailedreports as standard, stored locally with no separate toolsrequired. And our unique User Threat Quotient reports showyou which of your users are putting your security at risk.1Simply manage multiple firewallsSophos Firewall Manager provides a single console for thecomplete central management of multiple XG Firewalls.And if you also want to consolidate reporting acrossmultiple XG, SG, and Cyberoam appliances then withSophos iView, you can.

Sophos XG FirewallSecurity features you can’t get anywhere elseXG Firewall includes a number of innovations that not only makes your job a loteasier, but also ensures your network is more secure.A revolution in advanced threat protection –Sophos Synchronized SecurityAn industry first, Synchronized Security links your endpointsand your firewall to enable unique insights and coordination.Security HeartbeatTM relays Endpoint health status andenables your firewall to immediately identify and respondto a compromised system on your network. The firewall canisolate systems until they can be investigated and cleanedup. Another Synchronized Security feature, Dynamic AppIdentification, also enables the firewall to query the endpointto determine the source of unknown traffic on the network.Patented Layer-8 identity controlUser identity takes enforcement to a whole new layer withour patented Layer-8 identity based policy technologyenabling user level controls over applications, bandwidth andother network resources regardless of IP-address, location,network or device. It literally takes firewall policy to a wholenew layer.Policy templates get you protected fastPre-defined policy templates let you protect commonapplications like Microsoft Exchange or SharePoint quicklyand easily. Simply select them from a list, provide somebasic information and the template takes care of the rest.It sets all the inbound/ outbound firewall rules and securitysettings for you automatically – displaying the final policy ina statement in plain English.Automated user risk reportsThe Sophos User Threat Quotient (UTQ) indicator is a uniquefeature which provides actionable intelligence on userbehavior. Our firewall correlates each user’s surfing habitsand activity with advanced threat triggers and history toidentify users with risk-prone behavior.Flexible deployment, no compromiseUnlike our competitors whether you choose hardware,software, or virtual we don’t make you compromise – everyfeature is available on every model and form- factor.To find out more visit www.sophos.com/xgfirewallXG SeriesSoftwareVirtualAzurePurpose-built devicesto provide the ultimatein performance.Install the Sophos FirewallOS image on your ownIntel hardware or server.Install on VMware,Citrix, MicrosoftHyper-V and KVM.Protect your networkinfrastructure in theAzure cloud.2

Sophos XG FirewallNetwork ProtectionAll the protection you need to stop sophisticated attacks and advanced threatswhile providing secure network access to those you trust.Next-gen Intrusion Prevention SystemSecurity HeartbeatProvides advanced protection from all types of modernattacks. It goes beyond traditional server and networkresources to protect users and apps on the network as well.Creates a link between your Sophos Cloud Endpoints andyour Firewall to identify threats faster, simplify investigationand minimize impact from attacks. Easily incorporateHeartbeat status into firewall policies to automaticallyisolate compromised systems.Advanced Threat ProtectionInstant identification and immediate response to today’smost sophisticated attacks. Multi-layered protectionidentifies threats instantly and Security Heartbeat provides an emergency response.Web ProtectionAdvanced VPN technologiesAdds unique and simple VPN technologies including ourclientless HTML5 self-service portal that makes remoteaccess incredibly simple or utilize our exclusive light-weightsecure RED (Remote Ethernet Device) VPN technology.Comprehensive web protection and application control with powerful andflexible policy tools ensure your networked users are secure and productive.Powerful user and group web policyHigh performance transparent proxyProvides enterprise-level Secure Web Gateway policycontrols to easily manage sophisticated user and groupweb controls. You get an intuitive and easy to manageinheritance-based policy builder with in-line editing andinfinitely flexible URL and category configuration with anumber of common pre-configured policies you can use orcustomize right out of the box.Optimized for top performance, our transparent proxytechnology provides ultra-low latency inspection andHTTPS scanning of all traffic for threats and compliance.Advanced Web Threat ProtectionBacked by SophosLabs, our advanced engine providesthe ultimate protection from today’s polymorphic andobfuscated web threats. Innovative techniques likeJavaScript emulation, behavioral analysis, and originreputation help keep your network safe.3Layer-8 Application Control and QoSEnables user-aware visibility and control over thousands ofapplications with granular policy and traffic-shaping (QoS)options based on application category, risk, andother characteristics.

Sophos XG FirewallEmail ProtectionFull SMTP and POP message protection from spam, phishing and data losswith our unique all-in-one protection that combines policy-based emailencryption with DLP and anti-spam.Integrated Message Transfer AgentSPX Email EncryptionEnsures always-on business continuity for your email,allowing the firewall to automatically queue mail in theevent servers become unavailable.Unique to Sophos, SPX makes it easy to send encryptedemail to anyone, even those without any kind of trustinfrastructure using our patent-pending password-basedencryption technology.Live Anti-SpamProvides protection from the latest spam campaigns,phishing attacks, and malicious attachments .Self-serve QuarantineGives employees direct control over their spam quarantine,saving you time and effort.Data Loss PreventionPolicy based DLP can automatically trigger encryption orblock/notify based on the presence of sensitive data inemails leaving the organization.Web Server ProtectionHarden your web servers and business applications against hacking attemptswith a full-featured Web Application Firewall while providing secure access withreverse proxy authentication.Business Application Policy TemplatesReverse proxyPre-defned policy templates let you protect commonapplications like Microsoft Exchange Outlook Anywhere orSharePoint quickly and easily.With authentication options, SSL offloading, and server loadbalancing ensure maximum protection and performancefor your servers being accessed from the interent.Protection from the latest hacks andattacksWith a variety of advanced protection technologiesincluding URL and form hardening, deep-linking anddirectory traversal prevention, SQL injection and cross-sitescripting protection, cookie signing and more.4

Sophos XG FirewallHow to BuyEvery XG Firewall comes equipped with Base Firewall functionality includingIPSec, SSL VPN, and Wireless Protection. You can extend protection with ourTotal Protection bundles or by adding protection modules individually.Network ProtectionWireless ProtectionWeb ProtectionAll the protection you need to stopsophisticated attacks and advancedthreats while providing securenetwork access to those you trust.Set up, manage and securewireless networks in just minuteswith the UTM’s built-in wirelesscontroller that works with our fullrange of wireless access points.Comprehensive web protection andapplication control with powerful andflexible policy tools ensure your networkedusers are secure and productive.Security Heartbeat Email ProtectionWeb Server ProtectionLinks your Sophos endpoints withyour firewall to deliver unparalleledprotection from advanced threatsand reduce the time and complexityof responding to security incidents.Full SMTP and POP message protectionfrom spam, phishing and data losswith our unique all-in-one protectionthat combines policy-based emailencryption with DLP and anti-spam.Harden your web servers andbusiness applications againsthacking attempts while providingsecure access to external userswith reverse proxy authentication.A simple approach to comprehensive supportWe build products that are simple yet comprehensive. And, we take the same approach with our support. With optionsranging from basic technical support to those including direct access to senior support engineers and customized delivery.Licenses namesSupportVia telephone and emailSecurity Updates & PatchesFor the life of the productSoftware Feature Updates & UpgradesStandardEnhancedIncluded with purchaseIncluded in all bundlesFor 90 days(business hours only)Included(24x7)VIP Access(24x7)Included with an activesoftware subscriptionIncluded with an activesoftware subscriptionIncluded with an activesoftware subscriptionIncluded 90-daysIncludedIncludedConsultingRemote consultation on your firewall configuration andsecurity with a Sophos Senior Technical Support EngineerWarranty and RMAFor all hardware appliancesTechnical Account ManagerDedicated named technical account manager5Enhanced PlusIncluded(up to 4 hours)1 year (return / replace)Advance Exchange(max. 5 years)Advance Exchange(max. 5 years)Optional(extra cost)Optional(extra cost)

Sophos XG FirewallSophos XG Series Appliances – at a glanceOur XG Series hardware appliances are purpose-built with the latest multi-core Intel technology, generous RAMprovisioning, and solid-state storage. Whether you’re protecting a small business or a large datacenter, you’re gettingindustry leading performance.Product MatrixModelTech. SpecsThroughputFormFactorPorts/Slots(Max Ports)w-model802.11 G 85(w)desktop4a/b/g/n8 GB eMMC2n/a2000200235330XG 105(w)desktop4a/b/g/n64 GB2n/a3000300270430XG 115(w)desktop4a/b/g/n64 GB4n/a3,500350310520XG 125(w)desktop8a/b/g/n/ac64 GB4n/a5,000410360590XG 135(w)desktop8a/b/g/n/ac64 GB6n/a7,0009508801,400XG 2101U6/1 (14)n/a120 GB8n/a14,0001,3501,7002,300XG 2301U6/1 (14)n/a120 GB8n/a18,0001,5002,4202,800XG 3101U10/1 (18)n/a180 GB12n/a25,0002,5002,7003,300XG 3301U10/1 (18)n/a180 GB12n/a30,0003,2004,2206,000XG 4301U8/2 (24)n/a240 GB16n/a37,0004,8004,8006,500XG 4501U8/2 (24)n/a2*240 GB16opt. Power45,0005,5005,0007,000XG 5502U8/2 (24)n/a2*300 GB24Power, SSD60,0008,4008,00010,000XG 6502U8/3 (32)n/a2*480 GB48Power, SSD80,0009,0009,00013,000XG 7502U8/7 (64)n/a2* 512 GB64Power,SSD, Fan140,00011,00011,80017,000Sophos XG Firewall TotalProtect BundleFor the ultimate in protection, value, and peace-of-mind, get our convenient TotalProtect bundle.What you getTotalProtect BundleBase Firewall Firewall, IPsec and SSL VPN, Wireless Protection (APs sold separately)Network Protection IPS, RED, HTML5 VPN, ATP, Security HeartbeatWeb Protection Anti-malware, Web and App visibility, control, and protectionEmail Protection Anti-spam, SPX Email Encryption, and DLPWeb Server Protection Web Application Firewall and reverse proxyEnhanced Support 24x7 support, security and software updates, adv. exchange warrantyXG Series Hardware Appliance Multi-core Intel processor, solid-state storage, flexible connectivity6

Sophos XG FirewallSophos XG Series Desktop Appliances:XG 85 and XG 85wTechnical SpecificationsThese entry-level desktop firewalls are the ideal choice for budget-conscious small businesses, retail and small or homeoffices. They are available with and without integrated wireless LAN, so you can have an all-in-one network security andhotspot solution without the need for additional hardware. The Intel dual-core technology makes them highly efficient andas they’re fanless, they won’t add unwanted noise to your office space.Note: The XG 85 and 85w do not support some advanced features like on-box reporting, dual AV scanning, WAF AV scanningand the email message transfer agent (MTA) functionality. If you need these capabilities, the XG 105(w) is recommended.Front ViewPerformanceXG 85(w) Rev. 1Firewall throughputStatus LEDsBack View2 GbpsFirewall IMIX780 MbpsVPN throughput200 MbpsIPS throughput510 MbpsNGFW (IPS App Ctrl WebFilter) max.235 MbpsAntivirus throughput (proxy)330 MbpsConcurrent connections2,000,000New connections/sec2 x external antennas(XG 85w only)Maximum licensed users18,000unrestrictedWireless Specification (XG 85w only)No. of antennas2 x USB 2.02 externalMIMO capabilities2 x 2:2Wireless interface802.11a/b/g/n (2.4 GHz / 5 GHz)Physical interfaces1 x COM(RJ45)4 x 1GbEcopper portOperating temperatureHumidity3.24W, 11.04 BTU/h (idle)5.64W, 19.232 BTU/h (full load)0-40 C (operating)-20 to 80 C (storage)10%-90%, non-condensingProduct CertificationsCertifications78 GB eMMCEthernet interfaces (fixed)4 GE copperI/O ports (rear)EnvironmentPower consumptionStorageCB, CE, FCC Class B, IC, VCCI,MIC, RCM, UL, CCC2 x USB 2.01 x COM (RJ45)Power supplyExternal auto ranging DC: 12V,100-240VAC, 50-60 HzPhysical specificationsMountingRackmount kit available(to be ordered separately)DimensionsWidth x Depth x Height225 x 150 x 44 mm8.86 x 5.91 x 1.73 inchesWeight0.95 kg / 2.09 lbs (unpacked)1.97 kg / 4.34 lbs (packed)

Sophos XG FirewallSophos XG Series Desktop Appliances:XG 105, XG 105w, XG 115, XG 115wTechnical SpecificationsThese desktop firewall appliances offer an excellent price-to-performance ratio making them ideal for small businessesor branch offices. They are available with or without integrated wireless LAN, so you can even have an all-in-one networksecurity and hotspot solution without the need for additional hardware. Of course, you can also add external access points.With Intel multi-core technology designed for best performance and efficiency in a small form factor, these models comeequipped with 4 GbE copper ports built-in.Front ViewXG 105(w)Status LEDsBack View3 x external antennas(XG 105w and XG 115w only)Rev. 2Rev. 2Firewall throughput3 Gbps3.5 GbpsFirewall IMIX1.04 Gbps1.33 GbpsVPN throughput300 Mbps350 MbpsIPS throughput700 Mbps900 MbpsNGFW (IPS App Ctrl WebFilter) max.270 Mbps310 MbpsAntivirus throughput (proxy)430 Mbps520 MbpsConcurrent tedunrestrictedNew connections/secMaximum licensed usersWireless Specification (XG 105w and XG 115w only)2 x USB 2.0No. of antennas1 x VGAportXG 115(w)Performance1 x COM(RJ45)3 external3 externalMIMO capabilities3 x 3:33 x 3:3Wireless interface802.11a/b/g/n(2.4 GHz / 5 GHz)802.11a/b/g/n(2.4 GHz / 5 GHz)integrated SSDintegrated SSDEthernet interfaces (fixed)4 GE copper4 GE copperI/O ports (rear)2 x USB 2.02 x USB 2.01 x COM (RJ45)1 x COM (RJ45)4 x 1GbEcopper portPhysical interfacesStorage (localquarantine/logs)EnvironmentPower consumptionOperating temperatureHumidity4.83W, 16.468 BTU/hr (idle)9.84W, 33.55 BTU/hr (full load)0-40 C (operating)-20 to 80 C (storage)10%-90%, non-condensingPower supplyProduct CertificationsCertificationsCB, CE, FCC Class B, IC, VCCI,MIC, RCM, UL, CCC1 x VGA1 x VGAExternal autoranging DC: 12V,100-240VAC,50-60 HzExternal autoranging DC: 12V,100-240VAC,50-60 HzPhysical specificationsMountingRackmount kit available(to be ordered separately)DimensionsWidth x Depth x Height225 x 150 x 44 mm8.86 x 5.91 x 1.73 inchesWeight1.19 kg / 2.62 lbs (unpacked)2.185 kg / 4.82 lbs (packed)8

Sophos XG FirewallSophos XG Series Desktop Appliances:XG 125, XG 125w, XG 135, XG 135wTechnical SpecificationsThese powerful firewall appliances offer 1U performance with a desktop form factor and price. If you have a small businessor branch offices to protect and are working on a tight budget, these models are the ideal choice. They are also availablewith integrated 802.11ac wireless LAN for optimal coverage and connectivity for your mobile workers. Built upon the latestIntel architecture, our software makes optimal use of the multi-core technology to provide excellent throughput for all yourkey processes. These models come equipped with 8 GbE copper ports built-in.Front ViewXG 125(w)Status LEDsRev. 2Rev. 2Firewall throughput5 Gbps7 GbpsFirewall IMIX1.75 Gbps2.75 GbpsVPN throughput410 Mbps950 MbpsIPS throughput1 Gbps1.75 Gbps360 Mbps880 MbpsNGFW (IPS App Ctrl WebFilter) max.Back View3 x external antennas(XG 125w and XG 135w only)Antivirus throughput (proxy)590 Mbps1.4 GbpsConcurrent tedunrestrictedNew connections/secMaximum licensed users2 x USB 2.01 x VGAportWireless Specification (XG 125w and XG 135w only)No. of antennas1 x COM (RJ45)XG 135(w)Performance3 external3 externalMIMO capabilities3 x 3:33 x 3:3Wireless interface802.11a/b/g/n/ac(2.4 GHz / 5 GHz)802.11a/b/g/n/ac(2.4 GHz / 5 GHz)integrated SSDintegrated SSDEthernet interfaces (fixed)8 GE copper8 GE copperI/O ports (rear)2 x USB 2.02 x USB 2.01 x COM (RJ45)1 x COM (RJ45)8 x 1GbE copper portPhysical interfacesEnvironmentPower consumptionOperating temperatureHumidity12.46W, 49.3 BTU/hr (idle)26.16W, 89.2 BTU/hr (full load)0-40 C (operating)-20 to 80 C (storage)10%-90%, non-condensingPower supplyProduct CertificationsCertificationsStorage (localquarantine/logs)CB, CE, FCC Class B, IC, VCCI,MIC, RCM, UL, CCC1 x VGA1 x VGAExternal autoranging DC: 12V,100-240VAC,50-60 HzExternal autoranging DC: 12V,100-240VAC,50-60 HzPhysical specificationsMountingRackmount kit available(to be ordered separately)DimensionsWidth x Depth x Height288 x 186.8 x 44 mm11.38 x 7.35 x 1.73 inchesWeight91.7 kg / 3.75 lbs (unpacked)2.82 kg / 6.22 lbs (packed)

Sophos XG FirewallSophos XG Series Rackmount Appliances:XG 210, XG 230Technical SpecificationsThe Sophos XG 210 and XG 230 are designed to protect small to mid-sized businesses and branch offices. Based on thelatest Intel technology and equipped with 6 GbE copper ports plus one FleXi Port slot to configure with an optional module,they provide high flexibility and throughput at an excellent price-to-performance ratio.Front ViewPerformanceNavigationbuttons for LCD1 x COM(RJ45)1 x expansion bay(shown here withoptional FleXi Portmodule)6 x 1GbEcopper port– fixed2xUSB 3.0Multifunction LCDdisplay18 GbpsFirewall IMIX4.9 Gbps6.11 GbpsVPN throughput1.35 Gbps1.5 GbpsIPS throughput2.7 Gbps4.2 GbpsNGFW (IPS App Ctrl WebFilter) max.1.7 Gbps2.42 GbpsAntivirus throughput (proxy)New connections/secMaximum licensed users1 x USB2.01 x VGA portEthernet interfaces (fixed)No. of FleXi Port slotsFleXi Port m

Live Anti-Spam Provides protection from the latest spam campaigns, phishing attacks, and malicious attachments . Self-serve Quarantine Gives employees direct control over their spam quarantine, saving you time and effort. SPX Email Encryption Unique to Sophos, SPX makes it easy to send encryp