SonicWall Secure Mobile Access 100 Series Datasheet

Transcription

Secure Mobile Access100 SeriesEnable mobile and remote worker productivity while protecting yourorganization from threatsThe SonicWALL Secure Mobile Access(SMA) 100 Series provides mobile andremote workers using smartphones,tablets or laptops — whether managedor unmanaged BYOD — with fast, easy,policy-enforced access to missioncritical applications, data and resources,without compromising security.For mobile devices, the solutionincludes the intuitive SonicWALLMobile Connect app that providesiOS, Android, Kindle Fire, Windows,Chrome and Mac OS X devices secureaccess to allowed network resources,including shared folders, client/serverapplications, intranet sites and email.Users and IT administrators candownload the Mobile Connect appvia the Apple App Store, Google Play,Kindle and Microsoft store. The solutionalso supports clientless, secure browseraccess, including support for industrystandard HTML 5 browsers and thinclient VPN access for PCs and laptops,including Windows, Mac OS X andLinux computers.To protect from rogue access andmalware, the SMA 100 Seriesappliance connects only authorizedusers and trusted devices to permittedresources. When integrated with aSonicWALL next-generation firewall asa Clean VPN, the combined solutiondelivers centralized access control,malware protection, applicationcontrol and content filtering. Themulti-layered protection of CleanVPN decrypts and decontaminates allauthorized SSL VPN traffic before itenters the network environment.Why you need SMAThe proliferation of mobile devicesin the workplace has increasedthe demand for secure access tomission-critical applications, data andresources. Granting that access offersimportant productivity benefits to theorganization, but introduces significantrisks as well.For example, an unauthorized personmight access company resources usinga lost or stolen device; an employee’smobile device might act as a conduitto infect the network with malware; orcorporate data might be interceptedover third-party wireless networks.Also, loss of business data stored ondevices can occur if rogue personalapps or unauthorized users gain accessto that data.Securing these devices is becomingincreasingly difficult, as organizationsmay no longer influence deviceselection or control devicemanagement. Organizations mustimplement solutions that safeguardaccess to ensure only authorized usersand devices that meet security policyare granted network access, and thatcompany data in-flight and at rest onthe device are secure. Unfortunately,this often involves complex multi-boxsolutions from multiple vendors andadds significantly to the total cost ofownership behind providing mobileaccess. Organizations are lookingfor easy-to-use, cost-effective andsecure mobile access solutions thataddress the needs of their increasinglymobile workforces.Benefits: Single access gateway to allnetwork resources, via mobileapp, clientless or web-deliveredclients, works to lower IToverhead and TCO Common user experience acrossall operating systems facilitatesease of use from any endpoint Mobile Connect app for iOS,Android, Windows, Chrome andMac OS X offers mobile deviceease of use Context aware authenticationensures only authorized usersand trusted mobile devices aregranted access One-click secure intranet filebrowse and on-device dataprotection HTML5 enhancements that alloweverything to be run from withinthe context of the browser window Adaptive addressing and routingdeploys appropriate accessmethods and security levels Setup wizard makes deploymenteasy Easy-to-use "policy wizards"making IT administratorsmore productive and loweringcompany's overall TCO Efficient object-based policymanagement of all users, groups,resources and devices Web Application Firewall enablesPCI compliance Geo IP detection and Botnetprotection

FeaturesSingle access gateway for mobileapp, clientless or web-deliveredclients — SMA 100 Series lowers ITcosts by enabling network managersto easily deploy and manage a singlesecure access gateway that extendsremote access via SSL VPN for bothinternal and external users to allnetwork resources — including webbased, client/server, host-based (suchas virtual desktop) and back-connectapplications (such as VoIP). SMAs areeither clientless with browser access tothe customizable SMA Workplace portalor use mobile apps or lightweight webdelivered clients, reducing managementoverhead and support calls.Fast, easy, policyenforced accessto mission-criticalapplications, data andresources, withoutcompromisingsecurity.Common user experience across alloperating systems — SMA technologyprovides transparent access tonetwork resources from any networkenvironment or device. A SMAappliance provides a single gateway forsmartphone, tablet, laptop and desktopaccess and a common user experienceacross all operating systems — includingWindows, Mac OS X, iOS, Android,Kindle, Chrome and Linux — frommanaged or unmanaged devices.Mobile Connect app — MobileConnect app for iOS, Mac OS X,Android, Kindle, Chrome and Windowsmobile devices provides userswith easy, network-level access tocorporate and academic resourcesover encrypted SSL VPN connections.Mobile Connect is easily downloadablefrom the Apple App Store, GooglePlay, Microsoft or Kindle store andembedded with Windows 8.1 devices.HTML5 Enhancements — Providesend-users a rich access experiencewithin their own choice of webbrowser, which eliminates their needto download, install and maintainadditional software on their systems.Everything can be run from withinthe context of the browser window,making connection to resources veryeasy and zero day support for all majorOSs and browsers.Context awareness — Access to thecorporate network is granted only afterthe user has been authenticated andmobile device integrity has been verified.Protects data at rest on mobiledevices — Authenticated userscan securely browse and viewallowed intranet file shares and filesfrom within the Mobile Connectapp. Administrators can establishand enforce mobile applicationmanagement policy.Adaptive addressing and routing —Dynamically adapts to networks,eliminating conflicts common withother solutions.Setup wizard — All SMAs are easy toset up and deploy in just minutes. Thesetup wizard provides an easy, intuitive“out-of-the-box” experience with rapidinstallation and deployment.Policy Wizards — Easy-to-use wizardsto deploy policies for OWA, ActiveSync,Outlook Anywhere and Autodiscover.This saves IT administratorsconsiderable time for the mostcommonly created policies, makingthem more productive and loweringthe company's overall TCO.Unified policy — SMA unified policyoffers easy, object-based policymanagement of all users, groups,resources and devices whileenforcing granular control basedon both user authentication andendpoint interrogation.Web Application Firewall (WAF)Enhancements – Helping to secureinternal web applications from remoteusers, SonicWALL’s award winning WAFengine has been enhanced to detectagainst additional exploits and threats.This allows customers to ensure theconfidentiality of data, and internalweb services remain uncompromised,should there be malicious or rogueauthenticated user access.Geo IP Detection and BotnetProtection – Grants customers witha mechanism to allow or restrict useraccess from various geographicallocations. Also provides additionalprotection from compromisedendpoint participating in a botnet,further verifying the validity of theconnecting device.

SonicWALL SMA 100 Series –anytime, anywhere accessSimple, secure mobile accessto resourcesThe SMA 100 Series can be used toprovide Windows, Mac OS X, iOS,Linux, Android, Chrome and Kindleusers with access to a broad range ofresources.Granular access to authorized usersThe SMA 100 Series extends securemobile and remote access beyondmanaged employees to unmanagedmobile and remote employees,partners and customers by employingpolicy-enforced fine-grained accesscontrols.Employee oncorporate laptopin hotelEmployee onhome computerEmployee onsmartphone/tabletEmployeeat kioskAuthorizedpartnerTightly controlledand managed byIT departmentAuthorizedcustomerNot controlledand managed byIT departmentInternetCorporate LANFiles andapplicationsDell SonicWALL SMAat corporate networkIntranetUser desktopOther serversand applicationsCitrix PresentationServers (ICA) andMicrosoft terminalserversOther desktops

Easy-to-use, costeffective and securemobile access thataddresses the needsof your increasinglymobile workforce.Context-aware authenticationClean VPNBest-in-class, context-awareauthentication grants access only totrusted devices and authorized users.Mobile devices are interrogated foressential security information suchas jailbreak or root status, device ID,certificate status and OS versions priorto granting access. Laptops and PCsare also interrogated for the presenceor absence of security software, clientcertificates, and device ID. Devices thatdo not meet policy requirements arenot allowed network access and theuser is notified of non-compliance.When deployed with a SonicWALLnext-generation firewall, MobileConnect establishes a Clean VPN, anextra layer of protection that decryptsand scans all SSL VPN traffic formalware before it enters the network.Protection of data at rest onmobile devicesAuthenticated Mobile Connectusers can securely browse and viewallowed intranet file shares and filesfrom within the Mobile Connectapp. Administrators can establishand enforce mobile applicationmanagement policy for the MobileConnect app to control whether filesviewed can be opened in other apps(iOS 7 and newer), copied to theclipboard, printed or cached securelywithin the Mobile Connect app. For iOS7 and newer, this allows administratorsto isolate business data from personaldata stored on the device and reducesthe risk of data loss. In addition, if theuser’s credentials are revoked, contentstored in the Mobile Connect app islocked and can no longer be accessedor viewed.Web Application Firewall andPCI complianceThe SonicWALL Web ApplicationFirewall Service offers businesses acomplete, affordable, well integratedcompliance solution for web-basedapplications that is easy to manage anddeploy. It supports OWASP Top Tenand PCI DSS compliance, providingprotection against injection andcross-site scripting attacks (XSS), creditcard and Social Security numbertheft, cookie tampering and crosssite request forgery (CSRF). Dynamicsignature updates and custom rulesprotect against known and unknownvulnerabilities. Web Application Firewallcan detect sophisticated web-basedattacks and protect web applications(including SSL VPN portals), denyaccess upon detecting web applicationmalware, and redirect users to anexplanatory error page. It provides aneasy-to-deploy offering with advancedstatistics and reporting options formeeting compliance mandates.

Personalizedweb portal3Corporate LAN3 Files andapplicationsDell SonicWALLSMA Appliance1IntranetUser desktopDecryptedtraffic2InternetEncryptedSSL trafficUnified threatmanagementscanningRemote user1Users are authenticated using theonboard database or through thirdparty authentication methods suchSimple to manageSMA 100 Series solutions featureunified policy and an intuitiveweb-based management interfacethat offers context-sensitive helpto enhance usability. In addition,multiple products can be centrallymanaged using the SonicWALL GlobalManagement System (GMS 4.0 ).Resource access via the products canbe effortlessly monitored using theSonicWALL Analyzer reporting tool.Otherservers andapplicationsas LDAP, Active Directory, Radius,Defender and other two-factorauthentication solutions.Incoming traffic is seamlesslyforwarded by the SonicWALL NSA orTZ Series firewall to the SonicWALLSMA appliance, which decrypts andauthenticates network traffic.324Dell SonicWALLNSA or TZ firewallA personalized web portal providesaccess to only those resources thatthe user is authorized to view basedon company policies.Citrix XenAppOtherand Microsoftdesktopsterminal servers4ActiveDirectory,RADIUS,LDAP orlocaldatabaseTo create a Clean VPN environment,traffic is passed through to theNSA or TZ Series firewall (runninggateway anti-virus, anti-spyware,intrusion prevention, and applicationintelligence and control), whereit is fully inspected for viruses,worms, Trojans, spyware and othersophisticated threats.

SpecificationsSonicWALL SMA 100 SeriesPerformanceSMA 200SMA 400Recommended for organizations with50 or fewer employeesRecommended for organizations with250 or fewer employeesRecommended for SMB companieswith 250 or fewer employeesConcurrent user licenseStarts with 5 concurrent users.Additional user licenses available in 5and 10 user incrementsStarts with 25 users. Additional userlicences are available in 10, 25 and 100user incrementsUser licenses available in 5, 10, and 25user incrementsUser censable5-included/250-licensable30-day trial-included/10-concurrenttechnicians maximum30-day trial-included/25-concurrenttechnicians maximum30-day trial-included/25-concurrenttechnicians maximum75751Secure Virtual Assist technicians–Maximum allowable Meeting participantsUnified policyYes. Also supports policies which have multiple AD groupsLoggingDetailed logging in an easy-to-read format, Syslog supported email alertsSingle-arm modeYesDell SonicWALL Secure Virtual Assist or SecureVirtual Access (licensed together)Connection to remote PC, chat, FTP, session recording and diagnostic toolsSecure Virtual MeetingInstantly brings meeting participants together securely and cost-effectively2YesSMA 500v (virtual)YesIPv6 supportBasicLoad balancingHTTP/HTTPS load balancing with failover. Mechanisms include weighted requests, weighted traffic, least requestsHigh Availability–YesYesApplication offloadingYesYesYesWeb Application FirewallYesYesYesEnd Point Control (EPC)YesYesYesYesYesYesYesYesYesGeolocation-based policiesBotnet filtering44BasicBasicKey featuresApplications supported3 Web portal access: Supports HTML5, proxy and application offloadingWeb services: HTTP, HTTPS, FTP, SSH, Telnet, VNC, Windows file sharing (Windows SMB/CIFS), OWA 2003/2007/2010Virtual Desktop Infrastructure (VDI): Citrix (ICA), RDPMobile Connect and NetExtender: Any TCP/IP based application: ICMP, VoIP, IMAP, POP, SMTP, etc. EncryptionARC4 (128), MD5, SHA-1, SHA-256, SHA-384, SSLv3, TLSv1, TLS 1.1, TLS 1.2, 3DES (168, 256), AES (256), RSA, DHEAuthenticationDell Quest Defender, other two-factor authentication solutions, One-time Passwords, Internal user database, RADIUS, LDAP,Microsoft Active Directory and Single Sign On (SSO) for most web based apps, RDP and VNCMultiple domain supportYesMultiple portal supportYesFine grain access controlAt the user, user group and network resource levelSession securityInactivity timeouts prevent unauthorized use of inactive sessionsCertificates Server: Self-signed with editable common name and imported from third parties Client: Optional client certificates supportedCache cleanerConfigurable. Upon logout all cached downloads, cookies and URLs downloaded through the SSL tunnel are erased from theremote computerClient support33 Web portal access: Internet Explorer, Mozilla, Chrome, Opera, and Safari browsers NetExtender: Windows 2003, 2008, XP/Vista (32-bit and 64-bit), 7 (32-bit and 64-bit), 8 (32-bit and 64-bit), Mac OS X 10.4 ,Linux Fedora Core 3 / Ubuntu 7 / OpenSUSE, Linux 64-bit Mobile Connect: iOS 4.2 and higher, OS X 10.9 and higher, Android 4.0 and higher, Chrome 43 and higher, Kindle Firerunning Android 4.0 and higher and Windows 8.1Personalized portalThe remote user sees only those resources that the administrator has granted access to based on company policyManagementWeb GUI (HTTP, HTTPS), Send syslog and heartbeat messages to GMS (4.0 and higher) SNMP SupportUsage monitoringGraphical monitoring of memory, CPU, users and bandwidth usageThe recommended number of users supported is based on factors such as access mechanisms, applications accessed and application traffic being sent.Available in conjunction with Secure Virtual Assist for SMA 400 and SRA Virtual Appliances only.Refer to the latest SMA 100 Series release notes and admin guide for supported configurations.Botnet filtering and Geolocation-based policies require an active support contract to be in place on the hardware or virtual appliance.1234

SonicWALL SMA 100 SeriesHardwareSMA 200SMA 400Hardened security applianceYesYesInterfaces(2) GB Ethernet, (2) USB, (1) console(4) GB Ethernet, (2) USB, (1) consoleProcessorsx86 main processorx86 main processorMemory (RAM)2 GB4 GBFlash memory2 GB2 GBPower supply/inputInternal, 100-240VAC, 50-60MHzInternal, 100-240VAC, 50-60MHzMax power consumption26.9 W31.9 WTotal heat dissipation92 BTU109 BTUDimensions16.92 x 10.23 x 1.75 in43x26x4.5cm16.92 x 10.23 x 1.75 in43x26x4.5cmAppliance weight11 lbs5 kg11 lbs5 kgsWEEE weight11 lbs5.3 kg11 lbs5.3 kgsMajor regulatory complianceFCC Class A, ICES Class A, CE, RCM, VCCI Class A, ANATEL, BSMI, UL, cUL, UL Mexico CoC, TUV/GS, CB, MSIP Class ARegulatory Model1RK33-0BBEnvironment32-105 F, 0-40 CHumidity 5-95% RH, non-condensingMTBF7.06 years1RK33-0BC6.87 yearsSMA 500v (virtual)SMA 500v virtualized environment requirements(Minimum)Hypervisor: VMWare ESXi and ESX (version 4.0 and newer)Appliance size (on disk): 2 GBAllocated memory: 2 GBAbout Dell SecuritySMA 200, 5 user. 01-SCC-2231SMA 200 additional users (50 user maximum)Add 5 Concurrent users. 01-SSC-2232Add 10 Concurrent users.01-SSC-2233SMA 200 supportSonicWALL Dynamic Support24x7 for up to 25 Users (1-year). 01-SSC-2234SonicWALL SMA 500v (virtual)5 User.01-SSC-8469SMA 500v (virtual) additional users(250 user maximum)Add 5 concurrent users.01-SSC-9182Add 10 concurrent users.01-SSC-9183Add 25 concurrent users. 01-SSC-9184SMA 500v (virtual) supportSonicWALL Dynamic Support24x7 for up to 25 users (1-year). 01-SSC-9191Dell Security solutions help youcreate and maintain a strong securityfoundation with interconnectedsolutions that span the enterprise. Fromendpoints and users to networks, dataand identity, Dell Security solutionsmitigate risk and reduce complexity soyou can drive your business forward.www. dell.com/securitySonicWALL Dynamic Support24x7 for up to 50 users (1-year).01-SSC-9197SMA 400, 25 user .01-SSC-2243For more information on Dell SonicWALL SecureMobile Access solutions, visit www.sonicwall.com.SMA 400 additional users (250 user maximum)Add 10 Concurrent Users. 01-SSC-2244Add 25 Concurrent Users.01-SSC-2245Add 100 Concurrent Users. 01-SSC-2246SMA 400 SupportSonicWALL Dynamic Support24x7 for up to 100 Users (1-year).01-SSC-2247SonicWALL Dynamic Support24x7 for 101 to 250 users (1-year). 01-SSC-2248Dell5455 Great America Parkway, Santa Clara, CA 95054www.dell.com/securityIf you are located outside North America, you canfind local office information on our web site. 2016 Dell Inc. ALL RIGHTS RESERVED. Dell and Dell Security logo and products—as identified in thisdocument—are trademarks or registered trademarks of Dell, Inc. in the U.S.A. and/or other countries. Allother trademarks and registered trademarks are property of their respective owners.DataSheet-SonicWALL-SMASeries-US-CW-20260

PCI compliance The SonicWALL Web Application Firewall Service offers businesses a complete, affordable, well integrated compliance solution for web-based applications that is easy to manage and deploy. It supports OWASP Top Ten and PCI DSS compliance, providing protection against