SonicWall TZ Series - SonicWall Products & Solutions

Transcription

SonicWall TZ seriesExceptional security and stellar performance at a disruptively low TCOThe SonicWall TZ series of Unified ThreatManagement (UTM) firewalls is ideallysuited for any organization that requiresenterprise-grade network protection.SonicWall TZ series firewalls providebroad protection with advancedsecurity services consisting of onbox and cloud-based anti-malware,anti-spyware, application control,intrusion prevention system (IPS), andURL filtering. To counter the trend ofencrypted attacks, the TZ series has theprocessing power to inspect encryptedSSL/TLS connections against the latestthreats. Combined with Dell X-Seriesswitches, selected TZ series firewalls candirectly manage the security of theseadditional ports.Backed by the SonicWall GlobalResponse Intelligent Defense (GRID)network, the SonicWall TZ series deliverscontinuous updates to maintain a strongnetwork defense against cybercriminals.The SonicWall TZ series is able to scanevery byte of every packet on all portsand protocols with almost zero latencyand no file size limitations.The SonicWall TZ series features GigabitEthernet ports, optional integrated802.11ac wireless*, IPSec and SSL VPN,failover through integrated 3G/4Gsupport, load balancing and networksegmentation. The SonicWall TZ seriesUTM firewalls also provide fast, securemobile access over Apple iOS, GoogleAndroid, Amazon Kindle, Windows,Mac OS X and Linux platforms.The SonicWall Global ManagementSystem (GMS) enables centralizeddeployment and management ofSonicWall TZ series firewalls from asingle system.Managed security fordistributed environmentsSchools, retail shops, remote sites,branch offices and distributedenterprises need a solution thatintegrates with their corporatefirewall. SonicWall TZ series firewallsshare the same code base—andsame protection—as our flagshipSuperMassive next-generation firewalls.This simplifies remote site management,as every administrator sees the sameuser interface (UI). GMS enablesnetwork administrators to configure,monitor and manage remote SonicWallfirewalls through a single pane ofglass. By adding high-speed, securewireless, the SonicWall TZ series extendsthe protection perimeter to includecustomers and guests frequenting theretail site or remote office.* 802.11ac currently not available on SOHO models; SOHO models support 802.11a/b/g/nBenefits: Enterprise grade networkprotection Deep packet inspection of all trafficwithout restrictions on file size orprotocol Secure 802.11ac wirelessconnectivity using integratedwireless controller or viaexternal SonicPoint wireless accesspoints SSL VPN mobile access for AppleiOS, Google Android, AmazonKindle, Windows, Mac OS andLinux devices Over 100 additional ports canbe securely managed by theTZ console when deployed incombination with Dell X-Seriesswitches

SonicWall TZ600 seriesFor emerging enterprises, retail and branch offices looking for security performance at a value price, the SonicWall TZ600 nextgeneration firewall secures networks with enterprise-class features and uncompromising performance.SpecificationTZ600 seriesFirewall throughput1.5 GbpsFull DPI throughput500 MbpsAnti-malware throughput500 MbpsIPS throughput1.1 GbpsIMIX throughput900 MbpsMax DPI connections125,000New connections/sec12,000Power LEDTest LEDUSB portLink and(3G/4G WAN activityFailover)Indicator LEDsExpansion Console 8x1GbEX0 LANmodule Slot portswitchPort X1(future)(configurable) WANPortSonicWall TZ500 seriesFor growing branch offices and SMBs, the SonicWall TZ500 series delivers highly effective, no-compromise protection withnetwork productivity and optional integrated 802.11ac dual-band wireless.SpecificationTZ500 seriesFirewall throughput1.4 GbpsFull DPI throughput400 MbpsAnti-malware throughput400 MbpsIPS throughput1.0 GbpsIMIX throughput700 MbpsMax DPI connections100,000New connections/sec8,000Power LED2Test LEDUSB portLink and(3G/4G WAN activityFailover)Indicator LEDsOptionalwirelessConsoleport6x1GbE switch(configurable)X0 LAN PortX1 WAN PortSecurepowerSecurepower

SonicWall TZ400 seriesFor small business, retail and branch office locations, the SonicWall TZ400 series delivers enterprise-grade protection. Flexiblewireless deployment is available with either external SonicPoint Access points or 802.11ac wireless integrated into the unit.SpecificationTZ400 seriesFirewall throughput1.3 GbpsFull DPI throughput300 MbpsAnti-malware throughput300 MbpsIPS throughput900 MbpsIMIX throughput500 MbpsMax DPI connections90,000New connections/sec6,000Power LEDTest LEDUSB portLink and(3G/4G WAN oleport5x1GbE switch(configurable)X0 LAN PortX1 WAN PortSecurepowerSonicWall TZ300 seriesThe SonicWall TZ300 series offers an all-in-one solution that protects networks from attack. Unlike consumer grade products, theSonicWall TZ300 series firewall combines effective intrusion prevention, anti-malware and content/URL filtering with optional802.11ac integrated wireless and broadest secure mobile platforms support for laptops, smartphones and tablets.SpecificationTZ300 seriesFirewall throughput750 MbpsFull DPI throughput100 MbpsAnti-malware throughput100 MbpsIPS throughput300 MbpsIMIX throughput200 MbpsMax DPI connections50,000New connections/sec5,000Power LED3Test LEDUSB portLink and(3G/4G WAN activityFailover)Indicator LEDsOptionalwirelessConsoleport3x1GbE switch X0 LAN(configurable) Port X1WAN PortSecurepower

SonicWall SOHO seriesFor wired and wireless small and home office environments, the SonicWall SOHO series delivers the same business-class protectionlarge organizations require at a more affordable price point.SpecificationSOHO seriesFirewall throughput300 MbpsFull DPI throughput50 MbpsAnti-malware throughput50 MbpsIPS throughput100 MbpsIMIX throughput60 MbpsMax DPI connections10,000New connections/sec1,800Power LEDTest LEDLink andactivityIndicator LEDsOptionalwirelessConsole 3x1GbE switchport(configurable)USB port(3G/4G WANFailover)Extensible architecture for extreme scalabilityand performanceThe Reassembly-Free Deep Packet Inspection (RFDPI) engineis designed from the ground up with an emphasis on providingsecurity scanning at a high performance level, to match boththe inherently parallel and ever-growing nature of networktraffic. When combined with multi-core processor systems, thisparallel-centric software architecture scales up perfectly toX0 LAN PortX1 WAN Portaddress the demands of deep packet inspection at high trafficloads. The SonicWall TZ Series platform relies on processorsthat, unlike x86, are optimized for packet, crypto and networkprocessing while retaining flexibility and programmability inthe field — a weak point for ASICs systems. This flexibility isessential when new code and behavior updates are necessaryto protect against new attacks that require updated and moresophisticated detection techniques.NSA or SuperMassiveSOHOHome officeInternetCorporateHeadquartersTZ400Global Management SystemSmallbranch officeTZ60018 portX-series switch4SecurepowerLargebranch office

Reassembly-Free Deep Packet Inspection(RFDPI) engineThe RFDPI engine provides superior threat protection andapplication control without compromising performance. Thispatented engine inspects the traffic stream to detect threatsat Layers 3-7. The RFDPI engine takes network streams throughextensive and repeated normalization and decryption inorder to neutralize advanced evasion techniques that seekto confuse detection engines and sneak malicious codeinto the network. Once a packet undergoes the necessarypreprocessing, including SSL decryption, it is analyzed againstGlobal management and reportingFor larger, distributed enterprise deployments, the optionalSonicWall Global Management System (GMS) providesadministrators a unified, secure and extensible platform tomanage SonicWall security appliances and Dell X-Seriesswitches. It enables enterprises to easily consolidate themanagement of security appliances, reduce administrativeand troubleshooting complexities and governs all operational5a single proprietary memory representation of three signaturedatabases: intrusion attacks, malware and applications. Theconnection state is then advanced to represent the positionof the stream relative to these databases until it encountersa state of attack, or another “match” event, at which point apre-set action is taken. As malware is identified, the SonicWallfirewall terminates the connection before any compromisecan be achieved and properly logs the event. However, theengine can also be configured for inspection only or, in thecase of application detection, to provide Layer 7 bandwidthmanagement services for the remainder of the applicationstream as soon as the application is identified.aspects of the security infrastructure including centralizedpolicy management and enforcement, real-time eventmonitoring, analytics and reporting, and more. GMS also meetsthe firewall change management requirements of enterprisesthrough a workflow automation feature. GMS provides abetter way to manage network security by business processesand service levels that dramatically simplify the lifecyclemanagement of your overall security environments rather thanon a device-by-device basis.

Security and protectionThe dedicated, in-house SonicWallThreat Research Team workson researching and developingcountermeasures to deploy to thefirewalls in the field for up-to-dateprotection. The team leverages morethan one million sensors across theglobe for malware samples, and fortelemetry feedback on the latest threatinformation, which in turn is fed intothe intrusion prevention, anti-malwareand application detection capabilities.SonicWall firewall customers with currentsubscriptions are provided continuouslyupdated threat protection aroundthe clock, with new updates takingeffect immediately without rebootsor interruptions. The signatures onthe appliances protect against wideclasses of attacks, covering up to tensof thousands of individual threats witha single signature. In addition to thecountermeasures on the appliance, allSonicWall firewalls also have accessto the SonicWall CloudAV service,which extends the onboard signatureintelligence with more than 17 millionsignatures, and growing. This CloudAVdatabase is accessed via a proprietarylight-weight protocol by the firewall toaugment the inspection done on theappliance. With Geo-IP and botnetfiltering capabilities, SonicWall nextgeneration firewalls are able to blocktraffic from dangerous domains or entiregeographies in order to reduce the riskprofile of the network.Application intelligenceand controlApplication intelligence informsadministrators of application traffictraversing the network, so they canschedule application controls based onbusiness priority, throttle unproductiveapplications and block potentiallydangerous applications. Real-timevisualization identifies traffic anomaliesas they happen, enabling immediatecountermeasures against potentialinbound or outbound attacks orperformance bottlenecks. SonicWallTZ product lineInternetHome office / small office LANInternetCorporateHeadquarters3G/analog failoverGlobal Management System Secure wireless zoneSales networkPrintersEngineering network18 port X-series switchStoragePOEcamerasFinance networkProtected server networkapplication traffic analytics providegranular insight into applicationtraffic, bandwidth utilization andsecurity threats, as well as powerfultroubleshooting and forensicscapabilities. Additionally, secure singlesign-on (SSO) capabilities enhance theuser experience, increase productivityand reduce support calls. Managementof application intelligence and controlis simplified by using an intuitive webbased interface.Flexible and secure wirelessAvailable as an optional feature, highspeed 802.11ac wireless* combines* 802.11ac currently not available on SOHO models; SOHO models support 802.11a/b/g/n6TZ product lineNSA or SuperMassivewith SonicWall next-generationfirewall technology to create a wirelessnetwork security solution that deliverscomprehensive protection for wired andwireless networks.This enterprise-level wirelessperformance enables WiFi-ready devicesto connect from greater distancesand use bandwidth-intensive mobileapps, such as video and voice, inhigher density environments withoutexperiencing signal degradation.

FeaturesRFDPI engineFeatureDescriptionReassembly-Free Deep Packet InspectionThis high-performance, proprietary and patented inspection engine performs stream based bi-directional trafficanalysis, without proxying or buffering, to uncover intrusion attempts, malware and identify application trafficregardless of port.Bi-directional inspectionScans for threats in both inbound and outbound traffic simultaneously to ensure that the network is not used todistribute malware, and does not become a launch platform for attacks in case an infected machine is brought inside.Single-pass inspectionA single-pass DPI architecture simultaneously scans for malware, intrusions and application identification, drasticallyreducing DPI latency and ensuring that all threat information is correlated in a single architecture.Stream-based inspectionProxy-less and non-buffering inspection technology provides ultra-low latency performance for deep packetinspection of simultaneous network streams without introducing file and stream size limitations, and can be appliedon common protocols as well as raw TCP streams.Deep Packet Inspection of Secure Socket Shell(DPI-SSH)Detects and prevents advanced encrypted attacks that leverage SSH, blocks encrypted malware downloads, ceasesthe spread of infections, and thwarts command and control communications and data exfiltration.Capture Advanced Threat ProtectionFeatureDescriptionMulti-engine sandboxingThe multi-engine sandbox platform, which includes virtualized sandboxing, full system emulation, and hypervisorlevel analysis technology, executes suspicious code and analyzes behavior, providing comprehensive visibility tomalicious activityBroad file type analysisSupports analysis of a broad range of file types, including executable programs (PE), DLL, PDFs, MS Officedocuments, archives, JAR, and APK plus multiple operating systems including Windows, Android, Mac OSX andmulti-browser environments.Rapid deployment of signaturesWhen a file is identified as malicious, a signature is immediately deployed to firewalls with SonicWall Capturesubscriptions and GRID Gateway Anti-Virus and IPS signature databases and the URL, IP and domain reputationdatabases within 48 hours.Block until verdictTo prevent potentially malicious files from entering the network, files sent to the cloud for analysis can be held at thegateway until a verdict is determined.Encrypted Threat ProtectionFeatureDescriptionTLS/SSL decryption and inspectionDecrypts and inspects SSL traffic on the fly, without proxying, for malware, intrusions and data leakage, and appliesapplication, URL and content control policies in order to protect against threats hidden in TLS/SSL encrypted traffic.Included with security subscriptions for all models except SOHO. Sold as a separate license on SOHO.SSH inspectionDeep packet inspection of SSH (DPI-SSH) decrypts and inspects data traversing over SSH tunnels to prevent attacksthat leverage SSH.Intrusion preventionFeatureDescriptionCountermeasure-based protectionTightly integrated intrusion prevention system (IPS) leverages signatures and other countermeasures to scan packetpayloads for vulnerabilities and exploits, covering a broad spectrum of attacks and vulnerabilities.Automatic signature updatesThe SonicWall Threat Research Team continuously researches and deploys updates to an extensive list of IPScountermeasures that covers more than 50 attack categories. The new updates take immediate effect without anyreboot or service interruption required.Intra-zone IPS protectionBolsters internal security by segmenting the network into multiple security zones with intrusion prevention, preventingthreats from propagating across the zone boundaries.Botnet command and control (CnC) detectionand blockingIdentifies and blocks command and control traffic originating from bots on the local network to IPs and domains thatare identified as propagating malware or are known CnC points.Protocol abuse/anomalyIdentifies and blocks attacks that abuse protocols in an attempt to sneak past the IPS.Zero-day protectionProtects the network against zero-day attacks with constant updates against the latest exploit methods andtechniques that cover thousands of individual exploits.Anti-evasion technologyExtensive stream normalization, decoding and other techniques ensure that threats do not enter the networkundetected by utilizing evasion techniques in Layers 2-7.Threat prevention7FeatureDescriptionGateway anti-malwareThe RFDPI engine scans all inbound, outbound and intra-zone traffic for viruses, Trojans, key loggers and othermalware in files of unlimited length and size across all ports and TCP streams.CloudAV malware protectionA continuously updated database of over 17 million threat signatures resides in the SonicWall cloud servers and isreferenced to augment the capabilities of the onboard signature database, providing RFDPI with extensive coverageof threats.Around-the-clock security updatesNew threat updates are automatically pushed to firewalls in the field with active security services, and take effectimmediately without reboots or interruptions.

Threat prevention con'tFeatureDescriptionSSL decryption and inspectionDecrypts and inspects SSL traffic on the fly, without proxying, for malware, intrusions and data leakage, and appliesapplication, URL and content control policies in order to protect against threats hidden in SSL encrypted trafficIncluded with security subscriptions for all models except SOHO. Sold as a separate license on SOHO.Bi-directional raw TCP inspectionThe RFDPI engine is capable of scanning raw TCP streams on any port bi-directionally preventing attacks that they tosneak by outdated security systems that focus on securing a few well-known ports.Extensive protocol supportIdentifies common protocols such as HTTP/S, FTP, SMTP, SMBv1/v2 and others, which do not send data in raw TCP,and decodes payloads for malware inspection, even if they do not run on standard, well-known ports.Application intelligence and controlFeatureDescriptionApplication controlControl applications, or individual application features, that are identified by the RFDPI engine against a continuouslyexpanding database of over 3,500 application signatures, to increase network security and enhance networkproductivity.Custom application identificationControl custom applications by creating signatures based on specific parameters or patterns unique to an applicationin its network communications, in order to gain further control over the network.Application bandwidth managementGranularly allocate and regulate available bandwidth for critical applications or application categories while inhibitingnonessential application traffic.Granular controlControl applications, or specific components of an application, based on schedules, user groups, exclusion lists and arange of actions with full SSO user identification through LDAP/AD/Terminal Services/Citrix integration.Content filteringFeatureDescriptionInside/outside content filteringEnforce acceptable use policies and block access to websites containing information or images that are objectionableor unproductive with Content Filtering Service. Extend policy enforcement to block internet content for deviceslocated outside the firewall perimeter with the Content Filtering Client.Granular controlsBlock content using the predefined categories or any combination of categories. Filtering can be scheduled by timeof day, such as during school or business hours, and applied to individual users or groups.YouTube for SchoolsEnable teachers to choose from hundreds of thousands of free educational videos from Yo

(3G/4G WAN Failover) Link and activity Indicator LEDs Power LED Test LED X0 LAN Port X1 WAN Port Secure power 8x1GbE switch (configurable) Console port Expansion module Slot (future) SonicWall TZ500 series For growing branch offices and SMBs, the SonicWall TZ500 series