
DATA SHEET
WATCHGUARD
®
FIREBOX
™
SYSTEM
Easy To Install. Easy To Manage. Always Up-To-Date.
Overview
The WatchGuard Firebox System is a comprehensive firewall
and VPN security solution that reduces the time and resources
required to secure your network. Unlike traditional firewall and
VPN products that are difficult to install and maintain, the
WatchGuard Firebox System is simple to install and can be
managed from a central location.
A selection of Firebox models lets you choose the best combi-
nation of performance, features and price for your business.
WatchGuard also offers optional products to expand the
capabilities of your Firebox System. Every Firebox
System includes a one-year subscription to the LiveSecurity
™
Service, an annual subscription service that delivers software
updates, security information alerts, and technical support
directly to you.
Firebox
TM
III System Security Features
The WatchGuard Firebox System includes a comprehensive
suite of security software. WatchGuard’s firewall technologies
let you control incoming and outgoing traffic between the
Internet and your protected networks. Network Address Translation (NAT) makes it possible to hide your internal IP
addresses from the external network, and to allow internal hosts with unregistered IP addresses to function as Internet-
reachable servers. Mobile User and Branch Office Virtual Private Networking (VPN) allow you to set up secure com-
munication tunnels between your protected network and traveling employees,
branch offices, and trading partners. User Authentication allows you to configure access rules by user or group. URL
Filtering improves productivity by filtering or blocking Web site privileges.
Firewall
• Security Proxies are used to apply filter rules to the
contents of TCP/IP packets.
• Stateful Dynamic Packet Filtering lets you build
filtering rules based on the state of the connection.
• Anti-spamming Filter, SpamScreen
®
option enables
you to automatically tag or deny e-mail received from
questionable sources.
• Scan Detection automatically detects and blocks port
scanning attempts.
• Spoofing Detection protects internal hosts against
spoofing by hostile external hosts.
• Site Blocking prohibits certain Internet addresses from
accessing your protected networks.
• Port Blocking prohibits access to dangerous ports in
your TCP and UDP services.
• Synflood Protection stops Synflood denial of
service attacks.
Network Address Translation
• Dynamic NAT hides internal IP addresses from the
external network.
• Static NAT allows internal hosts with unregistered IP
addresses to function as Internet-reachable servers.
• One-to-one NAT allows mapping of a range of IP
addresses to an alternate range of IP addresses.
User Authentication
• Positively identifies users and defines “user” and
“group” policies.
• Authenticates users against Windows NT
®
servers,
RADIUS
™
- compliant authentication servers (as defined
in RFC 2138), SecurID
®
and CRYPTOCard
®
authentica-
tion, and WatchGuard’s built-in authentication.
Komentáře k této Příručce