Policy-Based L7 Firewall
A fully stateful firewall
with layer-7 packet inspection.
The firewall is policy-based
meaning that each rule is based
on objects and each object can
be manipulated to create very
simple or highly complex rule
structures. The firewall also
includes packeting logging which
is very helpful for network
troubleshooting.Enahanced DDoS Protection
The Edge platform includes
powerful DDoS protection which
monitors and automatically drops
traffic which exceeds the
defined connection limits. This
capability is used to prevent
hackers from using hundreds of
computers to disable the
network.
VPN Support
The Edge supports SSL
(Site2Site tunnel), PPTP
(point-to-point tunneling
protocol, and IPSec VPN tunnel
termination. Site2Site tunnels
are unique to the Edge platform
and were developed by XRoads
Networks. PPTP is incorporated
into Microsoft Windows and is
thus an inexpensive remote
end-user tunneling technology.
IPSec support is extended to
legacy remote firewalls and
other appliances that need to
connect to the Edge platform.
SSL Client Support
A Microsoft Windows based
software client which allows
remote end-users to securely
connect to the Edge appliance
using 3DES encryption and
provide automated tunnel
failover in the event one of the
appliances WAN links were to
fail. (coming soon)
VPN Tunnel Balancing
Using the Site2Site tunnel
technology developed by XRoads
Netwoks two or more sites can be
connected via multiple tunnels
across multiple WAN links. This
allows for the balancing of
network traffic between multiple
tunnels and thus increase
performance between sites.
VPN Tunnel Failover
The Site2Site tunnel module
has the ability to automatically
failover between tunnels in the
event of a network outage. The
tunnels will automatically
failback once the network
connection has been restored.
SourceFire IDS
Working with SourceFire,
XRoads Networks has developed an
Intruson Detection and
Prevention system which
automatically scans network
traffic for potential hack
attempts and viruses. Using its
IDS/IDP engine and signatures
updated by SourceFire identified
attacks are logged and
additional actions can be taken
by the administrator. Enhanced
signature updates are also
available via a SourceFire
subscription.
SourceFire Anti-Virus
Based on the popular ClamAV
engine, XRoads Networks has
developed both an internal and
external software client for
detecting and removing viruses
from the network. The CAValier
software client for Windows
allows users of the Edge
platform to easily detect and
remove infected files.
Netsweeper WebFiltering
XRoads Networks has partnered
with Netsweeper to develop one
of the most powerful and
cost-effective web content
filtering solutions available on
the market today. The Netsweeper
database has categorized over
1/2 billion websites and
counting. With its granular
controls and excellent reporting
capabilities this filtering
system is second to none.
Peer-to-Peer Control
The Edge utilizes two methods
for controlling P2P traffic,
these include session limiting,
and signature-based application
blocking. Session limiting
allows the administrator to set
a specific limit to the number
of sessions any one user can
open at a time, this prevents
large numbers of users
downloading unauthorized content
(music downloads, etc).
Signature-based application
blocking is used to identify a
particular type of P2P
application, like BitTorrent,
and prevent that application
from working.
|
WAN Load Balancing
The original technology
developed by XRoads Networks was
WAN load balancing. When it
comes to WAN load balancing,
XRoads Networks is the expert.
Our load balancing solutions
include full session persistance,
multi-level outage detection,
and Best Path Routing. Each of
these components are required to
ensure a solid and stable load
balancing system. Most standard
firewall appliances which have
added WAN load balancing are
missing these components and are
thus limited in their
capabilities.ActiveDNS Server
Unlike most other standard
firewall appliances which have
WAN load balancing, the Edge
incorporates a fully functional
DNS server module which allows
the Edge to handle both outbound
and inbound WAN load balancing.
Other firewall appliances which
have WAN load balancing as an
add-on include the ability to
sign-up for a Dynamic DNS
service, which has an ongoing
annual fee and does not provide
the responsiveness or extended
capabilities of the ActiveDNS
module.
Full NAT Support
The Edge supports
bi-direction network address
translation and port translation
services.
RIP/OSPF Router
The Edge platform includes
supports full static routing
capabilities as well as RIP and
OSPF routing support.
Packet Sniffer
Incorporated in to the Edge
platform is a full featured
packet sniffer. The packet
sniffer can be used to capture
complete packet information,
including header and data types.
Very useful for troubleshooting
network related issues.
Network Monitoring
Use the built-in network
monitoring system to ping
internal network devices and
ensure they stay up and running.
The network monitor also support
port probing for testing the
availability of web, email, and
other services.
Syslog / Email Alerts
With a wide range of
capabilities the Syslog server
is very useful for traffic
capturing as well as obtaining
bandwidth updates and system
changes. Email alerts can be
setup for up to 10,000 end-users
with various alerts which can be
enabled or disabled on a per
user basis.
SLA Reporting
SLA reports can be created
using the Best Path Routing
module. The BPR module will
automatically probe each WAN
connection and provide graphical
updates in terms of latency,
packet loss, and calculated
jitter. These reports are highly
useful for determining how each
WAN link is performing.
Top Usage Reporting
Provides a quick snap-shot of
the top users and application
usage on the network. Quickly
see who is pushing the most
traffic, and when. Identify the
top applications and use that
information to add/remove
bandwidth shaping policies.
User Management /
Reporting
The Edge platforms includes
full user management via the web
interface. Users are
automatically identified based
on IP address which allows for
detailed per user reporting,
including reporting on top
application usage per user,
which is useful for identifying
who is using unauthorized
applications.
|