Stonesoft 5.4 new features antti kuvaja

28
Stonesoft version 5.4 NEW FEATURES

Transcript of Stonesoft 5.4 new features antti kuvaja

Page 1: Stonesoft 5.4 new features   antti kuvaja

Stonesoft version 5.4

NEW FEATURES

Page 2: Stonesoft 5.4 new features   antti kuvaja

Release highlights

STONESOFT 5.4

New transformable

Security Engine

New visualizations and

evasion awareness

Page 3: Stonesoft 5.4 new features   antti kuvaja

Security Engine

Page 4: Stonesoft 5.4 new features   antti kuvaja

FW

Security Engine

IPS NGN

2001 2004 2012

Page 5: Stonesoft 5.4 new features   antti kuvaja

IPS FW VPN L2FW

Security Engine Roles

NGN

Page 6: Stonesoft 5.4 new features   antti kuvaja

New Statistics and Visualizations

Page 7: Stonesoft 5.4 new features   antti kuvaja

Evasion awareness SEE THE ANOMALIES IN LOGS…

”Anomaly” log field available

that shows the detected

atomic evasions

”Top Anomalies” statistics

Page 8: Stonesoft 5.4 new features   antti kuvaja

Log Visualizations UNDERSTAND YOUR ENVIRONMENT

See which users use what applications as a single diagram

What services and situations are used and by whom?

Log Analysis mode can handle up to 100 000 (prefiltered) log events

Page 9: Stonesoft 5.4 new features   antti kuvaja

Status diagrams LINK/TUNNEL USAGE INFO EMBEDDED TO…

See the relative amount of

traffic flowing in each VPN

tunnel or Netlink

Page 10: Stonesoft 5.4 new features   antti kuvaja

Statistics Sections ENHANCED REPORTING

Ability to reuse Statistics

Sections

A lot of out-of-box

sections available

Ability to create ad-hoc

filters for Reports

Page 11: Stonesoft 5.4 new features   antti kuvaja

Enhancements

SMC

Page 12: Stonesoft 5.4 new features   antti kuvaja

Audit Log Enhancements

REGULATORY COMPLIANCE

Element snapshots

Audit data syslog

forwarding

More granular auditing

Page 13: Stonesoft 5.4 new features   antti kuvaja

Traffic Capture MORE CONVENIENT TROUBLESHOOTING

It is now possible to take

tcpdump directly from

Management Client user

interface

Makes troubleshooting

easier for customers and

Stonesoft Support

tcpdump

Page 14: Stonesoft 5.4 new features   antti kuvaja

Better SMC Scalability MANAGEMENT UP TO 2000 NODES

One Management

Server can serve up to

2000 nodes

Improved policy upload

performance

5.3

1000

2000

5.4

Nodes

Version

Page 15: Stonesoft 5.4 new features   antti kuvaja

Localization Support SMC IN CHINESE, RUSSIAN, SPANISH, …

Most important SMC labels

are parameterized

Introducing a new SMC

language is a matter of

translating one text file

containing about 5000+

labels/messages

Page 16: Stonesoft 5.4 new features   antti kuvaja

Country flags in logs NEW USAGE OF GEOIP DETECTION…

See the country flags directly

in Log records table

Useful information for anomaly

detection

Helps you to visually identify

which log entries are related

Page 17: Stonesoft 5.4 new features   antti kuvaja

Other SMC Enhancements

Internal User Database replication to separate

administrative Domains

Interface comments visible in statistics

Policy usability enhancements

LEEF forwarding/reception support

Page 18: Stonesoft 5.4 new features   antti kuvaja

Enhancements

NGN

Page 19: Stonesoft 5.4 new features   antti kuvaja

Advanced Routing VPN WITH DYNAMIC ROUTING AVAILABLE

Tunneling interface

support with Route-Based

VPN

Dynamic routing over

Route based VPN

Page 20: Stonesoft 5.4 new features   antti kuvaja

Snort Signatures ABILITY TO IMPORT AND USE…

Snort signatures can be

automatically translated into

Stonesoft custom fingerprints

Page 21: Stonesoft 5.4 new features   antti kuvaja

File context BETTER DEEP INSPECTION WITH…

Makes possible to inspect

directly the transferred files

More accurate inspection

Page 22: Stonesoft 5.4 new features   antti kuvaja

Auth. Server & Firewall DEEPER INTEGRATION

Easier way to use

Authentication Server for VPN

and possibly also for wireless

access point authentication

Multi-Link capable channel

between the Authentication

Server and Firewall

FW AS

Page 23: Stonesoft 5.4 new features   antti kuvaja

Improved Application Identification

MORE PROTOCOLS SUPPORTED

Port independent access

control and application

identification also for non-web

traffic

Amount of Applications

increasing all the time.

Page 24: Stonesoft 5.4 new features   antti kuvaja

Other NGN Enhancements

Increased small packet throughput with big

appliances

HTTP IPv6 inspection in L3

Page 25: Stonesoft 5.4 new features   antti kuvaja

Enhancements

SSL VPN

Version 1.5.100

Page 26: Stonesoft 5.4 new features   antti kuvaja

Integrated Directory Service

BETTER ROBUSTNESS AND SCALABILITY

Provides better resilience for

userbase without the need to

have external Directory

Services

USERS

SSL VPN

SSL VPN

Page 27: Stonesoft 5.4 new features   antti kuvaja

Access client for Linux, and OS X

IMPROVED PLATFORM SUPPORT

Native client for

Linux and Mac OS X

SSL VPN

Page 28: Stonesoft 5.4 new features   antti kuvaja

Thanks!