|
|
GateMAN 4012 firewall is a high performance plug and play core switch
to be installed in the heart of corporate networks with advanced security
features. It drops all IP packets with wrong checksums. All TCP connections
will be checked, from the checksum to the state transition and sequence numbers
of TCP sessions. If configured, the logs about all fetched URLs, Email senders/recipients,
FTP users and commands, besides hundreds of statistical information will be sent
to the log collector system. Logs of 4012 are sent by a special purpose protocol
which will not be saturated by SPAM and/or junk Sync floods. GateMAN 4012 is a
12-ports, layers 2-7 switch with many advanced features1 including2:
-
Twelve 10/100/1000 TX Ethernet
ports.
-
Serial port console with full
setup capabilities.
-
Traffic shaping features
including:
-
Frames per second limit on
in/out frames per port
-
Frame drops per port
statistics
-
Bytes dropped per port
statistics
-
IP, ARP, Reverse ARP,
IPX, PUP, Loop back, and RAW frame type filtering (e.g. “allow NO IPX frames
to
come in from port 6” or “allow frames with type 0x805 to go out from port
43”, etc).
-
Current/Max so far
Frames/Bytes per second in/out statistics per port with capability to reset
the statistics.
-
Per port queue with statistics
on queues (e.g.: “Max number of frames queued on port number 5 so far”) with
capability to reset the values
-
Per port queue length
adjustment capability
-
Full layer three, packet
filtering with automatic IP checksum control
-
Tight TCP stateful inspection
including:
-
TCP sequence number checking
and tracing
-
Syn/Ack/Fin state transition
and violation control
-
TCP checksum checking
-
Out of sequence TCP packet
alignment
-
Per TCP connection bandwidth
limitation
-
DDoS attack per destination
control and protection
-
Port scan reporting and
limitation
-
Application layer protocol
monitoring and violation control for Telnet, SMTP, FTP, and HTTP (e.g.:
invalid HTTP requests cause TCP connection termination).
-
URL filtering with user
defined URL databases to filter domains, sub-domains, directories in sites.
-
White list URL databases.
-
Per entry URL database
classification to let administrator classify sites in more than 64000
classes.
-
Regular expression matching
with space for 100 regular expressions to match with HTTP requests.
-
SMTP session filtering based
on entries defined in databases of username, domain name, user@domain.
-
Plug and play installation as
any industry standard Ethernet switch.
-
LAN user authentication to
allow/disallow users to pass the switch to see/filter the classified site in
periods of time, with periodic and total quotas on send, receive, login
count, connection duration.
-
GUI based setup programs for
Windows™ and Linux™.
-
Ultra fast log protocol with
additional free software to manage the logs for months and make reports
(requires a computer to collect the logs – not supplied).
-
IPSec support.
-
NAT/PAT/MAT (MAC Address
translation) support.
-
IP/MAC database as source
and/or destination in rules.
-
MAC address dump feature for
debugging the network.
-
Operation Temperature: 0 ~ 50
-
Color: Black
-
19 inches rack mountable
chassis with 4U height.
-
Please Contact your local distributor for complete list of features.
-
The Provided information is subject to change without notice.
-
The Syntax of Firewall Rules is just for demonstration.
|