Stopping inBound and outBound threats Juniper networks firewall/ipSec Vpn with unified threat ManageMent (UTM)
Challenge - As the network attack landscape continues to evolve, IT managers can no longer afford to focus solely on protection against a single type of attack and expect their network to remain unaffected.
Solution - Stopping all manner of inbound and outbound attacks, requires a concerted, multi-layered solution to prevent them from inflicting damages on the network, your assets and the end user.
Benefits - To provide protection against inbound and outbound attacks at all levels, Juniper Networks integrates a complete set of best-in-class Unified Threat Management (UTM) features into their line of branch office firewall/VPN platforms. By leveraging the development, support and market expertise of many of the leading content security partners, Juniper is able to deliver a set of best-in-class UTM features.
Would you like more information about Juniper Content Security Services
Then please download the datasheet by clicking here
Content Security Specifications - AV, Web Filtering, Anti-Spam, IPS
AV (Kaspersky Labs):
Protocols scanned SMTP, POP3, Webmail, FTP, IMAP, HTTP
Inbound/outbound protection Yes/Yes
New virus responsiveness Average 30 minutes
Update frequency Hourly
Number of virus signatures 480,000 +
Archive and extractor formats ACE, ARJ, Alloy, Astrum, BZIP2, BestCrypt, CAB, CABSFX, CHM, Catapult, CaveSFX, CaveSetup, ClickTeam, ClickTeamPro, Commodore, compiled HLP, CreateInstall, DiskDupe, DiskImage, EGDial, Effect Office, Embedded, Embedded Class, Embedded EXE, Embedded MS Expand, Embedded PowerPoint, Embedded RTF, FlyStudio, GEA, GKWare Setup, GZIP, Gentee, Glue, HA, HXS, HotSoup, Inno, InstFact, Instyler, IntroAdder, LHA, MS Expand, MSO, Momma, MultiBinder,
NSIS, NeoBook, OLE files, PCAcme, PCCrypt, PCInstall, PIMP, PLCreator, PaquetBuilder, Perl2Exe, PerlApp, Presto, ProCarry, RARv 1.4 and above, SEA, SbookBuilder, SetupFactory, SetupSpecialist, SilverKey, SmartGlue, StarDust Installer, Stream 1C, StubbieMan, Sydex, TSE, Tar, Thinstall, ViseMan, WinBackup, WiseSFX, ZIP, 7-Zip
Win semi-executable extensions pif, lnk, reg, ini (Script.Ini, etc), cla (Java Class), vbs (Visual Basic Script), vbe (Visual Basic Script Encrypted), js (Java Script), jse (Java Script Encrypted), htm, html, htt (HTTP pages), hta - HTA (HTML applications), asp (Active Server Pages), chm – CHM (compressed HTML), pht – PHTML, php – PHP, wsh, wsf, the (.theme)
MS office extensions doc, dot, fpm, rtf, xl*, pp*, md*, shs, dwg (Acad2000), msi (MS Installer), otm (Outlook macro), pdf (AcrobatReader), swf (ShockwaveFlash), prj (MapInfo project), jpg, jpeg, emf (Enhanced Windows Metafile), elf doS executable extensions: com, exe, sys, prg, bin, bat, cmd, dpl(Borland’s Delphi files), ov*
Win executable extensions dll, scr, cpl, ocx, tsp, drv, vxd, fon 386
Email file extensions Eml, nws, msg, plg, mbx (Eudora database)
Help file extensions hlp
Other file extensions sh, pl, xml, itsf, reg, wsf, mime, rar, pk, lha, arj, ace, wmf, wma, wmv, ico, efi
Integrated Web Filtering Specifications (Websense)
URL database >25 Million – growing daily
Pages covered within database >3.9 Billion
New pages added 250,000 list changes every day
Number of categories covered 40 including phishing & fraud, spyware, Adult/Sexually Explicit, Alcohol & Tobacco, Criminal Activity, Gambling, Hacking, illegal Drugs, Intolerance & Hate, Tasteless & Offensive, Violence, Weapons
Languages 70
Countries 200
Anti-spam Specifications (Symantec)
SPAM list update frequency The anti-spam list is updated twice every hour.
Types of spam covered Zombies, open proxies, suspect spam
Percentage of WW email used to generate list Approximately 20%-25% of all global email traffic is analyzed to generate the anti-spam list.
Number of mechanisms (honeypots etc) used to collect and perform analysis anti-spam list is generated from approximately 3 million honeypots across more than 25
different countries
IPS (Deep Inspection FW) Specifications
Methods of detection Two methods of detection:
- 1. Stateful Signatures
- 2. Protocol Anomaly (Zero-day coverage)
Worm protection Yes
Trojan protection Yes
Other malware protection Yes
Reconnaissance protection Yes
Client to server and server to client attack protection Yes
Create custom attack signatures Yes
Application contexts for signature customization 90+
Stream Signatures for worm mitigation Yes – in worm mitigation signature pack. Stream256 used in other signature packs.
Number of response options
- Close: Severs connection and sends RST to client and server
- Close Server: Severs connection and sends RST to server
- Close Client: Severs connection and sends RST to client
- Drop: Severs connection without sending anyone a RST
- Drop Packet: Drops a particular packet, but does not sever connection
- Ignore: After detecting an attack signature or anomaly, the Juniper Networks NetScreen 5000 Series Security System makes a log entry and stops checking – or ignores – the remainder ofthe connection
- None: No action
Attack notification mechanisms
- Session Packet Log
- Session Summary
- E-mail
- SNMP
- Syslog
- Webtrends
Create and enforce appropriate application usage policies Yes– For Instant messenger and Peer to Peer applications
Frequency of updates Monthly and Emergency