Secure Thought
mark.lewis@secure-thought.com

Secure-Thought

Secure Thought Ltd, has been set up to provide independent consultancy within the IT Network Security field. With over 15 years of IT experience, specialising in Global IT Security for over half this time, we are well placed to provide efficient and effective solution for your company.


Firewalls:

Enterprise Appliance Firewalls

Sun Cobalt Adaptive Firewall

  www.sun.com

http://www.sun.com/hardware/serverappliances/qube3/adaptive.html

The Sun Cobalt Adaptive Firewall is a high-performance; commercial-grade product that goes above and beyond the protection offered by the Basic Firewall that comes standard with the Sun Qube 3 appliance. It is designed to offer proven protection for your network assets, and can be easily installed on your Sun Qube 3 appliance through the Sun Cobalt BlueLinQ Application Delivery Service.

Symantec Firewall VPN Appliance

  www.symantec.com

http://enterprisesecurity.symantec.com/products/

Symantec Firewall/VPN Appliance (Models 100, 200, 200R) is an integrated security and networking device that provides easy secure, and cost-effective Internet connectivity between locations. With its all-in-one functionality, small businesses and remote offices can create a high-speed local network that enables secure access and interaction via the Internet with remote locations, business partners, and corporate networks. The appliance can be installed quickly, offering offices with up to 40 employees a turnkey solution for securing outbound and inbound web, email, FTP traffic and more. And for larger, dispersed organizations, Symantec Firewall/VPN offers an affordable and easy-to-manage solution for extending firewall protection and IPSec gateway-to-gateway VPN access to satellite offices and branch locations and a remote client-to-gateway IPSec VPN for traveling users.

BioData

  www.biodata-systems.info

http://www.biodata-systems.info/index_e.html

Biodata BIGfire protects your network against attacks from the Internet. Dynamic packet filter monitor data flow between corporate network and Internet, check sender and recipient, service, time, port and user. Unwanted connection requests are blocked, optionally even without error message to leave an attacker without any clue about your infrastructure. User defined rules allow a maximum of flexibility.

Dedicated solution with clear mission: network protection
Biodata BIGfire is a stand-alone hardware solution which comes in a standard 19" box. The system has neither a hard disk nor any other drive and is therefore immune against hard disk problems. It's high reliability is complemented by a boot process of just a few seconds.

In contrast to combined systems or software solutions on computers, Biodata BIGfire's memory contains only the code necessary for protection. This makes it more secure than many other solutions.
Demilitarized Zone (DMZ)

Biodata BIGfire offers three different network interfaces (10/100 MBit/s): intern, extern and a dedicated administration network, which can also be used as SSN (Secure Server Network) or DMZ.

VPN Option
Biodata BIGfire is more than just a firewall. The optional VPN features (Virtual Private Network) allows to connect networks via Internet in a secure way. Internationally recognized cryptographic algorithms like Triple-DES (192 Bit keys) protect transported data by encryption. Even firewalls and VPN products of other manufacturers can be included if they support IPSec. Starting in Q3 2002, Biodata BIGfire offers full IPSec- and IKE functionality.

Easy configuration
Biodata BALI gives you security through easy maintenance: the graphical user interface lets you choose appropriate options for your needs in a concise way. Even remote administration is possible, which is again protected with strong encryption. With Biodata BALI, administrators of large IT infrastructures can easily manage all devices at all sites. SNMP support allows quick integrati9on into existing SNMP management systems. For authentication of users, Biodata BIGfire supports RADIUS, a standard authentication

The Firebox 500

 www.watchguard.com

http://www.watchguard.com/products/firebox500.asp

The Firebox® 500 Is Recommended For Smaller businesses needing a hardened firewall appliance for networks with up to 250 authenticated users Businesses needing advanced application security proxies, stateful packet filtering, and Web content filtering Organizations requiring easy deployment and default configurations Businesses wanting an easy-to-manage security solution with full logging, historical reporting, and secure remote management IT staff who want customizable alerts and event notifications

More Models Available: Firebox® 4500 Firebox® 2500 Firebox® 1000 Firebox® 700

Cyberguard Firewall & VPN Appliances

www.cyberguard.com

http://www.cyberguard.com/solutions/product_overview.cfm

The KS1000/1500, SL2000, FS250/500 and LX series of premium firewall/VPN appliances from CyberGuard carry on a strong tradition of offering the world's most secure firewalls. CyberGuard has been developing its extensive knowledge and expertise in security systems, designing and implementing the best performing, easiest to use and most secure network solutions for the world's most demanding customers: major banks, financial institutions, corporations and governments. Today, with the offering of appliance firewalls, security is almost "plug and play" as our firewalls are delivered pre-loaded on an appliance -- ready to install and protect your network.

CyberGuard firewall/VPN appliances have been designed and developed with the utmost attention to detail, functionality, user friendliness and a corporate passion for providing the most secure firewall/VPN solutions available. CyberGuard’s firewall technology has earned all the industry's major awards and certifications including the world's most rigorous IT security evaluation – the internationally accepted Common Criteria Evaluation Assurance Level 4+ (EAL4+).

NetWolves Wolfpac 2020/3000

  http://www.netwolves.com

http://www.netwolves.com/nss.htm

The WolfPac 2020 contains the following hardware specifications: 600MHz AMD IDE Hard Drive 128 MB RAM WAN Interface: Ethernet 10/100 RJ45 port LAN Interface: Ethernet 10/100 RJ45 port DMZ Interface: Ethernet 10/100 RJ45 port Dimensions: 17.5" W x 10.5" D x 3.5" H with out rack ears

The WolfPac 3000 contains the following hardware: 900MHz AMD 512 MB IDE Hard Drive WAN Interface: Ethernet 10/100 RJ45 port LAN Interface: Ethernet 10/100 RJ45 port DMZ Interface: Ethernet 10/100 RJ45 port

The firewall incorporates three separate technologies:
Packet filters verify that an authorized user from your protected network has requested all IP packets coming from the Internet. Proxy accepts requests from the authorized user for Internet service and then acts on behalf of this client by establishing a connection for the requested service to the intended host. Network Address Translation (NAT) allows an organization to identify itself to the Internet with one IP address, providing another layer of protection by keeping individual IP addresses hidden from the outside world.

Global Technology associates, Inc.
GB-1000
 

  Global Technology Associates Inc

http://www.gta.com/products/main-gb1000.php

Larger companies require a firewall capable of keeping up with the intense demands of their high-bandwidth Internet connection. A VPN tunnel is almost always needed for a secure connection to the main office by remote offices and users. The GB-1000 Firewall/VPN Appliance is a perfect solution for larger companies seeking tight security, high performance, and adaptability. Excellent Price / Performance Flexible Configuration Low Cost of Ownership Ease of Use Proven Technology

NetScreen-5000 Series

NetScreen

http://www.netscreen.com/products/NS5000.html

The NetScreen-5000 Series of purpose-built, high performance security systems, including the 2-slot NetScreen-5200 and 4-slot NetScreen- 5400, delivers a new level of high-performance capabilities for large enterprise, carrier, and data center networks. Built around NetScreen’s third-generation security ASIC technology and distributed system architecture, the NetScreen-5000 Series offers excellent scalability and flexibility in network security systems.

NetScreen-200 Series

NetScreen

http://www.netscreen.com/products/appliances.html#ns208ns204

The NetScreen-200 Series includes two products, the NetScreen-204 and the NetScreen-208, differentiated by the number of 10/100 interfaces (four and eight respectively). Together, they are two of the most versatile security appliances available today, easily integrating into many different environments, including medium and large enterprise offices, e-business sites, data centers, and carrier infrastructures. Complete with either four or eight auto-speed-sensing, auto-polarity-correcting 10/100 Base-T Ethernet ports, the NetScreen-200 Series performs firewall functions at near wire-speed (550 Mbps on the NetScreen-208 and 400 Mbps on the NetScreen-204). Even the most computationally intense applications, such as 3DES and AES encryption, are performed at speeds greater than 200 Mbps. In addition to physical interface density, the NetScreen-200 Series optionally supports virtualization, including VLAN support and additional custom security zones and virtual routers.

NetScreen 50 & 25

NetScreen

http://www.netscreen.com/products/appliances.html#ns208ns204

The NetScreen-50 and NetScreen-25 offer a complete security solution for enterprise branch and remote offices as well as small- and mediumsized companies. Featuring four auto-sensing 10/100 Base-T Ethernet ports, the NetScreen-50 and NetScreen-25 provide for flexible deployment solutions where multiple DMZs are required, Wireless LAN segmentation, or segmentation of the internal network. The NetScreen-50 is a high performance security appliance, offering 170 Mbps of firewall and 50 Mbps of 3DES or AES VPN performance, with support for 32,000 sessions, 100 site-to-site VPN tunnels, and 400 VPN users. The NetScreen-25 has the same interfaces and offers 100 Mbps of firewall and 20 Mbps of 3DES or AES VPN performance, with support for 8,000 sessions, 25 site-to-site VPN tunnels, and 100 VPN users.

SonicWall Applicances

SSI Services

http://www.ssimail.com/NT_firewall_appliance.htm

SonicWALL appliances offer two product ranges to cover the enterprise level. The PRO range is aimed at the small to medium office environment, while the GX range is aimed to cover the large corporate level of network with high-bandwidth and a large volume of network connections/VPNs

PRO Range

PRO 100:- "The best value for branch offices and institutions. It supports unlimited network nodes for low cost-per-user protection including an integrated DMZ to support public servers. The PRO 100's optional IPSec VPN upgrade future-proofs network infrastructure investments by adapting to changing security requirements."

Upto the PRO 330:- "Also delivers high firewall and 3DES VPN performance, mission-critical network security and secure connectivity for large businesses and main offices. Built on SonicWALL's CyberSentry Security Processor, the PRO 330 delivers breakthrough performance with hardware-acceleration for superior VPN and security throughput. The PRO 330 includes SonicWALL High Availability for mission-critical security and a DMZ port for public servers. The PRO 330 can support up to 1000 VPN tunnels."

GX Range

GX 250:- "The GX 250 delivers high-bandwidth firewall and VPN solutions for large enterprise installations. The 3U rack-mount GX 250 provides hardened firewall protection with an ICSA-certified, stateful inspection firewall and integrated IPSec VPN connectivity. Built on ASIC security architecture, the GX 250 provides breakthrough performance for superior VPN and security throughput. By offloading processing overhead associated with encryption, the GX 250 can support up to 5,000 VPN tunnels."

Upto GX 650:- "The GX 650 provides mission-critical security with redundant, hot-swappable power supplies and SonicWALL High Availability, which enables two SonicWALL GXs (one primary and one backup) to operate as a redundant pair. The flexible chassis-based design of the GX 650 also provides a scalable path for future performance upgrades or network interface types. The GX 650 can support up to 10,000 VPN tunnels."