Multi-layered Security Protection to Meet All Your Network Concerns

Despite the enormous potential of e-commerce, it brings along with itself various nuisances and security risks such as spam, viruses, Trojans, hacker attacks, etc. Accordingly, Nusoft presents you with NGFW Firewall Series, the ultimate solution to network security and management concerns. Its multi-layered spam filtering and training mechanisms help filter out unsolicited and virus-infected emails, merely keeping the legitimate ones.

  • Saves the budget for an IPv6-based gateway simply for IPv4-to-IPv6 address translation.
  • Provides user-definable NIC ports (LAN / WAN / DMZ) and teaming features.
  • Offers complete fault tolerance solutions, including link failover, VPN trunking, email archiving, high availability, etc. to ensure network continuity and email accessibility.
  • Features a full range of email services, including spam filtering, virus scanning, email auditing, etc. to process email messages as well as gives network administrator an instant insight into the email system by providing statistical graphs and email logs.
  • Protects business network or website from hacker attacks and malicious code (viruses, Trojans, spyware, fishing frauds, etc.) by employing dual anti-virus engines, IDP system and Web application firewall (WAF).
  • Prevents Internet-based applications or Web browsing from non-work related uses.
  • Allows in- / outbound traffic to be routed based on network polices.
  • Delivers security to network connections with comprehensive VPN connectivity.
  • Adds flexibility to bandwidth management by providing QoS and individual QoS.

Multi-layered Network Security Protection

SPI / Internal Firewall

Based on ICSA-certified SPI firewall technology, Nusoft NGFW Firewall can be deployed at the network perimeter to fully protect against various security threats. Besides, the NIC Teaming feature enables it to physically segment a network, adding an extra layer of protection by serving as an internal firewall to efficaciously prevent viruses or worms from spreading over the network.

Viruswall

The inbuilt dual anti-virus engines, ClamAV and CYREN, are able to effectively filter out over fifty thousand kinds of viruses, Trojans, spyware and phishing frauds. Besides, ClamAV virus signatures are available for free updates 24/7, which offers your network the most up-to-date virus protection at a minimum ownership cost.

Intrusion Detection and Prevention (IDP)

The IDP inspection, integrating intrusion detection system (IDS) and intrusion prevention system (IPS) together, focuses on OSI layer 4 (transport layer) through 7 (application layer) to block malicious code and attacks originating from the Internet. Aside from the present 3,000 signatures and an auto-update at a 30-minute interval, custom signatures and timely reporting are also provided for better network protection and diagnosis.

Web Application Firewall (WAF)

It offers PCI DSS and HIPAA compliance by the support of Web 2.0 technologies, various server types (Apache / Java / IIS) and multiple scripting languages (Perl / Python / TCL / PHP). Not only the Web application attacks (XSS / SQLIA) can be blocked, but also the detailed operation logs and statistical reporting are provided.

Anti-Spam

The spam filtering can reach 99% accuracy by training and multiple filtering mechanisms such as Fingerprint, Bayesian, Global / Personal Rule, Grey-/Black-/White-/Auto White-list, RBL, SPF, DomainKeys, email spoofing detection, etc. In addition, quarantined messages may be retrieved by their intended recipients through a daily mail notice without the intervention of network administrator, greatly reducing the management load.

One-Time Password (OTP)

Nusoft OTP app is an OTP client specially dedicated for Nusoft NGFW / MHG Series products. It can generate an unpredictable and unrepeatable password, which can be used as a "two-factor authentication" to protect your online sessions.

Comprehensive Network Traffic Management

Multi-WAN Load Balancing

With the multi-WAN module, outbound traffic are distributed across WAN links by load-balancing algorithms, due to which it delivers bandwidth aggregation and link failover capabilities, making the most of bandwidth, yet with reliable connectivity. Besides, inbound traffic to your company website can be evenly load-balanced across each link to mitigate the load of page requests, ensuring the accessibility to the website should any link failure occur.

Bandwidth Management

Quality of Service (QoS), individual QoS, P2P QoS, Traffic Quota and Flow Analysis are provided as tools to base bandwidth allocation on network policies, preventing the bandwidth being exhausted by minorities.

Policy-based Routing (PBR)

The network traffic generated from a specific service or user can be routed through a designated WAN link based on the company's network policies.

Custom NIC Ports & Groups

Multiple NIC ports are available for defining as LAN, WAN, DMZ or network groups (isolated from one another).

Flexible Network Access Management

Application Blockin

The use of instant messaging (both login and file transfer), peer-to-peer sharing, multimedia streaming, web-based email service, online gaming, VPN tunneling and remote controlling can be effortlessly blocked by their packet signatures. Free signature updates are available around the clock to ensure the reliability of blocking.

Web Filtering

The Web Filtering feature employs a cloud-based URL database which is categorized into Anti-Social and Illegal, Pornographic and Abusive, Gaming and Gambling, Society and Commerce, Communication and Technology, Leisure, Information and Education, Other, and further categorized into sixty-four subcategories. Web access can be easily managed by category instead of a URL, keyword, etc.

AAA Server

Authentication:
Manages the Internet access by internal or external (RADIUS / POP3 / LDAP) authentication.

Authorization:
Permits access to a specific resource or service.

Accounting:
Provides detailed connection logs for network policy adjustment.

Total VPN Solution

Unlike conventional firewalls, Nusoft NGFW Firewall's VPN Trunking feature delivers link failover and bandwidth aggregation capabilities to IPSec / PPTP tunnels, greatly increasing the speed and stability of VPN connections. In addition, Hardware Authentication and SSL Application are incorporated into SSL Web VPN connectivity, which allows user authentication to base on hardware information as well as provides VNC connectivity and Wake-on-LAN capability. Branch offices and road warriors are offered with fast and easy VPN access along with advanced security (anti-virus, IDP, etc.) and controls (authentication, QoS, etc.).

Wireless AP Controller

With the AP controlling capability, Nusoft NGFW Firewall is able to centrally manage a number of access points, allowing you to perform a unified configuration, view AP status on Google Maps, check wireless client status, detect rogue APs, etc. It also helps prevent traffic from being congested to a specific AP by evenly load balancing wireless connections, effectively avoiding network bottleneck.

Additionally, a dedicated mobile app for monitoring on the go is made available on both iOS and Android. As for wireless client access, network policies can be applied to implement various authentication mechanisms (Captive Portal / RADIUS / LDAP / POP3), filter website categories, limit the user traffic, charge guests for Wi-Fi service, block Internet-based applications and more, fulfilling all your wireless management needs.

Note: The AP controller feature is only applicable for Nusoft APs.