Today’s continuously shifting security environment presents a challenge for small/home office networks with limited IT capabilities. Fortunately, the D-Link NetDefend Unified Threat Management (UTM) firewalls provide a powerful security solution to protect business networks from a wide variety of threats. UTM Firewalls offer a comprehensive defense against virus attacks, unauthorized intrusions, and harmful content, successfully enhancing fundamental capabilities for managing, monitoring, and maintaining a healthy network.
Enterprise-Class Firewall Security
NetDefend UTM Firewalls provide complete advanced security features to manage, monitor, and maintain a healthy and secure network. Network management features include: Remote Management, Bandwidth Control Policies, URL Black/White Lists, Access Policies, and SNMP. For network monitoring, these firewalls support e-mail alerts, system logs, consistency checks and real-time statistics.
Unified Threat Management
NetDefend UTM Firewalls integrate an intrusion detection and prevention system, gateway antivirus, and content filtering for superior Layer 7 content inspection protection. An acceleration engine increases throughput, while the real-time update service keeps the IPS information, antivirus signatures, and URL databases current. Combined,
these enhancements help to protect the office network from application exploits, network worms, malicious code attacks, and provide everything a business needs to safely manage employee Internet access.
Powerful VPN Performance
NetDefend UTM Firewalls offer an integrated VPN Client and Server. This allows remote offices to securely connect to a head office or a trusted partner network. Mobile users working from home or remote locations can also safely connect to the office network to access company data and e-mail. NetDefend UTM Firewalls have hardware-based VPN engines to support and manage a large number of VPN configurations. They support IPSec, PPTP, and L2TP protocols in Client/Server mode and can handle passthrough traffic as well. Advanced VPN configuration options include: DES/3DES/AES/Twofish/Blowfish/CAST-128 encryption, Manual or IKE/ISAKMP key management, Quick/Main/Aggressive Negotiation modes, and VPN authentication support using either an external RADIUS server or a large user database.
Maintaining an effective defense against the various threats originating from the Internet requires that all three databases used by the NetDefend UTM Firewalls are kept up-to-date. In order to provide a robust defense, D-Link offers optional NetDefend Firewall UTM Service subscriptions which include updates for each aspect of defense: Intrusion Prevention Systems (IPS), Antivirus and Web Content Filtering (WCF). NetDefend UTM Subscriptions ensure that each of the firewall’s service databases are complete and effective.
Robust Intrusion Prevention
The NetDefend UTM Firewalls employ componentbased signatures, a unique IPS technology which recognizes and protects against all varieties of known and unknown attacks. This system can address all critical aspects of an attack or potential attack including payload, NOP sled, infection, and exploits. In terms of signature coverage, the IPS database includes attack information and data from a global attack sensor-grid and exploits collected from public sites such as the National Vulnerability Database and Bugtrax. The NetDefend UTM Firewalls constantly create and optimize NetDefend signatures via the D-Link Auto-Signature Sensor System without overloading existing security appliances. These signatures ensure a high ratio of detection accuracy and a low ratio of false positives.
Stream-Based Virus Scanning
The NetDefend UTM Firewalls examine files of any size, using a stream-based virus scanning technology which eliminates the need to cache incoming files. This zero-cache scanning method not only increases inspection performance but also reduces network bottlenecks. NetDefend UTM firewalls use virus signatures from Kaspersky Labs to provide systems with reliable and accurate antivirus protection, as well as prompt signature updates. Consequentially, viruses and malware can be effectively blocked before they reach the desktops or mobile devices.
Web Content Filtering
NetDefend UTM Subscription
The standard NetDefend UTM Subscription provides your firewall with UTM service updates for 12 months* starting from the day you activate or extend your service. The NetDefend UTM Subscription can be renewed regularly to provide your firewalls with the most up-to-date security service available from D-Link.
NetDefend Center: http://security.dlink.com.tw
*Actual service package may vary depending on region.
Powerful VPN Engine
Hardware-based data encryption and authentication for IPSec, PPTP, and L2TP in Client/Server mode enable fast and safe handling of VPN traffic. Professional Intrusion Prevention System (IPS) Automatic updates from a comprehensive IPS signature database focus on attack payloads to protect the network against zero-day attacks.
Real-Time Antivirus Inspection (AV)
The antivirus engine scans using the most complete, most up-to-date antivirus signature database. Streaming-based pattern matching provides the effective protection against viruses.
Fast, Efficient Web Content Filtering
Multiple index server implementation, granular policies, black lists and active content handling enhance performance and effectiveness of web surfing control.
Acceleration Engine for Unified Threat Management
A powerful processor allows the firewall to carry out IPS and Antivirus scanning simultaneously without performance degradation.
Licensed for Unlimited Users
Optional subscription services for IPS, Antivirus Scanning, and Web Content Filtering are priced per firewall rather than per user, thus reducing the total cost of ownership for licensing.
WAN Link Load-Balancing and Fault-Tolerance
Multiple WAN ports support traffic load balancing and failover, thus guaranteeing Internet availability and bandwidth.
D-Link End-to-End Security (E2ES) Solutions*
The ZoneDefense mechanism operating in conjunction with D-Link xStack switches automatically quarantines infected workstations and prevents them from flooding the internal network with malicious traffic.
*For DFL-860E, DFL-1660, and DFL-2560(G) only
D-Link Green Certified
The D-Link Green certified DFL-1660 and DFL-2560(G) are built with an 80 PLUS internal power supply.
80 PLUS certified power supplies offer increased reliability due to greater efficiency, and provide a reduced cost of ownership through longer equipment life. Additionally, 80 PLUS power supplies help prevent pollution by limiting energy consumption, and run at a lower temperature to reduce cooling costs.
The DFL-260E and DFL-860E save energy automatically through cable length and link status detection. By detecting the length of cables connected to a port, the amount of power used for the port can be adjusted, only using as much as is needed. The DFL-260E/860E can also detect if a port is not in use, such as when a connected computer is shut down or if nothing is connected to the port, and can automatically reduce the power used for that port, cutting energy used for it by a substantial amount.
D-Link Green certified devices comply with RoHS (Restriction of Hazardous Substances) and WEEE (Waste Electrical and Electronic Equipment) directives. RoHS directives restrict the use of specific hazardous materials during manufacturing, while WEEE implements standards for proper recycling and disposal. Together, these considerations make D-Link Green firewall products the environmentally responsible choice.
• Ethernet: 10 Gigabit Ethernet ports configurable
• USB: 2 USB ports (reserved)
• Console: a DB-9 RS-232
• Performance Firewall ekrana2 2 Gbit / s
• Performance VPN3: 1 Gbit / s.
• Performance IPS4: 600 Mbit / s
• Performance antivirusa4: 450 Mbit / s
• The number of concurrent sessions: 1500.000
• Number of new sessions (in second): 20,000
• Policy: 6000
• Transparent mode
• NAT, PAT
• Dynamic routing protocols: OSFP
• H.323 NAT Traversal
• Policy on schedule
• Application Layer Gateway
• Active network security
• DHCP server / client
• DHCP Relay
• Policy-based routing
• IEEE 802.1q VLAN: 2048
• VLAN port-based
• IP Multicast: IGMP v3
Virtual Private Network (VPN)
• Encryption (DES)
• Dedicated VPN-tunnels: 5,000
• Server PPTP/L2TP
• Hub and Spoke
• IPSec NAT Travesal
• SSL VPN: The function will be available in the future
• Balancing the outgoing traffic
• Server Load Balancing
• The algorithm of load balancing servers: Round-robin, Weight-based Round-robin, Destination-based, Spill-over
• Redirects traffic channel at break (fail-over)
• Traffic Shaping policy-based
• Guaranteed bandwidth
• The maximum bandwidth
• The bandwidth based on priority
• Dynamic bandwidth allocation
High Availability (HA)
• Redundant WAN link
• Mode Active / Passive
• failure detection device
• Definition of cliff channel
• Synchronize sessions FW / VPN
Intrusion Detection & Prevention System (IDP / IPS)
• Automatic updating of templates
• Protection against attacks DoS, DDoS
• Prevention of attacks via e-mail
• Extended subscription IDP / IPS (optional)
• Blacklist IP (threshold or IDP / IPS)
• The type of HTTP: white / black list URL
• The type of script: Java Cookie, ActiveX, VB
• The type of e-mail: white / black list e-mail
• External database content filtering
• Virus scanning in real time
• Unlimited file size
• Scan a VPN-tunnel
• Compressed files
• Provider signature: Kaspersky
• The number of virus signatures: 12000 *
• Automatic updating of templates
• Internal Power Supply 80 PLUS
• 440 x 400 x 44 mm
• Rack Mounting 19''
• 0 º to 40 º C
• From -20 º to 70 º C
• 5% to 95%, noncondensing
• FCC Class A
• CE Class A
• UL LVD (EN60950-1)
• 310.000 h
* Available with a firmware 2.30.hh used for the actual signatures of viruses at the time of your subscription.
1 Actual performance may vary depending on network conditions and activity services.
2 The maximum firewall performance is based on RFC2544.
3 VPN throughput measured using UDP traffic and packet size of 1420, according to RFC 2544
4 Performance test antivirus and IPS based on the HTTP protocol with an attachment file is 1 MB, running on the IXIA IxLoad. Test is done with many threads through several pairs of ports.
5 Productivity is defined based on firmware 2.27.00 or higher
6 Available when DMZ port is configured as a WAN port
7 Compatible with SFP-Transceiver Modules D-Link: DEM-310GT, DEM-311GT, DEM-312GT2, DEM-314GT, DEM-315GT, DEM-330T, DEM-330R, DEM-331T, DEM-331R, DGS-712