3Com X5 Скачать руководство пользователя страница 3

3COM

®

X5 AND X506 UNIFIED SECURITY PLATFORMS

IP MULTICAST WITH VPN

The 3Com X5 and X506 platforms perform the necessary prioritization for real-time applications such as IP
telephony and video conferencing with an innovative tunneling approach that secures the traffic in both
directions inside and outside VPN tunnels. 

Organizations can use this capability to deliver next-generation services such as distance learning and multi-
media conferencing across the network using IP multicast in conjunction with VPN—two technologies which
up until now have been mutually exclusive. Prioritized traffic shaping within a VPN tunnel can provide cost
savings on long distance phone calls and leverages centralized business applications.

Support for Protocol Independent Multicast - Dense Mode (PIM-DM) routing between sites over an IPSec VPN
enables next generation applications such as distance-based learning and real-time training and conferencing
to be realized.

APPLICATION BLOCKING AND WEB FILTERING

The platforms enforce usage policies by blocking or rate limiting applications such as instant messaging
(IM) and peer-to-peer file sharing that are not essential to business and can waste bandwidth.

3Com offers an optional integrated Web content filter subscription service that limits employee access to
objectionable or unacceptable websites that could lower productivity or cause legal problems. This protection
is kept current because content is filtered through a continually updated database.

FLEXIBLE SECURITY ZONE CONTAINMENT

The flexible architecture of the 3Com X5 and X506 Unified Security Platforms allows the creation of multiple
security zones—wired/wireless and student/teacher LANs and DMZs, for example—for greater IPS and fire-
wall control of resources and networks. Traffic between these security zones can then be fully inspected and
prioritized using stateful packet inspection for access control and IPS for security control.

STATEFUL PACKET INSPECTION FIREWALL

3Com X5 and X506 platforms are equipped with a stateful packet inspection firewall which provides access
control and also recognizes prioritized packet flows and helps maintain QoS. This firewall function replaces
router- or switch-based access control lists that can lower performance in those devices.

SECURITY MANAGEMENT SYSTEM

In situations where there are multiple X5, X506 and other 3Com TippingPoint-based devices, the optional
3Com TippingPoint Security Management System (SMS) offers comprehensive management capabilities.

Delivered as a rack-mount appliance, SMS enables administrators to monitor, configure, diagnose and create
reports for TippingPoint installations. With SMS, administrators can create IPS and firewall profiles, implement
VPNs, manage bandwidth, set content filters and perform other tasks from a central location. SMS comes with
factory-installed software for simple installation, and is the only management system that provides high-avail-
ability HA/failover capabilities.

QUARANTINE PROTECTION

Often the most dangerous security threats emanate from within the corporate network. These threats may
include worms from traveling laptops and visitor/guest PCs, or installation of unapproved applications such
as peer-to-peer file sharing that can carry spyware.

X5 and X506 devices configured with SMS can automatically remove an infected PC from the network, or
“move” the PC into quarantine VLAN where it can be safely repaired before being allowed back on the net-
work. Quarantine protection will isolate infected devices from the network without the need for PC software
agents, and transparently redirect web requests so users know they are infected or running applications
which do not conform to corporate policies. 

3

KEY BENEFITS

(CONTINUED)

Содержание X5

Страница 1: ... means of management 3Com X5 and X506 Unified Security Platforms deliver unprecedented threat protection for organizations with several branch offices or numerous teleworkers helping prevent business disruptions revenue loss and damage to an organization s reputation caused by security breaches Built on the award winning 3Com TippingPoint Intrusion Protection System IPS architecture the X5 and X50...

Страница 2: ...ress security within a VPN connection 3Com Unified Security platforms take a uniquely com prehensive approach to VPN based security by providing the ability to look inside VPN IPSec tunnels for threats This thorough inspection pre vents propagation of exploits and other malware between sites and can also be used to provide protection from security risks that occur when laptop users terminate VPN c...

Страница 3: ...d networks Traffic between these security zones can then be fully inspected and prioritized using stateful packet inspection for access control and IPS for security control STATEFUL PACKET INSPECTION FIREWALL 3Com X5 and X506 platforms are equipped with a stateful packet inspection firewall which provides access control and also recognizes prioritized packet flows and helps maintain QoS This firew...

Страница 4: ...t to be used as a secure connectivity mechanism for IPSec VPN site to site connections and remote user connectivity Ability to apply IPS inside VPN tunnels Offers complete security protection ensuring that remote VPN clients or branch offices cannot be used to propagate threats into the LAN APPLICATION PRIORITIZATION AND OPTIMIZATION Single high performance resilient Reduces the number of devices ...

Страница 5: ...the risk of hackers MAC address and no changes needed discovering devices on the network to network configuration High speed low latency operation Enables devices to be deployed without impacting performance delivers high quality convergence services Office LAN Clients IP Phones Voice zone Wireless zone Work zone Guest zone DMZ zone PC 3Com X5 3Com 3108 Cordless Phone Server 3Com Wireless 7760 Acc...

Страница 6: ...6 PWR Voice zone Wireless zone Work zone Guest zone DMZ zone 3Com Switch 4500 PWR 3CR17571 91 SuperStack 3 Switch 4500 PWR 26 Port 3Com Wireless LAN Switch WX1200 3CRWX120695A Wireless LAN Switch WX1200 3CRWX440095A Wireless LAN Controller WX4400 PC VPN tunnel VPN tunnel TippingPoint SMS 3Com X5 3Com X5 3Com VCX V6000 V6000 POWER FXO FXS CPU CM 3Com VCX V6000 FXO 3Com VCX V7000 Server 3Com 3108 Co...

Страница 7: ...outer interfaces 6 IP address groups X5 25 X506 200 Static routes X5 100 X506 500 PPPoE L2TP PPTP IP assignment DHCP client IEEE 802 1Q VLAN support Internal multi scope DHCP server DHCP relay over VPN GRE tunneling Dynamic routing RIP v1 and 2 IP multicast routing PIM DM IGMP v1 and 2 SYSTEM AND ADMINISTRATION Dual box high availability Web interface via HTTPS Command line interface via console t...

Страница 8: ...TPX5 U 96 unlimited user license 3Com X506 Unified Security Platform 3CRX506 96 unlimited user license Product Options 3Com X5 Digital Vaccine Gold Attack Filter Update Service 3CTPX5 DVGOLD One year of Digital Vaccine IPS updates web content filtering telephone technical support advance hardware replacement and software updates 3Com X506 Digital Vaccine Gold Attack Filter Update Service 3CX500 DV...

Отзывы: