SlideShare a Scribd company logo
1 of 28
Download to read offline
Stonesoft
version
5.4
NEW FEATURES
STONESOFT 5.4
Release highlights

 New transformable
 Security Engine
 New visualizations and
 evasion awareness
Security Engine
Security Engine



 FW      NGN IPS
  2001    2012    2004
Security Engine Roles



        NGN
         IPS
         FW
         L2FW
         VPN
New Statistics and
Visualizations
SEE THE ANOMALIES IN LOGS…
Evasion awareness
 ”Anomaly” log field available
 that shows the detected
 atomic evasions
 ”Top Anomalies” statistics
UNDERSTAND YOUR ENVIRONMENT
Log Visualizations
 See which users use what
 applications as a single
 diagram
 What services and situations
 are used and by whom?
 Log Analysis mode can
 handle up to 100 000
 (prefiltered) log events
LINK/TUNNEL USAGE INFO EMBEDDED TO…
Status diagrams
 See the relative amount of
 traffic flowing in each VPN
 tunnel or Netlink
ENHANCED REPORTING
Statistics Sections
 Ability to reuse Statistics
 Sections
 A lot of out-of-box
 sections available
 Ability to create ad-hoc
 filters for Reports
SMC

Enhancements
REGULATORY COMPLIANCE
Audit Log
Enhancements
 Element snapshots
 Audit data syslog
 forwarding
 More granular auditing
MORE CONVENIENT TROUBLESHOOTING
Traffic Capture
 It is now possible to take
 tcpdump directly from
 Management Client user       tcpdump
 interface
 Makes troubleshooting
 easier for customers and
 Stonesoft Support
MANAGEMENT UP TO 2000 NODES
Better SMC Scalability
                          Nodes
 One Management
 Server can serve up to
 2000 nodes                2000
 Improved policy upload
 performance
                           1000


                                  5.3   5.4   Version
SMC IN CHINESE, RUSSIAN, SPANISH, …
Localization Support
 Most important SMC labels
 are parameterized
 Introducing a new SMC
 language is a matter of
 translating one text file
 containing about 5000+
 labels/messages
NEW USAGE OF GEOIP DETECTION…
Country flags in logs
 See the country flags directly
 in Log records table
 Useful information for anomaly
 detection
 Helps you to visually identify
 which log entries are related
Other SMC
Enhancements
Internal User Database replication to separate
administrative Domains
Interface comments visible in statistics
Policy usability enhancements
LEEF forwarding/reception support
NGN

Enhancements
VPN WITH DYNAMIC ROUTING AVAILABLE
Advanced Routing
 Tunneling interface
 support with Route-Based
 VPN
 Dynamic routing over
 Route based VPN
ABILITY TO IMPORT AND USE…
Snort Signatures
 Snort signatures can be
 automatically translated into
 Stonesoft custom fingerprints
BETTER DEEP INSPECTION WITH…
File context
 Makes possible to inspect
 directly the transferred files
 More accurate inspection
DEEPER INTEGRATION
Auth. Server & Firewall
 Easier way to use
 Authentication Server for VPN
 and possibly also for wireless
 access point authentication      AS   FW
 Multi-Link capable channel
 between the Authentication
 Server and Firewall
MORE PROTOCOLS SUPPORTED
Improved Application
Identification
 Port independent access
 control and application
 identification also for non-web
 traffic
 Amount of Applications
 increasing all the time.
Other NGN
Enhancements
Increased small packet throughput with big
appliances
HTTP IPv6 inspection in L3
SSL
    VPN
          Version 1.5.100

Enhancements
BETTER ROBUSTNESS AND SCALABILITY
Integrated Directory
Service
                                        USERS
 Provides better resilience for
 userbase without the need to
 have external Directory
 Services

                                  SSL       SSL
                                  VPN           VPN
IMPROVED PLATFORM SUPPORT
Access client for Linux,
and OS X
 Native client for          SSL
                            VPN

 Linux and Mac OS X
Thanks!

More Related Content

What's hot

[Webinar] End User Experience Monitoring with Site24x7
[Webinar] End User Experience Monitoring with Site24x7[Webinar] End User Experience Monitoring with Site24x7
[Webinar] End User Experience Monitoring with Site24x7Site24x7
 
Direct access for dummies
Direct access for dummiesDirect access for dummies
Direct access for dummiesAlex de Jong
 
radius dhcp dot1.x (802.1x)
radius dhcp dot1.x (802.1x)radius dhcp dot1.x (802.1x)
radius dhcp dot1.x (802.1x)rinnocente
 
DirectAccess, do’s and don’ts
DirectAccess, do’s and don’tsDirectAccess, do’s and don’ts
DirectAccess, do’s and don’tskieranjacobsen
 
Cisco Spark Hybrid Service Design Guide by PlanetComm
Cisco Spark Hybrid Service Design Guide by PlanetCommCisco Spark Hybrid Service Design Guide by PlanetComm
Cisco Spark Hybrid Service Design Guide by PlanetCommNarin Fungsatit
 
Firewall Analyzer 6 - Highlights
Firewall Analyzer 6 - HighlightsFirewall Analyzer 6 - Highlights
Firewall Analyzer 6 - HighlightsRagavan Seetharaman
 
[Webinar] Site24x7 - The All-in-One Monitoring Solution for DevOps & IT
[Webinar] Site24x7 - The All-in-One Monitoring Solution for DevOps & IT[Webinar] Site24x7 - The All-in-One Monitoring Solution for DevOps & IT
[Webinar] Site24x7 - The All-in-One Monitoring Solution for DevOps & ITSite24x7
 
AAA & RADIUS Protocols
AAA & RADIUS ProtocolsAAA & RADIUS Protocols
AAA & RADIUS ProtocolsPeter R. Egli
 
Services @ vfm
Services @ vfmServices @ vfm
Services @ vfmvfmindia
 
Application Performance Monitoring (APM)
Application Performance Monitoring (APM)Application Performance Monitoring (APM)
Application Performance Monitoring (APM)Site24x7
 
Site24x7 Cloud Monitoring
Site24x7 Cloud MonitoringSite24x7 Cloud Monitoring
Site24x7 Cloud MonitoringSite24x7
 
Crear un centro de datos virtual en AWS
Crear un centro de datos virtual en AWSCrear un centro de datos virtual en AWS
Crear un centro de datos virtual en AWSAmazon Web Services
 
Evaluating Network and Security Devices
Evaluating Network and Security DevicesEvaluating Network and Security Devices
Evaluating Network and Security Devicesponealmickelson
 
802 11 3
802 11 3802 11 3
802 11 3rphelps
 
Fiddler web testing tool
Fiddler web testing toolFiddler web testing tool
Fiddler web testing toolHimaniChauhan
 
NetMonitor - Network Monitoring Solution
NetMonitor - Network Monitoring SolutionNetMonitor - Network Monitoring Solution
NetMonitor - Network Monitoring SolutionGautam Ganguly
 
Consolidating DNS with Amazon Toute 53 - Pop-up Loft Tel Aviv
Consolidating DNS with Amazon Toute 53 - Pop-up Loft Tel AvivConsolidating DNS with Amazon Toute 53 - Pop-up Loft Tel Aviv
Consolidating DNS with Amazon Toute 53 - Pop-up Loft Tel AvivAmazon Web Services
 
Vfm packetshaper presentation
Vfm packetshaper presentationVfm packetshaper presentation
Vfm packetshaper presentationvfmindia
 

What's hot (20)

[Webinar] End User Experience Monitoring with Site24x7
[Webinar] End User Experience Monitoring with Site24x7[Webinar] End User Experience Monitoring with Site24x7
[Webinar] End User Experience Monitoring with Site24x7
 
Direct access for dummies
Direct access for dummiesDirect access for dummies
Direct access for dummies
 
radius dhcp dot1.x (802.1x)
radius dhcp dot1.x (802.1x)radius dhcp dot1.x (802.1x)
radius dhcp dot1.x (802.1x)
 
Dean – first draft
Dean – first draftDean – first draft
Dean – first draft
 
DirectAccess, do’s and don’ts
DirectAccess, do’s and don’tsDirectAccess, do’s and don’ts
DirectAccess, do’s and don’ts
 
Cisco Spark Hybrid Service Design Guide by PlanetComm
Cisco Spark Hybrid Service Design Guide by PlanetCommCisco Spark Hybrid Service Design Guide by PlanetComm
Cisco Spark Hybrid Service Design Guide by PlanetComm
 
OpUtils Free training
OpUtils Free training OpUtils Free training
OpUtils Free training
 
Firewall Analyzer 6 - Highlights
Firewall Analyzer 6 - HighlightsFirewall Analyzer 6 - Highlights
Firewall Analyzer 6 - Highlights
 
[Webinar] Site24x7 - The All-in-One Monitoring Solution for DevOps & IT
[Webinar] Site24x7 - The All-in-One Monitoring Solution for DevOps & IT[Webinar] Site24x7 - The All-in-One Monitoring Solution for DevOps & IT
[Webinar] Site24x7 - The All-in-One Monitoring Solution for DevOps & IT
 
AAA & RADIUS Protocols
AAA & RADIUS ProtocolsAAA & RADIUS Protocols
AAA & RADIUS Protocols
 
Services @ vfm
Services @ vfmServices @ vfm
Services @ vfm
 
Application Performance Monitoring (APM)
Application Performance Monitoring (APM)Application Performance Monitoring (APM)
Application Performance Monitoring (APM)
 
Site24x7 Cloud Monitoring
Site24x7 Cloud MonitoringSite24x7 Cloud Monitoring
Site24x7 Cloud Monitoring
 
Crear un centro de datos virtual en AWS
Crear un centro de datos virtual en AWSCrear un centro de datos virtual en AWS
Crear un centro de datos virtual en AWS
 
Evaluating Network and Security Devices
Evaluating Network and Security DevicesEvaluating Network and Security Devices
Evaluating Network and Security Devices
 
802 11 3
802 11 3802 11 3
802 11 3
 
Fiddler web testing tool
Fiddler web testing toolFiddler web testing tool
Fiddler web testing tool
 
NetMonitor - Network Monitoring Solution
NetMonitor - Network Monitoring SolutionNetMonitor - Network Monitoring Solution
NetMonitor - Network Monitoring Solution
 
Consolidating DNS with Amazon Toute 53 - Pop-up Loft Tel Aviv
Consolidating DNS with Amazon Toute 53 - Pop-up Loft Tel AvivConsolidating DNS with Amazon Toute 53 - Pop-up Loft Tel Aviv
Consolidating DNS with Amazon Toute 53 - Pop-up Loft Tel Aviv
 
Vfm packetshaper presentation
Vfm packetshaper presentationVfm packetshaper presentation
Vfm packetshaper presentation
 

Viewers also liked

Stonesoft roadmap 2012 2013 - antti kuvaja
Stonesoft roadmap 2012 2013 - antti kuvajaStonesoft roadmap 2012 2013 - antti kuvaja
Stonesoft roadmap 2012 2013 - antti kuvajaStonesoft
 
Ctab intro juha kivikoski
Ctab intro   juha kivikoskiCtab intro   juha kivikoski
Ctab intro juha kivikoskiStonesoft
 
Mpltr crazy deal_us
Mpltr crazy deal_usMpltr crazy deal_us
Mpltr crazy deal_usDoug Peters
 
Anti evasion and evader - klaus majewski
Anti evasion and evader - klaus majewskiAnti evasion and evader - klaus majewski
Anti evasion and evader - klaus majewskiStonesoft
 
Fast and Free SSO: A Survey of Open-Source Solutions to Single Sign-On
Fast and Free SSO: A Survey of Open-Source Solutions to Single Sign-OnFast and Free SSO: A Survey of Open-Source Solutions to Single Sign-On
Fast and Free SSO: A Survey of Open-Source Solutions to Single Sign-Onelliando dias
 
OAuth In The Real World : 10 actual implementations you can't guess
OAuth In The Real World : 10 actual implementations you can't guessOAuth In The Real World : 10 actual implementations you can't guess
OAuth In The Real World : 10 actual implementations you can't guessMehdi Medjaoui
 

Viewers also liked (7)

Stonesoft roadmap 2012 2013 - antti kuvaja
Stonesoft roadmap 2012 2013 - antti kuvajaStonesoft roadmap 2012 2013 - antti kuvaja
Stonesoft roadmap 2012 2013 - antti kuvaja
 
Ctab intro juha kivikoski
Ctab intro   juha kivikoskiCtab intro   juha kivikoski
Ctab intro juha kivikoski
 
Mpltr crazy deal_us
Mpltr crazy deal_usMpltr crazy deal_us
Mpltr crazy deal_us
 
Anti evasion and evader - klaus majewski
Anti evasion and evader - klaus majewskiAnti evasion and evader - klaus majewski
Anti evasion and evader - klaus majewski
 
Presentation
PresentationPresentation
Presentation
 
Fast and Free SSO: A Survey of Open-Source Solutions to Single Sign-On
Fast and Free SSO: A Survey of Open-Source Solutions to Single Sign-OnFast and Free SSO: A Survey of Open-Source Solutions to Single Sign-On
Fast and Free SSO: A Survey of Open-Source Solutions to Single Sign-On
 
OAuth In The Real World : 10 actual implementations you can't guess
OAuth In The Real World : 10 actual implementations you can't guessOAuth In The Real World : 10 actual implementations you can't guess
OAuth In The Real World : 10 actual implementations you can't guess
 

Similar to Stonesoft 5.4 release highlights new security engine features

Manageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An InsightManageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An InsightSai Sundhar Padmanabhan
 
OVNC 2015-Enabling Software-Defined Transformation of Service Provider Networks
OVNC 2015-Enabling Software-Defined Transformation of Service Provider NetworksOVNC 2015-Enabling Software-Defined Transformation of Service Provider Networks
OVNC 2015-Enabling Software-Defined Transformation of Service Provider NetworksNAIM Networks, Inc.
 
Acclerating SDN and NFV Deployments with Spirent
Acclerating SDN and NFV Deployments with SpirentAcclerating SDN and NFV Deployments with Spirent
Acclerating SDN and NFV Deployments with SpirentMalathi Malla
 
Banv meetup 04162014
Banv meetup 04162014Banv meetup 04162014
Banv meetup 04162014ozkan01
 
Cisco Sona
Cisco SonaCisco Sona
Cisco Sonajayconde
 
Asg V7 4 Whats New
Asg V7 4 Whats NewAsg V7 4 Whats New
Asg V7 4 Whats Newpjanicek
 
Colubris Basic Customer Presentation
Colubris Basic Customer PresentationColubris Basic Customer Presentation
Colubris Basic Customer Presentationdaten
 
Introduction to NBL
Introduction to NBLIntroduction to NBL
Introduction to NBLFei Ji Siao
 
Ugif 04 2011 informix fug-paris
Ugif 04 2011   informix fug-parisUgif 04 2011   informix fug-paris
Ugif 04 2011 informix fug-parisUGIF
 
Service Delivery Networking for Next-Gen Infrastructures
Service Delivery Networking for Next-Gen InfrastructuresService Delivery Networking for Next-Gen Infrastructures
Service Delivery Networking for Next-Gen InfrastructuresF5 Networks
 
09 (IDNOG02) Services SDN & NFV Delivering more with less by Mochammad Irzan
09 (IDNOG02) Services SDN & NFV Delivering more with less by Mochammad Irzan09 (IDNOG02) Services SDN & NFV Delivering more with less by Mochammad Irzan
09 (IDNOG02) Services SDN & NFV Delivering more with less by Mochammad IrzanIndonesia Network Operators Group
 
Wx Customer Preso
Wx Customer PresoWx Customer Preso
Wx Customer Presofaiiqb
 
Aceleracion de aplicacione 2
Aceleracion de aplicacione 2Aceleracion de aplicacione 2
Aceleracion de aplicacione 2jfth
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrailnvirters
 

Similar to Stonesoft 5.4 release highlights new security engine features (20)

Manageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An InsightManageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An Insight
 
OVNC 2015-Enabling Software-Defined Transformation of Service Provider Networks
OVNC 2015-Enabling Software-Defined Transformation of Service Provider NetworksOVNC 2015-Enabling Software-Defined Transformation of Service Provider Networks
OVNC 2015-Enabling Software-Defined Transformation of Service Provider Networks
 
Acclerating SDN and NFV Deployments with Spirent
Acclerating SDN and NFV Deployments with SpirentAcclerating SDN and NFV Deployments with Spirent
Acclerating SDN and NFV Deployments with Spirent
 
Banv meetup 04162014
Banv meetup 04162014Banv meetup 04162014
Banv meetup 04162014
 
Cisco Sona
Cisco SonaCisco Sona
Cisco Sona
 
ICC Networking Link Series unified controller solution
ICC Networking Link Series unified controller solutionICC Networking Link Series unified controller solution
ICC Networking Link Series unified controller solution
 
ICC Networking Link Series unified controller solution
ICC Networking Link Series unified controller solutionICC Networking Link Series unified controller solution
ICC Networking Link Series unified controller solution
 
Iuwne10 S03 L04
Iuwne10 S03 L04Iuwne10 S03 L04
Iuwne10 S03 L04
 
Asg V7 4 Whats New
Asg V7 4 Whats NewAsg V7 4 Whats New
Asg V7 4 Whats New
 
Colubris Basic Customer Presentation
Colubris Basic Customer PresentationColubris Basic Customer Presentation
Colubris Basic Customer Presentation
 
Introduction to NBL
Introduction to NBLIntroduction to NBL
Introduction to NBL
 
TeraVM_overview_021115
TeraVM_overview_021115TeraVM_overview_021115
TeraVM_overview_021115
 
TeraVM_overview
TeraVM_overviewTeraVM_overview
TeraVM_overview
 
F5 TMOS v13.0
F5 TMOS v13.0F5 TMOS v13.0
F5 TMOS v13.0
 
Ugif 04 2011 informix fug-paris
Ugif 04 2011   informix fug-parisUgif 04 2011   informix fug-paris
Ugif 04 2011 informix fug-paris
 
Service Delivery Networking for Next-Gen Infrastructures
Service Delivery Networking for Next-Gen InfrastructuresService Delivery Networking for Next-Gen Infrastructures
Service Delivery Networking for Next-Gen Infrastructures
 
09 (IDNOG02) Services SDN & NFV Delivering more with less by Mochammad Irzan
09 (IDNOG02) Services SDN & NFV Delivering more with less by Mochammad Irzan09 (IDNOG02) Services SDN & NFV Delivering more with less by Mochammad Irzan
09 (IDNOG02) Services SDN & NFV Delivering more with less by Mochammad Irzan
 
Wx Customer Preso
Wx Customer PresoWx Customer Preso
Wx Customer Preso
 
Aceleracion de aplicacione 2
Aceleracion de aplicacione 2Aceleracion de aplicacione 2
Aceleracion de aplicacione 2
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
 

Stonesoft 5.4 release highlights new security engine features