Opnsense A10 Dual & Quad Core Desktop Series DATASHEET
Total Page:16
File Type:pdf, Size:1020Kb
OPNsense A10 Dual & Quad Core Desktop Series All Rights Reserved. [rev.150818] (c) 2018 Deciso B.V., DEC600, DEC610, DEC620, DEC630 The OPNsense A10 Quad Core Desktop secures your network with high-end features such as inline intrusion prevention, virtual private networking, two factor authentication, captive portal and filtering web proxy. The optional high availability setup ensures stable network performance with automatic failover and synchronised states, minimising disruption. Keep your network secure and the good packets flowing. (For A10 dual core model specifications see last page, DEC600 & DEC610) Guard Web Access 3.300Mbps Throughput Filtering (SSL) Proxy 250.000 Packets per Second Captive Portal with Voucher 327Mbps Inline High Speed Up to 128Gb SSD Intrusion Prevention & Offering Sufficient Space for SSL Finger Printing Logging & Reporting Fast Filtering System wide two-factor 35.000 connections P/S authentication. Low Latency ~1.6mS (with Compatible with Google CoDel & Traffic Shaper) Authenticator. Hardware Assisted Encryption 600Mbps IPsec (AES256GCM16) Se#$%&n( Ne+w.k0 DATASHEET Deciso Sales B.V. • +31 187 744 020 • [email protected] • www.deciso.com HARDWARE DUTCH QUALITY - MADE IN THE NETHERLANDS DEC620 & DEC630 DESKTOP APPLIANCES DEC600 & DEC610 (3 ethernet ports) Se#$%&n( Ne+w.k0 Deciso Sales B.V. • +31 187 744 020 • [email protected] • www.deciso.com SOFTWARE VERSATILE - OPEN SOURCE - FULLY FEATURED OPNsense is Deciso’s fast growing open source firewall and security platform released under an Open Source Initiative approved license. It’s rich feature set is combined with the benefits of open and verifiable sources. All features can be used from within the easy to use graphical interface, equipped with a build-in search feature for quick navigation. Protecting your network has never been this easy, utilise the integrated intrusion prevention capable of blacklisting based on SSL fingerprints and the two-factor authentication for safely connecting mobile users. Keep full insight on the traffic flowing trough your firewall at all times, with its advanced Netflow capture, aggregate & reporting tool ‘Insight’. High-end Security Made Easy™ Businesses School networks Protect your business network and secure Limit and share available bandwidth your connections. evenly amongst students and utilise the From the stateful inspection firewall to the category based web filtering to filter inline intrusion detection & prevention unwanted traffic such as adult content and system everything is included for free.Use malicious websites. Its easy to setup as no the traffic shaper to enhance network additional plugins nor packages are performance and prioritise you voice over required. ip above other traffic. Backup your configuration to the cloud automatically, no need for manual backups. Hotels & Campings On the road Hotels and campings usually utilise a Even on the road OPNsense is a great captive portal to allow guests (paid) asset to your business as it offers access to internet for a limited duration. OpenVPN and IPSec VPN solution with Guests need to login using a voucher they road warrior support and two-factor can either buy or obtain for free at the authentication. The easy client exporter reception. OPNsense has a build-in make configuring your OpenVPN SSL captive portal with voucher support and client setup a breeze. can easily create them on the fly. Remote Offices & SOHO Utilise the integrated site to site VPN (IPsec or SSL VPN) to create a secure network connection to and from your remote offices. Enjoy the easy configuration and online searchable documentation with simple how-to type of articles to get you started, quickly. Se#$%&n( Ne+w.k0 Deciso Sales B.V. • +31 187 744 020 • [email protected] • www.deciso.com SOFTWARE FEATURE OVERVIEW • GUI ๏ Integrated rulesets ๏ File Backup • SSH / Console • SSL Blacklists ๏ Cloud Backup Certificates • Feodo Tracker SNMP Stateful firewall ๏ Certificate Authority • Geolite2 Country IP ๏ Monitor & Traps ๏ Filter by • Create or Import CA’s • Emerging Threats ETOpen Diagnostics • Source • Create or Import Certificates ๏ SSL Fingerprinting ๏ Filter reload status • Destination ๏ Let’s Encrypt (Plugin) ๏ Auto rule update using ๏ Firewall Info (pfInfo) • Protocol • Automated (Trusted) CA configurable cron ๏ Top Users (pfTop) • Port 802.1Q VLAN support Captive Portal ๏ Firewall Tables • OS (OSFP) ๏ max 4096 VLAN’s ๏ Typical Applications • Aliases ๏ Limit simultaneous connections on Link Aggregation & Failover • Guest Network • Bogons a per rule base ๏ Failover • Bring Your Own Device (BYOD) ๏ Current Open Sockets ๏ Log matching traffic on a per rule ๏ Load Balance • Hotel & Camping Wifi Access ๏ Show All States bases ๏ Round Robin • Template Management ๏ State Reset ๏ Policy Based Routing ๏ Cisco Ether Channel (FEC) • Multiple Zones ๏ State Summary ๏ Packet Normalisation ๏ 802.3ad LACP ๏ Authenticators ๏ Wake on LAN ๏ Option to disable filter for pure Other Interface types • All available authenticators ๏ ARP Table router mode ๏ Bridged interfaces • None (Splash Screen Only) ๏ DNS Lookup Policy organisation ๏ Generic Tunnel Interface (GIF) ๏ Voucher Manager ๏ NDP Table ๏ Alias Support ๏ Generic Routing Encapsulation • Multiple Voucher Databases ๏ Ping • IP addresses Network Address Translation • Export vouchers to CSV ๏ Packet Capture • Port ranges ๏ Port forwarding ๏ Timeouts & Welcome Back ๏ Test Port • Domain names (FQDN) ๏ 1:1 of ip’s & subnets ๏ Bandwidth Management ๏ Trace route ๏ Interface Groups ๏ Outbound NAT • Use Traffic Shaper Monitoring • Create security zones with equal ๏ NAT Reflection ๏ Portal bypass ๏ Zabbix Agent (Plugin) rules Traffic Shaping • MAC and IP whitelisting ๏ Monit (Plugin) ๏ Rule Category ๏ Limit bandwidth ๏ Real Time Reporting • Proactive System Monitoring • Easy access rule sets ๏ Share bandwidth • Live top IP bandwidth usage Enhanced Reporting Granular control state table ๏ Prioritise traffic • Active Sessions ๏ Network Flow Analyser ‘Insight’ ๏ Adjustable state table size ๏ Rule based matching • Time left • Fully Integrated ๏ On a per rule bases • Protocol • Rest API • Detailed Aggregation • Limit simultaneous client • Source Virtual Private Networks • Graphical Representation connection • Destination ๏ IPsec • Clickable and Searchable • Limit states per host • Port • Site to Site • CVS Exporter • Limit new connections per • Direction • Road Warrior ๏ System Health second IGMP Proxy ๏ OpenVPN • Round Robin Data • Define state timeout ๏ For multicast routing • Site to Site • Selection & Zoom • Define state type Universal Plug & Play • Road Warrior • Exportable ๏ State types ๏ Fully supported • Easy client configuration ๏ Traffic Graph • Keep Dynamic DNS exporter • Live Traffic Monitoring • Sloppy ๏ Selectable form a list ๏ Tinc (Plugin) Network Monitoring • Modulate ๏ Custom • Full mesh routing ๏ Netflow Exporter • Synproxy ๏ RFC 2136 support ๏ ZeroTier (Plugin) • Version 5 & version 9 • None DNS Forwarder • VPN, SDN & SD-WAN • Local for ‘Insight’ ๏ Optimisation options ๏ Host Overrides ๏ PPTP (Legacy) Firmware • Normal ๏ Domain Overrides ๏ LT2P (Legacy) ๏ Support Virtual Installs • High latency DNS Server High Availability • VMware tools (Plugin) • Agressive ๏ Host Overrides ๏ Automatic hardware failover • Xen Guest Utilities (Plugin) • Conservative • A records ๏ Synchronised state table ๏ Easy Upgrade Authentication • MX records ๏ Configuration synchronisation • Reboot warning for base ๏ External Servers ๏ Access Lists Caching Proxy upgrades • LDAP DNS Filter ๏ Multi interface ๏ SSL Flavour selectable • Radius ๏ Supports OpenDNS ๏ Transparent Mode • OpenSSL ๏ Integrated Servers DHCP Server ๏ Support SSL Bump • LibreSSL • Local User Manager ๏ IPv4 & IPv6 ๏ SSL Domain only (easy filtering) ๏ Selectable Package Mirror • Vouchers / Tickets ๏ Relay Support ๏ Access Control Lists ๏ Reinstall Single Package • FreeRadius (Plugin) ๏ BOOTP options ๏ Blacklists ๏ Lock Package (prevents upgrade) Authorisation Multi WAN ๏ Category Based Web-filter ๏ Audit Feature ๏ User Interface ๏ Load balancing ๏ Traffic Management • Check installed packages for • Local User Manager ๏ Failover ๏ Auto sync for remote blacklists known security vulnerabilities Accounting ๏ Aliases ๏ ICAP (supports virus scan engine) ๏ Plugin Support ๏ FreeRadius (Plugin & External) Load Balancer Virus scanning REST API ๏ Vouchers / Tickets ๏ Balance incoming traffic over ๏ External engine support (ICAP) ๏ ACL support 2-Factor Authentication multiple servers ๏ ClamAV (Plugin / C-ICAP) Online Documentation ๏ Supports TOTP Network Time Server Reverse Proxy ๏ Free & Searchable ๏ Google Authenticator ๏ Hardware devices ๏ HAProxy - Load balancer (Plugin) ๏ Support services: • GPS Online Identity Protection • Captive Portal • Pulse Per Second ๏ Tor - Anonymity online (Plugin) • Proxy Intrusion Detection & Prevention Backup & Restore • VPN ๏ Inline Prevention ๏ History & Diff support Se#$%&n( Ne+w.k0 Deciso Sales B.V. • +31 187 744 020 • [email protected] • www.deciso.com SPECIFICATIONS PERFORMANCE & FEATURES DEC600 DEC610 DEC620 DEC630 Hardware Specifications GbE RJ45 Ports [ 10/100/1000Mbps ] 3 3 4 4 USB Ports 1 1 1 1 Console Port 1 1 1 1 Internal Storage 16GB 128GB 16GB Flash 128GB SSD Memory 4GB DDR3 4GB DDR3 4GB DDR3 4GB DDR3 CPU Cores 2 (1.0Ghz) 2 (1.0Ghz) 4 (1.6Ghz) 4 (1.6Ghz) Virtual Interfaces (802.1q VLANS)1 4093 4093 4093 4093 System Performance Firewall Throughput 900 Mbps 900 Mbps 3300 Mbps 3300 Mbps Firewall Packets Per Second 75000 75000 250000 250000 Firewall Port to Port Throughput 850Mbps 850Mbps 941Mbps