Dell Sonicwall Supermassive Next-Generation Firewall Series
Total Page:16
File Type:pdf, Size:1020Kb
Dell SonicWALL SuperMassive Next-Generation Firewall Series Network security The Dell™ SonicWALL™ SuperMassive™ limitations. The RFDPI engine delivers Series is Dell’s Next-Generation Firewall full content inspection to eliminate (NGFW) platform designed for large threats before they enter the network networks to deliver scalability, reliability and provides protection against millions and deep security at multi-gigabit of unique malware variants without file speeds with near zero latency. size, performance or latency limitations. SuperMassive E10000 Series The RFDPI engine also provides full Built to meet the needs of enterprise, inspection of SSL-encrypted tra!c as government, university, and service well as non-proxyable applications provider deployments, the SuperMassive enabling complete protection Series is ideal for securing enterprise regardless of transport or protocol. networks, data centers and service SuperMassive 9000 Series providers. Application tra!c analytics allow for the identification of productive and Combining its massively multi-core unproductive application tra!c in real Ŕ$PNQMFUFUISFBUQSPUFDUJPO architecture and Dell SonicWALL’s time which can then be controlled JODMVEJOHIJHIQFSGPSNBODF patented* Reassembly-Free Deep through powerful application-level JOUSVTJPOQSFWFOUJPOBOEMPX ® Packet Inspection (RFDPI) technology, policies. Application control can be MBUFODZNBMXBSFQSPUFDUJPO the SuperMassive E10000 and 9000 exercised on both a per-user and Ŕ4VQFSJPSHSBOVMBSBQQMJDBUJPO Series deliver industry-leading application per-group basis, along with schedules JOUFMMJHFODF DPOUSPMBOE control, intrusion prevention, malware and exception lists. All application, WJTVBMJ[BUJPO protection and SSL inspection at multi- intrusion prevention, and malware gigabit speeds. The SuperMassive Series signatures are constantly updated Ŕ'VMMJOTQFDUJPOPG44-FODSZQUFE is designed with power, space, and by the Dell SonicWALL Threats Research USBťDXJUIPVUPWFSIFBE MBUFODZ cooling (PSC) in mind, providing the Team. Additionally, SonicOS, an BOENFNPSZUISBTIJOHBTTPDJBUFE leading Gbps/Watt NGFW in the advanced purpose-built operating XJUITPDLFUCBTFE44-QSPYJFT industry for application control and system, provides integrated tools that Ŕ.BTTJWFMZTDBMBCMFNVMUJDPSF threat prevention. allow for custom application BSDIJUFDUVSFEFTJHOFEGPS identification and control. (CQTJOGSBTUSVDUVSF The Dell SonicWALL RFDPI engine scans every byte of every packet across all The design of the SuperMassive ports, delivering full content inspection Series firewalls provides near-linear of the entire stream while providing high performance increases and scales up to performance and low latency. This 96 cores of processing power to deliver technology is superior to outdated up to 30 Gbps of threat prevention and proxy designs that reassemble content 30 Gbps of application inspection and using sockets bolted to anti-malware control. The SuperMassive E10000 programs that are plagued with Series is field upgradeable, future- ine!ciencies and overhead of socket proofing the security infrastructure memory thrashing that leads to high investment as network bandwidth and latency, low performance and file size security requirements increase. *U.S. Patents 7,310,815; 7,600,257; 7,738,380; 7,835,361 Series lineup redundant fan modules, and massively 1 GbE management interfaces, with an The Dell SonicWALL SuperMassive scales up to 96 processing cores. expansion port for an additional 2 x E10000 Series chassis includes 6 x 10-GbE SFP+ interfaces (future 10-GbE SFP+ and 16 x 1-GbE SFP The Dell SonicWALL SuperMassive release). The 9000 Series features dual ports, redundant 850W AC power 9000 Series features 4 x 10-GbE SFP+, hot swappable fan modules and supplies, hot swappable dual 8 x 1-GbE SFP, 8 x 1-GbE Copper and power supplies. SuperMassive E10000 Series 80 GB 6 x 10-GbE 16 x LCD display LCD controls SSD drive SFP+ ports 1-GbE SFP ports Hot swappable redundant 850W power supplies Module slot fan Console Future 1-GbE Dual Status LED port use management USB ports indicators Two hot swappable dual redundant fan modules interface SuperMassive 9000 Series LCD Dual 4 x 10-GbE 8 x 1-GbE 8 x 1-GbE Expansion bay for Dual hot controls USB ports SFP+ ports SFP ports ports future use swappable fans LCD Console 1 GbE management display port interface Two hot swappable redundant power supplies $BQBCJMJUZ & & & Processing cores 24 32 32 24 48 96 Firewall throughput 15 Gbps 20 Gbps 20 Gbps 10 Gbps 20 Gbps 40 Gbps Application intelligence 5 Gbps 8 Gbps 9.7 Gbps 7.5 Gbps 15 Gbps 30 Gbps throughput IPS throughput 5 Gbps 8 Gbps 9.7 Gbps 7.5 Gbps 15 Gbps 30 Gbps Anti-malware 3.5 Gbps 4.5 Gbps 5 Gbps 3 Gbps 6 Gbps 12 Gbps throughput Maximum connections 1.25 M 1.25 M 1.5 M 3 M 6 M 12 M %FQMPZNFOU.PEFT & & & L2 Bridge, Transparent Mode Yes Yes Yes Yes Yes Yes Wire Mode Yes Yes Yes Yes Yes Yes Gateway/NAT Mode Yes Yes Yes Yes Yes Yes Tap Mode Yes Yes Yes Yes Yes Yes Transparent Bridge Mode Yes Yes Yes Yes Yes Yes 2 Reassembly-Free Deep and decryption in order to neutralize databases until it encounters a state of Packet Inspection engine advanced evasion techniques that attack, or other “match” event, at which seek to confuse detection engines point a pre-set action is taken. In most The Dell SonicWALL Reassembly-Free and sneak malicious code into the cases, the connection is terminated Deep Packet Inspection (RFDPI) engine network. Once a packet undergoes and proper logging and notification provides superior threat protection the necessary pre-processing, events are created. However, the and application control without including SSL decryption, it is analyzed engine can also be configured compromising performance. This against a single proprietary memory for inspection only or, in case of patented engine relies on streaming representation of three signature application detection, to provide Layer tra!c payload inspection in order to databases: intrusion attacks, malware 7 bandwidth management services detect threats at Layers 3-7. The RFDPI and applications. The connection state for the remainder of the application engine takes network streams through is then advanced to represent the stream as soon as the application is extensive and repeated normalization position of the stream relative to these identified. Traitement des paquets par assemblage Processus RFDPI Désassemblage Proxy Analyse des paquets Trafic Trafic Tra!c entrant Trafic sortant entrant sortant Durée de filtrage Capacité de Durée de filtrage Capacité de Si le proxy est plein ou le contenu trop !ltrage !ltrage volumineux, les fichiers contournent l'analyse Analyse des paquets sans réassemblage, sans proxy ni limitation de la taille des contenus Architecture concurrente Architecture Dell SonicWALL Extensible architecture for sophisticated detection techniques. approach delivers extremely high new extreme scalability and Another aspect of the platform design session establishment rates (new conn/ performance is the unique ability to establish new sec) while Deep Packet Inspection is connections on any core in the system, enabled—a key metric that is often a The RFDPI engine is designed from the providing ultimate scalability and the bottleneck for data center ground up with an emphasis on ability to deal with tra!c spikes. This deployments. providing security scanning at a high level of performance, to match both the inherently parallel and ever- growing nature of network tra!c. When combined with 24-, 32-, 48- or 96-core processor systems, this parallelism-centric software architecture scales up perfectly to address the demands of deep packet inspection at high tra!c loads. The 240 GbE 16 x 1 GbE SFP SM Interconnect SuperMassive platform relies on processors that, unlike x86, are optimized for packet, crypto and network processing while retaining flexibility and programmability in the 6 x 10 GbE SFP+ field—a weak point for ASICs systems. This flexibility is essential when new code and behavior updates are 96 Cores necessary to protect against new attacks that require updated and more 3 Security and protection are designed to protect against wide The dedicated, in-house Dell classes of attacks, covering up to tens SonicWALL Threats Research Team of thousands of individual threats with works on researching and developing a single signature. In addition to the countermeasures to deploy to the countermeasures on the appliance, SuperMassive firewalls also have access firewalls in the field for up-to-date Protection Recueil protection. The team leverages more to the Dell SonicWALL CloudAV Service, than one million sensors across the which extends the onboard signature Création Classification globe for malware samples, and for intelligence with more than twelve telemetry feedback on the latest threat million signatures, and growing. This information, which in turn is fed into CloudAV database is accessed via a the intrusion prevention, anti-malware proprietary light-weight protocol by and application detection capabilities. the firewall to augment the inspection Dell SonicWALL NGFW customers done on the appliance. With Geo-IP with the latest security capabilities are and botnet filtering capabilities, Dell provided continuously updated threat SonicWALL NGFWs are able to block protection around the clock, with new tra!c from dangerous domains or updates taking e"ect immediately entire geographies in order to reduce without reboots or interruptions. The the risk profile of the network. signatures resident on the appliances Application intelligence and control