GRIDtoday Logo AMD

DAILY NEWS AND INFORMATION FOR THE GLOBAL GRID COMMUNITY / MAY 5, 2003: VOL. 2 NO. 18

( Previous Article )   ( Table of Contents )   ( Next Article )

Breaking News - Security:

New Watchguard Firewall/VPN Offers EAL4 Availability

The new high performance, highly scalable WatchGuard Firebox V200 multi-gigabit firewall/VPN appliance, now available from Wick Hill, is the first application specific integrated circuit (ASIC) firewall device to provide EAL4 availability. This makes it suitable for a wide range of enterprises and larger organisations, including government, NGOs, major financial institutions and the health sector.

The Firebox V200, now WatchGuard's top of the line, high-performance Firebox Vclass security solution, is designed to eliminate the need for multiple appliances in environments requiring multi-gigabit throughput. It provides a cost-effective, easy-to-implement security solution, delivering a combination of performance, functionality and value.

Based on WatchGuard's intelligent custom security ASIC architecture, the Firebox V200 delivers 2 Gbps firewall throughput and 1.1 Gbps 3DES VPN throughput, supports up to 40,000 VPN tunnels and manages 500,000 sessions concurrently.

The Firebox V200 effectively doubles network throughput by allowing two like-model systems to pass traffic simultaneously, while a failover capability provides transparent transition to another system in the event of a failure. It also provides greater flexibility by enabling enterprises to set up virtual firewalls for individual departments, business partners or employees.

ASIC Architecture

The Firebox V200, like the entire Firebox Vclass line, is based on WatchGuard's intelligent security ASIC architecture that is designed to eliminate system bottlenecks, increase performance and scalability, improve network security and control, and adapt quickly to the changing needs of a rapidly-evolving market.

Most firewall and VPN solutions today -- even those using traditional first generation security ASIC technology -- use the host CPU and system bus for operations such as firewall policy enforcement, Network Address Translation (NAT), load balancing, packet classification and look ups, which can have a significant impact on performance in real-world environments. WatchGuard's Vclass products employ a "cut-through architecture" that bypasses the system bus by using embedded RISC processors built into the ASIC, to provide:

  • Up to 2 Gbps of firewall throughput 40,000 VPN tunnels 500,000 simultaneous sessions Multi-tenant support for advance VLAN tagging and user domains
  • Advanced routing protocols such as OSPF Server load balancing with six different algorithms for up to 16 servers Advanced load sharing and fail over/redundancy

The four embedded RISC processors in the intelligent security ASIC can be programmed with additional functions such as packet classification, load balancing and routing, adapting to emerging business requirements while a first-generation ASIC must be designed from the ground up to address the same needs.

The WatchGuard V200 includes a 90-day renewable subscription to WatchGuard's LiveSecurity Service. In addition to the Firebox V200, WatchGuard's Firebox Vclass product line includes the Firebox V100, V80, V60, V60L and V10 models.

Management

Each Firebox Vclass appliance includes Vcontroller, a robust, Java-based software application that provides an added layer of security when managing and configuring site-to-site and site-to-remote VPN locations. An integrated, intuitive icon- and wizard-based graphical user interface manages firewall and VPN policies.

Pricing and Availability

The Firebox V200 is available now from Wick Hill priced from £44,000.

( Top of Page )

( Previous Article )   ( Table of Contents )   ( Next Article )