HomeProducts › ProSecure™ UTM Series

Die NETGEAR® ProSecure™ UTM Reihe

Für kleine Unternehmen - Umfassende All-in-One Gateway Security - ohne Kompromisse.

Hierbei handelt es sich um eine All-in-One Gateway >Security Hardware-Appliance für kleine Unternehmen mit bis zu 30 Benutzern. Die ProSecure UTM Application Proxy Firewall, VPN, Zero-Day Protection, Antivirus, Anti-Spyware, Anti-Spam, Eindringschutz und URL-Filterung für vollkommene Sicherheit.

 

ProSecure Unified Threat Management (UTM) Appliance von NETGEAR vereinen hohe Leistung mit umfassendem Schutz für kleine Unternehmen. Die flexible und modulare Architektur nutzt die patentierte Stream Scanning-Technologie zum Scannen von Dateien und Datenströmen und ist dabei bis zu 5x schneller als herkömmliche Methoden. Diese Architektur ermöglicht der ProSecure UTM auch die Nutzung der Virus- und Malware-Datenbanken von NETGEAR und Sophos mit mehreren Tausend Signaturen. Diese Datenbanken sind bis zu 200x umfassender als herkömmliche UTM-Plattformen für kleine Unternehmen.

 

Key Features & Vorteile:

  • All in one Unified Threat Management
  • Best-of-Breed-Viruserkennung in Zusammenarbeit mit Sophos™
  • Patentierte Stream Scanning-Technologie garantiert minimale Latenzzeit
  • Hybrides "In-the-Cloud"-Antispamsystem - kein Feintuning erforderlich
  • Hybrider "In-the-Cloud"-Webfilter mit überwachung von P2P & IM für kontrollierten Internetzugang
  • Zero Hour - Schutz vor unbekannten Bedrohungen in Echtzeitli>
  • IPsec sowie SSL-VPN für Fernzugriff
  • Keine nutzerabhängigen Lizenzgebühren
  • Einfache Abo-Optionen
UTM ModelsUTM Models UTM 5 UTM 10 UTM 25
Sizing Guidelines
Recomended Number of Concurrent Users 1-5 1-15 10-30
Average Anti-virus Throughput¹ 15 Mbps 20 Mbps 25 Mbps
Stateful Packet Inspection Firewall Throughput¹ 90 Mbps 90 Mbps 127 Mbps
Maximum VPN Throughput¹ 40 Mbps 50 Mbps 70 Mbps
Maximum Concurrent Connections 8,000 12,000 27,000
VLANs 255 255 255
Content Security
Web (HTTP, HTTPS, FTP) ✓ ✓ ✓
Email (SMTP, POP3, IMAP) ✓ ✓ ✓
Stream Scanning ✓ ✓ ✓
Inbound and Outbound Inspection ✓ ✓ ✓
Signature-Less Zero Hour Protection ✓ ✓ ✓
Malware Signatures 1 Million+ 1 Million+ 1 Million+
Automatic Signature Updates Hourly Hourly Hourly
Web Content Filters Filter By: HTML Body Keywords, File Extension
Web Object Filters ActiveX, Java™, Flash, JavaScript™, Proxy, Cookies
Email Content Filters Filter By: Subject Keywords, Password-protected Attachments, File Extension, File Name
Distributed Spam Analysis ✓ ✓ ✓
Distributed Spam Analysis Supported Protocols SMTP, POP3
Anti-spam Real-time Blacklist (RBL) ✓ ✓ ✓
User Defined Spam Allowed/Block Lists Filter By: Sender Email Address, Domain, IP Address, Recipient Email Address, Domain
Distributed Web Analysis w/ 64 categories ✓ ✓ ✓
Instant Messaging (IM) Control MSN® Messenger, Yahoo!® Messenger, mIRC, Google Talk
Peer to Peer (P2P) Control BitTorrent™, eDonkey, Gnutella
Maximum Number of Users Unlimited
Firewall Features
Stateful Packet Inspection (SPI) Port/Service Blocking, Denial-of-service (DoS) Prevention, Stealth Mode, Block TCP Flood, Block UDP Flood, WAN/LAN Ping Response Control
Intrusion Detection & Prevention (IPS) ✓ ✓ ✓
WAN Modes NAT, Classical Routing
ISP Address Assignment DHCP, Static IP Assignment, PPPoE, PPTP
NAT Modes 1-1 NAT, PAT
Routing Static, Dynamic, RIPv1, RIPv2
VoIP SIP ALG
DDNS DynDNS.org, TZO.com, Oray.net
Firewall Functions Port Range Forwarding, Port Triggering, DNS proxy, MAC Address Cloning/spoofing, Network Time Protocol NTP Support, Diagnostic Tools (ping, DNS lookup, trace route, other), Auto-Uplink on Switch Ports, L3 Quality of Service (QoS), LAN-to-WAN and WAN-to-LAN (ToS)
DHCP DHCP Server, DHCP Relay
User Authentication for VPN Active Directory, LDAP, Radius, Local User Database
PCI Compliance Two Factor Authentication Support ✓ ✓ ✓
VPN
Site to Site VPN Tunnels 5 10 25
SSL VPN for Remote Access 2 5 13
IPsec Encryption Algorithm DES, 3DES, AES(128,192,256bit)
IPsec Authentication Algorithm SHA-1, MD5
Key Exchange IKE, Manual Key, Pre-Shared Key, PKI, X.500
IPsec NAT Traversal ✓ ✓ ✓
SSL Version Support SSLv3, TLS1.0
SSL Encryption Support DES, 3DES, ARC4, AES(128,256bit)
SSL Message Integrity MD5, SHA-1, MAC-MD5/SHA-1, HMAC-MD5/SHA-1
SSL Certificate Support RSA, Diffie-Hellman, Self
SSL VPN Platforms Supported Windows 2000 / XP / Vista® (32bit), Mac® OS X 10.4+
Deployment
VLAN Support ✓ ✓ ✓
Dual-WAN Fail-over     ✓
Intelligent Traffic Load Balancing Based on Traffic Byte Count     ✓
Configuration Wizards Setup, IPsec VPN, SSL VPN
Logging and Reporting
Management HTTP/HTTPS, SNMP v2c
Reporting Summary Statistics, Graphical Reporting, Automatic Outbreak Alerts, Automatic Malware Notifications, System Notifications
Logging Traffic, Malware, Spam, Content Filter, Email Filter, System, Service, IPS, Port Scan, IM, P2P, Firewall, IPsec VPN, SSL VPN
Log Delivery Management GUI Query, Email Delivery, Syslog
Hardware
Gigabit RJ45 Ports WAN/LAN 1/4 1/4 2/4
DMZ Interfaces (Configurable) 1 1 1
Flash Memory/RAM 2 GB/512 MB 2 GB/512 MB 2 GB/1 GB
USB Ports 1 1 1
Certifications ICSA: Anti-virus VPNC: AES Interop, Basic Interop
Checkmark: Anti-Malware, Anti-Spam, Enterprise Firewall, VPN, IPS, URL Filtering
Major Regulatory Compliance FCC Class A, CE, WEEE, RoHS
Storage and Operating Temperatures Operating Temperature 0-45°C (32°-113°F),
Storage Temperature -20-70°C (-4°-158°F)
Humidity Operation 90% Maximum Relative, Storage 95% Maximum Relative
Electrical Specifications 100-240V, AC/50-60Hz, Universal Input, 1.2 Amp Max
Dimensions (W x H x D) cm 33 x 4.3 x 20.9 33 x 4.3 x 20.9 33 x 4.3 x 20.9
Dimensions (W x H x D) inches 13 x 1.7 x 8.2 13 x 1.7 x 8.2 13 x 1.7 x 8.2
Weight (kg/lb) 2.1/4.6 2.1/4.6 2.1/4.6
Package Contents ProSecure Appliance (UTM10 or UTM25), Power Cable, Rubber Feet, Resource CD, Rackmount Kit*, Warranty Card, Quick Installation Guide, Subscription Card (Bundles Only)
Hardware Warranty 2 Years

¹ Testing performed in a lab benchmark environment. Actual performance may vary.
*Available on the UTM25

Folgende Screenshots zeigen das Web user interface der NETGEAR® ProSecure™ STM Reihe der Gateway Security Geräte.

 

Network Config › WAN Settings › WAN 1 ISP Settings

Determine the ISP settings for the primary WAN.

 
 

Network Config › WAN Settings › WAN Mode

Determine the ISP settings for the primary WAN.

 
 

Network Config › Protocol Binding › WAN 1 Protocol Bindings

Add and configure protocol bindings for the primary WAN.

 
 

Network Config › Dynamic DNS › Dynamic DNS

Configure the UTM to utilize DynDNS.com DNS services.

 
 

Network Config › Dynamic DNS › DNS TZO

Configure the UTM to utilize tzo.com DNS services.

 
 

Network Config › Dynamic DNS › DNS Oray

Configure the UTM to utilize Oray.net DNS services.

 
 

Network Config › WAN Metering › WAN 1 Traffic Meter

Configure traffic metering for the primary WAN.

 
 

Network Config › LAN Settings › LAN Setup

Add and configure virtual LANs, including IP address, DHCP status, and port assignment settings.

 
 

Network Config › LAN Settings › LAN Groups

Add computers and devices the LAN manually.

 
 

Network Config › LAN Settings › LAN Multi-Homing

Add a secondary LAN IP address to and existing LAN configuration.

 
 

Network Config › DMZ Setup

Enable and configure the DMZ.

 
 

Network Config › Routing

Add and manage static routes. Configure RIP settings.

 
 

Network Config › Email Notification

Enter account settings for Email notifications. The UTM will utilize this information for sending any necessary alerts.

 

Network Security › IPS › Global

Enable intrusion prevention and port scan detection.

 
 

Network Security › IPS › Advanced

Determine which intrusion prevention rules to enable, and select the appropriate action to take, in the event of an attack.

 
 

Network Security › Firewall Objects › Services

Add and configure services to be used in firewall rules.

 
 

Network Security › Firewall Objects › QoS Profile

Add and configure QoS profiles to be used in firewall rules.

 
 

Network Security › Firewall Objects › Bandwidth Profile

Enable bandwidth profiles. Add and configure bandwidth profiles to be used in firewall rules.

 
 

Network Security › Firewall Objects › Schedule 1

Configure a schedule for firewall rules to be active. Choose specific times of the day and days of the week.

 
 

Network Security › Firewall Objects › Schedule 2

Configure a schedule for firewall rules to be active. Choose specific times of the day and days of the week.

 
 

Network Security › Firewall Objects › Schedule 3

Configure a schedule for firewall rules to be active. Choose specific times of the day and days of the week.

 
 

Network Security › Firewall › LAN WAN Rules

Define firewall rules for traffic between the LAN and the WAN/Internet.

 
 

Network Security › Firewall › DMZ WAN Rules

Define firewall rules for traffic between the DMZ and the WAN/Internet.

 
 

Network Security › Firewall › LAN DMZ Rules

Define firewall rules for traffic between the LAN and the DMZ.

 
 

Network Security › Firewall › Attack Checks

Configure the UTM to protect against commonly used network attacks.

 
 

Network Security › Firewall › Session Limit

Configure user session limit and session timeout parameters.

 
 

Network Security › Address Filter › Source MAC Filter

Enable and configure filtering of MAC addresses.

 
 

Network Security › Address Filter › IP/MAC Binding

Bind IP to MAC address and vice-versa. Enable and configure email logs for IP/MAC binding violations.

 
 

Network Security › Port Triggering

Add and configure port triggering rules.

 

Application Security › Services

Configure scanning and security policies for email, Web, IM, and P2P.

 
 

Application Security › Email Anti-Virus

Determine what action the UTM will take when malware is detected. Configure email security settings, including scanning and user notification − to alert users and/or senders regarding the security status of their email. Custom alerts can be sent when malware is found, when it is not found, or when a scan has been skipped. Infected attachments can also be replaced with a customized warning message.

 
 

Application Security › Email Filters

Configure the UTM to filter email based on keywords in the subject line, or by the file type, name, or password status of attachments. Also tells the UTM what action to take when an email meets any of these pre-determined parameters. Emails and/or attachments can be logged, or blocked and logged.

 
 

Application Security › Anti-Spam › Whitelist/Blacklist

Configure white lists and black lists for Email, based on the recipient's IP address, domain, or Email address. Email can also be white listed based on the recipient's domain or email address.

 
 

Application Security › Anti-Spam › Real-Time Blacklist

Provides the capability to quickly enable or add real-time blacklists to the UTM.

 
 

Application Security › Anti-Spam › Distributed Spam Analysis

Enable and configure Distributed Spam Analysis anti-spam detection.

 
 

Application Security › HTTP/HTTPS › Malware Scan

Configures the UTM for Web-based malware handling, including what action the UTM will take when infections are found and how to handle messages that are larger than a pre-determined size. Custom alerts can also be sent when malware is found.

 
 

Application Security › HTTP/HTTPS › Content Filtering

Perform Web content filtering. Block specified file types, Web objects, and keywords within Web pages.

Configure the UTM to block URLs from the selected categories. The content filter consists of 64 different categories with a real-time "in the cloud" database of hundreds of millions of URLs. Filtering can be designed to be continuously enforced, or only during certain scheduled days/times. URLs can be submitted to check for classification.

 
 

Application Security › HTTP/HTTPS › URL Filtering

Configure URL white lists and black lists.

 
 

Application Security › HTTP/HTTPS › HTTPS Settings

Configure HTTPS scan Settings.

 
 

Application Security › HTTP/HTTPS › Certificate Management

Catalogs all certificates for the UTM and tells it what Web sites to allow without a corresponding certificate.

 
 

Application Security › HTTP/HTTPS › Trusted Hosts

Configure the UTM to bypass the HTTPS scanning of specific trusted hosts.

 
 

Application Security › FTP

Configure the UTM for FTP-based malware handling, including what action the UTM will take when infections are found, how to handle messages that are larger than a pre-determined size, and what file extensions should be blocked.

 
 

Application Security › Block/Accept Exceptions

The UTM can be configured to override previously determined application rules.

 
 

Application Security › Scanning Exclusions

The UTM can be configured to bypass the content filtering for specified client or destination IP addresses.

 

VPN › IPsec VPN › Internet Key Exchange (IKE) Policies

Configure IKE policies.

 
 

VPN › IPsec VPN › VPN Policies

Manage and configure VPN tunnels and policies.

 
 

VPN › IPsec VPN › VPN Wizard

The VPN wizard used for simplified VPN setup.

 
 

VPN › IPsec VPN › Mode Config

Configure DHCP over VPN settings.

 
 

VPN › IPsec VPN › RADIUS Client

Configure the UTM as a RADIUS client.

 
 

VPN › SSL VPN › Policies

Configure SSL VPN policies.

 
 

VPN › SSL VPN › Resources

Assign specific network services to defined resources for use in SSL VPN tunnels.

 
 

VPN › SSL VPN › Portal Layouts

Select and configure portal layouts for SSL VPN tunnels.

 
 

VPN › SSL VPN › SSL VPN Client

Configure the IP address range and routes assigned to SSL VPN Tunnel clients.

 
 

VPN › SSL VPN › Port Forwarding

Detect and reroute data sent by remote users to the SSL VPN gateway to predefined applications running on private networks.

 
 

VPN › Certificates

Manage and generate certificates used in SSL VPN connections.

 

Users › Users

Add and manage user accounts on the UTM on any configured domains.

 
 

Users › Groups

Add and manage user groups on any configured domains.

 
 

Users › Domains

Enable local authentication to authenticate users locally. Add and manage domains.

 

Administration › Remote Management

Configure the UTM for remote management.

 
 

Administration › SNMP

Configure the UTM for integration with third party SNMP network monitoring tools.

 
 

Administration › Backup and Restore Settings

Enables settings to be backed up or restored − to factory defaults, or from a specified file.

 
 

Administration › System Update › Signatures & Engine

Configure update settings for the UTM. Updates to the scan engine and pattern file are performed online and automatically.

 
 

Administration › System Update › Firmware

Configure firmware update settings for the UTM. Query, download, and install new firmware versions.

 
 

Administration › System Date & Time

Set the system time and local time zone.

 

Monitoring › System Status

Contains information on the overall status of the UTM, including current version, most recent update of all software elements, and license status information. Network address and interface information is also communicated.

 
 

Monitoring › Active Users & VPNs › Active Users

Provides a list of administration and SSL VPN users currently logged into the UTM, including the group, IP address, and login time for each.

 
 

Monitoring › Active Users & VPNs › IPsec VPN Connection Status

Display the status of IPsec connections.

 
 

Monitoring › Active Users & VPNs › SSL VPN Connection Status

Display the status of SSL VPN connections.

 
 

Monitoring › Dashboard

Show current threat detection statistics.

 
 

Monitoring › Diagnostics

Enable diagnostic tools, including ping, trace route, DNS lookup, packet capture, important log generation, or network usage reports for troubleshooting purposes. Display the routing table, reboot the UTM.

 
 

Monitoring › Logs & Reports › Email and Syslog

Tells the UTM which logs to generate, when, and how frequently. Also tells the UTM whether to send the logs via Email or syslog.

 
 

Monitoring › Logs & Reports › Firewall Logs

Tells the UTM which routing and event logs to generate.

 
 

Monitoring › Logs & Reports › Alerts

Tells the UTM which activities warrant alerts and determines the construct of the message that will be received.

 
 

Monitoring › Logs & Reports › Log Query

Enables log files to be generated for a specified set of criteria.

 
 

Monitoring › Logs & Reports › Generate Report

Enables the generation of email, Web, or system reports for a specified date range.

 
 

Monitoring › Logs & Reports › Scheduled Report

Tells the UTM which reports to generate on a regular basis, when and how frequently to generate them, and where to send them when completed.

 

Support › Online Support

Enable a secure online support connection with the ProSecure™ Support Team.

 
 

Support › Malware Analysis

Send a suspicious file or suspected malicious Email to the ProSecure™ malware labs for analysis.

 
 

Support › Registration

Register and manage the Web protection, Email protection, and Support & Maintenance licenses for the UTM.

 

Wizards › Setup Wizard › Welcome Page

Select the type of Wizard.

 
 

Wizards › Setup Wizard › Step 1

Enter basic LAN settings for the UTM.

 
 

Wizards › Setup Wizard › Step 2

Enter ISP settings for WAN connectivity.

 
 

Wizards › Setup Wizard › Step 3

Set the system time and local time zone.

 
 

Wizards › Setup Wizard › Step 4

Configure scanning and security policies for email, Web, IM, and P2P.

 
 

Wizards › Setup Wizard › Step 5

Determine all email scanning parameters, including what action the UTM will take when infections are found.

 
 

Wizards › Setup Wizard › Step 6

Determine all Web scanning parameters, including what action the UTM will take when malware is detected.

 
 

Wizards › Setup Wizard › Step 7

Configure the UTM to block URLs from the selected categories. The content filter consists of 64 different categories with a real-time "in the cloud" database of hundreds of millions of URLs. Filtering can be designed to be continuously enforced, or only during certain scheduled days/times. URLs can be submitted to check for classification.

 
 

Wizards › Setup Wizard › Step 8

Enter account settings for email notifications.

 
 

Wizards › Setup Wizard › Step 9

Determine the time, frequency, and source of scan engine and malware signature updates.

Sizing Guidelines

NETGEAR ProSecure UTM appliances are situated between an organization's internal network and the Internet. The UTM acts as a stateful packet inspection firewall, keeping track of TCP connection state for every connection that is maintained through the UTM. Moreover, the UTM manages an organization's Internet usage and protects these organizations from Internet borne malware, spam, viruses, and inappropriate web surfing. With the NETGEAR ProSecure UTM appliance sitting between the organization and the Internet, it is critical that the UTM appliance is sized appropriately and matches the performance needs of the organization.

There are no industry-standard metrics for determining the model to select, as every organization is unique and displays different network traffic characteristics. Moreover, the performance of the UTM can vary widely depending on a number factors including the complexity of the firewall rules loaded, the number of current active VPN users, the IPS signatures employed, the number of active connections used by each user, and a host of other metrics, including, last but not least, the number of protocols inspected by the Antivirus engine and the number of signatures applied to the AV engine.

As such, NETGEAR highly recommends that you contact your ProSecure authorized VAR who is well versed in UTM sizing to benchmark your organization and recommend the best model for your needs. That said, NETGEAR generally uses several specifications to roughly evaluate the applicability of an UTM appliance:

Firewall Throughput

A starting point is to estimate the throughput your organization requires between its internal network and the Internet. As the UTM appliance sits between your internal network and the Internet, firewall throughput number is the total amount of traffic that can be passed with the UTM in place.

Concurrent Sessions

Users typically engage in a host of activities that consume TCP sessions. Web browsing over HTTP and HTTPS, FTP file transfers, Email over POP3, SMTP, and IMAP, Instant Messenger, Peer to Peer Traffic, TELNET, SSH and streaming audio and video all consume TCP sessions.

On the average, "normal" users typically consume 100-300 active TCP sessions. Virus Infected PCs turned into zombies can often consumer upwards of 1000 active TCP sessions, although NETGEAR ProSecure UTM appliances have administrator-definable limits to contain infected PCs from consuming an excessive number of TCP sessions

Anti-Virus Throughput & Virus Coverage

Anti-Virus scanning can be performed against files or data embedded in time-sensitive applications such as web browsing over HTTP(s) or in latency-tolerant applications such as Email. Because Anti-Virus speed is directly correlated to the number of signatures applied in the scanning process and in the protocols being scanned, Anti-Virus throughput can typically be inflated by reducing the signature set size or reducing the numbers of protocols scanned. Thus, Anti-Virus effectiveness is often a balance between speed and thoroughness. NETGEAR ProSecure UTM appliances employ signature sets that are up 200x larger than competing legacy small business UTM solutions while employing patent-pending Stream Scanning technology to vastly increase Anti-Virus throughput.

UTM Appliance Model Comparison
UTM Model Capacity UTM10 UTM25
Firewall Throughput (Mb/s) 133 153
Concurrent TCP Sessions 8000 20000
Anti-Virus Throughput (Mb/s) 31 45
Anti-Virus Signature Set Size Hundreds of Thousands Hundreds of Thousands
Recommended # of Users 1-15+ 15-30+

News & Events

Whitepapers

Data Sheets

  • UTM Series: Unified Threat Management Appliance
    ProSecure Unified Threat Management (UTM) Appliance von NETGEAR vereinen hohe Leistung mit umfassendem Schutz für kleine Unternehmen. Die flexible und modulare Architektur nutzt die patentierte Stream Scanning-Technologie zum Scannen von Dateien und Datenströmen und ist dabei bis zu 5x schneller als herkömmliche Methoden.
    Download PDF ›

Entdecken Sie unsere Lösungen

Web Security

Bei unseren Lösungen kommt eine professionelle Enterprise-Class Sicherheitsarchitektur zum Einsatz. Diese schützt Unternehmensnetzwerke effektiv vor Viren, Würmern, Spyware, Trojanern, Rootkits, Keyloggern und unberechtigtem Surfen im Web, ohne die Produktivität einzuschränken.

 
Netzwerk Security

Firewall-Funktionalität mit einer breiten Palette von Netzwerk-Sicherheitstechnologien, darunter Stateful Packet Inspection (SPI), Eindringschutz (Intrusion Prevention, IPS) und Schutz vor Denial-of-Service-Attacken (DoS).

Email Security

Distributed Spam Analyse-Architektur zum Einsatz, die Ausbrüche von Spam mit Hilfe eines in-the-Cloud-Ansatzes bereits im Keim erstickt. Die patentierte Stream Scanning-Architektur garantiert somit E-Mails ohne Malware.

 
Remote Access

Die ProSecure UTM-Reihe kombiniert das Beste aus beiden Welten mit zwei Arten von VPN-Tunneln (Virtual Private Network), Secure Socket Layer (SSL) und IP Security (IPsec) für die optimale Anbindung an Ihr Netzwerk.

Back to Top

Partner Login

Mit dem PowerShift Programm haben Sie viele Ressourcen immer zur Hand.

Login Seite:
http://www.netgear.de/partner-programm/index.html

Registrierung als Powershift-Fachhandels-Partner:
http://www.netgear.de/partner-programm/register.html

Passwort vergessen:
http://www.netgear.de/de/partner/pasverg.html