Next Generation UTM

Threats to various attack patterns and intrusion paths are all resolved when you meet the KX NexG UTM equipment.

It provides the next-generation integrated threat management security policy service with its own multi-core Deep Packet Inspection engine.

Main Functions of
Next-Generation Firewalls

01Firewall

  • Stateful Inspection
  • 5 Tuples (IP/Port/Protocol)
  • Zone-based policy support
  • User-based policy support
  • MAC Address-based policy support
  • Object and Schedule-based policy support
  • Independent of policy and number of sessions
  • Policy statistics and scanning support
  • Static, Dynamic NAT, Excluded, Twice NAT

02VPN

  • Multi-tunnel
  • Bonding Tunnel
  • Split Tunneling
  • Transport / Tunnel Mode
  • Crypto Algorithm (3DES, AES128/192/256, SEED, ARIA, LEA)
  • Integrity Algorithm (MD5, SHA1, SHA2)
  • DPD (Dead Peer Detection)
  • NAT Traversal
  • L2 Bridge VPN

03IPS

  • Deep Packet Inspection
  • 4500+ Keep Signature
  • Snort Rule Format Support
  • Profile-based policy settings
  • PCRE Support
  • Black-list / White-list
  • Anti-Evasion
  • Anti-Virus (Stream-based) Detection and Blocking

04Anti DDoS

  • TCP/UDP/ICMP/DNS/HTTP Flooding Defense
  • Scan, Sweep Defense
  • Signature-based defense
  • Counterfeiting / modulation behavior-based defense
  • Traffic Limit-based defense

05Web Filter

  • URL and URI Extension Check
  • Custom DB Filter
  • Web Surfing Control with 96 Web Category DB Filters
  • External DB filters such as KISCOM, Malware, Phishing, etc.

06Network

  • Route / Bridge Mode
  • 802.1Q VLAN Trunk
  • 802.3ad LACP
  • ECMP Routing
  • Policy-based Routing
  • RIP, OSPF
  • PIM-SM/DM, IGMP
  • VoIP(H.323, SIP) Support
  • QoS (Guaranteed, Limit, DSCP)
  • DHCP Server , Relay, HA
  • 3G/LTE Support
  • DDNS Support
  • Secure DNS Support
  • LLDP Support

07Management

  • CLI ,Web UI
  • Dashboard
  • SNMP Version 1 / 2 / 3 Support
  • Syslog Transfer Support
  • Policy Export / Import Support
  • Query unused policies and objects
  • Statistics and Reports Support
  • System Settings / Support for Firmware backup and recovery
  • Administrator external authentication support
  • VForce NMS and KX NexG ESM Interworking

08HA

  • Active-Active / Active-Standby
  • VRRP, IPAT
  • LLCF
  • L2 Bypass
  • Synchronization (Policy, Session)

09Application Control

  • Control behavior by application
  • Game, P2P, HTS Control
  • Web Mail Control
  • Instants Messenger Control
  • Web Hard Control
  • Streaming, File-type Control

10IPv6

  • IPv6 Routing
  • IPv6 Firewall
  • IPv6 IPsec
  • 6 to 4, ISATAP