Webinar Fortinet Secure Web Gateway 0204 - FortiProxy Presentation
Webinar Fortinet Secure Web Gateway 0204 - FortiProxy Presentation
Webinar Fortinet Secure Web Gateway 0204 - FortiProxy Presentation
Fortinet Vietnam SE
1
Agenda
Introducing FortiProxy
Proxy Features
FortiProxy vs FortiGate
FortiProxy Models
FortiProxy Licensing
Deployment Modes & Scalability
Competitive Analysis
2
Introducing FortiProxy
Next-Gen Secure Web Gateway
Secure Web Gateway market
Protect users against internet threats
Web Application
Servers
Secure web gateways (SWG) utilize URL filtering, advanced
threat defense and legacy malware protection to defend
users from internet-borne threats, and to help enterprises
Internal User
enforce internet policy compliance
FortiWeb
External User
4
Secure Web Gateway Role
• Defend users from internet-borne threats
5
FortiProxy Secure Web Gateway (SWG)
6
FortiProxy Features
FortiProxy Features
• Intrusion Prevention System
• Full Proxy Application • Monitor and Logging
• Application Control
• Content Caching • Data Analytics
• Antivirus
• WAN Optimization • FortiView Integration
• Web Filtering
• Video Caching & Stream Splitting • FortiAnalyzer Integration
• DNS Filtering
• FortiCloud Integration
• Web Rating Overrides
• Data Leak Prevention
• SSL/SSH Inspection
• Content Analysis (3rd party solution)
• User Authentication
• Sandbox Inspection
• Browser Isolation
FortiProxy OS
8
Integration with Advanced Threat Protection
FortiGuard Labs
4 Security Updates
3b Intelligence Sharing
1 FortiSandbox 1
File Submission/ 3a File Submission/
Result Real-time Intelligence Updates Result
2a Block Objects
FortiProxy
FortiClient (ATP Agent)
3rd party Endpoint Agent
2a
File Quarantine
9
Browser Isolation - Zero Trust Web Browsing
• Clientless remote browser isolation
• Works with any modern HTML5 capable browser
• Mitigate against web based threats whilst retaining productivity
• No third party code ever runs on the local machine
• Browser session runs in clean remote container
• Rendered page image displayed to client
• Supports web page interactivity e.g. links, forms,
video, audio
10
FortiProxy Integration with Browser Isolation (FortiIsolator)
• Provide full Browser isolation based on Web categories
• FortiProxy policy integration with FortiIsolator with Several deployment modes:
• Explicit Proxy
• Transparent Proxy
11
Integration with FortiIsolator
12
Integration with FortiIsolator
13
“ On-box AI” - Content Analysis
• Content Analysis is able to detect NSFW
images and videos
• Near zero false negatives or near zero false
positives achievable
• Accomplished with Neural Network based
Image recognition technology
Weapons Extremism Graphic Violence
• Enforce for end user very sensitive to of illicit
images & videos
Image
Videos
Pornography Drugs
Text
14
Acceptable Use Policy Enforcement
Authentication
FortiProxy Build-In Authentication Methods
• FSSO
• LDAP/Radius
• Kerberos
• Single Sign On – SAML
FortiAuthenticator • FortiToken
• X-Auth-User Header
SSL
Inspection
FortiProxy
Web Filtering
• Integration with threat intelligence
• Upload external blacklists
• Web Application Control
• Static web filtering
User accessing web • Warning Page to user
15
SSL-VPN & IPsec VPN
FEATURES FEATURES
Provide full SSL VPN support Provide full IPSEC VPN support
Support Wizard configuration
Support the following modes:
Support following methods:
»Tunnel mode configuration
»Site to Site (FPX, FGT and Cisco)
»Web Mode configuration
»Remote Access (FortiClient, MAC, Android,
Provide a custom login page to SSL VPN Windows)
connections »Custom
Full FortiClient Support Provide several Tunnel Templates
16
Most Popular Supported CDNs
Content Caching & Video Caching Youtube
Google Video
17
Video Content Caching
Optimise the network during high bandwidth corporate events
RTMP/T Stream Splitting, HTTP Live Streaming and MPEG-DASH
• Download live video streams once, serve to many clients
• Useful for live video events (sporting events, corporate
presentations etc.)
• Optimise the network during high bandwidth corporate events
18
WAN Optimization
19
Caching Feature
CACHE CACHE PRELOAD CHUNKED CACHE
COLLABORATION SUPPORT SUPPORT
Cache content sharing and Pre-load cache content based on Support for caching of chunked
clustering protocol manually defined URL pattern with and ranged requests
scheduled crawling function Commonly seen in video
Useful for schools and hotels where downloads
popular content can be predicted
20
Reverse Cache Prefetch
PREFETCH
FEATURES
Benefits
More accurate prefetch based on user agent
21
FortiView - Real time Monitoring
Provides a real-time and historical traffic data from log
devices by source, domain, destination, threat map,
RTT, and Application Service.
Application Service:
» HTTP/S Traffic Statistics
» User Analytics
» Cloud Applications
» Caching and Optimization
» Top Sources, Destination and Sessions
Security:
» Threat map
» Top attacks, Geo IP, Quarantine
System:
» System logs
» Traffic logs
22
Logging and Monitoring
Provides a real-time and historical data and security
logs from security profiles.
» Forward Traffic
» AntiVirus
» Web Filtering
» Application Control
» IPS and more…
23
FortiCloud Integration
26
Comparing “Apples-to-Apples”
Comparing apples to apples: FortiProxy talk the same language & metrics as SWG solution
• “Seat license”- this is crucial when replacing Symantec SG and any SWG gear. FGT has
throughput and not # of seat.
• PAYG and All-Inclusive license - customers pay only for the exact capacity currently required,
which prevents over-spending on the initial solution
• Number session per seat. FPX has 2x more session for each seat compare to Symantec.
Flexible deployment (Transparent, Explicit, Inline…) multi Pac files, multiple different policies
(transparent, SSL, explicit, redirection…)
Best Caching and Optimization – Caching is one of the core features when using forward proxy
solution. FortiProxy provide advanced caching features such:
• Cache-collaboration - Collaboration web caching allows multiple FortiProxy units within one
organization to share all cached objects
• Prefetch URL (Crawl) – proactive preload caching objects
• Reverse Cache Prefetch
• RTMP/HTTP Stream Splitting
• Dynamic Adaptive Streaming over HTTP (MPEG-DACH)
27
Comparing “Apples-to-Apples”
FortiProxy WebUI: FortiProxy is focus on Proxy features WebUI. With FortiProxy, you can create all the configuration
from WebUI without the need of CLI (compare to FortiGate)
• Features like Web Proxy profile, Kerberos and others are needed to be add via CLI in FortiGate compare to
FortiProxy
Hardware: best hardware for a firewall is not necessarily the same as for SWG solution. FortiProxy is a Proxy oriented
Software Architecture compare to Firewall which is Flow oriented
• FortiProxy support more memory and disk for caching & performance scaling
• FortiProxy support Bypass ports for flexible deployment
FortiIsolator/Fireglass – Symantec has “Fireglass” solution which provide isolate-browser for customers. FortiProxy
has integration with FortiIsolator as part of the configuration. FGT is still not there.
Credential Phishing prevention (will be part of FGT 6.4) - detects and blocks known credentials being sent by web
requests. Scan username and password in submission traffic to internet websites against your sensitive corporate
network credential, and define right action FortiGate can take to prevent credential phishing
28
Feature FortiProxy 1.2 FortiGate 6.2
Deployment & Performance
Flexible deployment
Performance (“Seat” license, PAYG)
Bypass ports
Security Features
Intrusion Prevention
Application Control
IPS
AntiVirus
Web & DNS Filtering
Web Rating Overrides
DLP
SSL/SSH Inspection
Content Analysis (on-box AI)
FortiIsolator Integration
Credential Phishing prevention
Caching & WAN Optimization
Advanced Web & Video Caching
High throughput caching
High volume storage
WAN Optimization
Reverse Web Cache
RTMP/HTTP Stream Splitting
Dynamic Adaptive Streaming over HTTP (MPEG-DACH)
Generic
User Authentication
Policy Test
Multiple Pac Files/Policies
FortiSandbox Integration
29
FortiProxy Models
FortiProxy Form Factors
Multiple options for maximum deployment flexibility
Centralized Management
• Perpetual licensing
SWG
500 – 4,000 users 2,500 – 15,000 users 10,000 – 50,000 users 100 – 50,000 users
3 Gbps Proxy Mode 9 Gbps Proxy Mode 18 Gbps Proxy Mode Performance HW
1.5 Gbps AV, WF, App 4 Gbps AV, WF, App 9 Gbps AV, WF, App dependant
1 Gbps AV,WF, 3 Gbps – AV,WF, 6 Gbps – AV,WF,
App.Ctrl, IPS, SSL Full App.Ctrl, IPS, SSL Full App.Ctrl, IPS, SSL Full
Inspection Inspection Inspection
32
FortiProxy Appliance Lineup
Service License
(All-Inclusive) Web Filtering, DNS Filtering, Application Control, DLP, AV, IPS, Botnet (IP/Domain) and FortiSandbox Cloud
Storage 4TB (2 x 2TB HDD) 8TB (4 x 2TB HDD) 8TB (4 x 2TB HDD)
(plus 4 x 2TB Optional) (plus 8 x 2TB Optional)
SSL Hardware 2 x CP9 2 x CP9 2 x CP9
Power Supply AC power supply (Optional Dual) Dual AC power supply Dual AC power supply
User 100 Users 100 - 500 Users 100 -2,500 Users 100 - 10,000 Users 100 -25,000 Users 100 - 50,000 Users
License
Hypervisor
Support VMware ESX/ESXi, KVM Platform and Microsoft HyperV
Service
License SWG Protection Bundle:
Web Filtering, DNS Filtering, Application Control, DLP, Antivirus, IPS, Botnet (IP/Domain) and FortiSandbox Cloud
CPU 2x vCPU 4x vCPU 8x vCPU 16x vCPU 32x vCPU Unlimited vCPU
Memory
Unlimited (G) x RAM
Ports Up to 10 Interface
34
Cloud Services
MICROSOFT AMAZON WEB GOOGLE
AZURE SERVICE CLOUD
Deployed on a with 3rd party cloud solution Deployed on a with 3rd party cloud solution Deployed on a with 3rd party cloud solution
35
FortiProxy Licensing
FortiProxy License Offering
FortiProxy offers PAYG License (per “seat”) which allows the customer to
scale according to his needs.
Benefits:
• Scalable performance without the need for hardware replacement
• Customers pay only for the exact capacity currently required, which prevents over-
spending on the initial solution
• Overcomes capacity planning challenges
• Reduces the risk associated with data center growth for best investment protection
37
Licensing Model
• PAYG User Based Licensing – Minimum users required
Hardware / Virtual
1
Fixed Price
(Include Advanced Caching and WAN Optimization + DNS Protection)
38
Licensing Scenario 1
Number of seats: 5,000
Appliance Type: Hardware
Services and Support: SWG Protection Bundle, Content Analysis Service and 24x7 FortiCare Contract
Content Analysis: Required
1
FortiProxy-2000E FPX-2000E FortiProxy2000E, 2xRJ45 GbE, 2xRJ45 GbE Bypass, 2xSFP GbE, 2xSFP+ 10GbE
SWG Protection - Web Filtering, DNS Filtering, Application Control, DLP, AV, Botnet 10
2 (IP/Domain), IPS, Sandbox Cloud. 500 User license with SWG Protection (Minimum Orders
FC-10-XY2KE-620-02-DD order 5 and up to 30)
10
3 FC-10-XY2KE-160-02-DD Content Analysis Service. 500 User license (Minimum order 5 and up to 30) Orders
39
Licensing Scenario 2
Number of seats: 3,000
Appliance Type: Virtual
Services and Support: SWG Protection Bundle, Content Analysis Service and 24x7 FortiCare Contract
Content Analysis: Not Required
2 SWG Protection - Web Filtering, DNS Filtering, Application Control, DLP, AV, Botnet 30 Orders
(IP/Domain), IPS, Sandbox Cloud. 100 User license with SWG Protection license
FC-10-XYVM8-621-02-DD with 24x7 support (Minimum order 1 and up to 10)
FC-10-XYVM8-160-02-DD Content Analysis Service. 100 User license (Minimum order 1 and up to 10)
40
Deployment Modes & Scalability
Deployment Modes
Inline (L2/L3) Deployment (Transparent)
• Suitable for smaller enterprises (Less than 500 users)
• Deployed behind the NGFW
• Interesting traffic that needs to be inspected configures on
Proxy, and the remaining traffic is automatically bypassed
to the NGFW
Explicit Deployment
• Suitable for larger enterprises
• Proxy can be deployed in any location within the enterprise
• Support for multiple PAC files allows flexibility
42
High Availability
Active/Passive Failover
• Full configuration synchronization
• Seamless failover
• No downtime
• WCCP Load Balancing
Configuration-Sync
Sync FortiProxy devices
Seamless integration into already existing HA/LB
environments
43
Active-Passive Cluster & Central Logging
Master Passive
Configure
44
Config Sync Cluster & Central Logging
FortiAnalyzer
Config Sync cluster
45
FortiProxy Vs. Broadcom
(Symantec Blue Coat)
Market Focus
Broadcom lacks focus or vision to when it comes to a SWG solution.
“Broadcom is a hardware company and software isn't their core competency. Broadcom doesn't seem
to be a vision or roadmap for how it fits into Broadcom's existing software business…”
“As with recent Broadcom acquisitions (Brocade & CA Technologies), drastically cutting costs and
selling to only the largest clients is the preferred playbook to be followed with Symantec as well. This
strategy has left many customers with diminished support, end-of-life products, and technology that will
either be retired or no longer receive investments in either R&D or support.
• They will eliminate over $1 Billion in spending across R&D (40% cut) and Sales (82% cut)
• They will only focus on the Global 2000 customer base and essentially let the commercial accounts
churn out of their business” 1
1 https://www.observeit.com/blog/why-broadcoms-symantec-acquisition-wont-solve-their-insider-threat-problems/
47
Positioning Against Broadcom (Symantec <== Blue Coat)
Broadcom Strengths Broadcom Weaknesses FortiProxy Advantages
• Best Price/performance
• Public company and established • Highest TCO
• All features included at no extra cost
brand • Lack of Focus and vision on
• Strong advertising SWG market/customers • FortiGuard Labs delivers robust, real-time
threat intelligence from around the globe
• Broad product lines • Broadcom HW are expensive
• Industry market leadership and underperform (SSL) • Part of Fortinet Security Fabric
• Leader in features • Expensive configuration options • Strong security offering
• Vast experience with SWG • Customers need to pay for each
• Superior GUI design, usability and visibility
market feature/module, making the
(FortiView)
product extremely expensive
• Integration with Fortinet product such:
FortiGate, FortiSandbox, FortiAnalyzer,
FortiIsolator and FortiADC
48
FortiProxy Vs Broadcom - Features
Low Level Mid Level High Level
FortiProxy-400E ASG-200-X FortiProxy-2000E ASG-400-X FortiProxy-4000E ASG-500-X
Users (Seat) 500-4,000 500-2,500 2,500-15,000 1,000-25,000 10,000-50,000 10,000-50,000
Session per user 10 5 10 5 10 5
performance
Need to replace Need to replace
Memory/HDD Maximum value Maximum value Maximum value based on users* Maximum value based on users*
IPS X X X
Antivirus
DLP
Anti-Malware Protection
Web Reputation/Score
Content Analysis/Filtering Additional HW Additional HW Additional HW
Web & DNS Filtering
Application Control
Stateful Firewall X X X
Modules / Features
Sandbox Cloud Basic Basic Basic
Sandbox On-prem
Web and Video Caching
Cache Collaboration X X X
Traffic Shapping/QoS Policy
WAN Optimization
Advanced WebUI Basic Basic Basic
Advanced Visibility Basic Basic Basic
Logging and Reporting Basic Basic Basic
10/100/1000 Mbps Ports 4 2 4 2 6 2
Build-in Ports 10 Gbps Ports 0 0 2 0 4 1
Bypass Ports 0 2 2 2 2 2
Drive Disk Disk for Cache 4TB (2 TB x2) 2x 500GB 8TB (2 TB x2) 3-8x 1TB 8TB (2 TB x2) 8-16x 1TB
49
FortiProxy Key Differentiators
50
Summary