@2009 XRoads Networks
22642 Lambert St, Suite 403
888-9-XROADS
Table of Contents
Firewall Overview
User/Device Management
Network Access Control
L7 Firewall Rules
L7 Firewall Control
L7 DoS/SYN Filtering
Site2Site Client Termination
PPTP Client Termination
Advanced Spyware & Web Filtering
Basic Web Domain & URL Filtering
Email Defense & Spam Filtering
Edge Configuration Series
Firewall Overview
The EdgeXOS appliance includes a fully stateful and hardened firewall. Our firewall
meets the highest standards in terms of network security and the ability to block
unwanted access to the internal network.
The firewall has been certified as being compliant with ICSA standards and has passed
multiple tests to become PCI compliant for ecommerce networks.
Firewall Modules
The firewall components are designed to provide network administrators with a complete
cloud security system, from a layer-7 stateful firewall to built-in web content filtering, and
enhanced anti-spyware and anti-virus filtering, to remote access software to allow
teleworkers to connect to the local network, the EdgeXOS platform is a complete
security solution. The EdgeXOS firewall also includes enterprise class email and anti-
spam filtering along with on and offsite backup solutions.
The EdgeXOS platform is able to achieve its industry leading security solution through
strategic partnerships with companies like Weboot, Netsweeper, and McAfee.
These companies provide the databases and filtering capabilities that our solution utilize
to provide our enhanced security offerings.
Site2Site Client Termination
If you have remote users that wish to access the local network from their home or on the
road, the Site2Site software client enables any Windows-compatible computer to
connect back to the EdgeXOS appliance.
The client is small and installs in seconds. The configuration is simple ad only requires
the IP address of the EdgeXOS appliance (two can be provided for failover) and the port
which is being used for client connections. This information can be obtained by the
EdgeXOS administrator. Additional step-by-step installation instructions for the client
are provided in our Platform Notes section. The client includes 3DES encryption
protection using standard SSL tunneling technology, which is an improvement over
IPSec based VPNs as they do not have any issues going through hotel firewalls, etc.
To get started simply download the client from the link on the configuration page.
Site2Site Configuration Details
In order for a remote client to connect they must first be defined within the User/Device
Management tool. This tool includes an authentication field which is used as the remote
users password.
If “client-to-client” communication is enabled then two remote users will be able to share
network information and potentially connect to each others shared resources.
If the “force default gateway” option is used, then all of the remote users traffic will go
through the EdgeXOS appliance, i.e. the user will not be able to surf the Internet locally.
When defining the client network make sure that it is not part of any local network,
including the local LAN IP addresses, this network MUST be separate from any other
networks used by the EdgeXOS appliance.
The EdgeXOS administrator can use any port they wish for client connections, however
keep in mind that many ISPs will block high ports so it is typically recommended to use
ports under 1200.
Finally, if you have local resources which should be passed to the remote clients they
can be passed using the DNS and WINS fields.
Advanced Spyware & Web Filtering
The EdgeXOS appliance can be used as a complete Web Threat Protection appliance
by simply enabling the advanced spyware and web filtering module. This module does
require additional licensing however when enabled it provides some of the most
advanced Internet protection in the industry, including zero hour spyware and virus
filtering. Real-time URL and web filtering with built-in phishing protection. Detailed
usage reporting, including allowed and denied sites, top sites accessed and many
others. With per user licensing network administrators can create different user groups
which can have different privileges based on their group definition.
To enable this feature simply click the link to active the spyware account, additional
licensing may be required.
Once activated and enabled, simply use the “SERVICE MANAGER” to control website
access and view usage information in real-time. This service establishes a real-time
connection to our partners portal for instant site updates and real-time spyware and virus
filtering thus the service manager is used to control that functionality.
The acceleration engine provides for faster web downloads and optimizes the web threat
protection to enhance the end-user experience.
For more information please review the Platform Notes for the Spyware & Web Filtering
module.
Basic Web Domain & URL Filtering
This module provides global domain and URL filtering and is included with the purchase
of our annual platform maintenance agreement. This module cannot be used in
conjunction with the Spyware & Web Filtering module. To get started simply click on the
“activate your account” link to obtain the account ID and login information.
This service provides real-time URL filtering by connecting to our partners portal and
obtaining instant allow and deny status based on the URL requested. The redirect site
is can be customized to point to any domain the EdgeXOS administrator selects,
example: [Link], etc. The default is our own [Link]
web page which provides a simple default block page.
The “SERVICE MANAGER” can be used to view real-time usage statistics and configure
specific URL categories be allowed or denied. This functionality is similar to the
Spyware & Web Filtering module accept that “basic” filtering does not include spyware or
virus filtering and does not provide per user control.
The filtering engine works in three stages, the first stage checks the local “Rules
Database”. This database is controlled by the EdgeXOS administrator and can be used
to quickly block specific sites. The second stage checks the local URL cache to
determine if the site has been checked recently, if it has been then the cached response
will be provided up until the defined cache clearing time has been met for that specific
domain (the default is five days). The third stage is performed if the first two do not
match any domains, this third stage makes an automated scan of the website to
determine if the site should be allowed or blocked based on the defined categories using
the service manager. If it is determined that the site should be blocked it will be blocked
immediately.
It is important to note that sites which have no status i.e. it has not yet been checked or
are not in the URL cache, and which should be blocked, may be initially allowed when
the first request to the site is made. This is because the site is being scanned and that
scan may take several moments. For this reason, there is an option to allow or deny all
sites by default. For organizations where end-users should only go to a small number of
sites, the deny default may be the best option; the default is to allow by default and
simply log the traffic. All site requests, whether allowed or denied are logged.
Please review the Platform Notes for more details on the Netsweeper portal controls.
Email Defense & Spam Filtering
The EdgeXOS can also perform spam filtering services by leveraging our partners real-
time spam filtering portal. This service provides for granular spam filtering not available
through other spam filtering solutions, including zero hour virus scanning, and detailed
email reporting.
The process for setting up the spam filtering is simple, just click the “activate your
account” link, this will require additional per mailbox licensing. If the mail server is
located on the LAN side of the EdgeXOS appliance, it will automatically scan email for
spam, however if the mail server is located offsite, then a modification to the customers
MX rules will be necessary. The XRoads Network support team can assist with this
configuration in either scenario.
To configure the spam filtering rules click on the “SERVICE MANAGER” to open access
to our partners portal. Through this portal all real-time spam controls can be accessed.
These are the settings which are used for all mail either going through the EdgeXOS
appliance or being redirected by the MX records.
Please review the Platform Notes for more details on the Email Defense & Spam
Filtering portal controls.