Notes
Slide Show
Outline
1
Introducing the
Mercury Firewall
2
What is the Mercury Firewall?
  • Open Source Software
  • Dell Hardware
  • Custom Configuration
  • Web (HTTP) Proxy
  • Intrusion Detection System (IDS)
  • VPN Support
  • Highly Available (HA)
3
Feature Comparison Matrix
4
Open Source Software
      • More Secure than proprietary software.
        • Full disclosure
        • Large peer review of code
      • No Software Licenses in the price.
        • One size fits all pricing is easy to understand
        • No additional costs as your needs increase
      • Best of Breed applications instead of competing products.


5
Dell Hardware
      • Dell Servers are made with reliable and high-quality components.
      • Dell’s pricing is aggressive and machines are sold at or near cost.
      • Every firewall has a three-year on-site warranty on the hardware from Dell corp.
      • Dell’s shipping and production capabilities insures rapid customer satisfaction.
6
Custom Configuration
      • NDP pre-configures the firewall for all customers to meet their unique needs.
      • Customers receive a server from Dell and an install image from NDP.
      • Install image on CD is a backup of the configuration as well as the install medium.
      • The configuration is tested in NDP’s labs and validated prior to shipping.
      • Little or no associated deployment cost to the customer.



7
Web (HTTP) Proxy

      • Squid Web-Caching software is industry standard for Web Proxy.
      • Speeds up performance for web browsing.
      • Reduces Internet Traffic.
      • It provides security and protection to web browsers on insecure platforms.
8
Intrusion Detection System (IDS)
      • If a firewall is a locked door, and IDS is an alarm.
      • Snort is a world-class IDS system that has recently won performance tests against all the commercial competitors.
      • IDS systems are the only way to monitor what potentially malicious traffic is being sent at the network.
9
Virtual Private Network (VPN)
      • Remote Access (VPN access from remote users over the Internet)
      • Site-to-Site VPN.  Use inexpensive Internet circuits to connect multiple locations securely.  Connect securely with business partners over IPSEC VPN’s.
      • SSH and OpenSSL provide a myriad of options for high-security cryptographic protection of your data.
10
Graphical Security Console
  • Graphical Web-based security output / alerts.
  • Intrusion Detection System (IDS) alerts sorted by priority and type.
  • Packet Filter log shows all packets allowed and blocked.
  • Web Proxy statistics shows a detailed breakdown of web usage.
  • Detailed network and system statistic trends displayed graphically.
11
Integrated T1 / T3 Router
  • Optional T1  or T3 CSU/DSU adapter for directly attaching a high-speed Internet connection.
  • No additional expensive T1 Router required when using high-speed lines.
  • Fewer points of failure in the network.
  • Ideal for remote office networks as T1 routers / VPN gateways.


12
Highly Available (HA).
      • New VRRP daemon available
      • If the Internet is mission critical, use 2 firewalls for maximum uptime.  If one fails the other will silently take over.
      • Use two firewalls for load-balancing.  Add capacity with multiple redundant load-balancing firewalls.
      • Dedicated Services with failover capacity!
        • Use 1 Mercury as your firewall and 1 Mercury as a passive IDS monitor.
        • Have the IDS monitor backup your firewall for redundancy.
        • 100% uptime and dedicated IDS sensors with Mercury!

13
Managed Firewall Service
  • NDP Managed Security will provide Firewall outsourcing services to clients.
  • Basic service includes all firewall configuration changes, product updates, and software patches.
  • Advanced service includes Incident Response, Intrusion Detection System (IDS) monitoring, and VPN link monitoring.


14
Pricing Models
  • Basic Firewall for DSL available for $2500.
  • Additional features, T1 or T3 adapter, better warranty, or more powerful hardware add marginally to the price.
  • No licenses involved in the pricing.  No additional costs for additional features / users.
  • Multiple firewall orders available at substantial discount (perfect for meshed VPN or HA firewall solutions).