|
Requirements
Map:
All of the SonicWALL products share a common software code
base, which means that the technicians and operators from IPRVnet
will be able to manage any product in our family after they become
familiar with our easy-to-use management tools. In this proposal,
we are proposing the following products:
- SonicWALL PRO-VX or SonicWALL PRO for larger central sites
(e.g. the headquarters in scenario 3)
- SonicWALL SOHO2 with VPN Upgrade for branch offices (e.g.
the branch offices in scenario 3) and also for small businesses
(e.g. the small business in scenario 1)
- SonicWALL TELE2 for broadband-connected telecommuters (e.g.
in scenarios 2 and 3)
In addition to the products above, SonicWALL is proposing the
following for telecommuters and mobile workers using dial-up Internet
access:
- SonicWALL VPN Client Software for Windows
Finally, it is critically important for IPRVnet to have a set
of robust management tools to enable scalable, central management
and monitoring of the CPE being used to deliver these services.
For this requirement, SonicWALL proposes:
- SonicWALL Global Management System (SGMS)
SGMS is a robust management system that resides at the ISP NOC
on a Windows NT 4.0, Windows 2000 or Solaris server. It is capable
of managing thousands of remote SonicWALLs, and can handle the
activation and configuration of all of the standard features and
optional upgrades available for SonicWALL Internet Security Appliances.
We are confident that IPRVnet will find the SonicWALL solution
to be very compelling for the managed security services that they
are planning to roll out.
|
|
Hardware Installation:
|
|
Yes
|
Turn-key hardware solution
|
|
Yes
|
No truck roll required for existing accounts
(drop-ship CPE, plug in, turn on) |
|
Yes
|
Remote configuration of all
but basic network parameters |
|
Yes
|
4. Remote activation of add-on
features |
|
|
Software/Policy Installation:
|
|
Yes
|
Central (ISP) policy definition and update |
|
Yes
|
Central (ISP) software update |
|
Yes
|
IPSec client support for all Windows
OSs |
|
|
Physical:
|
|
Yes
|
Two or more 10BaseT or 10/100
ports; All SonicWALL Internet Security Devices ship
with 2 or 3 10/100 ports. |
|
Yes
|
Support for both DSL bridging
modem and router environments |
|
Yes
|
AC Power |
|
Yes
|
Enclosure should be tamper-resistant;
Two-piece plastic enclosure is assembled with 4 screws,
which deters casual tampering. Option available to add
factory seal to detect tampering. |
|
|
Management:
|
|
Yes
|
Enable secure remote management
by ISP NOC |
|
Yes
|
Some method of out-of-band management
in case of failure; SonicWALL Internet Security Appliances
with serial port can be managed out-of-band using a
modem to access a command line interface (CLI). |
|
Yes
|
Configuration backup/restore; Configuration
can be exported for local backup and also using SGMS. |
|
Yes
|
Remote diagnostics; ping and traceroute |
|
Yes
|
Enable customer management of remote access
user accounts; Multiple authentication methods including
RADIUS and PKI. Customers can get limited access to
policy management through SGMS. |
|
Yes
|
Single-point administration of multiple
devices from ISP NOC |
|
No
|
Configuration change audit trail; SGMS
maintains an audit trail of configuration changes. |
|
|
Monitoring:
|
|
Yes
|
Enable remote monitoring from ISP NOC
|
|
Yes
|
For site-to-site tunnels, traffic stats;
This is a planned enhancement to VPN logging functionality. |
|
Yes
|
For remote user tunnels, user
session stats |
|
Yes
|
Configurable real-time alerts; SNMP, email,
and/or pager |
|
Yes
|
Event logging, stored locally and aggregated
centrally; Each SonicWALL Internet Security Appliance
maintains an internal log, and this log information
can also be sent via SYSLOG for central aggregation. |
|
|
Firewall Features:
|
|
Yes
|
Stateful inspection and/or application
proxy firewall; |
|
Yes
|
Please see www.icsalabs.com. |
|
Yes
|
Logging with configurable detail, alerting
|
|
Yes
|
Network/Port address translation; NAT
and IP masquerading |
|
Yes
|
DMZ option |
|
|
VPN Features:
|
|
Yes
|
IPSec support for ESP, 3DES, SHA-1, and
Diffie-Hellman Group2 |
|
Yes
|
IKE automated key management |
|
Yes
|
IPSec used for remote access. |
|
Yes
|
Detailed logging of IPSec/IKE events. |
|
Yes
|
ICSA IPSec certification pending. |
|
Yes
|
Authentication: Pre-Shared Secret, X.509,
and RADIUS; All authentication methods supported. |
|
|
A La Carte Options:
|
|
Yes
|
Content-filtering plug-in; Value-added
service integrated into SonicWALL Internet Security
Appliance. No additional CPE equipment needed to deploy,
and can be activated remotely using SGMS. |
|
No
|
Intrusion detection plug-in; not currently
available |
|
Yes
|
Antivirus scanning plug-in; Value-added
service integrated into SonicWALL Internet Security
Appliance. No additional CPE equipment needed to deploy,
and can be activated remotely using SGMS. |
|
|
Vendor Support:
|
|
Yes
|
Technical support, accessible 24/7 to
ISP NOC. |
|
Yes
|
Marketing support program |
|
Yes
|
ISP staff training program. Capacity planning,
Backup and recovery planning, technical certification
and training |
|
Yes
|
24-hour parts replacement and warranty
program |
|
Yes
|
Software upgrades and patches
available on-line. Automated OS updates via Web |
|
|
Price:
|
| Vendors must be able to satisfy
an entry-level customer such as that described in Scenario
#1 with CPE retailing for no more than $2,000 (US).
SonicWALL Internet Security Appliances range in price
from $495 to $4995 (US list prices). |
|
|