Main » 2011 » Март » 16 » Content filtering on the stream of software and hardware esafe
13:31
Content filtering on the stream of software and hardware esafe
I would like to share their experiences provide content filtering means of hardware and software eSafe.

ESafe - a proactive remedy to be installed at the gateway to the Internet, and prevents the penetration of the protected network of known and unknown malware, spam, as well as limiting access to data and applications that do not comply with corporate policy, or moral and ethical standards.

ESafe is the development of Aladdin is now SafeNet. eSafe has 4 operating modes eSafe Mail, eSafe Web, eSafe Web & Mail and eSafe Web SSL. eSafe can work as a bridge for users it is invisible, except when there is a lock and the user sees the page locks. Page lock can be modified adjusting the code in the console, or disabled.

Complex Pluses:
  • filtering on the fly
  • blocking applications (Skype, ICQ, XMPP, etc.) and annonimayzerov
  • virus removal and blocking communications Trojans
  • possibility of clustering
  • main network card has ByPass (only if you appliance), in the case of an emergency stop of the complex network continues to work


Cons:
  • to version 8.5 application filter can not work with LDAP groups
  • to version 8.5 when configuring the bridge mode need to enter ip address on the main network interfaces
  • zamudrennaya system release messages from quarantine
  • carrier platform RedHat 9 - require additional protection of the complex


We eSafe is used to filter Internet traffic of users. At the beginning of eSafe is also responsible for anti-spam protection, but due to problems extracting messages from quarantine, it was decided to transfer e-mail filtering for McAfee EWS. Extraction system from the spam quarantine is tuned to Microsoft Outlook, for other clients, you must have an additional server with IIS on board, but not always, this band works correctly. For example, in McAfee EWS everything is on the board, but may be transferred to a single quarantine server.
ESafe has onboard antivirus (up to version 8.x - antivirus eSafe, version 8.x - Kaspersky Anti-Virus), URL filters, application filters, content, version 8.x is DLP.

Anti-Virus scans traffic on the fly, any file downloaded to 80% transparent to the user, then download to the user as if suspended, and eSafe blocks completion of the file and checks if the file is clean user receives the remaining 20%, if not - for the user download is interrupted. Visually eSafe version 7.x seems faster than version 8.x, but I did not make measurements.

URL Filtering - sites separated by categories, there are initially predefined templates permits. Able to work with LDAP groups that have no need to start at the eSafe users to provide privileged access. List of sites in one category or another can not see. The site can be found in several categories, with it anywhere will appear on the second level domain, for example, if a user is to prohibit use Web mail, but allow read blogs, he can not go on mail.ru. URL filter will not work if you open a site on HTTPS, to monitor HTTPS requires a separate device with a regime eSafe Web SSL. It seems that the URL filter is used on IBM Proventia.

Filter applications - for his work required to provide privileged access to any ip address, or run on the client utility authorization eslogin, which transmits to the eSafe username and ip address of your computer. Prior to version 8.5 you must specify user / ip address directly through the management console to version 8.5, you can use LDAP groups. Filter applications very well blocks: skype, IM, twitter, facebook, tunneling (TOR, ultrasurf, etc), P2P, communication malware World Wide Web, and more.

Filters on the content can block selected file types, dangerous features scripts, voluminous archives and files with a password.

Using this complex has reduced the infection of computers through the Internet, lower bandwidth consumption for personal use.

One physical device calmly pulls a simultaneous surfing 1500 users.
ESafe is not alone in this segment, the nearest rivals IBM Proventia and McAfee EWS
Views: 700 | Added by: w1zard | Rating: 0.0/0
Total comments: 0
Имя *:
Email *:
Код *: