Forcepoint SD-WAN Highlight

Download as pdf or txt
Download as pdf or txt
You are on page 1of 22

Forcepoint

Next Generation
Firewall with
Secure SD-WAN

© 2022 Forcepoint | 1
Traditional
Networking

© Forcepoint 2021 | Public


Modern
Networking

© Forcepoint 2021 | Public


Connectivity
MPLS “Hub-and-Spoke” Enterprise SD-WAN Direct-to-Cloud

 Expensive  Efficiency & Scale


 Slow  Speed & Resilience
 Time-consuming  Branch Simplification
 Fragile  Integrated Security
 Inflexible  Agility

MPLS or other
dedicated lines Internet Internet

Commodity
Broadband
Links

© 2022 Forcepoint | 4
Forcepoint Builds on Gartner’s Definition of SD-WAN

Replace WAN routers  Integrate WAN router + NGFW

 Mix transports & ISPs for each site


Support multiple WAN connections
 Optimize apps’ use of links & bandwidth

Simplify WAN management,  Unify policies for connectivity + security


configuration and orchestration  Manage >1500 sites in one console

Provide secure VPNs,  Automate VPN setup with site drag-and-drop


integrate additional network services  Service-chain Web Security + CASB in cloud

© 2022 Forcepoint | 5
Immediate Visibility into SD-WAN Performance

• Connections

• App Usage

• Link Health

© 2022 Forcepoint | 6
Forcepoint NGFW VPN Technologies
Types
Site-To-Site IPsec-based VPN
Mobile VPN
• Client-based IPsec and SSL VPN
REMOTE
• Clientless-Based HTTP Portal access IPSEC

INTERNET

IPSEC SITE-TO-SITE
BRANCH Forcepoint NGFW Forcepoint NGFW
HEADQUARTER

Benefits SSL VPN


(CLIENT OR PORTAL)
World-class certified Security R EMOTE

High Availability via Multi-Link technology

© 2022 Forcepoint | 7
SSL VPN Portal
FREE
URL

 Self-signed certificates for easy PoC


 Quick setup of portal and access to users
without client installation
 Free URL box for quick, configuration-
intranet.forcepoint.com
free intranet access
▪ Only the whitelisted servers will be accessible
via the Free URL
 Easy Customization and localization

PREDEFINED
URLS

© 2022 Forcepoint | 8
Drag-and-Drop Setup of VPNs in Minutes, not Hours

Enable site-to-site
communications

Tailor policies for groups of sites

Create many different topologies


• Full-mesh, star, hub-and-spoke
• Handle thousands of sites efficiently

Scale up VPNs with just a few clicks

© 2022 Forcepoint | 9
Site-to-Site VPN
The whole setup up and running
Rapid Expansion To New Locations in seconds – with one or tens of
sites
Two Steps Site-to-Site VPN Deployment
 Drag & drop gateway selection
 Use the VPN in the Policy

© 2022 Forcepoint | 10
Drilling into SD-WAN Connections within a Site

© 2022 Forcepoint | 11
Associating QoS with Applications

© 2022 Forcepoint | 12
Setting up, Seeing & Monitoring VPN Star Topologies

Set Up See Monitor © 2022 Forcepoint | 13


Setting Up, Seeing & Monitoring VPN Full Meshes

Set Up See Monitor © 2022 Forcepoint | 14


Setting up, Seeing & Monitoring VPN Mixed Topologies

Set Up See Monitor © 2022 Forcepoint | 15


QoS and Traffic Prioritization

Provide better service to certain traffic by managing existing bandwidth more efficiently
Prioritize network communication in QoS policy per (VLAN) interface
Manage existing bandwidth more efficiently instead of buying additional bandwidth
Traffic classification can be used to select preferred tunnels in Multi-Link VPN

Mission Critical (Controls)

High Priority, Low Latency Traffic (VolP)

Low Priority Traffic (Web)

HEADQUARTERS BRANCH

© 2022 Forcepoint | 16
Multi-ISP WAN Clustering
Ability to cluster different network ISP links together and dynamically balance connections
between ISPs, transparently transferring connections from one ISP to another in case of a
failure
Easy and simple ISP multi-homing
Better service for users by selecting always the fastest link
Business Continuity
For inbound, outbound and VPN traffic
Forcepoint
NGFW

ISP 1

ISP 2

ISP 3
Internet
HEADQUARTERS ISP Link Failure
Automatic Link Failover

© 2022 Forcepoint | 17
Forcepoint Secure SD-WAN Achieves Top Ratings

Awarded ‘AA’ Rating by CyberRatings.org

© Forcepoint 2021 | Public 24


perior security included
Forcepoint

NGFW NGIPS SD-WAN


6 times in a row Top Security 100% Security
Top Security 2017 2018
2017, 2018

“The Forcepoint 2105 had the highest security


effectiveness in the NSS Labs 2018 NGFW
Group Test and its throughput was rated even
higher than Forcepoint’s claimed performance.”
NSS Labs 2018 NGFW Test
Vikram Phatak, CEO
NSS Labs

© 2022 Forcepoint | 25
Demo SD-WAN

ISP A Branch

20 Mbps DSL Internet

ISP B

50 Mbps CABLE
Office Branch

5 Mbps MPLS
Combined 75 Mbps with resilience and lower costs
Demo SD-WAN
Q&A

© 2022 Forcepoint | 28

You might also like