INTRODUCTION
Thank you for choosing Stormshield Network. Designed to protect networks of all sizes,
Stormshield Network - SN range appliances are pre-configured: no hardware or software
installation is needed and no UNIX knowledge is necessary, just a user-friendly configuration via
a graphical interface.
The Stormshield Network (SN) range consists of twelve products:
SN160, SN160W, SN210, SN210W, SN310, SN510, SN710, SN910, SN2100, SN3100, SN6100
and SNi40.
The architecture of the new-generation SN range was specifically designed to maximize the
performance of the Stormshield Network protection engine. Complex application traffic is therefore
inspected at high speed at the heart of the network and without discernible latency (less than 1
millisecond).
Hardware acceleration for data encryption also anticipates the multiplication of high-speed VPN
access.
The SN Firewall allows the definition of incoming or outgoing access control rules. Its concept is
simple: any incoming or outgoing transmission passing through the Firewall is monitored,
authorized or denied according to the rules, packet by packet.
The SN Firewall is based on a sophisticated packet filtering mechanism that provides a high level
of security. All Firewalls integrate the ASQ (Active Security Qualification) technology developed by
Stormshield Network Security. This technology allows detecting and blocking hacking attempts
in real time illegal packets, denial of service attempts, anomalies in a connection, port scans,
buffer overflows, etc.
In the event of an intrusion attempt, depending on the instructions given in the security policy,
the SN Firewall blocks the transmission, generates an alarm and stores the information linked to
the packet which had set off the alarm. As such, you would be able to analyze the attack and
trace its source.
The SN Firewall not only allows preventing, or restricting to just certain services, incoming
connections on your network, but also allows monitoring the use of the Internet by your internal
users (HTTP, FTP, SMTP, etc.). You may also monitor your users by authenticating them via an
internal or external authentication database.
The SN Firewall also manages port and address translation mechanisms. These mechanisms
provide security (by masking your internal address range) and flexibility (by enabling the use of
any private internal addressing range) and reduce costs (by enabling the provision of several
servers on the Internet with a single public IP address).
SNS - PRODUCT PRESENTATION AND INSTALLATION 2019
INTRODUCTION
Page 6/66 sns-en-SNrange_installation_guide-2019 - 09/2019