<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>StoneBlog.stonesoft.com &#187; Feature Previews</title>
	<atom:link href="http://stoneblog.stonesoft.com/category/feature-previews/feed/" rel="self" type="application/rss+xml" />
	<link>http://stoneblog.stonesoft.com</link>
	<description>Share knowledge about StoneGate</description>
	<lastBuildDate>Fri, 20 Jan 2012 11:06:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>StoneGate Authentication Server: Dynamic User Linking</title>
		<link>http://stoneblog.stonesoft.com/2011/07/stonegate-authentication-server-dynamic-user-linking/</link>
		<comments>http://stoneblog.stonesoft.com/2011/07/stonegate-authentication-server-dynamic-user-linking/#comments</comments>
		<pubDate>Thu, 07 Jul 2011 06:00:46 +0000</pubDate>
		<dc:creator>RoarinPenguin</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Feature Previews]]></category>
		<category><![CDATA[SMC]]></category>
		<category><![CDATA[AD]]></category>
		<category><![CDATA[Authentication Server]]></category>
		<category><![CDATA[MobileID]]></category>
		<category><![CDATA[Secure access to cloud]]></category>

		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3278</guid>
		<description><![CDATA[This post is deepening the ability of StoneGate Authentication Server to integrate transparently with existing user bases with a technique called dynamic user linking. The idea is to be able to pull information about user profiles from a wide range of directory servers and use dynamically these information to populate user accounts in StoneGate Authentication Server. [...]]]></description>
			<content:encoded><![CDATA[<p>This post is deepening the ability of StoneGate Authentication Server to integrate transparently with existing user bases with a technique called dynamic user linking.</p>
<p>The idea is to be able to pull information about user profiles from a wide range of directory servers and use dynamically these information to populate user accounts in StoneGate Authentication Server.</p>
<p><span id="more-3278"></span></p>
<p>Connection to the backend directory servers can be established using LDAP or LDAPS protocol as illustrated below:</p>
<p><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/07/Authentication-Server-User-Database-Integration.png"><img class="alignnone size-medium wp-image-3283" title="Authentication Server User Database Integration" src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/07/Authentication-Server-User-Database-Integration-274x300.png" alt="" width="274" height="300" /></a></p>
<p>Once a directory server is defined and linked, it is possible to activate Automatic User Linking. Using this technique, as soon as a user tries to authenticate with his password from the directory server, a user profile is automatically created and enabled with the desired strong authentication methods.</p>
<p>Passwords, PINs or other authentication related information are notified to the user in separated messages via mail or SMS.</p>
<p>Dynamic user linking is also possible in manual mode from Authentication Server User configuration (with dynamic typeahead search) or while browsing the content of a directory server in SMC GUI.</p>
<div id="attachment_3284" class="wp-caption alignnone" style="width: 310px"><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/07/ManualUserLinking-Typeahead.png"><img class="size-medium wp-image-3284" title="ManualUserLinking-Typeahead" src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/07/ManualUserLinking-Typeahead-300x188.png" alt="" width="300" height="188" /></a><p class="wp-caption-text">Dynamic Manual User Linking with Typeahead Search</p></div>
<div id="attachment_3285" class="wp-caption alignnone" style="width: 310px"><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/07/ManualUserLinkingFromLDAPBrowsing.png"><img class="size-medium wp-image-3285" title="ManualUserLinkingFromLDAPBrowsing" src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/07/ManualUserLinkingFromLDAPBrowsing-300x164.png" alt="" width="300" height="164" /></a><p class="wp-caption-text">Manual User Linking from LDAP Browse in SMC GUI</p></div>
<p>Dynamic User Linking reduce dramatically the time needed to define the user accounts and enable authentication, minimizing the TCO of the whole solution.</p>
<p>Strong Authentication! Simplified!</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://stoneblog.stonesoft.com/2011/07/stonegate-authentication-server-dynamic-user-linking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>StoneGate Authentication Server: Ergonomic Authentication</title>
		<link>http://stoneblog.stonesoft.com/2011/07/stonegate-authentication-server-ergonomic-authentication/</link>
		<comments>http://stoneblog.stonesoft.com/2011/07/stonegate-authentication-server-ergonomic-authentication/#comments</comments>
		<pubDate>Tue, 05 Jul 2011 06:00:55 +0000</pubDate>
		<dc:creator>RoarinPenguin</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Feature Previews]]></category>
		<category><![CDATA[SMC]]></category>
		<category><![CDATA[Authentication Server]]></category>
		<category><![CDATA[MobileID]]></category>
		<category><![CDATA[Secure access to cloud]]></category>

		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3263</guid>
		<description><![CDATA[Let&#8217;s start to analyze some of the important features of StoneGate Authentication Server, beginning with the concept of ergonomic authentication. The concept of ergonomics is defined in Oxford Dictionary as &#8220;The study of people&#8217;s efficiency in their working environment&#8221;. In StoneGate Authentication Server we applied this definition to innovative authentication methods, to make them designed [...]]]></description>
			<content:encoded><![CDATA[<p>Let&#8217;s start to analyze some of the important features of StoneGate Authentication Server, beginning with the concept of ergonomic authentication.</p>
<p>The concept of ergonomics is defined in <a href="http://oxforddictionaries.com/definition/ergonomics#m_en_gb0271960.005" target="_blank">Oxford Dictionary</a> as &#8220;The study of people&#8217;s efficiency in their working environment&#8221;.</p>
<p>In StoneGate Authentication Server we applied this definition to innovative authentication methods, to make them designed for human beings.</p>
<p>Ergonomic Authentication means to offer authentication methods based on several factors of strength, without impacting on the user&#8217;s natural way of using common devices he&#8217;s using daily, such as his mobile phone or smartphone or tablet.<span id="more-3263"></span>In Stonesoft we believe it is useless to force the user to carry additional devices just for the purpose of authenticating, hence we propose three methods to ease user&#8217;s life when requiring Radius-based strong authentication.</p>
<h3>StoneGate MobileID Synchronized</h3>
<p>Features 2 factors strong authentication with a software token available for a <a href="http://www.stonesoft.com/en/downloads/" target="_blank">wide variety of platforms</a>, including iPhone/iPad and Android devices.</p>
<p>Allows to use your smartphone or tablet also as a strong authentication device.</p>
<h3>StoneGate MobileID Challenge</h3>
<p>Same client of previous method can be also used to implement a 3 factors strong authentication.</p>
<p>The picture below clarifies the logic.</p>
<p><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/07/MobileID-logic.png"><img class="size-medium wp-image-3267 alignnone" title="MobileID-logic" src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/07/MobileID-logic-300x270.png" alt="" width="300" height="270" /></a></p>
<h3>StoneGate Mobile Text</h3>
<p>This feature allows the user to type in his username and a password. A One Time Password is then sent to the user&#8217;s mobile phone as shown in the picture below:</p>
<p><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/07/MobileText-logic.png"><img class="alignnone size-medium wp-image-3268" title="MobileText-logic" src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/07/MobileText-logic-300x249.png" alt="" width="300" height="249" /></a></p>
<p>These three Radius-based authentication techniques are included, together with a standard username/password pair one, in every StoneGate Authentication Server license.</p>
<p>Ergonomic Strong Authentication! Simplified!</p>
]]></content:encoded>
			<wfw:commentRss>http://stoneblog.stonesoft.com/2011/07/stonegate-authentication-server-ergonomic-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>StoneGate 5.3 &#8211; Other Enhancements</title>
		<link>http://stoneblog.stonesoft.com/2011/07/stonegate-5-3-other-enhancements/</link>
		<comments>http://stoneblog.stonesoft.com/2011/07/stonegate-5-3-other-enhancements/#comments</comments>
		<pubDate>Fri, 01 Jul 2011 06:00:14 +0000</pubDate>
		<dc:creator>Tero Jantunen</dc:creator>
				<category><![CDATA[Feature Previews]]></category>
		<category><![CDATA[Firewall Engine]]></category>
		<category><![CDATA[SMC]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[5.3]]></category>
		<category><![CDATA[ADSL]]></category>
		<category><![CDATA[Certificates]]></category>
		<category><![CDATA[Dynamic routing]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[SNMP agent]]></category>
		<category><![CDATA[WiFi]]></category>

		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3375</guid>
		<description><![CDATA[SMC 5.3.1 is now publicly available and FW/VPN 5.3.0 is also published as controlled shipment. I wanted to conclude the StoneGate 5.3 feature previews by listing the other significant enhancements that are introduced in version 5.3. More details can be found from SMC and FW Release Notes and product manuals. Improved SNMP Agent. SNMP agent [...]]]></description>
			<content:encoded><![CDATA[<table>
<tr>
<td>
SMC 5.3.1 is now publicly available and FW/VPN 5.3.0 is also published as controlled shipment. I wanted to conclude the <a href="http://stoneblog.stonesoft.com/tag/5-3/">StoneGate 5.3 feature previews</a> by listing the other significant enhancements that are introduced in version 5.3. More details can be found from SMC and FW <a href="https://my.stonesoft.com/support/browse.do?product=StoneGate&amp;browsetype=type&amp;selection=Release+Notes">Release Notes</a> and <a href="http://www.stonesoft.com/en/support/technical_support_and_documents/manuals/current/">product manuals</a>.
</td>
<td>
<a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/07/stonegate_logo.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/07/stonegate_logo.png" alt="StoneGate logo" title="stonegate_logo" width="153" height="142" class="alignnone size-full wp-image-3384" /></a>
</td>
</tr>
</table>
<p><span id="more-3375"></span></p>
<p><strong>Improved SNMP Agent</strong>. SNMP agent functionality in Firewal/VPN is enhanced with support for 64bit counter values and new trap types.</p>
<p><strong>Support for ADSL and WiFi Interfaces</strong>. You can now configure one Wireless Interface on each single firewall. The Wireless Interface can have one or two SSID (service set identifier) Interfaces that represent a wireless LAN. In addition to Wireless Interfaces, there is now possibility to configure ADSL interface for Single Firewall elements. Both ADSL and Wireless Interfaces are supported only on a few specific StoneGate appliance models.</p>
<p><strong>Dynamic routing enhancements</strong>. StoneGate Firewall/VPN and SMC version 5.3 provides enhanced (but still limited support) for dynamic routing. Supported protocols are <a href="http://www.faqs.org/rfcs/rfc1058.html">RIP version 1</a>, <a href="http://www.faqs.org/rfcs/rfc2453.html">RIP version 2</a>, <a href="http://www.faqs.org/rfcs/rfc2080.html">RIPng</a>, <a href="http://www.faqs.org/rfcs/rfc2328.html">OSPF version 2</a>, <a href="http://www.faqs.org/rfcs/rfc2740.html">OSPF version 3</a> and <a href="http://www.faqs.org/rfcs/rfc1771.html">BGP version 4</a>. Support for these protocols is implemented via <a href="http://www.quagga.net/docs.php">Quagga Software Routing Suite</a>.</p>
<p><strong>Longer IPsec certificates now supported</strong>. SMC 5.3 allows administrators to create longer IPsec certificate requests. The maximum key length of the certificate key is now 4096 bits instead of 2048 bits. The default key length is 2048 bits instead of 1024 bits. For GOST SMC versions the default value is still 1024 bits.</p>
<p><strong>Improved SMC scalability and performance</strong>. StoneGate Management Center can scale up to manage up to 1000 Firewall/VPN or IPS nodes. The performance of simultaneous policy uploads has been significantly improved, and the Log Server&#8217;s log reception rate has been increased. Additionally, communication between the Management Client and the Management Server has been optimized.</p>
<p><strong>New Online Help</strong>. The Java-based Online Help has been replaced with HTML Online Help that is located in the <a href="http://help.stonesoft.com/onlinehelp/StoneGate/SMC/5.3.1/SG_Online_Help.htm#SGAG/SGOH_GETTING_HELP/SGOH_GETTING_HELP.htm">public web site</a>. </p>
<p><strong>New option in Configure Updates and Upgrades dialog</strong>. Configure Updates and Upgrades dialog now contains the option to remind the administrator with an alert when a policy refresh is needed after successful update package activation. It is also possible to refresh the policies automatically.</p>
<p><strong>See who is currently editing the policy</strong>. SMC 5.3 shows in the policy tree-table and Info panel the name of the administrator who is currently editing the policy. Note that you can right-click the administrator and send an instant message to him/her directly from the Management Client.</p>
<p><strong>Administrator&#8217;s IP address visible in Info panel</strong>. You are now able to see the IP address of the client that an administrator has had when logging in to the Management Client. The IP address is shown in Info panel when you have selected an Administrator element.</p>
<p><strong>New Report templates</strong>. In SMC 5.3 there are new report templates for Anti-Virus and Application Usage.</p>
<p><strong>Zoomable Geolocation statistics</strong>. It is now possible to zoom in to Geolocation top rate statistics in Overviews and Log Statistics.</p>
]]></content:encoded>
			<wfw:commentRss>http://stoneblog.stonesoft.com/2011/07/stonegate-5-3-other-enhancements/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>StoneGate 5.3 &#8211; Authentication Server</title>
		<link>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-authentication-server/</link>
		<comments>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-authentication-server/#comments</comments>
		<pubDate>Thu, 30 Jun 2011 07:00:45 +0000</pubDate>
		<dc:creator>Tero Jantunen</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Feature Previews]]></category>
		<category><![CDATA[SMC]]></category>
		<category><![CDATA[5.3]]></category>
		<category><![CDATA[AD]]></category>
		<category><![CDATA[Authentication Server]]></category>
		<category><![CDATA[MobileID]]></category>
		<category><![CDATA[Secure access to cloud]]></category>

		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3241</guid>
		<description><![CDATA[Version 5.3.1 of StoneGate Management Center includes a brand new functionality which enables Stonesoft to become a player in Identity Management and Authentication arena: StoneGate Authentication Server. Built to answer the pressing need to secure the access to the cloud (no matter if it is a private or public one), StoneGate Authentication Server is completely [...]]]></description>
			<content:encoded><![CDATA[<table>
<tbody>
<tr>
<td>Version 5.3.1 of StoneGate Management Center includes a brand new functionality which enables Stonesoft to become a player in Identity Management and Authentication arena: StoneGate Authentication Server. Built to answer the pressing need to secure the access to the cloud (no matter if it is a private or public one), StoneGate Authentication Server is completely integrated in StoneGate Management Center from configuration, usability and backup/restore standpoint.</td>
<td><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/authentication_server1.png"><img class="alignnone size-thumbnail wp-image-3245" title="authentication_server" src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/authentication_server1-150x150.png" alt="Authentication Server logo" width="150" height="150" /></a></td>
</tr>
</tbody>
</table>
<p><span id="more-3241"></span></p>
<p>Available with an optional license per named users, it can be easily enabled on every installation of StoneGate Management Center from 5.3.1 onward, on same server of SMC or onto other servers and even in mirrored configuration to maximize availability.</p>
<table>
<tr>
<td>
It features four Radius based servers to provide ergonomic authentication methods. It can participate in Federated Authentication scenarios as Identity Provider and provides great log processing,  reporting and auditing information with geolocation thanks to its complete integration with SMC. Another very nice feature is transparent integration with a wide variety of user repositories (for example, MS Active Directory, Novell eDirectory, LDAPV3-based systems, etc) to perform automatic user linking.
</td>
<td>
<a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/mobile_id_clients.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/mobile_id_clients.png" alt="Mobile ID clients" title="mobile_id_clients" width="180" height="215" class="alignnone size-full wp-image-3393" /></a>
</td>
</tr>
</table>
<p>This means that users do not have to be imported or redefined in Authentication Server, but they are generated as they are taken into use, with automatic notification via mail/sms of passwords, PIN, seeds or whatever else is needed to activate automatically the desired authentication method for a user account.</p>
<p><a href="http://www.stonesoft.com/en/downloads/"><img class="alignnone size-full wp-image-3250" title="free_mobileid_download" src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/free_mobileid_download.png" alt="Download MobileID for free" width="252" height="112" /></a></p>
<p>StoneGate Authentication Server is also a part of StoneGate Authentication Solution, that is the combination of StoneGate Authentication Server and StoneGate SSL VPN to achieve highly secured access to the cloud, complete with multiple access criteria and authentication methods combined, plus verification of connecting client security posture and single sign-on.</p>
<p>Secured Access to the Cloud. Simplified!</p>
]]></content:encoded>
			<wfw:commentRss>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-authentication-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>StoneGate 5.3 &#8211; Anti-Spam</title>
		<link>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-anti-spam/</link>
		<comments>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-anti-spam/#comments</comments>
		<pubDate>Tue, 28 Jun 2011 07:00:26 +0000</pubDate>
		<dc:creator>Tero Jantunen</dc:creator>
				<category><![CDATA[Feature Previews]]></category>
		<category><![CDATA[Firewall Engine]]></category>
		<category><![CDATA[SMC]]></category>
		<category><![CDATA[5.3]]></category>
		<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[DNSBL]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[UTM]]></category>

		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3363</guid>
		<description><![CDATA[StoneGate Firewall 5.3 contains a new integrated Anti-Spam feature that complements the StoneGate UTM feature portfolio. The Anti-Spam feature has been developed in-house and contains a lot of different algorithms and tools for spam detection. It suits well for example small MSSP customers that have a single firewall and own email domain. The fundamental idea [...]]]></description>
			<content:encoded><![CDATA[<table>
<tr>
<td>
StoneGate Firewall 5.3 contains a new integrated Anti-Spam feature that complements the StoneGate UTM feature portfolio. The Anti-Spam feature has been developed in-house and contains a lot of different algorithms and tools for spam detection. It suits well for example small MSSP customers that have a single firewall and own email domain.
</td>
<td>
<a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/anti-spam_logo.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/anti-spam_logo.png" alt="Anti-Spam" title="anti-spam_logo" width="160" height="148" class="alignnone size-full wp-image-3364" /></a>
</td>
</tr>
</table>
<p><span id="more-3363"></span></p>
<p>The fundamental idea of StoneGate Anti-Spam is that each incoming e-mail is assigned a score to determine the likelihood of its being spam. The user can alter the score thresholds 1) after which the firewall will add SPAM prefix to the message subject and 2) after which the firewall will reject the message.</p>
<p><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/anti-spam_settings_scoring.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/anti-spam_settings_scoring.png" alt="Anti-Spam scoring" title="anti-spam_settings_scoring" width="492" height="289" class="alignnone size-full wp-image-3369" /></a></p>
<p>The system uses many different functions and algorithms for spam detection including:</p>
<ul>
<li>Local Antispoofing and Anti-Relay</li>
<li>Honeypot filtering</li>
<li>SPF/MX record matching</li>
<li>DNS-based blackhole lists</li>
<li>Envelope and Header fields</li>
<li>Email Content</li>
</ul>
<p>In addition to score based spam detection it is possible to mark email as spam, discard, reject, blacklist and graylist based on any envelope field, header field or email payload. The values can be input either as plain text or regular expressions. If none of these custom rules matches the received email message, then the scoring is used to make the decision whether the message is allowed, blocked or marked as spam.</p>
<p><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/anti-spam_settings_rules1.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/anti-spam_settings_rules1.png" alt="Anti-Spam rules" title="anti-spam_settings_rules" width="497" height="257" class="alignnone size-full wp-image-3404" /></a></p>
<p>The Anti-Spam licenses will be published later in autumn 2011. The product can be already evaluated with StoneGate Firewall 5.3.0 and SMC 5.3.0.</p>
]]></content:encoded>
			<wfw:commentRss>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-anti-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>StoneGate 5.3 &#8211; VPN enhancements</title>
		<link>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-vpn-enhancements/</link>
		<comments>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-vpn-enhancements/#comments</comments>
		<pubDate>Mon, 27 Jun 2011 07:00:10 +0000</pubDate>
		<dc:creator>Tero Jantunen</dc:creator>
				<category><![CDATA[Feature Previews]]></category>
		<category><![CDATA[SMC]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[5.3]]></category>
		<category><![CDATA[IKEv2]]></category>
		<category><![CDATA[SA]]></category>
		<category><![CDATA[troubleshooting]]></category>

		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3329</guid>
		<description><![CDATA[Internet Key Exchange (IKE or IKEv2) is the protocol used to set up a security association (SA) in the IPsec protocol suite. StoneGate FW/VPN 5.3 introduces the support for IKEv2 (in addition to IKEv1) in VPN configuration. IKEv2 includes the support for IKEv2 Mobility and Multihoming Protocol (MOBIKE). MOBIKE enables transparent recovery for VPN clients [...]]]></description>
			<content:encoded><![CDATA[<table>
<tr>
<td>
Internet Key Exchange (<a href="http://tools.ietf.org/html/rfc2409">IKE</a> or <a href="http://tools.ietf.org/html/rfc4306">IKEv2</a>) is the protocol used to set up a security association (SA) in the IPsec protocol suite. StoneGate FW/VPN 5.3 introduces the support for IKEv2 (in addition to IKEv1) in VPN configuration. IKEv2  includes the support for IKEv2 Mobility and Multihoming Protocol (MOBIKE). MOBIKE enables transparent recovery for VPN clients if the IP address of the VPN client or the IP address of the gateway to which the VPN client is connected changes in the middle of an open VPN connection.
</td>
<td>
<a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/vpn1.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/vpn1.png" alt="IKEv2 support" title="vpn" width="135" height="160" class="alignnone size-full wp-image-3334" /></a>
</td>
</tr>
</table>
<p><span id="more-3329"></span></p>
<table>
<tr>
<td>
In addition to IKEv2 support, StoneGate 5.3 provides also nice new tools for VPN troubleshooting. The new VPN data type allows you to quickly navigate into VPN logs in StoneGate Management Center&#8217;s Log Browser. Limiting the logs to VPN data type also affects the column selection, available filters and log statistics, so all the necessary tools for VPN troubleshooting are now more easily accessible. Remember also that now there are the <a href="http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-vpn-sa-monitoring/">VPN SA monitoring</a> view where you can see all the negotiated VPN Security Associations and <a href="http://stoneblog.stonesoft.com/2011/05/stonegate-5-3-authenticated-user-monitoring/">Authenticated User Monitoring</a> view that lists also active IPsec VPN client users.
</td>
<td>
<a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/vpn_data_type1.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/vpn_data_type1.png" alt="VPN data type" title="vpn_data_type" width="224" height="261" class="alignnone size-full wp-image-3339" /></a>
</td>
</tr>
</table>
<p></p>
]]></content:encoded>
			<wfw:commentRss>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-vpn-enhancements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>StoneGate 5.3 &#8211; Multi-Link VPN enhancements</title>
		<link>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-multi-link-vpn-enhancements/</link>
		<comments>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-multi-link-vpn-enhancements/#comments</comments>
		<pubDate>Thu, 23 Jun 2011 07:00:24 +0000</pubDate>
		<dc:creator>Tero Jantunen</dc:creator>
				<category><![CDATA[Feature Previews]]></category>
		<category><![CDATA[MultiLink VPN]]></category>
		<category><![CDATA[SMC]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[5.3]]></category>
		<category><![CDATA[Aggregation]]></category>
		<category><![CDATA[multilink]]></category>
		<category><![CDATA[QoS]]></category>
		<category><![CDATA[Throughput]]></category>
		<category><![CDATA[traffic balancing]]></category>
		<category><![CDATA[VoIP]]></category>

		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3308</guid>
		<description><![CDATA[StoneGate FW/VPN and SMC 5.3 provide a couple of nice enhancements related to StoneGate&#8217;s unique Multi-Link feature. VPN Multi-Link aggregation provides the ability to spread traffic evenly to all active VPN links. With this feature you can achieve higher VPN throughput by effectively making sure that all connections use all active VPN links. The achieved [...]]]></description>
			<content:encoded><![CDATA[<p>StoneGate FW/VPN and SMC 5.3 provide a couple of nice enhancements related to StoneGate&#8217;s unique <a href="http://www.stonesoft.com/en/products/fw/isp_load_balancing/">Multi-Link</a> feature.</p>
<p><span id="more-3308"></span></p>
<p><strong>VPN Multi-Link aggregation</strong> provides the ability to spread traffic evenly to all active VPN links. With this feature you can achieve higher VPN throughput by effectively making sure that all connections use all active VPN links. The achieved aggregated throughput is optimized when ADSL lines are very similar in throughput and latency. In practice, the VPN link aggregation feature will cause some packet reordering that slightly decreases the theoretical max throughput. (It is much up to the TCP connection endpoint’s TCP stack behavior how packet reordering will affect to the throughput).</p>
<p><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/multi-link_vpn_aggregation2.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/multi-link_vpn_aggregation2.png" alt="Multi-Link VPN Aggregation" title="multi-link_vpn_aggregation" width="495" height="141" class="alignnone size-full wp-image-3352" /></a></p>
<table>
<tr>
<td>
<strong>QoS Based Multi-Link Selection</strong>: In StoneGate 5.3 it is also possible to classify VPN traffic with QoS classes and select the VPN Multilink tunnel based on this QoS classification. This feature lets you to configure e.g. VoIP traffic in one VPN link and other type of traffic to some other VPN link(s). This complements nicely the other VPN Multi-Link traffic balancing methods earlier described <a href="http://stoneblog.stonesoft.com/2008/12/how-traffic-is-balanced-in-multilink-vpn/">here</a>.
</td>
<td>
<a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/qos_based_multi-link_selection2.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/qos_based_multi-link_selection2.png" alt="QoS based Multi-Link selection" title="qos_based_multi-link_selection" width="150" height="130" class="alignnone size-full wp-image-3318" /></a>
</td>
</tr>
</table>
<p></p>
]]></content:encoded>
			<wfw:commentRss>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-multi-link-vpn-enhancements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>StoneGate 5.3 &#8211; Automatic initial policy installation</title>
		<link>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-automatic-initial-policy-installation/</link>
		<comments>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-automatic-initial-policy-installation/#comments</comments>
		<pubDate>Wed, 22 Jun 2011 06:45:07 +0000</pubDate>
		<dc:creator>Tero Jantunen</dc:creator>
				<category><![CDATA[Feature Previews]]></category>
		<category><![CDATA[SMC]]></category>
		<category><![CDATA[5.3]]></category>
		<category><![CDATA[automatic policy push]]></category>
		<category><![CDATA[Initial configuration]]></category>
		<category><![CDATA[Policy]]></category>

		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3235</guid>
		<description><![CDATA[In StoneGate 5.3, you can now predefine the policy to be installed on the firewall engine after it has contacted the Management Server for the first time. With this small enhancement the administrators can make sure that the devices start working in a planned way right from the beginning without the need of someone waiting [...]]]></description>
			<content:encoded><![CDATA[<p>In StoneGate 5.3, you can now predefine the policy to be installed on the firewall engine after it has contacted the Management Server for the first time. With this small enhancement the administrators can make sure that the devices start working in a planned way right from the beginning without the need of someone waiting at HQ to be ready to upload the correct security policy for the device once it is deployed. </p>
<p><span id="more-3235"></span></p>
<p><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/initial_policy_push.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/initial_policy_push.png" alt="Initial policy push" title="initial_policy_push" width="484" height="438" class="alignnone size-full wp-image-3236" /></a></p>
<p>Note that administrators can still change the security policy after the initial configuration has been stored in USB stick or Installation Server. When saving the initial configuration, you just define which security policy the appliance should use. The most recent version of that policy will get installed to the appliance after it has successfully made the initial contact with the Management Server.</p>
<p>The automatic initial policy push feature can be used directly from &#8220;Save Initial Configuration&#8221; dialog or as part of the new <a href="http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-firewall-element-creation-wizard/">FW element creation wizard</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-automatic-initial-policy-installation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>StoneGate 5.3 &#8211; CEF log format support</title>
		<link>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-cef-log-format-support/</link>
		<comments>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-cef-log-format-support/#comments</comments>
		<pubDate>Mon, 20 Jun 2011 10:00:54 +0000</pubDate>
		<dc:creator>Tero Jantunen</dc:creator>
				<category><![CDATA[Feature Previews]]></category>
		<category><![CDATA[SMC]]></category>
		<category><![CDATA[5.3]]></category>
		<category><![CDATA[ArcSight]]></category>
		<category><![CDATA[CEF]]></category>
		<category><![CDATA[Log forwarding]]></category>
		<category><![CDATA[logs]]></category>
		<category><![CDATA[Third-Party Monitoring]]></category>

		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3222</guid>
		<description><![CDATA[StoneGate Log Server can be configured to forward StoneGate Firewall/VPN and IPS logs in Common Event Format (CEF) to ArcSight. This streamlines and simplifies the integration of StoneGate product family event logs with the Arcsight Security Information and Event Management (SIEM) solution. Stonesoft is one of the first security vendors to offer full CEF support. [...]]]></description>
			<content:encoded><![CDATA[<p>StoneGate Log Server can be configured to forward StoneGate Firewall/VPN and IPS logs in <a href="http://www.arcsight.com/solutions/solutions-cef/">Common Event Format (CEF)</a> to ArcSight. This streamlines and simplifies the integration of StoneGate product family event logs with the Arcsight Security Information and Event Management (SIEM) solution. Stonesoft is one of the first security <a href="http://www.arcsight.com/index.php/partners/tech-partners">vendors</a> to offer full CEF support.</p>
<p><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/TAP_Affiliate_Color_RGB_LargeWeb.gif"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/TAP_Affiliate_Color_RGB_LargeWeb.gif" alt="ArcSight CEF-partner" title="TAP_Affiliate_Color_RGB_LargeWeb" width="227" height="155" class="alignnone size-full wp-image-3223" /></a></p>
<p><span id="more-3222"></span></p>
<p>There is also a new Logging Profile that allows you to easily receive logs from other vendors&#8217; products that are CEF compatible. This makes StoneGate Management Center&#8217;s Third Party event management easier from customer point of view because there is no need to define specific logging profiles anymore for those devices that can send the logs in CEF format. In addition to CEF, StoneGate Management Center has <a href="http://stoneblog.stonesoft.com/2010/01/stonegate-5-1-3rd-party-monitoring-enhancements/">predefined logging profiles</a> for <a href="http://en.wikipedia.org/wiki/Common_Log_Format">CLF</a> and WELF as well.</p>
]]></content:encoded>
			<wfw:commentRss>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-cef-log-format-support/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>StoneGate 5.3 &#8211; Firewall element creation wizard</title>
		<link>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-firewall-element-creation-wizard/</link>
		<comments>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-firewall-element-creation-wizard/#comments</comments>
		<pubDate>Thu, 16 Jun 2011 07:00:49 +0000</pubDate>
		<dc:creator>Tero Jantunen</dc:creator>
				<category><![CDATA[Feature Previews]]></category>
		<category><![CDATA[Firewall Engine]]></category>
		<category><![CDATA[SMC]]></category>
		<category><![CDATA[5.3]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[Plug and play]]></category>
		<category><![CDATA[Wizard]]></category>

		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3196</guid>
		<description><![CDATA[To make the mass deployment scenarios even more convenient from the administrator point of view, StoneGate 5.3 introduces a new &#8220;Create Multiple Single Firewalls&#8221; wizard. With that wizard the administrator can create hundreds of Single Firewall and Internal Gateway elements. In the end of the wizard, you can optionally upload the initial configurations to be [...]]]></description>
			<content:encoded><![CDATA[<table>
<tr>
<td>
To make the mass deployment scenarios even more convenient from the administrator point of view, StoneGate 5.3 introduces a new &#8220;Create Multiple Single Firewalls&#8221; wizard. With that wizard the administrator can create hundreds of Single Firewall and Internal Gateway elements. In the end of the wizard, you can optionally upload the initial configurations to be available for <a href="http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-plug-play-installation/">Plug &#038; Play installation</a>.
</td>
<td>
<a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/single_fw_wizard2.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/single_fw_wizard2.png" alt="Firewall element creation wizard" title="single_fw_wizard" width="218" height="172" class="alignnone size-full wp-image-3204" /></a>
</td>
</tr>
</table>
<p>The end result is that the administrator can set up hundreds of Firewalls ready to be deployed in a few minutes. And the appliances can actually be delivered directly to the remote office &#8211; the administrators don&#8217;t even need to open the appliance boxes before they are deployed.</p>
<p><span id="more-3196"></span></p>
<p>The most convenient way to launch the wizard is to copy-paste the POS codes from the order confirmation email to the first page of the wizard in the SMC. The serial numbers of the devices are appended to each element name by default. Once you know which appliance has been sent to which location it makes sense to rename the Firewall element with more meaningful name. That can be done already as part of the wizard before elements are created.</p>
<p><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/single_fw_wizard_pos_codes.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/single_fw_wizard_pos_codes.png" alt="Launch the wizard by copy-pasting the POS codes" title="single_fw_wizard_pos_codes" width="495" height="377" class="alignnone size-full wp-image-3209" /></a></p>
<p>In the wizard you basically define the same settings what you need to configure for individual Single Firewall element. The only difference is that those settings are automatically applied to all firewalls you create with the wizard. You can also create Internal Gateway elements as part of the wizard to make the initial VPN configuration smoother.</p>
<p><a href="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/single_fw_wizard_interface_configuration.png"><img src="http://stoneblog.stonesoft.com/wp-content/uploads/2011/06/single_fw_wizard_interface_configuration.png" alt="Firewall element configuration wizard - Interface configuration" title="single_fw_wizard_interface_configuration" width="495" height="314" class="alignnone size-full wp-image-3210" /></a></p>
<p>What comes to interface configuration, you need to have at least one dynamic interface per firewall that is used as default route to Internet. You can select that interface as separate part of the wizard. It also makes sense to create Firewall elements for same type of appliances at once because they may contain different amount of interfaces for example. Note that in addition to regular Ethernet, VLAN and 3G interfaces, StoneGate FW/VPN contains now also WiFi and ADSL interfaces that you can also configure as part of the wizard.</p>
<p>Remember that SMC provides excellent tools for further management of hundreds of firewalls. You can utilize the new <a href="http://stoneblog.stonesoft.com/2011/05/stonegate-5-3-access-control-by-zones/">Zone based policy configurations</a>, Aliases, Sub-Policies, Policy Templates, editing of common properties, flexible search capabilities, category filters, and of course automatic updates and upgrades</a> designed especially for managing large customer deployments.</p>
]]></content:encoded>
			<wfw:commentRss>http://stoneblog.stonesoft.com/2011/06/stonegate-5-3-firewall-element-creation-wizard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

