Users & Access Security – DCS Website
 
 
 
 
 

  Web Security

 
 
Forcepoint Web Security Architecture
Forcepoint uses a distributed enforcement architecture so that organizations have more flexibility to meet changing business requirements. Forcepoint Web Security allows for enforcement using either the forward proxy (cloud, on-prem, or hybrid) for sites and branch offices or the unique agent-based proxy for managed devices. With the forward proxy, organizations can provide all users at sites, even guests and those on unmanaged devices, with reliable, safe web access as well as remote users on managed devices.

Key Benefits:

  • 99.999% uptime SLA
  • Smart steering pivots from web proxy to direct connection to minimize latency and maximize throughput without sacrificing security
  • Multiple real-time content engines analyze full web page content, active scripts, web links, contextual profiles, files and executables for the ultimate protection
  • SCIM provisioning accelerates user on-boarding
  • Data-in-motion scanning blocks malware and data exfiltration between users and any web application, no matter where they are located.
  • RBI with CDR enables safe use of unknown websites and safe use of files downloaded from those websites
  • Controls website access down to the URL directory level
  • SWG function cannot be bypassed or disabled by the user
 
FortiProxy – Secure Web Gateway
FortiProxy brings comprehensive web security for threat prevention, SaaS access security, and data protection.FortiProxy is a high-performance secure web gateway that safeguards employees from online threats through advanced filtering and inspection. It integrates URL filtering, DLP with OCR, application control, inline CASB, intrusion prevention, and content analysis in one solution. With image analysis, SSL decryption, and high scalability, FortiProxy ensures continuous protection for users.
 
Sangfor Internet Access Gateway
Sangfor IAG enables you to identify, analyze and take immediate action upon user internet access behavior. Gain full visibility to find any bad behavior in encrypted traffic. Uncover user identity with analytics into who is using what applications and when it is used on your network. Take full control to increase user productivity by ensuring internet access compliance.Product Advantages

Proxy Avoidance Protection:
Web filters are commonly used by the organization to restrict user internet access to certain web application content, and it has increasingly become non-effective against proxy avoidance applications. IAG collaborates with Endpoint Secure to enforce Proxy Avoidance Protection on any user attempt to use this application for bypassing the security perimeter more effectively. The R&D team within Sangfor employs a dedicated team of application signatures security experts who are continuously categorizing and adding the latest proxy avoidance applications to ensure that detection rate and blocking capabilities are current and up to date.

Intelligent Traffic Management
Sangfor IAG improves bandwidth utilization by more than 30% using three unique major traffic management solutions. Dynamic Traffic Control automatically adjusts traffic control policies and intelligently allocates idle bandwidth resources. Intelligent Flow Control manages both up-link and down-link P2P traffic and can customize traffic “packages” for different users, allocating specific traffic quotas and limiting bandwidth for heavier users.

Gateway and Client Decryption to Uncover Encrypted Traffic
Typically, most of the internet traffic is protected by SSL/TLS encryption. While encryption helps to keep user and corporate data protected and private, it also creates security challenges when it comes to the rapid growth of malware infections and other malicious content. Sangfor IAG offers both decryption methods including gateway and client decryption to overcome these challenges. This enables an organization to have the flexibility to run either one or both in parallel to uncover encrypted traffic according to your corporate IT strategy and planning.

Unified Network-wide Management of all Clients
Sangfor IAG provides Unified Management and effectively controls both Wired and Wireless networks for the entire network. With intuitive and flexible authentication methods, it fully guarantees the security of access control, supporting a variety of traditional authentication methods such as username/password, IP/MAC binding, and a wide array of value-added marketing authentication methods (QR code, SMS, WeChat, social media, OA account, SAML 2.0, third-party system, etc.). Permissions are controlled based on user, application, location, and client types while using IAG or third-party wireless controller as a unified authentication server, building a faster and more cost-effective wireless network.

Precise and Accurate Application Control
Sangfor IAG manages and controls network applications more comprehensively, accurately, and conveniently with the largest application signature database in Asia, which can identify more than 6,000+ applications in its database including 700+ cloud applications, 1,000+ mobile applications, 300+ web applications, and is updated every 2 weeks. In addition, it precisely controls applications according to their specific functions, such as distinguishing upload, download, and other actions in the network. Finally, bulk management mode for large enterprises greatly improves management efficiency.

Offloading Performance When Using ICAP Integration with Third-Party System
Sangfor IAG can act as an ICAP client to be used with any ICAP server-enabled network appliance by offloading threat protection or other value-added services. In addition, Sangfor IAG provides request and response inspection mode while enabling the ICAP server group to run on a round-robin or concurrent condition.

Secure Onboarding Devices with Endpoint Compliance Check
Sangfor IAG identifies and secures endpoint devices with or without agents, it helps to ensure these devices are connected with compliance and security. You gain visibility and control of what is in your environment without impacting your network performance.

 
 
 
 

Email Security

Endpoint Security

NAC (Network Access Control)

Web Security