January 28, 2008
Hitachi Cable develops AccessDefender next-generation network security system incorporating the iUTM concept
- New model in the Apresia authentication switch series features AccessDefender -
Following its recent development of the AccessDefender next-generation network security system, Hitachi Cable, Ltd. plans to launch sales of Apresia4328GT, a new model in the Apresia*1 line of authentication switches, on February 1.
Recent years have seen growing awareness of security issues related to corporate data networks, leading not only to various measures to protect corporate networks against external attacks, but to measures to ensure the security of network connections from within the company, a domain previously considered secure. The latter includes infections involving viruses originating from inadequately secured PCs, information leaks by users not authorized to connect to the network, and unauthorized network use.
UTM*2, a popular assessment solution that assesses the potential for external attacks on corporate networks, integrates multiple functions conventionally provided by separate devices, including firewall and VPN. UTM appliances simplify the introduction of security measures and provide various advanced functions. Hitachi Cable has applied the UTM concept to internal network security, proposing an iUTM (Internal UTM) concept that integrates and implements security functions for network access originating from within the company. AccessDefender, developed concurrently by Hitachi Cable, realizes the iUTM concept to create a network security system integrating various security functions into a single unit offering network authentication as a core function and implementing a functionality and operability unique to integrated environments.
As a core network authentication function, AccessDefender supports the international IEEE 802.1X authentication standard*3, WEB authentication*4, and MAC authentication*5, with a proven track record in Hitachi Cable's unique ApresiaNA authentication system, as well as gateway authentication based on IP addresses.
The integrated security functions include authentication bypass functions, permitting communications that meet specific conditions regardless of authentication conditions; a LAN sniffing prevention function that guards against data sniffing across the network when malicious users achieve authentication; an IP address spoofing prevention function that keeps users from using the IP address of another user without permission; and a terminal number control function that controls the number of terminals that can be authenticated per port or per Apresia unit. (Please refer to the [Comparison of security functions for AccessDefender and conventional Apresia].)
Incorporating all these functions, AccessDefender makes it easy to establish networks with improved security, while the integration of these security functions in AccessDefender provides a simpler setting and operating environment than conventional methods, reducing burdens on network administrators.
AccessDefender will be available in Apresia switches starting with the Apresia4328GT, scheduled to be released February 1.
The Apresia4328GT is an Ethernet switch*6 featuring low power consumption and low noise, characteristics in high demand. It provides 4 SFP*7 ports supporting 1000BASE-X and 24 ports supporting 10BASE-T/100BASE-TX/1000BASE-T in a 1U case (4.5 cm high and mountable in a 19-inch rack).
All 28 ports support gigabit Ethernet, while 55 W power consumption is realized by modifying components. It adopts a semi-fanless design designed for low noise generation. The semi-fanless design operates the cooling fan based on the load placed on the switch or ambient temperatures, operating only when needed and thereby minimizing noise generated by the device. This gives companies using Apresia4328GT much greater latitude in selecting an installation site.
Apresia4328GT is the first model among Apresia series in which all ports support gigabit Ethernet to adopt the semi-fanless design.
Hitachi Cable plans to incorporate AccessDefender into future releases of the Apresia13000-48X, Apresia4348GT, and Apresia4348GT-PSR, models already on the market, as well as in new Apresia models developed and marketed in the future.
Hitachi Cable anticipates sales of 12 billion yen for the Apresia series in Fiscal 2009.
| *1 | Apresia is a registered trademark of Hitachi Cable, Ltd. |
| *2 | UTM is a single-unit security system that integrates multiple functions, including firewall, VPN, anti-virus, anti-spyware, and intrusion detection and prevention. UTM is an abbreviation for Unified Threat Management. |
| *3 | IEEE802.1X is an authentication standard established by the IEEE (US Institute of Electrical and Electronics Engineers, Inc.) to control access to each port, based primarily on authentication by RADIUS (authentication system developed by Livingston Enterprises, Inc.) servers. It provides standard compatibility with the Windows 2000 and XP operating systems. Windows is a registered trademark of Microsoft Corporation in the US. |
| *4 | WEB authentication provides user authentication independent of client operating systems through Web interfaces. |
| *5 | MAC authentication authenticates terminals based on MAC addresses. |
| *6 | Ethernet is a product name of Xerox Corp. Ethernet is a registered trademark of Fuji Xerox Co., Ltd. in Japan. |
| *7 | SFP is an abbreviation for Small Form factor Pluggable. |
 |
 |
Comparison of security functions of AccessDefender and conventional Apresia |
| |
AccessDefender |
Security functions provided by conventional Apresia |
| Authentication functions supported |
IEEE802.1X |
Supported |
Supported |
| WEB authentication |
Supported |
Supported (by ApresiaNA) |
| MAC authentication |
Supported |
Supported (by ApresiaNA) |
| Gateway authentication |
Supported (available soon) |
Not supported |
| Authentication bypass function |
Supported |
Not supported |
| LAN sniffing prevention function |
Supported by DHCP snooping function(Concurrent use with network authentication to be supported soon) |
Can be supported by DHCP snooping functionConcurrent use with ApresiaNA not possible |
| IP address spoofing prevention function |
Supported by DHCP snooping function(Concurrent use with network authentication to be supported soon) |
Can be supported by DHCP snooping functionConcurrent use with ApresiaNA not possible |
| Terminal number control function per Apresia unit or port |
Possible |
Not possible |
| Other |
Easy settings for various functions |
- |
|
 |
 |
Major specifications for Apresia4328GT |
(Specifications subject to change without notice)
| Item |
Specifications |
| Basic configuration |
Main unit |
| Interface |
SFP(SW)x4(SFP module is an option available at extra cost.)10-T/100-TX/1000-T(SW)x24 |
| Power supply |
100-120/200-240 VAC 50-60Hz |
| Power consumption |
55W or less |
| Approximate mass |
6kg or less |
| External dimensions |
436mm(W)x342mm(D)x43.8mm(H) |
| Operating temperature |
0 to +50°C |
|
 |
 |
External appearance of Apresia4328GT |