Firewall-Systeme (engl.)
Watchguard Firebox X5500e
To secure servers and network, the high capacity firewall “Watchguard Firebox X5500e” was implemented. Its task is to protect networks and single hosts respectively from attacks from other networks. The applications of the IWI are versatile. For the configuration a compromise between maximum security and maximum accessibility is made. Hence the optimal configuration is only possible by extensive discussion. By from the administrator pre-defined complex security policies the firewall controls which network traffic is permitted or blocked.
Furthermore passing network traffic is checked about malicious code. If single computers behave unsteady compared to the network, the firebox detects this and blocks the incoming data traffic. Unified Threat Management (Firewall-) Solutions (UTM) like the Watchguard Firebox provides also comprehensive protection against spyware, Trojans, bots, viruses, spam and so on. Constant updates secure that newly detected threats could be identified and blocked within briefest time by the UTM-solution. The Firebox X5500e is equipped with 8 network ports, which could be connected to different networks. It distinguishes between the unsecure and public link, a trusted link for internal communication, a management link, a trusted and so-called demilitarized zone and some more optional links.
Panda Gatedefender
This virus-wall was purchased to protect the exchange server of the IWI. The exchange server is the strategic important network spot, which is used to send and receive emails and every description of web content. In place the Gatedefender applies, it secures the system before viruses could reach the communications server. Encrypted connections become cleaned from malicious code by Symantec Antivirus for Exchange in second instance.
- Automatic updates. The signature file is updated every 4 hours.
- Complete protection. Scan of the most used protocols (HTTP, SMTP, POP3, IMAP4, FTP, and NNTP).
- Anti-spam. Blocks unwanted mails before they reach the network.
- Web-filtering. Access on websites and inadequate content respectively is manageable.
- Content-filtering. Blocks potential dangerous contents.
- High scalability and load-balancing. Matches the scan capacity to the total volume of network traffic.
- Detailed reports and customizable alert messages.
- Real-time monitoring of the network traffic and activity statistics of the antivirus-protection
Virtual Firewall URZ of the University of Leipzig
The URZ of the University of Leipzig Institute offers the possibility
of a virtual firewall. This is a special system on backbone
routers. Several instances are operated firewall can thus
simultaneously and independently managed. The URZ provides the basic
configuration, which adapt the administrators of the institution's
needs individually.
The technical implementation is a Cisco Catalyst 6500 Switch with Cisco 7600 Series Router Firewall Services Modules.
Contact: G. Hennig, U. Tönjes, University Computer Center at the
University of Leipzig







