Gibraltar

 
Gibraltar

Formerly known as Ronin NG, Gibraltar is a firewall and a router based on Debian/GNU Linux taking advantage of the latest technologies in terms of information system protection. Gibraltar is independent of the connection type (ADSL, RTC, ISDN, dedicated line) and it provides secured connections.
Therefore you can focus on the most important thing, without worrying about anything else: your business!
 
 

Main features of Gibraltar 2.4

  • Stateful firewall: Gibraltar’s core protects your business from main outer risks.
  • VPN gateway: safely, you can remotely log onto the local network and you can also interconnect different sites at a very low cost..
  • Anti-Virus gateway: Gibraltar filters all the web and mail traffic, thanks to Kaspersky virus scanner.
  • Anti-Spam gateway: how many unsolicited emails do you receive every day? Gibraltar filters 95% of spam emails.
  • Proxy server: control, protect, and speed up your internet.
  • Trafic shaping: share your internet connection effectively and optimize your bandwidth.
  • Anonymization gateway: Gibraltar makes you network traffic anonymous.
  • And more!

Why choosing Gibraltar?

All-in-one package

Gibraltar is a technological combo. Forget about multiple gateways and licences, as well as recurrent costs. Gibraltar is a compact noiseless box including all the essential solutions to a confident internet use within your company. You can also choose a rack server version.

Peace of mind

Focus your attention on your business, Corporate Hackers takes care of everything!
We install and configure Gibraltar according to your needs and requirements. You are protected against new risks in real time thanks to the automatic update feature. And if you have a doubt or question, you can use our included email-based support.

Open-source development

Gibraltar uses open-source technologies: the most powerfull and stable. Proven, tested and improved by thousands of developers and users all over the world, these technologies offer guaranteed stability, reliability and security, which are hard to match. The source code is fully open allowing every developer or user to check it in order to be sure that the code is free of potential vulnerabilities or spyware. Thanks to constant improvements provided by the Open-source community, Gibraltar remains on the top of the state-of-the-art regarding security.

Secure and simple management by Read-only technology

Gibraltar boots and runs fully off physically write protected media. Therefore, an attacker is unable to install resident program in the system (commonly called “root-kits”). Moreover, using the Read-only technology allows to considerably simplify the update process: either you may replace the outdated media with the updated one, or you may use the automatic update feature.
The system configuration could also be saved on a USB key.

Telecommuters' security with the Virtual Private Networks

Gibraltar creates and provides secured network connections between different distant sites (the main corporate site and/or the telecommuters’ personal computer) via VPN tunnels using strong data encryption. In this way, either the telecommuter or the company can access all the corporate resources with security and confidentiality.

Protection against viruses and spam

It is not essential anymore to install antivirus programs on every computer in the company, to check if updates are needed, or to configure each email client in order to avoid any spam. All updates are automatic. Therefore they protect the whole network against any viruses, worms or trojans.
Besides, Gibraltar stops 95% of spam emails, thanks to three different technologies: blacklist, illegal header/body analysis, and Bayes filtering. Therefore Gibraltar's users do not waste their time downloading and filtering spam emails.

Technical features

System

  • Read-only technology: Gibraltar boots and runs fully off physically write protected media
  • Specially hardened Linux kernel
  • Automatic live updates: interval can be configured

Network support

  • Ethernet: 10/100/1000 MBit/s: static or DHCP, virtual IP addresses
  • ADSL Ethernet modems: PPP over Ethernet, PPTP
  • ADSL USB modems: PPP over ATM
  • Modem dial in: serial, USB
  • Unlimited number of network interfaces

Stateful packet inspection

  • Protocol support: ICMP, TCP, UDP, GRE, ESP, AH, IPv4-over-IPv6
  • Flexible packet filter: interface, MAC address, IP address, service, port,...
  • NAT: Network address translation: dynamic and static
  • PAT: Port address translation: load balancing (Round Robin)
  • Free definition of aliases and groups: addresses and ports
  • DoS/flood - protection: predefined, expandable
  • Randomized IP sequencing
  • Selective TTL manipulation
  • Protocol pass through: PPTP, FTP, H.323, IRC
  • Bridging firewall: transparent firewalling
  • Services definition: combining different protocols and ports to services

VPN (Virtual private networks)

  • VPN IPSec gateway
  • VPN L2TP/IPSec server
  • VPN PPTP server: MPPE 128 Bit data encryption
  • Network-to-network VPN
  • Network-to-client VPN: compatible with Microsoft Windows 2000 / XP
  • Unlimited number of VPN tunnels
  • Authentication with PSK (Private shared key) and X.509 certificates
  • Encryption: 3DES, Blowfish, Twofish, AES, CAST, Serpent
  • Authentication PPTP: CHAP, MS-CHAPv1, MS-CHAPv2
  • NAT traversal
  • Perfect forward secrecy (PFS)

Deep packet inspection

  • Secure SMTP relay: incoming, outgoing, attachment blocking, block lists, antivirus and spam protection
  • Transparent HTTP proxy: no client configuration necessary, antivirus protection, Blocklists for URLs and domains
  • User authentication: user list, active directory integration, LDAP
  • Content caching
  • Content scanning: antivirus, cookies, active X, JavaScript
  • FTP proxy: transparent outgoing, incoming, including antivirus protection
  • Transparent POP3 proxy: antivirus, spam protection and protection from dangerous attachments

Additional services

  • Dynamic DNS
  • DHCP server
  • Secure DNS resolve
  • SSL wrapper for arbitrary services
  • Portscan detection
  • Traffic shaping
  • Antispam filter: rule based, Bayes, RBL, Razor and DCC
  • Kaspersky virus scanner

Want to get Gibraltar? Want to know more about it? Contact us!

Thomas – 2006, November 22 – 1:02pm