Security Management Portal (SMP)
Overview
ALL-IN-ONE MANAGED SECURITY
SMP integrates a wide array of built-in managed services into a single turnkey solution:
- Network and firewall management
- Dynamic VPN management
- Gateway firmware updates
- Antivirus and antispam
- URL filtering
- Gateway antivirus signature updates
- Logging, monitoring and reporting
- Notifications and custom alerts
- Dynamic DNS
- Vulnerability scanning
These services enable service providers to deliver a flexible and comprehensive value-added managed security service offering to small businesses, while maintaining cost-effectiveness. SMP allows complete remote management of all network security aspects and significantly reduces the need for onsite configuration and troubleshooting. In addition, Safe@Office gateways can be pre-configured before being shipped to the customer, thereby minimizing deployment time and costs.
STREAMLINED SERVICE PROVISIONING AND MAINTENANCE
SMP simplifies the deployment and maintenance of Safe@Office gateways by using group-based management tools. Administrators can define multiple service plans, each consisting of a template that defines the plan's expiration date, gateway properties, VPN settings and security policy, as well as additional services such as antivirus protection and content filtering.
Once the subscription-based service plan has been defined, it can be associated with an unlimited number of Safe@Office gateways. Each gateway that is assigned a particular service plan inherits all of that plan's properties, but specific aspects can be overridden if required. When the administrator updates the plan via SMP's Web-based interface, the changes are automatically applied to all the appropriate gateways. By eliminating the need to make repetitive policy changes to thousands of individual devices, SMP delivers unparalleled scalability and time-savings.

USER-FRIENDLY MANAGEMENT
SMP includes a user-friendly, Web-based interface, which allows you to provide efficient customer support and reduce customer representative training costs. The tree-based interface provides and intuitive display for viewing and editing service plans, customers, gateways, VPN communities and security policies. The interface also provides a single, centralized snapshot of all rules, objects, statuses and alerts for Safe@Office gateways.
GRANULAR ROLE-BASED ADMINISTRATION
SMP provides a flexible and granular method for distributing management responsibility among a group of administrators by dividing responsibilities according to type of service plan, customer or specific functional tasks. System administrators can create and customize system user roles with a fine level of detail, specifying exactly which objects can be viewed, edited or created. All administrator activity is logged and reported, thus improving security by providing information that can identify unauthorized policy changes.
INTEGRATION WITH BACK-OFFICE OPERATIONS
SMP includes a comprehensive SOAP/XML standards-compliant API that allows easy integration with third-party systems, customer service applications and other third-party systems, so that you can leverage your back-office infrastructure and support existing business processes.
REDUCED SUPPORT COSTS WITH SELF-PROVISIONING PORTAL
SMP provides the option of enabling a Web-based Self-Provisioning Portal (SPP) that allows customers to control certain aspects of their security services, thus reducing customer support overhead and operating costs. For example, customers can be permitted to change their personal details or to modify their list of Web Filtering categories.
LOGGING, REPORTING, MONITORING AND ALERTS
SMP turns the vast amount of data collected from security devices into understandable information that can be used to demonstrate security services’ effectiveness and value-for-money to customers. Security reports are automatically generated and emailed to customers at predefined intervals and can also be viewed directly from the SMP management interface. Security reports include information about blocked attacks, detected viruses, filtered Web sites and more.

In addition, SMP offers powerful real-time monitoring tools that enable you to see the status of the SMP server and connected devices at a single glance. These tools include real-time load visualization graphs, status displays and customizable alerts. You can use real-time alerts and notifications to proactively support your customers and notify them of connection outages, VPN tunnel drops or attacks, all before the customers become aware of these problems.
RESILIENT MANAGEMENT INFRASTRUCTURE
SMP provides a fully redundant management infrastructure that enables extensive control of customer security. Service providers can deploy more than one management server in a NOC, with full load balancing and automatic failover, thereby enabling around-the-clock business availability, fault tolerance, high performance and scalability.
AUTOMATIC FIRMWARE UPDATES
Ensuring that thousands of gateways all enforce the highest level of security can be a daunting administrative task. To alleviate this problem, Safe@Office gateways use “pull” technology for automatic and scheduled firmware updates: gateways automatically detect and download new firmware whenever it becomes available on the management server, instead of the management server initiating communications with each individual gateway. This reduces the load on the management server. In addition, updates can be scheduled to minimize gateway downtime, and administrators also have the option to override group settings and push unique firmware and settings to specific gateways.
VIRTUAL PORTAL MANAGEMENT
Service providers, value-added resellers (VARs) and system integrators can leverage their SMP deployment to create new business opportunities, in which they provide turnkey security management solutions to their business partners. SMP owners can create multiple virtual portals, each representing a “virtual SMP”, and sell them to partners that directly target end users in the SMB market segment. Such a business model allows SMP owners to further extend their product and service offering, while generating new revenue opportunities.
GATEWAY USER AUTHENTICATION MANAGEMENT
SMP can be used to remotely create and manage gateway administrator permissions, remote access VPN permissions, web filtering override permissions, hotspot authentication and remote desktop permissions. These permissions are defined using the user authentication community feature. Such communities are composed of a group of gateways and associated users, where each user is granted a specific set of access privileges for all gateways in the community.
COMPREHENSIVE WEB ACCESS POLICY
SMP supports a URL-based Web Filtering service that allows businesses to create Web access policies based on up to 60 categories of objectionable or malicious Web sites. In addition, service providers can also use Web rules to define gateway-specific or global white and black lists that allow or block access to specific URLs. By providing two ways of filtering content, SMP provides business owners with the flexibility to customize their Web Access policies to meet their needs.
ANTIVIRUS AND ANTISPAM
SMP offers support for Safe@Office automatic gateway antivirus updates and features a centralized, network-based email antivirus and antispam scanning solution. By scanning email traffic for security threats before they ever reach the customer's network, SMP ensures that the content entering the network is free of malicious code and that no bandwidth is wasted on downloading infected files.
DYNAMIC VPN COMMUNITY MANAGEMENT
Many businesses use Virtual Private Networks (VPNs) to secure traffic between headquarters and remote offices and users. However, VPN management can be a time-consuming and complex task. SMP simplifies this by providing the Dynamic VPN (DVPN) module. In one step, administrators can define VPN communities and set security parameters for the entire VPN. By grouping a customer’s VPN endpoints in a community, the administrator can automatically create fully meshed, star and nested VPN topologies, establishing Site-to-Site tunnels between VPN peers. Once the VPN community is created, all changes to gateways and internal networks are distributed to the entire community with the click of a button. New sites that are added automatically inherit the appropriate properties and establish secure IPSec sessions with the rest of the community. To ensure strong security in Site-to-Site VPN communications, the SMP internal Certificate Authority (CA) automatically issues X.509 digital certificates to all Safe@Office gateways that are part of a DVPN community and renews the certificates as needed.
VULNERABILITY SCANNING SERVICE
SMP integrates with a Vulnerability Scanning Service (VSS) that scans subscriber networks for security vulnerabilities. Vulnerability scanning reports include information about security vulnerabilities and information obtained by port scanning, and can be generated automatically at user-defined intervals and emailed to customers. These reports are HTML-based and customizable and are an excellent tool for a service provider to demonstrate the added value of managed security services to customers.
INTEGRATED DYNAMIC DNS
Tracking and monitoring customer gateways that use dynamic IP addresses can be difficult, since their IP addresses change each time they connect to the Internet. SMP alleviates this issue by fully supporting the management and monitoring of dynamically addressed gateways. SMP can act as a secure Dynamic Domain Name Service (Dynamic DNS or DDNS) server, which constantly checks and updates the mapping of a domain name to a gateway’s corresponding IP address. Each time the gateway’s IP address changes, Dynamic DNS maps the domain name to the new IP address. With SMP, service providers can become Dynamic DNS providers for gateway owners, without any need for third-party providers.
SUPPORTED SERVICES
|
SCALABILITY
INTEGRATION
OPERATING SYSTEMS
DIRECTORY SERVERS
MANAGED DEVICES
|