|
The Advanced Network
Infrastructure Security (ANIS) GigaCryptor is a small and
compact IP network encryption device, offering fast throughput
and high reliability. Armed with a full set of self-defending
mechanisms, the ANIS GigaCryptor is able to detect various
forms of attacks. Under any circumstance the privacy of
the key is maintained.
The ANIS GigaCryptor
can actively defend itself, even the power supply is removed.
The size and performance of the ANIS GigaCryptor makes it
an ideal solution for a wide range of network security applications,
especially in non-trusted environments, such as the encryption
of the IP traffic in data centers.
Performance Overview
|
ANIS GigaCryptor |
| 1000 MBit throughput in half duplex |
| 1000 Mbit throughput in full duplex |
|
Encryption Algorithms supported
256/128-bits AES
168-bits Triple DES
112-bits Extended DES
Proprietary Algorithms
|
| 40,000 clients/subnets supported |
| Optimized for small packets for real-time traffic |
| High reliability - No moving parts |
Self Defending Mechanisms
The ANIS GigaCryptor feature a full complement of self-defending
mechanisms that can detect even the most sophisticated attacks.
The self-defending mechanisms are combined with various
alarm actions to form a product that is able to fully protect
the device and the keys stored in it. Each of the alarms
can be configured in GlobalAdmin, and can be dynamically
turned-on or turned-off for easy administration.
Some of the different self-defending mechanisms and alarm
actions are:
|
Touch Sensors |
Detects physical opening of the device and probing of the PCB |
|
Motion Sensors |
Detects when the ANIS GigaCryptor is being moved |
|
Secondary Power |
Self-defending mechanism can work even when power is removed |
|
Hidden Alarms |
Silently sends an encrypted alarm to the GlobalAdmin station |
Modes of Operation
The ANIS GigaCryptor is available
in either a bridge
mode or gateway mode.
The bridge-mode GigaCryptor works as a bump-in-the-wire
concept and can be easily deployed into existing networks,
or MPLS networks. Gateway-mode ANIS GigaCryptor encapsulate
the original IP packet with new headers, allowing the original
IP headers to be concealed, as well as secure remote access
from client machines using IPCrypt Client.
Enhanced IPSec
The ANIS GigaCryptor provide an alternative
key management protocol called
Enhanced
IPSec developed by CE-Infosys. Using Enhanced IPSec,
faster connections can be made as there is no need for lengthy
session key negotiations using IKE to establish a tunnel.
In addition, each IP packet is implicitly authenticated
with any modified or malicious packets automatically discarded.
In addition, the session keys used for encryption can be
changed as rapidly as every 1, 5, 10, or 20 packets to defeat
any attempts at statistical analysis of the encrypted packets.
Central Management
The ANIS GigaCryptor can be easily
managed using GlobalAdmin. This central management station
provides an intuitive Graphical User Interface for simple
administration of the ANIS GigaCryptor . Using GlobalAdmin,
keys and policies used by the ANIS GigaCryptor can be pushed
down remotely. In addition, firmware upgrades can be sent
remotely to the ANIS GigaCryptor .
Highest Reliability
As a high end product for the most
demanding customers reliability is a key asset. ANIS GigaCryptor
are designed for reliability. No mechanical moving parts
are found in ANIS GigaCryptor s. No high voltage components
are used in the products. ANIS GigaCryptor s have an outstanding
MTBF rate and are resistant against dust, sand and humidity.
They are designed to be useable in cars, trucks and other
vehicles.
Miscellaneous
|
Size |
230 mm X 147 mm X 45 mm
2 ANIS GigaCryptor s can be placed in a
1U slot in a standard 19-inch rack
|
|
Interfaces |
2 x 10/100/1000 MBit auto-sensing Copper Ethernet Interface
Optional Fibre-optic interface
RS232 Diagnostic Port
USB slot for USB token
|
|
Power Specification |
12V/1A DC input
An external power adapter for 110/230V 50-60
Hz AC is provided
|
|
Logging and Reporting |
Syslog and Syslog-Mail
SNMP
GlobalAdmin
|
|
Additional Features |
UDP Tunneling
Source and Destination NAT
Configurable Routes
Configurable Bypass Rules
IP Address Pools
High Availability and Load-sharing
|
Optional Accessories
Sold Separately |
1U Server Rack
|
> top <
|