【正文】
What’s New in Fireware XTM New Features in Fireware XTM ? Major Changes ? IPv6 – Network Configuration and Routing ? FIPS 1402 ? Dynamic Routing Enhancements ? Clientless SSO ? Log and Report Manager ? Log Server UTC Timestamp Conversion ? ConnectWise Integration ? SMTPProxy TLS Encryption 2 WatchGuard Training New Features in Fireware XTM ? Minor Changes ? Debug Logging Per Proxy Action (60099) ? WSM Management Server Search (62143) ? iOS Mobile VPN with IPSec (41602) ? Export AutoBlocked Sites (62511) ? Negotiate PPPoE Client IP Address (61930) ? New Platforms ? XTM 330 ? XTM 2050 3 WatchGuard Training IPv6 IPv6 Refresher ? WatchGuard IPv6 — ? Hype or Reality — Video and PPT ? Security Implications — Video and PPT ? What to Expect — Video and PPT ? IPv6 is manageable ? If you impose a false minimum of a /24 on IPv4 ? Subting IPv4 /8 ~ IPv6 /48 5 WatchGuard Training 16bits 2561:1900:4545:0003:0200:F8FF:FE21:67CF Interface ID Network Prefix 16bits IPv6 in ? If it routes, the traffic will pass No security policies, features, or configurations are applied ? Static configuration of IPv6 addresses and DNS ? Router Advertisement for stateless address autoconfiguration ? Static routes 6 WatchGuard Training IPv6 Certifications ? IPv6 Ready ? Phase 1, Silver Logo, was in ? Phase 2, Gold Logo, Core is in this release ? The Phase 2 Logo is a requirement for extended test categories, including: – IPSec – IKEv2 – MIPv6 – NEMO – DHCPv6 – SIP – SNMPMIBs – MLDv2 7 WatchGuard Training IPv6 Roadmap IPv6 Planned Features Static configuration of IPv6 addresses Router Advertisement for stateless address autoconfiguration Static routes and DNS servers DHCPv6 client for external interface V6 policies Blocked sites/ports, and autoblock Default threat protection BOVPN 6in6, 6in4, 4in6 6to4 transition tunnel Future Features Authentication, SSO, Terminal Service DHCP Server/Relay for trusted/optional interface Transparent bridge and dropin mode Traffic management and QoS 4to6 transition tunnel Proxy and security services (WebBloker, GAV, …) Application Control and IPS Mobile User VPN Cluster IPv6 Stage 1, () IPv6 Stage 2 IPv6 Stage 3 FIPS 1402 FIPS Support in Fireware XTM ? FIPS 1402 ? Federal Information Processing Standards Publication 1402, Security Requirements for Cryptographic Modules ? Describes the NIST requirements and standards for cryptographic modules for use by federal government departments and agencies ? Defines four security levels ? WatchGuard XTM ? XTM Devices and Fireware XTM are designed to meet the overall requirements for FIPS 1402 Level 2 security, when configured i