  

DESCRIPTION: YOU ARE BIDDING ON 1 TEROS 100 SSL UNIT... A NOTE - LISTED IT AS CITRIX BECAUSE TEROS BECAME CITRIX A COUPLE OF YEARS AGO. DETAILS CAN BE FOUND ON CITRIX WEBSITE INCLUDING THE FOLLOWING: "The 7000 platform is a direct replacement for the Teros T-100 hardware. The 12000 is a direct replacement for the Teros T-200 hardware. As the T-100 and T-200 are no longer manufactured, it is possible for an Application Firewall 5.5 cluster to contain a combination of T-100/T-200/7000/12000 hardware."<></> Description The Teros 100 is a web application firewall that protects as well as accelerates web apps. In addition to blocking application-layer attacks not detected by either network firewalls or IPS devices, the Teros 100 enhances application performance. It provides proven defenses for vulnerabilities in custom applications, as well as the known weaknesses in commercially-developed application software.
Teros-100 APS in a nutshell Teros-100 APS runs on a hardened Linux 1U server with an installed proprietary operating system for added security. The product’s price tag begins at $25,000 and is targeted to the medium-to-large distributed computing environments of today’s Fortune 1000. The product checks all HTTP and HTTPS data to make sure it’s suitable within the framework of the exchange. Teros-100 APS also ”learns” as it spends more time checking regular traffic, which enables it to speed up the time spent verifying data. Without adding latency to the Web traffic (it adds less than 1 ms to most Web transactions, according to technology assurance solution provider KeyLabs), Teros-100 APS checks all traffic coming into or leaving your Web server without aggravating your users or customers with long wait times.
Note For larger Web server environments, load balancing is supported and multiple Teros-100 APS systems can be implemented should the need arise.
Verification methods Teros-100 APS verification methods are based on the HTML interaction model (HIM), which provides the standards for what types of sessions can transpire between the browser to the Web server, and what can be returned by the server. The Teros-100 APS application uses HIM to block all traffic that strays from the standard, yet the learning engine of the application allows for individuals focused on Web development (who often need to code outside this standard) to bypass the security controls of the application.
The learning engine is perhaps the most critical piece of the Teros-100 APS system, since it develops a baseline for standard and nonstandard traffic patterns when the system is initially put into service. The learning engine provides the IT manager with a listing of policies the system will abide by; the manager can accept or reject these for future Web transactions. As nonstandard Web traffic is introduced to the network, Teros-100 APS takes its lessons learned from the past to deal with potential vulnerabilities.
Performance Perhaps most important to all IT managers who have to balance security and performance is the issue of latency. With Web content pushing some servers to their capacity limits, it is critical that an extra device put in the path of this traffic does not add latency.
Another KeyLabs study perhaps best explains the Teros-100 APS’s impact on performance. Using an Intel 933 MHz PIII server with 1 GB of RAM, the Teros-100 APS system was found to handle 64.7 million transactions per day at a rate of 32.48 Mb per second per unit of HTTP traffic. The maximum latency experienced by the system was 4.86 ms for a server with only 20 percent processor capacity available.
When to use Teros-100 APS While there is no price too great for a highly available secure network, many IT managers must make tough choices when it comes to protecting their Web traffic. The question of when Teros-100 APS could be beneficial really depends on the makeup of your Web site traffic content. For static Web sites that receive little packet exchange, the basic firewall protection you already have in place should suffice. For more active sites that are interacting with extranet, intranet, and Internet traffic, a security solution such as Teros-100 APS should be strongly considered, especially if the data sent back and forth is sensitive in nature.
n 2006, Citrix released Application Firewall 5.5 software on the NetScaler 7000 and 12000 platforms. The 7000 platform is a direct replacement for the Teros T-100 hardware. The 12000 is a direct replacement for the Teros T-200 hardware. As the T-100 and T-200 are no longer manufactured, it is possible for an Application Firewall 5.5 cluster to contain a combination of T-100/T-200/7000/12000 hardware. The above replacements are for the standard SSL hardware. There are currently no direct replacements for Teros T-100 and T-200 Federal Information Processing Standard (FIPS) hardware. There are no issues with homogeneous (all the same hardware) clusters. Supported interoperable hardware configurations N-node active/active cluster configurations Active/active clusters are composed of two or more Application Firewall nodes being online and available. HTTP and HTTPS traffic to the cluster is provided by an external load balancer that distributes the traffic evenly across all Application Firewall nodes. This allows a cluster to scale as requirements increase by adding additional nodes to the cluster.
Citrix supports Application Firewall 5.5 hardware interoperability in the following n-node active/active cluster configurations: - T-100 and T-200 hardware
Teros T-100 and T-200 hardware can be mixed within an n-node active/active cluster. All hardware must run the same Application Firewall (5.5.0 or later) software version. This configuration also supports Teros software earlier than version 5.5.0. - T-100 and 7000 hardware
Teros T-100 and NetScaler 7000 hardware can be mixed within an n-node active/active cluster. All hardware must run the same Application Firewall (5.5.0 or later) software version. - T-200 and 7000 hardware
Teros T-200 and NetScaler 7000 hardware can be mixed within an n-node active/active cluster. All hardware must run the same Application Firewall (5.5.0 or later) software version. - T-100 and 12000 hardware
Teros T-100 and NetScaler 7000 hardware can be mixed within an n-node active/active cluster. All hardware must run the same Application Firewall (5.5.0 or later) software version. - T-200 and 12000 hardware
Teros T-200 and NetScaler 12000 hardware can be mixed within an n-node active/active cluster. All hardware must run the same Application Firewall (5.5.0 or later) software version. - 7000 and 12000 hardware
NetScaler 7000 and 12000 hardware can be mixed within an n-node active/active cluster. All hardware must run the same Application Firewall (5.5.0 or later) software version.
Active/active configuration | T-100 | T-200 | NetScaler 7000 | NetScaler 12000 | T-100 | Yes | Yes | Yes* | Yes* | T-200 | Yes | Yes | Yes* | Yes* | NetScaler 7000 | Yes* | Yes* | Yes* | Yes* | NetScaler 12000 | Yes* | Yes* | Yes* | Yes* |
* Any cluster running with NetScaler hardware (7000 or 12000) must be running Application Firewall software version 5.5.0 or later. Basically, any combination of Teros and NetScaler hardware can be mixed in a heterogeneous n-node active/active Application Firewall 5.5.0 or later cluster configuration. Virtual Router Redundancy Protocol (VRRP) active/standby cluster configurations VRRP is a two-node High Availability (HA) active/standby cluster configuration. The primary node is active and accepting traffic. The secondary or backup node is live but in standby mode. The backup node monitors the health of the primary node. If the primary fails, the backup activates, becomes the primary, and starts passing traffic. Citrix supports Application Firewall 5.5 hardware interoperability in the following VRRP cluster configurations: Teros T-100 and T-200 hardware can be mixed within a VRRP cluster. All hardware must run the same Application Firewall (5.5.0 or later) software version. This configuration also supports Teros software earlier than version 5.5.0. NetScaler 7000 and 12000 hardware can be mixed within a VRRP cluster. All hardware must run the same Application Firewall (5.5.0 or later) software version. Note: The 7000 platform has 10/100/1000 interfaces. The 12000 platform only has 1 GB interfaces. VRRP configuration | T-100 | T-200 | NetScaler 7000 | NetScaler 12000 | T-100 | Yes | Yes | No | No | T-200 | Yes | Yes | No | No | NetScaler 7000 | No | No | Yes* | Yes* | NetScaler 12000 | No | No | Yes* | Yes* |
* Any cluster running with NetScaler hardware (7000 or 12000) must be running Application Firewall software version 5.5.0 or later. CONDITION: EXCELLENT - UNIT SHOWS VERY VERY LIGHT USE, BUT GREAT AND FULLY POWERS ON. YOU ARE BIDDING ON 1 UNIT AUCTION INCLUDES: 1 - TEROS 100 SSL UNIT (NO CABLES OR ANY ACCESSORIES)
|