HSG Brochure
HSG Brochure
HSG Brochure
HSG-1000
The HSG access controllers, applies to public access network such as Wi-Fi hotspots, network management, guest access, global roaming, and hospitality deployments - With reliability, capacity, efficiency, and ultra security.
Authentication: Firewall, SSL / IPSec VPNs, 802.1X, VLAN, VPN free client software Authorization: Guest/Role accounts and external Kerberos, RADIUS, LDAP Accounting/Billing for instant Hotspot Auditing: Client Session control, OS fingerprints detection, IP & bandwidth monitoring, network latency, server logs Alert: Intrusion Detection / Prevention Systems (IDS / IPS) as optional Seamless wireless / wired IP roaming Full stateful packet filter (firewall) Large number of access points (APs) Up to 250 (HSG-200) or thousands (HSG-1000) simultaneous users Support Credit card gateways, prepaid cards 802.11i, 802.1X, VPN with VLAN Security Full Quality of Service (QoS) functions Millions of transaction records for database Centralized management with associated APs and Customer Premise Equipments (CPEs) Remote administration and reconfiguring for Gateway and associated APs / CPEs (WAP/CAP) Data Roaming among HSG gateways CARP Firewall failover and redundancy for backup Walled Garden for redirection to customized pre/post/failure of authentication pages Optional 3G interface radio with major brands Optional high power onboard Access Point (up to 300mW) as radio for base station
USA Office: 4790 Irvine Blvd., Suite 105-458, Irvine, CA 92620 Tel: 1-949-903-8502 Fax:1-949-252-0888
Taiwan Office: No.5, Qiyan Rd., Beitou District, Taipei City 112, Taiwan Tel: 886-2-2898-4050 Fax: 886-2-2896-9157 157
Functions
Authentication (Walled Garden): single sign-on (SSO) client with authentication integrated into the local authentication environment through local/domain Kerberos, LDAP, RADIUS, MAC authentication, and 802.1x. Authorization: access control to network resources such as protected network with intranet, internet, bandwidth, VPN, and fully stateful packet firewall rulesets. Optional Intrusion detection and prevention systems to block potential Remote web base Accounting: sophisticated and complete billing system hosts, with small footprints d and serial console admin through SSL/TLS, configuration backup. that generates account information and invoices, 802.1X supported with EAP/TLS for port authentication. perform real-time credit-card processing. Interfaces based on PostgreSQL database are available to integrate with external billing/accounting systems and RADIUS servers. Redirection of clients to customized webpage of the hotspot provider, for authentication, billing, etc. Customizable company information, logo, web page and background. Clientless (VPN Bypass) mode for maximized hotspot efficiency. This also allows easy access to internet in a corporate environment while protecting sensitive information on the intranet. Secure clients via HTTPS for all platforms are provided as alternative to VPN. Where VPN is needed, open-standard IPSec and SSL/TLS protocols with AES, DES, 3DES, SHA-1, and Blowfish algorithms are supported to provide strong client-to-gateway integrity, authentication, and encryption for Windows 2000/XP/PocketPC, and most UNIX variants. No extra client licenses required. Accommodates a large number of 802.11 a/b/g/n APs of multiple vendors, with unlimited (hardware dependent) concurrent users Seamless IP roaming allows clients the freedom to move among connected APs. Optional onboard high power radio (200mW or 300mW) acts as radio for base station. Quality of Service (QoS) allows role based control of inbound/outbound bandwidth by prioritizing traffic. Comprehensive firewall ruleset and templates allow extremely granular control over network traffic. Guest/Role accounts can be defined and customized for VPN, bandwidth, billing, and are fully separated from the intranet for security. Local users policy management that include session time limits, time-of-day restriction, etc. Centralized AP logging, remote syslog server, real-time traffic monitoring and analysis system. Revocation of VPN and non-VPN clients for illegal usages. Performance: up to 100 Mbps unencrypted traffic, and 5 to 50 Mbps encrypted 3DES IPSec traffic for VPN clients. Optional SIP servers / telephony interface with Siproxd and Asterisk
Protocols/Standards Supported
Windows 7/XP/2K, Android, smartphones, PocketPC, MacOS, and UNIX variants for VPN clients, VoIP, media devices WLAN DHCP server, DNS server, NTP time server, NAT gateway, log servers, HostAP Protocols: 802.11 (a, b, or g variants), 802.1x, ARP, DNS, NTP, DHCP, ICMP, TCP/IP, UDP, NetBIOS, SNMP V2, HTTP, HTTPS, IPSec, AES, IKE(ISAKMP) and ESP tunnel modes, IPv4, IPv6, DES, 3DES, Blowfish, SHA-1 hashs, MD5, SSH, LDAP, RADIUS, Kerberos V (Heimdal), SSL, SSL2, TLS, SSH2, PKCS12, X.509, OSPF, BGP, RIP, SIP/SER, H.323, VOIP, CARP, PFSYNC, OSPFD, BGPD, GPRS, GSM, UMTS, HSDPA, 802.16e
USA Office: 4790 Irvine Blvd., Suite 105-458, Irvine, CA 92620 Tel: 1-949-903-8502 Fax:1-949-252-0888
Taiwan Office: No.5, Qiyan Rd., Beitou District, Taipei City 112, Taiwan Tel: 886-2-2898-4050 Fax: 886-2-2896-9157