CacheGuard-OS
User's Guide - Version UF-2.6.1
CacheGuard Overview
The User's Guide enables you to quickly and clearly learn how to configure and administer a CacheGuard appliance. For a detailed description of each command used in this guide, please refer to the Commands Manual. The web administration GUI provided with CacheGuard-OS acts as a front end to the CLI and is therefore not documented separately.
CacheGuard Gateway allows you to connect your networks to the internet securely while protecting your IT infrastructure against harmful traffic. It also enables you to provide the QoS (Quality of Service) required by critical network traffic such as VoIP. What makes CacheGuard Gateway a unique solution is its dual functionality: in forwarding mode, it protects users accessing the internet, while in reverse mode, it protects web applications. To deploy a CacheGuard Gateway, simply install CacheGuard-OS on the machine of your choice. The only requirement is that the machine must have at least two NICs (Network Interface Cards). For assistance with CacheGuard-OS installation, please refer to the Getting Started section.
CacheGuard-OS integrates a range of network security and traffic optimisation features including, but not limited to, a firewall, VPN, web antivirus, filtering proxy, reverse proxy, WAF, traffic shaping, and web caching. All these features can be securely and efficiently activated simultaneously on the same machine, ensuring optimal use of the underlying hardware resources.
Using CacheGuard-OS
Implementing and configuring CacheGuard-OS is straightforward and efficient, even if you are not a networking or security specialist. With CacheGuard-OS, the complexity of the integrated open-source components is hidden beneath the surface, allowing you to simply operate a single system and benefit from a powerful and reliable engine.
CacheGuard Gateway Functions
|
CacheGuard-OS Network Optimisation
- Web caching
- Web traffic compression
- Web application load balancing
- QoS & Traffic shaping
- Caching DNS
|
CacheGuard-OS IP Security
- Internal, external, and auxiliary zoning
- Forward and reverse web proxy
- Transparent HTTP proxy
- Proxy chaining and parallel deployment
- Access lists
- IP firewall with NAT and PAT
- IPsec VPN in site-to-site or remote access modes
- Protection against SYN flood, port scanning, spoofing, and more
|
|
CacheGuard-OS Web Security
- URL guarding based on URL blacklists, whitelists, and regular expressions
- URL guarding policies based on access time, IP, and LDAP requests
- Automatic blacklist updates
- Web Application Firewall (XSS, SQL injection, etc.)
- Access logging
- LDAP and Kerberos AD authentication
- SSL termination
- SSL mediation/inspection
- Web gateway antivirus
- Antivirus service for email
|
CacheGuard-OS High Availability
- RAID capabilities
- Backup and restore on a spare machine
- Ethernet link bonding
- VRRP redundancy
- Multi-WAN support
|
|
CacheGuard-OS Web Optimisation
- Persistent web caching
- HTTP compression
- Web cache sharing
- Traffic shaping
|
CacheGuard-OS Administration
- CLI (Command Line Interface) configuration
- Console port administration
- Remote administration via Web GUI and SSH
- Logging to remote syslog servers
- SNMP agent and trap generation
|