Sangfor Athena: NGFW, EPP, SWG, SASE, XDR, MDR and Security Services – Comprehensive Notes

Athena NGFW

  • Why customers need Athena NGFW
    • Firewall as the first line of defense for network boundaries (HQ, data centers, branches).
    • Reinvents firewall with cutting-edge features: Engine Zero AI-powered threat detection and Neural-X cloud threat intelligence.
    • Blocks up to
    • 99% of external threats.
    • Recognitions: Gartner Magic Quadrant for Network Firewalls (Visionary, 8th year; 2nd consecutive year as Visionary), Frost & Sullivan Asia-Pacific NGFW Company of the Year, CyberRatings “Recommended” rating in Enterprise Firewall tests.
    • Deployment scenarios: Network gateway, 2nd Tier Firewall, Secure-SDWAN (HQ & Branches).
    • Built-in protections: Sangfor Neural-X threat intelligence (viruses, botnets, trojans, worms, etc.), Engine Zero AI-powered threat detection (APTs, zero-days, ransomware variants, etc.).
    • Built-in NG-WAF for web app protection; Built-in Vulnerability Assessment; SOC Lite for simplified security operations, visibility, and automated guidance.
  • Core capabilities and coverage
    • Perimeter focus: L2–L7 routing, NAT, IPv4/IPv6, SSL/IPsec VPN, bandwidth management.
    • Threat prevention stack: Intrusion Prevention System (IPS), APT/Botnet protection, Antivirus/AI-based malware inspection, and URL filtering.
    • Application controls: Application Control & URL Filtering; Web protection via NG Web Application Firewall (WAF).
    • Integration: Seamless with Sangfor Athena EPP, XDR, etc.; SOC Lite for simplified operations.
  • Highlights and value propositions
    • Affordable price with strong capacity and performance; built-in WAF and SOC Lite for easier operation.
    • Extra protection for web apps (built-in WAF) and consolidated logging/operations.
    • AI-driven threat detection (Engine Zero) and cloud threat intelligence (Neural-X).
    • End-to-end protection from network to application, with centralized visibility and response guidance.
  • Sizing and throughput guidance (throughput references are approximate and model-based)
    • Throughput (uplink + downlink) per model (examples):
    • extM5100AC=160extMbpsext{M5100-AC} = 160 ext{ Mbps}
    • extM5200AC=400extMbpsext{M5200-AC} = 400 ext{ Mbps}
    • extM5400AC=600extMbpsext{M5400-AC} = 600 ext{ Mbps}
    • extM5500AC=1extGbpsext{M5500-AC} = 1 ext{ Gbps}
    • extM6000AC=2extGbpsext{M6000-AC} = 2 ext{ Gbps} to up to several Gbps on higher-end SKUs.
    • Quick sizing rule: size by expected concurrent users and total bandwidth, then compare with the model’s “Application Layer Throughput (Uplink + Downlink)” values and add headroom for peak traffic and WAF/IPS overhead.
    • Quick sizing guideline (illustrative): If estimated total throughput requirement is, e.g., 200 Mbps, a model like M5200-AC (≈400 Mbps) provides headroom; if near 1 Gbps, move to M5500-AC or higher.
  • Bundle, licensing, and promotions
    • Bundle options: Essential Bundle, Premium Bundle, Ultimate Bundle.
    • Common core features across bundles include Stateful Firewall, Granular Application Control, URL Content Filtering, IPS, Botnet & Advanced Threat Prevention, Security Log & Reporting, SOC Lite, Engine Zero AI, Neural-X threat intelligence, and EPP integration for higher tiers.
    • WAF, SD-WAN, and some advanced features may be optional depending on bundle.
    • Promotion (NGFW + EPP/MDR): Promotion bundles starting with 2 x NSF1200A-I / NSF3100A-1 or 1 x NSF3200A-I with free Sangfor Athena EPP & MDR for 1 year for 50 servers, applicable with 3-year minimum subscription of Sangfor Athena NGFW bundle. 1 server = 3 non-servers. Promotion applies to associated products: Athena EPP, Athena NGFW, Athena MDR.
  • Competitive positioning and model comparisons
    • Compared with competitors (Fortinet, Sophos, WatchGuard, Palo Alto) on features such as NAT/Routing, Application Control, URL Filtering, IPS, Antivirus/AI, APT/Botnet, Sandboxing, WAF, SD-WAN, and logs.
    • Athena NGFW emphasizes AI-driven detection (Engine Zero) and cloud threat intelligence (Neural-X), built-in WAF, SOC Lite, and integrated EPP/MDR options for a broader security stack.
  • Operational benefits
    • SOC Lite consolidates logs and provides threat visibility and guidance with intuitive operations.
    • Built-in vulnerability assessment as preventive security measure.
    • Centralized management with integration to EPP/XDR and automation features.
  • Additional notes
    • Real-world sizing requires considering: 1) number of assets, 2) concurrent users, 3) required features (IPS, WAF, SSL decryption, etc.), and 4) need for SD-WAN or API security.
    • Some capabilities like API Security or IoT/OT-focused hardware may be outside the current offering.

Athena EPP

  • What is Athena EPP?
    • Modern Endpoint Protection Platform (EPP) combining NGAV, EDR, and Endpoint Management in a single solution.
    • Positioned as a ransomware protection leader: detects ransomware in as little as 3 seconds and enables file recovery after encryption.
    • Awards/recognitions: AV-Test certifications (Top Product), Advanced Approved Endpoint Protection for ransomware protection tests.
  • Scenarios and coverage
    • AV & NGAV replacement; Continuous Threat Protection; Ransomware protection for endpoints and servers.
    • Built-in Ransomware Honeypot; supports legacy OS (Windows 7/8, Windows Server 2003/2008, etc.).
  • Key features and capabilities
    • Single license/agent for PC workstations and servers.
    • In-built ransomware honeypot; fast ransomware kill in 3 seconds; file recovery via backups and VSS where applicable.
    • On-premises and cloud management options; vulnerability management; asset inventory; application control; USB control; remote support; logging and reporting.
  • Architecture and components
    • Endpoint management and visibility; vulnerability management; patch management; automated remediation; integration with Sangfor network security (NGFW, XDR).
    • Real-time scanning with AI-enabled detection engines; file quarantine; remote support; analytics dashboards; policy enforcement.
  • Ransomware protection and recovery details
    • File backup and VSS snapshots for recovery; dynamic and on-demand restore capabilities; dedicated honeypot-based detection to stop encryption attempts.
    • Ransomware lifecycle protection: prevention, detection, response, and recovery integrated in one platform.
  • MAES bundle and licensing
    • Bundles: Essential Edition (core NGAV/AV features), Modern EPP (adds EDR, better zero-day protection, improved threat detection, and EPP+XDR integration), Ultimate Edition (further governance features, USB control, software metering, etc.).
    • License model: single license type across servers and endpoints; upgrade path between bundles possible mid-term; optional add-ons like EPP agents, centralized management, and MDR.
  • EPP vs NGFW integration and ecosystem
    • EPP integrates with NGFW (Athena NGFW) to block malicious domains and enable one-click scans/remediation from the firewall side.
    • Promotion details: Free Athena EPP & MDR service for 1 year for 50 servers when purchasing certain NGFW bundles (3-year minimum).
  • Competitive landscape (Endpoint Security)
    • Benchmarking against Symantec, Sophos, Bitdefender, ESET, Microsoft Defender, SentinelOne shows: built-in AI/ML ransomware protection, ransomware honeypots, file recovery options, and cross-platform coverage; Sangfor emphasizes integrated management and ransomware-focused features (honeypot, automated playbooks, and EPP-EDR integration) across a single intuitive console.
  • MAES bundle and end-to-end value
    • MAES: MDR Advanced for Endpoint Secure bundled with EPP Ultimate, ES Manager license, and broader protection; designed for SMBs and mid-market customers seeking a single, comprehensive endpoint security solution with managed detection and response.

Athena SWG (Secure Web Gateway)

  • Why Athena SWG matters
    • Threats originate from both inbound and outbound traffic; users may access malicious websites or exfiltrate data.
    • Athena SWG provides web access control, robust DLP, and outbound data protection to prevent data leaks and malware propagation.
  • Recognitions and scope
    • Gartner Magic Quadrant for SWG for 10 consecutive years; Gartner Hype Cycle sample vendor.
    • Features include broad application identification, proxy avoidance protection, DLP across all channels, device onboarding compliance, and bandwidth management.
  • Core capabilities
    • SWG functionalities: SSL decryption, compliance auditing, user identity alignment, endpoint onboarding, bandwidth management, SaaS application handling, data analytics, reporting.
    • SWG Analytics and Reporting: Identity-based access, visibility of user behavior, and detailed analytics.
  • Deployment and architecture
    • Deployment modes: Bridge Mode; Behaviour Audit; IAG (Identity, Access, Governance); Decryption, Authentication, and Application Control.
  • Differentiators vs firewall
    • SWG focuses on web-oriented controls, advanced proxy capabilities, and granular app control for web traffic; traditional firewalls provide broad network protections but may lack deep web/app visibility and DLP granularity.
  • Sizing, licensing, and features by model
    • Sizing guide and licensing: Throughput and concurrent users per platform, with examples provided to guide model selection; typical bundles include a mix of SWG features such as SSL decryption, URL filtering, data loss prevention, and reporting.
  • Use cases
    • Internet access management, bluecoat/broadcom proxy replacement, bandwidth management, deep packet inspection (SSL/TLS decryption), reporting/compliance.
    • Network access control (NAC) not supported (802.1x).

Athena SASE

  • What is SASE and why it’s needed
    • SASE combines networking and security as a cloud service, routing traffic to the nearest PoP for low latency and unified security policy enforcement across locations.
    • Addresses cloud-first access, remote work, cross-border traffic, and consistent security from edge to cloud.
  • Key positioning and recognitions
    • Frost Radar for SASE; Gartner Hype Cycle sample vendor.
    • Comprehensive security suite: NGFW, IPS, SWG, DLP, CASB; all-in-one endpoint agent with ZTNA and EDR for secure resource access.
    • Cloud-native architecture for scalable security as organizations grow.
  • Core components and capabilities
    • Secured Global Access (SGA): cloud-delivered secure internet access with edge presence.
    • Zero Trust Guard (ZTG): identity- and device-based access to private apps; adaptive access controls; MFA; continuous trust evaluation.
    • Endpoint Security Access (ESA): unified endpoint protection (EPP) + zero-trust access to internal apps.
    • Cloud-native architecture supports global PoPs, SASE connectors, and cross-border acceleration with cross-border compliance through partnerships.
  • End-to-end security and integration
    • ZTNA-based secure access to private apps, browser-based zero trust access (agentless for BYOD in some scenarios).
    • Cross-border acceleration with AIO (agent-based) for SD-WAN-like performance; cloud-native SGA with global edge presence.
    • Integrations: Athena NGFW, Athena EPP, Athena SASE connectors; Omni Client for end-to-end security.
  • Use cases and benefits
    • Hybrid work, threat prevention, secure connectivity, cross-border traffic acceleration.
    • Consolidates security services with zero-trust access, end-to-end data protection, and SASE-driven user experience.
  • FAQ highlights
    • SASE is not intended to replace on-site office firewalls entirely; in-office firewall presence is still relevant; SASE primarily serves remote/mobile users.
    • ZTNA can replace legacy SSL VPNs; supports Microsoft Active Directory integration for authentication.

Athena XDR

  • What is Athena XDR?
    • Advanced SIEM/SOC replacement with cross-domain data correlation across networks, endpoints, servers, applications, and cloud.
    • Integrates with Security GPT (generative AI assistant) for simplified SecOps operations via Omni-Command.
  • Highlights and benefits
    • Consolidates logs/alerts into single incidents; reduces false positives by up to about 90%.
    • Provides comprehensive network visibility for holistic threat understanding.
    • Security GPT enables chat-based operations and automation; trained on billions of parameters; reported accuracy > 99% in identifying advanced threats in some evaluations.
    • Reduces operational costs by consolidating products and capabilities; streamlined SecOps dashboard; easier third-party integrations.
  • Data sources and architecture
    • Endpoint data (Sangfor EPP/NGFW/STA) + Network data + 3rd-party endpoint/network/SIEM tools.
    • Data ingestion supports RESTful API, Syslog, Kafka (on-prem), and RESTful API (SaaS).
  • Functionality and workflow
    • Collect and ingest data, parse, correlate, and analyze to detect hidden threats; automate response and playbooks via SOAR.
    • Generative AI-assisted threat hunting and incident response; automated triage and analysis; contextual alerts to reduce noise.
    • Auto-pilot Security GPT for autonomous detection/investigation with human-in-the-loop as needed.
  • Maturity and versions
    • XDR v1 vs XDR v2: v2 introduces enhanced asset management, dedicated security alerts/incidents, 3rd-party data ingestion with adaptive AI rules, and enhanced reporting.
  • SOC integration and interoperability
    • Integrates with Splunk/SIEM-like platforms; supports 3rd-party data ingestion, SOAR playbooks; provides API/REST interfaces for automation.

Sangfor Security Services (MDR, IR, and related)

  • Sangfor Athena MDR overview
    • Managed Detection and Response service layered on top of Athena NGFW/EPP + XDR.
    • Aims to improve cyber security operations with continuous threat detection and remediation advisory.
    • SOC located in Malaysia (primary) with CN backup; ISO 27001:2022 certified security management.
    • Service zones: Detection, Remediation, Asset information, Threat/Events, IOCs; security analysts oversee operations with a cloud-based SOC.
  • Service delivery and process
    • threat intel, security rules, AI-powered machine analysis; human analyst verification; remote remediation recommendations.
    • Two-way real-time notifications; proactive threat response; remote device configuration for remediation.
    • Provides incident reports and improvement plans; supports playbooks; integrates with XDR, EPP, and NGFW.
  • Service delivery model and credentials
    • Operational-based MDR with continuous monitoring; incident-based IR as needed.
    • Service levels and outcomes: threat detection/notification, remote remediation advisory, incident investigation, and continuous improvement plans.
  • MAES bundle and offerings
    • MAES bundles combine MDR with endpoint security (EPP) and NGFW to deliver end-to-end protection; designed for different customer segments (SMB to enterprise).
    • End-to-end protection with ransomware honeypot, file backup, dynamic AI-based threat detection, and cross-domain visibility.
  • Practical use cases and customer value
    • Suitable for customers with limited in-house security resources, growing threat complexity, or regulatory requirements necessitating 24/7 monitoring.
    • Helps fill capability gaps and reduce mean time to detect (MTTD) and respond (MTTR) with AI-driven analytics and human expertise.
  • Service delivery architecture
    • Platform-X data lake hub; SOC operations run by Sangfor security experts; customer portal for visibility and reporting.
    • Partnerships for on-site support where required; MDR data centers in Malaysia.

Sangfor Security Solutions: Integrated and Simplified SecOps

  • Simplified Security Operations approach
    • Integrates Sangfor security products (NGFW, EPP, XDR) with third-party tools to streamline risk and asset management, threat detection, and incident response.
    • Emphasizes the synergy between network and endpoint security with AI-assisted threat detection and response.
  • Use-case-driven deployment planning
    • Typical customer requirements and segments: small teams with limited resources, mid-market needing MDR, large enterprises seeking full-stack SecOps.
    • Phase-based deployment approaches (Phase 1–3 for NGFW, EPP, XDR, MDR; later phases for added capabilities like STA network sensor).
  • Ransomware protection and MAES bundles
    • Endpoints + network protection with ransomware honeypot, file backups, and dynamic AI-based detection to prevent encryption and enable quick recovery.
  • Cross-product integration and AI capabilities
    • Security GPT and Auto-Pilot capabilities to automate threat detection, investigation, and remediation.
    • 3rd party data ingestion and SIEM integration to broaden visibility and improve correlation.

Sizing, Licensing, and Opportunities (Overview)

  • Sizing methodology and calculators
    • Throughput-based sizing by model (M5100/M5200/M5400/M5500, M6000 series) with recommended concurrent user counts per model.
    • Example sizing rule: Required throughput = Upload + Download; ensure model’s full throughput exceeds estimated needs with headroom for future growth and features such as WAF/IPS when applicable.
  • Licensing model overview
    • Bundles: ESSENTIAL, PREMIUM, ULTIMATE for NGFW; SWG and SASE have their own bundles with combinations of features.
    • Per-name/user-based licensing for SGA (Secured Global Access) and ZTG (Zero Trust Guard), with add-ons for connectors, cloud, and private/public cloud deployment.
    • Licensing for endpoints (EPP) and MDR add-ons; upgrade paths between bundles are supported mid-period.
  • Ordering scenarios (example)
    • Example: 4,000 users requiring secure internet and private apps access across multiple geographies could use SGA Ultimate bundle for 3-year subscription with ZTG for private app access and application acceleration for cross-border traffic; add SASE connectors for cloud-hosted apps.
  • Deployment and implementation considerations
    • In-office appliances vs. cloud-native deployments; cross-border traffic patterns; the need for SD-WAN integration and PoP distribution for low latency.
    • Data sovereignty and privacy considerations when deploying MDR and logging in a cloud-enabled model; NDA and data-sharing policies with customers.

Quick Reference: Notable Formulas and Figures

  • Throughput sizing principle:
    • extRequiredthroughput=extUpload+extDownloadext{Required throughput} = ext{Upload} + ext{Download}
  • Ransomware kill-time claim (Athena EPP): 3 seconds to detect and respond to ransomware activity.
  • 99% threat coverage claim for external threats with Engine Zero and Neural-X integration.
  • 3-year promotions and bundled licensing terms involve providing 1 year of EPP/MDR for certain server counts when purchasing NGFW bundles (3-year minimum).

Real-World Connections and Implications

  • Practical relevance
    • For organizations migrating to a cloud-first or hybrid model, SASE and SWG provide scalable internet access security with low latency and centralized policy enforcement.
    • Endpoint protection (EPP) combined with NGFW (NGFW + XDR) provides cohesive, cross-layer protection against sophisticated threats that leverage both network and endpoint vectors.
  • Ethical and practical implications
    • Data privacy and cross-border data handling in MDR/XDR deployments require clear NDA, data minimization, and encryption in transit/at rest; ensure transparency on what logs are collected and who has access.
  • Real-world relevance
    • Gartner and CyberRatings recognitions signal market validation for Sangfor’s integrated security approach.
    • The platform emphasizes automation and AI-assisted SecOps to address talent shortages and alert fatigue in modern security operations.

Quick Glance: What to Remember

  • Athena NGFW: AI threat detection (Engine Zero), Neural-X threat intel, built-in WAF, vulnerability assessment, SOC Lite; scalable by model with clear throughput guidance; bundles and promotions to incentivize bundled security.
  • Athena EPP: Modern EPP with NGAV/EDR, ransomware honeypot, 3-second kill, single license, asset/vulnerability management, cross-product integrations (NGFW, XDR); MAES bundles for managed endpoint security.
  • Athena SWG: Secure Web Gateway with DLP, SSL decryption, granular application control, compliance reporting; differentiates from traditional firewall through deep web/app controls and proxy capabilities.
  • Athena SASE: Cloud-native, integrates SGA, ZTG, ESA; secure internet access and private app access with zero-trust, cross-border acceleration, and agent/connector-based deployment.
  • Athena XDR: Cross-domain data correlation, AI-assisted SecOps (Security GPT), reduced false positives, SIEM-like capabilities with SOAR integration; two versions with expanded data ingestion and reporting.
  • Sangfor Security Services: MDR/IR as a managed layer; ISO-certified security operations center; 24x7 monitoring with threat intel and remediation playbooks; MAES bundles for end-to-end protection.
  • Licensing and sizing emphasize per-user/per-host licensing, throughput-based sizing, and flexible upgrade paths across bundles.