Sangfor Athena: NGFW, EPP, SWG, SASE, XDR, MDR and Security Services – Comprehensive Notes
Athena NGFW
- Why customers need Athena NGFW
- Firewall as the first line of defense for network boundaries (HQ, data centers, branches).
- Reinvents firewall with cutting-edge features: Engine Zero AI-powered threat detection and Neural-X cloud threat intelligence.
- Blocks up to
- 99% of external threats.
- Recognitions: Gartner Magic Quadrant for Network Firewalls (Visionary, 8th year; 2nd consecutive year as Visionary), Frost & Sullivan Asia-Pacific NGFW Company of the Year, CyberRatings “Recommended” rating in Enterprise Firewall tests.
- Deployment scenarios: Network gateway, 2nd Tier Firewall, Secure-SDWAN (HQ & Branches).
- Built-in protections: Sangfor Neural-X threat intelligence (viruses, botnets, trojans, worms, etc.), Engine Zero AI-powered threat detection (APTs, zero-days, ransomware variants, etc.).
- Built-in NG-WAF for web app protection; Built-in Vulnerability Assessment; SOC Lite for simplified security operations, visibility, and automated guidance.
- Core capabilities and coverage
- Perimeter focus: L2–L7 routing, NAT, IPv4/IPv6, SSL/IPsec VPN, bandwidth management.
- Threat prevention stack: Intrusion Prevention System (IPS), APT/Botnet protection, Antivirus/AI-based malware inspection, and URL filtering.
- Application controls: Application Control & URL Filtering; Web protection via NG Web Application Firewall (WAF).
- Integration: Seamless with Sangfor Athena EPP, XDR, etc.; SOC Lite for simplified operations.
- Highlights and value propositions
- Affordable price with strong capacity and performance; built-in WAF and SOC Lite for easier operation.
- Extra protection for web apps (built-in WAF) and consolidated logging/operations.
- AI-driven threat detection (Engine Zero) and cloud threat intelligence (Neural-X).
- End-to-end protection from network to application, with centralized visibility and response guidance.
- Sizing and throughput guidance (throughput references are approximate and model-based)
- Throughput (uplink + downlink) per model (examples):
- extM5100−AC=160extMbps
- extM5200−AC=400extMbps
- extM5400−AC=600extMbps
- extM5500−AC=1extGbps
- extM6000−AC=2extGbps to up to several Gbps on higher-end SKUs.
- Quick sizing rule: size by expected concurrent users and total bandwidth, then compare with the model’s “Application Layer Throughput (Uplink + Downlink)” values and add headroom for peak traffic and WAF/IPS overhead.
- Quick sizing guideline (illustrative): If estimated total throughput requirement is, e.g., 200 Mbps, a model like M5200-AC (≈400 Mbps) provides headroom; if near 1 Gbps, move to M5500-AC or higher.
- Bundle, licensing, and promotions
- Bundle options: Essential Bundle, Premium Bundle, Ultimate Bundle.
- Common core features across bundles include Stateful Firewall, Granular Application Control, URL Content Filtering, IPS, Botnet & Advanced Threat Prevention, Security Log & Reporting, SOC Lite, Engine Zero AI, Neural-X threat intelligence, and EPP integration for higher tiers.
- WAF, SD-WAN, and some advanced features may be optional depending on bundle.
- Promotion (NGFW + EPP/MDR): Promotion bundles starting with 2 x NSF1200A-I / NSF3100A-1 or 1 x NSF3200A-I with free Sangfor Athena EPP & MDR for 1 year for 50 servers, applicable with 3-year minimum subscription of Sangfor Athena NGFW bundle. 1 server = 3 non-servers. Promotion applies to associated products: Athena EPP, Athena NGFW, Athena MDR.
- Competitive positioning and model comparisons
- Compared with competitors (Fortinet, Sophos, WatchGuard, Palo Alto) on features such as NAT/Routing, Application Control, URL Filtering, IPS, Antivirus/AI, APT/Botnet, Sandboxing, WAF, SD-WAN, and logs.
- Athena NGFW emphasizes AI-driven detection (Engine Zero) and cloud threat intelligence (Neural-X), built-in WAF, SOC Lite, and integrated EPP/MDR options for a broader security stack.
- Operational benefits
- SOC Lite consolidates logs and provides threat visibility and guidance with intuitive operations.
- Built-in vulnerability assessment as preventive security measure.
- Centralized management with integration to EPP/XDR and automation features.
- Additional notes
- Real-world sizing requires considering: 1) number of assets, 2) concurrent users, 3) required features (IPS, WAF, SSL decryption, etc.), and 4) need for SD-WAN or API security.
- Some capabilities like API Security or IoT/OT-focused hardware may be outside the current offering.
Athena EPP
- What is Athena EPP?
- Modern Endpoint Protection Platform (EPP) combining NGAV, EDR, and Endpoint Management in a single solution.
- Positioned as a ransomware protection leader: detects ransomware in as little as 3 seconds and enables file recovery after encryption.
- Awards/recognitions: AV-Test certifications (Top Product), Advanced Approved Endpoint Protection for ransomware protection tests.
- Scenarios and coverage
- AV & NGAV replacement; Continuous Threat Protection; Ransomware protection for endpoints and servers.
- Built-in Ransomware Honeypot; supports legacy OS (Windows 7/8, Windows Server 2003/2008, etc.).
- Key features and capabilities
- Single license/agent for PC workstations and servers.
- In-built ransomware honeypot; fast ransomware kill in 3 seconds; file recovery via backups and VSS where applicable.
- On-premises and cloud management options; vulnerability management; asset inventory; application control; USB control; remote support; logging and reporting.
- Architecture and components
- Endpoint management and visibility; vulnerability management; patch management; automated remediation; integration with Sangfor network security (NGFW, XDR).
- Real-time scanning with AI-enabled detection engines; file quarantine; remote support; analytics dashboards; policy enforcement.
- Ransomware protection and recovery details
- File backup and VSS snapshots for recovery; dynamic and on-demand restore capabilities; dedicated honeypot-based detection to stop encryption attempts.
- Ransomware lifecycle protection: prevention, detection, response, and recovery integrated in one platform.
- MAES bundle and licensing
- Bundles: Essential Edition (core NGAV/AV features), Modern EPP (adds EDR, better zero-day protection, improved threat detection, and EPP+XDR integration), Ultimate Edition (further governance features, USB control, software metering, etc.).
- License model: single license type across servers and endpoints; upgrade path between bundles possible mid-term; optional add-ons like EPP agents, centralized management, and MDR.
- EPP vs NGFW integration and ecosystem
- EPP integrates with NGFW (Athena NGFW) to block malicious domains and enable one-click scans/remediation from the firewall side.
- Promotion details: Free Athena EPP & MDR service for 1 year for 50 servers when purchasing certain NGFW bundles (3-year minimum).
- Competitive landscape (Endpoint Security)
- Benchmarking against Symantec, Sophos, Bitdefender, ESET, Microsoft Defender, SentinelOne shows: built-in AI/ML ransomware protection, ransomware honeypots, file recovery options, and cross-platform coverage; Sangfor emphasizes integrated management and ransomware-focused features (honeypot, automated playbooks, and EPP-EDR integration) across a single intuitive console.
- MAES bundle and end-to-end value
- MAES: MDR Advanced for Endpoint Secure bundled with EPP Ultimate, ES Manager license, and broader protection; designed for SMBs and mid-market customers seeking a single, comprehensive endpoint security solution with managed detection and response.
Athena SWG (Secure Web Gateway)
- Why Athena SWG matters
- Threats originate from both inbound and outbound traffic; users may access malicious websites or exfiltrate data.
- Athena SWG provides web access control, robust DLP, and outbound data protection to prevent data leaks and malware propagation.
- Recognitions and scope
- Gartner Magic Quadrant for SWG for 10 consecutive years; Gartner Hype Cycle sample vendor.
- Features include broad application identification, proxy avoidance protection, DLP across all channels, device onboarding compliance, and bandwidth management.
- Core capabilities
- SWG functionalities: SSL decryption, compliance auditing, user identity alignment, endpoint onboarding, bandwidth management, SaaS application handling, data analytics, reporting.
- SWG Analytics and Reporting: Identity-based access, visibility of user behavior, and detailed analytics.
- Deployment and architecture
- Deployment modes: Bridge Mode; Behaviour Audit; IAG (Identity, Access, Governance); Decryption, Authentication, and Application Control.
- Differentiators vs firewall
- SWG focuses on web-oriented controls, advanced proxy capabilities, and granular app control for web traffic; traditional firewalls provide broad network protections but may lack deep web/app visibility and DLP granularity.
- Sizing, licensing, and features by model
- Sizing guide and licensing: Throughput and concurrent users per platform, with examples provided to guide model selection; typical bundles include a mix of SWG features such as SSL decryption, URL filtering, data loss prevention, and reporting.
- Use cases
- Internet access management, bluecoat/broadcom proxy replacement, bandwidth management, deep packet inspection (SSL/TLS decryption), reporting/compliance.
- Network access control (NAC) not supported (802.1x).
Athena SASE
- What is SASE and why it’s needed
- SASE combines networking and security as a cloud service, routing traffic to the nearest PoP for low latency and unified security policy enforcement across locations.
- Addresses cloud-first access, remote work, cross-border traffic, and consistent security from edge to cloud.
- Key positioning and recognitions
- Frost Radar for SASE; Gartner Hype Cycle sample vendor.
- Comprehensive security suite: NGFW, IPS, SWG, DLP, CASB; all-in-one endpoint agent with ZTNA and EDR for secure resource access.
- Cloud-native architecture for scalable security as organizations grow.
- Core components and capabilities
- Secured Global Access (SGA): cloud-delivered secure internet access with edge presence.
- Zero Trust Guard (ZTG): identity- and device-based access to private apps; adaptive access controls; MFA; continuous trust evaluation.
- Endpoint Security Access (ESA): unified endpoint protection (EPP) + zero-trust access to internal apps.
- Cloud-native architecture supports global PoPs, SASE connectors, and cross-border acceleration with cross-border compliance through partnerships.
- End-to-end security and integration
- ZTNA-based secure access to private apps, browser-based zero trust access (agentless for BYOD in some scenarios).
- Cross-border acceleration with AIO (agent-based) for SD-WAN-like performance; cloud-native SGA with global edge presence.
- Integrations: Athena NGFW, Athena EPP, Athena SASE connectors; Omni Client for end-to-end security.
- Use cases and benefits
- Hybrid work, threat prevention, secure connectivity, cross-border traffic acceleration.
- Consolidates security services with zero-trust access, end-to-end data protection, and SASE-driven user experience.
- FAQ highlights
- SASE is not intended to replace on-site office firewalls entirely; in-office firewall presence is still relevant; SASE primarily serves remote/mobile users.
- ZTNA can replace legacy SSL VPNs; supports Microsoft Active Directory integration for authentication.
Athena XDR
- What is Athena XDR?
- Advanced SIEM/SOC replacement with cross-domain data correlation across networks, endpoints, servers, applications, and cloud.
- Integrates with Security GPT (generative AI assistant) for simplified SecOps operations via Omni-Command.
- Highlights and benefits
- Consolidates logs/alerts into single incidents; reduces false positives by up to about 90%.
- Provides comprehensive network visibility for holistic threat understanding.
- Security GPT enables chat-based operations and automation; trained on billions of parameters; reported accuracy > 99% in identifying advanced threats in some evaluations.
- Reduces operational costs by consolidating products and capabilities; streamlined SecOps dashboard; easier third-party integrations.
- Data sources and architecture
- Endpoint data (Sangfor EPP/NGFW/STA) + Network data + 3rd-party endpoint/network/SIEM tools.
- Data ingestion supports RESTful API, Syslog, Kafka (on-prem), and RESTful API (SaaS).
- Functionality and workflow
- Collect and ingest data, parse, correlate, and analyze to detect hidden threats; automate response and playbooks via SOAR.
- Generative AI-assisted threat hunting and incident response; automated triage and analysis; contextual alerts to reduce noise.
- Auto-pilot Security GPT for autonomous detection/investigation with human-in-the-loop as needed.
- Maturity and versions
- XDR v1 vs XDR v2: v2 introduces enhanced asset management, dedicated security alerts/incidents, 3rd-party data ingestion with adaptive AI rules, and enhanced reporting.
- SOC integration and interoperability
- Integrates with Splunk/SIEM-like platforms; supports 3rd-party data ingestion, SOAR playbooks; provides API/REST interfaces for automation.
- Sangfor Athena MDR overview
- Managed Detection and Response service layered on top of Athena NGFW/EPP + XDR.
- Aims to improve cyber security operations with continuous threat detection and remediation advisory.
- SOC located in Malaysia (primary) with CN backup; ISO 27001:2022 certified security management.
- Service zones: Detection, Remediation, Asset information, Threat/Events, IOCs; security analysts oversee operations with a cloud-based SOC.
- Service delivery and process
- threat intel, security rules, AI-powered machine analysis; human analyst verification; remote remediation recommendations.
- Two-way real-time notifications; proactive threat response; remote device configuration for remediation.
- Provides incident reports and improvement plans; supports playbooks; integrates with XDR, EPP, and NGFW.
- Service delivery model and credentials
- Operational-based MDR with continuous monitoring; incident-based IR as needed.
- Service levels and outcomes: threat detection/notification, remote remediation advisory, incident investigation, and continuous improvement plans.
- MAES bundle and offerings
- MAES bundles combine MDR with endpoint security (EPP) and NGFW to deliver end-to-end protection; designed for different customer segments (SMB to enterprise).
- End-to-end protection with ransomware honeypot, file backup, dynamic AI-based threat detection, and cross-domain visibility.
- Practical use cases and customer value
- Suitable for customers with limited in-house security resources, growing threat complexity, or regulatory requirements necessitating 24/7 monitoring.
- Helps fill capability gaps and reduce mean time to detect (MTTD) and respond (MTTR) with AI-driven analytics and human expertise.
- Service delivery architecture
- Platform-X data lake hub; SOC operations run by Sangfor security experts; customer portal for visibility and reporting.
- Partnerships for on-site support where required; MDR data centers in Malaysia.
Sangfor Security Solutions: Integrated and Simplified SecOps
- Simplified Security Operations approach
- Integrates Sangfor security products (NGFW, EPP, XDR) with third-party tools to streamline risk and asset management, threat detection, and incident response.
- Emphasizes the synergy between network and endpoint security with AI-assisted threat detection and response.
- Use-case-driven deployment planning
- Typical customer requirements and segments: small teams with limited resources, mid-market needing MDR, large enterprises seeking full-stack SecOps.
- Phase-based deployment approaches (Phase 1–3 for NGFW, EPP, XDR, MDR; later phases for added capabilities like STA network sensor).
- Ransomware protection and MAES bundles
- Endpoints + network protection with ransomware honeypot, file backups, and dynamic AI-based detection to prevent encryption and enable quick recovery.
- Cross-product integration and AI capabilities
- Security GPT and Auto-Pilot capabilities to automate threat detection, investigation, and remediation.
- 3rd party data ingestion and SIEM integration to broaden visibility and improve correlation.
Sizing, Licensing, and Opportunities (Overview)
- Sizing methodology and calculators
- Throughput-based sizing by model (M5100/M5200/M5400/M5500, M6000 series) with recommended concurrent user counts per model.
- Example sizing rule: Required throughput = Upload + Download; ensure model’s full throughput exceeds estimated needs with headroom for future growth and features such as WAF/IPS when applicable.
- Licensing model overview
- Bundles: ESSENTIAL, PREMIUM, ULTIMATE for NGFW; SWG and SASE have their own bundles with combinations of features.
- Per-name/user-based licensing for SGA (Secured Global Access) and ZTG (Zero Trust Guard), with add-ons for connectors, cloud, and private/public cloud deployment.
- Licensing for endpoints (EPP) and MDR add-ons; upgrade paths between bundles are supported mid-period.
- Ordering scenarios (example)
- Example: 4,000 users requiring secure internet and private apps access across multiple geographies could use SGA Ultimate bundle for 3-year subscription with ZTG for private app access and application acceleration for cross-border traffic; add SASE connectors for cloud-hosted apps.
- Deployment and implementation considerations
- In-office appliances vs. cloud-native deployments; cross-border traffic patterns; the need for SD-WAN integration and PoP distribution for low latency.
- Data sovereignty and privacy considerations when deploying MDR and logging in a cloud-enabled model; NDA and data-sharing policies with customers.
- Throughput sizing principle:
- extRequiredthroughput=extUpload+extDownload
- Ransomware kill-time claim (Athena EPP): 3 seconds to detect and respond to ransomware activity.
- 99% threat coverage claim for external threats with Engine Zero and Neural-X integration.
- 3-year promotions and bundled licensing terms involve providing 1 year of EPP/MDR for certain server counts when purchasing NGFW bundles (3-year minimum).
Real-World Connections and Implications
- Practical relevance
- For organizations migrating to a cloud-first or hybrid model, SASE and SWG provide scalable internet access security with low latency and centralized policy enforcement.
- Endpoint protection (EPP) combined with NGFW (NGFW + XDR) provides cohesive, cross-layer protection against sophisticated threats that leverage both network and endpoint vectors.
- Ethical and practical implications
- Data privacy and cross-border data handling in MDR/XDR deployments require clear NDA, data minimization, and encryption in transit/at rest; ensure transparency on what logs are collected and who has access.
- Real-world relevance
- Gartner and CyberRatings recognitions signal market validation for Sangfor’s integrated security approach.
- The platform emphasizes automation and AI-assisted SecOps to address talent shortages and alert fatigue in modern security operations.
Quick Glance: What to Remember
- Athena NGFW: AI threat detection (Engine Zero), Neural-X threat intel, built-in WAF, vulnerability assessment, SOC Lite; scalable by model with clear throughput guidance; bundles and promotions to incentivize bundled security.
- Athena EPP: Modern EPP with NGAV/EDR, ransomware honeypot, 3-second kill, single license, asset/vulnerability management, cross-product integrations (NGFW, XDR); MAES bundles for managed endpoint security.
- Athena SWG: Secure Web Gateway with DLP, SSL decryption, granular application control, compliance reporting; differentiates from traditional firewall through deep web/app controls and proxy capabilities.
- Athena SASE: Cloud-native, integrates SGA, ZTG, ESA; secure internet access and private app access with zero-trust, cross-border acceleration, and agent/connector-based deployment.
- Athena XDR: Cross-domain data correlation, AI-assisted SecOps (Security GPT), reduced false positives, SIEM-like capabilities with SOAR integration; two versions with expanded data ingestion and reporting.
- Sangfor Security Services: MDR/IR as a managed layer; ISO-certified security operations center; 24x7 monitoring with threat intel and remediation playbooks; MAES bundles for end-to-end protection.
- Licensing and sizing emphasize per-user/per-host licensing, throughput-based sizing, and flexible upgrade paths across bundles.