- Does AppShield come as an appliance-based solution?
- What are the customer benefits of this solution?
- What are the different appliance models available?
- How can my current Sanctum VAR become a Sun iForce reseller?
- Can Sun VARs resell the product?
- Will Sun be reselling the appliance?
- How does this solution compare to the Teros APS-100?
- How does this solution compare to Kavado's InterDo?
- What is the expected performance?
- What are the recommended configuration guidelines?
- Can current Sanctum VARs resell the product?
- What are the warranty policies on the Sun hardware?
- What additional support does the customer receive on the Sun hardware?
|
|
Does AppShield come as an appliance-based solution? |
|
Yes. The AppShield appliance is a co-branded SunFire V100/V120 or SunFire 280R pre-installed with a Sanctum-hardened version of Solaris 8TM, AppShield, and an optional SSL card.
Back to Questions
|
|
What are the customer benefits of this solution? |
|
- Great TCO
- Simplified installation
- Reduced support costs
- Rapid deployment via security templates and automatic rules generation enables fast implementation
- Positive security model eliminates the need for costly signature updates, patches or surprise maintenance
- Secure Proxy architecture simplifies the manageability and configuration of the Web application layer.
Back to Questions
|
|
What are the different appliance models available? |
|
- AppShield 100 - (550MHz UltraSPARC IIi, w/1GB)
- AppShield 100s - (SunFire V120 : 650Mhz UltraSPARC IIi, w/1GB w/ SSL card)
- AppShield 280 - (2 x 900Mhz UltraSPARC III w/ 2GB RAM and GigE NIC)
- AppShield 280s - (same as above w/SSL card)
Back to Questions
|
|
How can my current Sanctum VAR become a Sun iForce reseller? |
|
Your VAR will need to contact GE Access
first to fill out a credit application and a terms and conditions agreement.
Secondly, the VAR will also have to become an authorized Sun iForce reseller.
GE Access can help with this process or the VAR can contact the local
Sun iForce (channel) rep at 1-800-555-9SUN or 1-650-960-1300 or visit the
Sun website.
Alternately, contact David Colodny
for more information if you have problems.
Back to Questions
|
|
Can Sun VARs resell the product? |
|
Yes as long as the VAR also agrees to Sanctum's requirements for becoming a Sanctum channel partner.
Back to Questions
|
|
Will Sun be reselling the appliance? |
|
Not at this time.
Back to Questions
|
|
How does this solution compare to the Teros APS-100? |
|
Teros APS-100 |
Sanctum AppShield Appliance |
Teros's solution is appliance only, based on a home-grown, hardened - Linux-based box for $25k list, protecting five to ten web servers. |
Sanctum's appliance is backed by a world -class hardware manufacturer, Sun. Solaris is well known as a one of the most robust, widely deployed operating systems |
0% protection - default (allow all) or customize. |
80% plus protection - site specific auto configuration tools provide excellent coverage. |
Very Low - has a learning mode. No automation. |
High - fully automated - templates, automated learning tools, site specific and customizable. |
No.
- Manual learning of site
- Requires maximum admin knowledge of apps (1 week)
- Manual policy creation - very slow
- Complex sites never fully protected
|
Yes
- Automated behavioral learning
- Requires minimal admin knowledge of apps
- Complex sites secure in less than 3 days
- Site fully protected during initial configuration
|
High - need to be able to write many policies specific to site and application. |
Low - automated policy generation tools do the work, admin designates trusted user for AppShield to learn from. |
Doesn't support privacy policies. |
Able to hide sensitive fields in logs to meet strict regulatory privacy requirements. |
$25,000 (plus redundant system) |
$15,000/Web/App Server |
One customer, less than three months of commercially available product. |
Over 250 customers, five years of commercially available product. |
Back to Questions
|
|
How does this solution compare to Kavado's InterDo? |
|
Kavado Interdo |
Sanctum AppShield Appliance |
Even though Kavado recently introduced a new appliance, the underlying technology is far from competitive with AppShield.. |
Sanctum's appliance are backed by a world-class hardware manufacturer, Sun. |
30% protection - pipes not site specific. |
80% plus protection - site specific auto configuration tools provide excellent coverage. |
Low - minimal automation not site specific; no customizable rules; no configurable settings. |
High - fully automated - templates, automated learning tools, site specific and customizable. |
No.
- Manual learning of site
- Complex: requires maximum admin knowledge of apps
- Manual policy creation - very slow
- Complex sites never fully protected
|
Yes
- Automated behavioral learning
- Requires minimal admin knowledge of apps
- Complex sites secure in less than three days
- Site fully protected during initial configuration
|
High admin knowledge required
- Beta-quality GUI
- Complex product
|
Low admin knowledge required
|
Doesn't support privacy policies. |
Able to hide sensitive fields in logs to meet strict regulatory privacy requirements. |
Real time alerts; Standard logging; OPSEC integration; flexible alerting. |
Real time alerts; Standard logging; OPSEC integration; SNMP traps; full featured alerts. |
OPSEC SAM |
ICSA Labs; OPSEC SAM |
Periodic updates needed. |
None needed. |
No named customers; one year of commercially available product. |
Over 250 customers; five years of commercially available product. |
Back to Questions
|
|
What is the expected performance? |
|
Performance depends on web server throughput / transactions per second (TPS).
AppShield 100 can sustain up to an estimated maximum 35Mbps or 428 TPS depending on transaction size.
AppShield 280 can sustain up to an estimated maximum of 120Mbps or 1400 TPS depending on transaction size. Sanctum will be providing more detailed performance numbers over the coming weeks.
Back to Questions
|
|
What are the recommended configuration guidelines? |
|
AppShield 100 protects approximately 3-5 web servers
AppShield 280 protects approximately 10-15 web servers
Always recommend a high-availability configuration. Sell a pair of appliances per supported configuration. For example, if a customer has 12 web servers to protect, you should sell 2 AppShield 280 ($160k) or 6 AppShield 100 ($150k) and recommend two F5 BIG-IPs for Load Balancing.
Back to Questions
|
|
Can current Sanctum VARs resell the product? |
|
Yes. However the VAR must also be or become a Sun iForce reseller as well, which is very easy. Currently Applied Computer Solutions and Sysix are the only two VARs who meet these requirements.
Back to Questions
|
|
What are the warranty policies on the Sun hardware? |
|
Both the SunFire V100 and V120 carry a 1 year warranty. Hardware repair and replacement for these products is 15 business days parts exchange when the customer sends defective part back to Sun. The SunFire 280R carries a 3 yr. warranty and provides 2 business days on-site parts exchange. Be aware that if the server or hard disk has to be replaced, it will not come pre-installed with with hardened Solaris or AppShield as does the appliance. The customer is responsible for re-installing his backed up image of both.
Back to Questions
|
|
What additional support does the customer receive on the Sun hardware? |
|
Sanctum is reselling the Sun Spectrum Silver support services that include the following highlights:
- Coverage for Sun hardware and the Solaris[tm] Operating Environment
- Telephone and online assistance from Sun's technical support specialists
- Four-hour on-site response for Priority 1 requests
- 24/7 access to Sun's technical knowledge database
- Software releases and patch access
- Online self-service resources
- Customer-defined priority on support requests
For more details on Sun�s Spectrum Silver support services, please click here.
Back to Questions
|
|
|
|
AppShield, Policy Recognition, and Adaptive Reduction are trademarks of
Sanctum, Inc. All other product names referenced are the property
of their respective owners and are hereby acknowledged.
|