Solution

Central Branch Network

Your branches in different cities work like a single closed-circuit network. You define who can reach what at the central site, and the log records of branch traffic are gathered centrally. Your management workload does not grow as your branch count does.

What You Gain

One network to manage instead of dozens of branch networks

Your branches connect to the central site regardless of location or service provider; they meet on the same local network as if there were a real cable between them. That way you build your own closed-circuit branch network and manage it from one place.

A single closed-circuit network

Your branches connect to the central site regardless of location or service provider; the link in between works as if there were a real cable. Branches stop being networks cut off from one another.

Policy at the central site

Access, filtering and bandwidth rules are defined centrally. When a rule changes you do not have to travel branch to branch; there is no separate rule set to configure at the branch.

Logging at the central site

Because branch traffic passes through the central site, the access records also accumulate there, are signed and reported from one place.

Architecture

Policy comes down from the center, all traffic comes up to it

However many branches there are, the traffic flow is two-way and both directions terminate at the central site. The only thing sent to the branch is policy; what comes from the branch is the traffic itself. The record is not created at the branch; the traffic is recorded and stored centrally.

BRANCHES Branch A switch, AP, users Branch B switch, AP, users Branch C switch, AP, users existing internet lines · any provider Encrypted tunnels a separate tunnel per branch, one central site CENTRAL SITE XLOG Firewall the tunnels terminate here, the records are kept here policy and configuration all traffic Adding a branch amounts to adding one more tunnel at the central site.
Central Policy

Services delivered without installing a device at the branch

When all of the branch traffic reaches the central site, every service below is delivered from the firewall there. You do not need to place a separate firewall, a separate logging device or an additional DHCP/DNS server at the branch.

Who can join the network

  • Hotspot (Captive Portal Login)
  • 802.1x MAC authentication
  • MAC-based allow and block definition

What they can reach

  • Firewall policy definition
  • Web filtering
  • IPS/IDS and application filter
  • NAT

How fast they can use it

  • MAC-based bandwidth definition
  • Live per-user bandwidth monitoring

What is recorded

  • Signed logging
  • Log reporting

This table describes the way of working where all branch traffic is carried to the central site. Carrying only part of the traffic is also possible; the difference between the two modes is explained on the XLOG Mini Tunnel page.

Central Logging

A signed record gathered in one place

Because branch traffic reaches the central site, the access records are kept there too. When an audit is requested you search from one place instead of travelling branch to branch.

Signed records
The records of branch traffic are kept centrally and signed
Time-stamp signing
Log records are signed automatically
2 years
Records are kept signed on the device

What can be searched in the records

Detailed reporting lets you search the internet records by the fields below.

MAC address Source IP Destination IP Username Destination port Domain Date

Keeping the record

On HTTPS visits, the host name of the destination address is recorded alongside the IP.
Internet logs from other firewall brands are signed through syslog signing.
Internet records can be copied to another device with FTP backup.
Internet records can be downloaded to your computer by selecting a date range.
Administrative logins to the system are also recorded separately.
Components

The parts that build the central branch network

A device that receives the traffic at the central site, and a device that establishes the tunnel at the branch. If you have a firewall of a different brand at the central site, you can build this without replacing it.

CENTRAL SITE

XLOG Firewall

The point where the tunnels from the branches terminate. Policy is defined here, and filtering and logging happen here.

XLOG Firewall
BRANCH

XLOG Mini Tunnel

The mini box at the branch end. It works with central management and central reporting; it joins the branch network to the central site at Layer 2.

XLOG Mini Tunnel
ALTERNATIVE CENTRAL END

Porsuk

If you have a firewall of a different brand at your central site, Porsuk works without replacing it and an unlimited number of branches can connect.

Porsuk

Let us bring your branch network to the central site

Share your branch count and your existing setup at the central site; let us work out together how your central branch network will be built.

Request a demo