Powerful Unified Threat Management (UTM) Firewall
Where to buy


D-Link, the world's leading provider of total network solutions for SOHO and SMB, with products ranging from broadband modems/routers to managed Ethernet/Gigabit switches, wireless LAN, surveillance IP cameras and network storage, introduces a series of highperformance NetDefend UTM firewalls designed to answer businesses' need for complete network integration across different product lines. The D-Link DFL-860 NetDefend Unified Threat Management (UTM) firewall are powerful security solution designed to protect the small to mid-sized offices from a wide variety of network threats. These firewalls provide integrated remote routing, Network Address Translation (NAT), Virtual Private Network (VPN), proactive network security, Intrusion Prevention System (IPS), Web Content Filtering (WCF), Anti-Virus (AV) Protection, traffic load balancing and bandwidth management, all in one compact desktop chassis that can be easily integrated to existing network.

Enterprise-Class Firewall Security

The DFL-860 complete advanced security features to manage, monitor, and maintain a healthy and secure network. Network management features include: Remote Management, Bandwidth Control Policies, URL/Keyword Blocking, Access Policies and SNMP. For network monitoring, these firewalls support e-mail alerts, system log, consistency checks and real-time statistics.


Powerful VPN Performance


For optimal VPN configuration, the DFL-860 has an integrated VPN Client and Server to support almost any required VPN policy. This allows a remote office to securely connect to a head office or a trusted partner network, while mobile users working from home or at other places can also safely connect to the office network to access company data and access e-mail. The DFL-860 has hardware-based VPN engines to support and manage a large number of VPN configurations. They support IPSec, PPTP, and L2TP protocols in Client/Server mode and can handle pass-through traffic as well. Advanced VPN configuration options include: DES/3DES/AES/Twofish/Blowfish/CAST-128 encryption, Manual or IKE/ISAKMP key management, Quick/Main/Aggressive Negotiation modes, and VPN authentication support using either an external RADIUS server or a large user database.


Unified Threat Management


The DFL-860 integrate an Intrusion Detection and Prevention System (IDP/IPS), gateway Anti-Virus (AV) and Content Filtering/Web URL Filtering for superior Layer 7 content inspection protection. They use a hardware accelerator approach to increase IPS and AV throughput, and a web surfing control database containing millions of URLs for Web Content Filtering (WCF). IPS, Anti-Virus and URL database real-time update services protect the office network from application exploits, network worms, malicious code attacks, and provide everything a business needs to manage employee Internet access behavior.


UTM Services


Maintaining an effective defense against the various threats originating from the Internet requires that all three databases used by the DFL-860 are kept up-to-date. In order to provide a robust defense, D-Link offers optional NetDefend Firewall UTM Services subscriptions which include distinct NetDefend service updates for each aspect of defenses: IPS, Anti-Virus and WCF. NetDefend UTM Subscription ensure that each of the firewall's service databases is always accurate and current.


Robust Intrusion Prevention


The DFL-860 adopt a unique IPS technology - component-based signatures, which are built to recognize and protect against all varieties of known and unknown attacks, and which can address all critical aspects of an attack or potential attack including payload, NOP sled, infection, and exploits. In terms of signature coverage, the IPS database includes attack information and data from a global attack sensor-grid and exploits collected from public sites such as the National Vulnerability Database and Bugtrax. The DFL-860 deliver high quality IPS signatures by constantly creating and optimizing NetDefend signatures via the D-Link Auto-Signature Sensor System. Without overloading existing security appliances, these signatures ensure a high ratio of detection accuracy and the lowest ratio of false positives.


Stream-Based Virus Scanning


The DFL-860 scan files of any sizes, using the stream-based virus scanning technology that does away with caching of incoming files. This scanning method increases inspection performance while eliminating network bottlenecks. The firewalls use virus signatures from the known, respected antivirus company Kaspersky Labs to provide users with reliable and accurate antivirus signatures, as well as prompt signature updates. Viruses and malware consequently can be effectively blocked before they reach the network's desktops or mobile devices.


Web Content Filtering


Web Content Filtering helps MIS monitor, manage, and control employee usage of and access to the Internet. The DFL-860 implement multiple global index servers with millions of URL and real-time website information to enhance performance capacity and maximize service availability. These firewalls use highly granular policies and explicit black lists/white lists to allow or disallow where and when access to certain types of websites for any combination of users, interfaces and IP networks. They can strip potential malicious objects, such as Java applets, JavaScripts/VBScripts, ActiveX objects and cookies to actively handle the Internet content.


Hardware Accelerator


Equipped with hardware accelerators, the DFL-860 can carry out IPS, Anti-Virus scanning functions simultaneously without degrading firewall and VPN performance. These powerful accelerators allow these firewalls to perform with a much higher throughput than other antivirus-capable UTM firewalls on the market.

General features


Order info


Front view
Back view


Support Resources