VT AIR Medical2023-02-20T06:04:46+01:00

VT AIR

Cyber security for medical practices and clinics

Clinics and medical practices cannot afford a loss of data or even an operational failure. VT AIR firewalls offer optimal protection against unauthorized access to the IT systems.

Prevent Data Loss

VT AIR. IT Made in Germany

The National Association of Statutory Health Insurance Physicians expects practices to better protect their IT systems and data. Not without reason: This is the only way to protect sensitive patient data from unauthorized access and attacks. Doctors best protect their IT systems and thus their data if they rely on modern IT technology in the backend. With smart IT, data loss or even a complete breakdown can be prevented. The KBV therefore demands that “the transition to other networks, in particular the Internet, must be protected by a firewall”. Modern firewall systems that are state-of-the-art and easy to set up are indeed the gatekeepers to security. VT AIR Next Generation Firewalls meet the highest security requirements and impress with their industry-leading usability.

Display Förderung

IT Made in Germany

VT AIR is a German technology that was specially developed for business and its requirements. Our claim: we protect your company value.

VT AIR. Simply Convincing

Your money, your time, your satisfaction … Benefit from a Next Gen Firewall that offers you more than security. We’ll make it easy for you.

VT AIR

Simply lower costs

VT AIR

Simply less time consuming

VT AIR

Simply better Customer Experience

Cyber-Security –
the next big thing

The digitalization opens up undreamt-of opportunities and freedoms for the economy and society – but it also presents us with new challenges, because risks increase with opportunities. Cyber threats are a real danger – cyber security is the answer. Think about it!

Advantages VT AIR

VT AIR belongs to the third generation of firewall technology. Thanks to their numerous features and modern security technology, VT AIR firewalls offer comprehensive network protection because they prevent attacks in advance and do not offer hackers a gateway. In this way, clinics and medical practices can protect themselves effectively against unauthorized access to their systems and thus also to critical patient data. In addition, effective IT security can also avoid costly and image-damaging operational failures. VT AIR Firewalls offer comprehensive protection against cyber threats.

VT AIR. Lots of Features

Advanced Threat Protection2020-10-27T12:05:40+01:00

VT AIR offers a variety of advanced threat protection mechanisms.

Blocking unwanted and unsafe websites via DNS sinkholing technology and advanced web filters with virus scanners and content filtering.

Various intrusion detection and protection rules are also available.

Application Control2020-11-28T12:24:44+01:00

Application Control allows you to create firewall rules on the application level.

Traditional firewalls, which only identify ports, protocols and IP addresses, cannot identify and control applications, but a next generation firewall can. VT AIR Next Generation Firewall allows you to create firewall rules based on applications.

Intrusion Detection and Protection2020-08-25T11:36:28+02:00

The Intrusion Detection and Prevention System (IDS / IPS) of the VT AIR Firewall significantly improves network security by providing complete and comprehensive real-time network protection against a wide range of network threats, vulnerabilities, exploits and threats in operating systems and applications.

VT AIR scans network traffic using powerful and comprehensive rules and signature language to detect complex threats with the Surricata program.

Suricata is an open source based intrusion detection system and intrusion prevention system

Automatic signature updates are provided regularly to ensure that the VT AIR Firewall is always up to date.

Network Flow Fastpath2020-08-25T11:39:23+02:00

VT AIR supports the acceleration of TCP and UDP connections using Network Flow Fastpath.

For this purpose, the NFTables flow table offload technology is used, which accelerates network traffic by a factor of 2-3, all with the usual network security.

With Flowtables you can accelerate packet forwarding in software with the help of a state that no longer runs through the entire network stack after a connection has been established.

Multi Factor Authentication2020-08-25T11:38:47+02:00

Multi-factor authentication (MFA) has become the standard to prevent unauthorized access to business-critical information.

VT AIR supports multi-factor authentication with the TOTP standard for the web interface and OpenVPN to protect your infrastructure in the best possible way.

Stateful Deep Package Inspection2020-08-25T11:37:59+02:00

VT AIR is a stateful firewall. A stateful firewall is a network firewall that tracks the operational status and characteristics of network connections that pass through them. The firewall is configured to distinguish between legitimate network packets for different connection types.

Packets are analyzed with NFTables (Deep Package Inspection) and allowed or blocked on the basis of firewall rules in order to ensure optimal protection of the network traffic.

Web Control/Web Protection2020-08-25T11:37:26+02:00

Advanced Web Protection combines advanced analysis functions, blacklists and ACLs to optimally protect your web traffic.

With the built-in virus scanner, you can optimally protect your web traffic.

VT AIR uses the Squid program, which is characterized by its diverse functions and security.

The web filter can be set up as a proxy, but also as a transparent HTTP / HTTPS proxy.

XDP/eBPF2020-08-25T11:40:16+02:00

With XDP, network functions (eBPF) can be executed as soon as a packet reaches the network card and before it is moved up into the kernel’s network subsystem, which leads to a significant increase in packet processing speed. This technology allows us to achieve significantly faster firewall speeds.

In general, all of our VT AIR appliances are already prepared for XDP / eBPF.

This technology will be available in VT AIR in 2021.

Authenticator 802.1X2020-08-25T11:45:35+02:00

The IEEE 802.1X standard provides a general method for authentication and authorization in IEEE 802 networks. At the network access, a physical port in the LAN, a logical IEEE 802.1Q VLAN or a WLAN, a participant is authenticated by the authenticator, who uses an authentication server (RADIUS server) to check the authentication information transmitted by the participant (supplicant) and, if necessary, the Permits or denies access to the services offered by the authenticator (LAN, VLAN or WLAN).

VT AIR has both an 802.1X authenticator and an 802.1X supplicant.

CaptivePortal2020-08-25T11:47:13+02:00

A captive portal is a facility that is usually used in public, wireless networks in order to link the access of end devices such as laptops or smartphones to the underlying network or the Internet to the user’s consent to certain usage rules. In addition, the network provider can link access to a specific user account. VT AIR allows you to set up a captive portal for each interface with its own HTML page for authentication.

DHCP2020-08-25T11:41:12+02:00

VT AIR comes with a built-in IPv4 and IPv6 Kea DHCP server.

Whether static or dynamic DHCP addresses and multiple networks, you can supply your clients with addresses without any problems.

The Kea DHCP server is also capable of high availability and can form an automatic failover with several VT AIRs.

DNS2020-08-25T11:43:07+02:00

VT AIR comes with the well-known Unbound DNS Server, which allows it to run as a stand-alone or as a forwarding DNS server. Unbound allows you to define any host overrides and domain forwarding. For security reasons, VT AIR uses different DNS block lists with categories. Encrypted DNS and DNSSEC are also not a problem.

Docker2020-08-25T11:45:10+02:00

Docker is a range of platform-as-a-service products that use virtualization at the operating system level to deliver software in packages. These are known as containers. Containers are isolated from each other and bundle their own software, libraries and configuration files. They can communicate with each other via precisely defined channels. VT AIR has support and management via the WebGUI for Docker.

HAProxy2020-08-25T11:47:55+02:00

HAProxy is free, open source software that provides a highly available load balancer and proxy server for TCP and HTTP-based applications that distribute requests across multiple servers. VT AIR has full support for setting up and operating a HAProxy via the web interface.

NtoPNG2020-08-25T11:54:08+02:00

ntopng is a software for monitoring data traffic on a computer network. It was developed as a powerful and resource-effective replacement for ntop. With ntopng on VT AIR you can analyze and monitor your network traffic per interface, host or network segment.

NTP2020-08-25T11:43:43+02:00

Network Time Protocol is the most common method of synchronizing a system’s software clock with Internet time servers. It is designed to mitigate the effects of variable network latency and can typically limit the time over the public Internet to ten milliseconds. The accuracy in local networks is even better with up to a millisecond. VT AIR comes with an NTP server for the network clients.

SNMP2020-08-25T11:54:47+02:00

The Simple Network Management Protocol is a standard Internet protocol used to collect and organize information about managed devices on IP networks and modify that information to change device behavior. VT AIR supports SNMPv1 / v2 and the encrypted SNMPv3 for high security. Read all the attributes of the firewall with SNMP, with the special VT AIR SNMP mibs you have full control over your monitoring.

BGP/OSPF2020-08-25T11:59:52+02:00

FRR is used for dynamic routing, which allows BGP and OSPF (v4 or v6).

Firewall Performance2020-08-25T12:02:48+02:00

VT AIR offers high firewall performance with NFTables, Flowtable Offload Technology and, in the future, XDP / eBPF.

High Availability2020-08-25T12:02:31+02:00

VT AIR comes fully equipped with high availability functionality. Use virtual IPs (VRRP) between multiple VT AIRs to enable failover without interruptions. The VT AIR configuration is automatically transferred from the master to the slaves and DHCP can also be used in HA operation to compensate for a failure. High availability is a must for critical installations and VT AIR enables smooth operation.

Interfaces2020-08-25T11:57:39+02:00

VT AIR offers a multitude of options for using and configuring interfaces. Real Interface, VLAN, QinQ, Bond, Bridge, PPP, PPTP, GRE, IPIP, SIT SHDSL, VDSL and MacVLAN are supported. In addition, various settings can be made IPv4 / IPv6, Static IP, DHCP Client, SLAAC, Mac, MTU, MSS, Link Mode, 802.1x (Suplicant) … and much more.

Routing2020-08-25T11:58:58+02:00

VT AIR offers static and dynamic routes. Gateways can be monitored using ping and intelligently interconnected in routing tables, either in failover or load balancing mode. A policy routing can also be set using firewall rules or a routing table can be assigned to clients. FRR is used for dynamic routing, which allows for BGP and OSPF (v4 or v6).

QoS2020-08-25T12:00:43+02:00

QoS is implemented with the Linux tool Traffic Control (TC) and allows incoming (ingress) or outgoing (egress) traffic to be classified according to categories and rules. QoS can easily be assigned to clients via firewall rules.

IPSec2020-08-25T12:04:23+02:00

Internet Protocol Security (IPsec) is a protocol suite that enables secure communication over potentially insecure IP networks such as the Internet. VT AIR offers full support for IPSec with Strongswan. Whether tunnel or transport mode, with or without an interface, with VT AIR you can connect your locations conveniently and securely.

OpenVPN2020-08-25T12:04:53+02:00

OpenVPN is free software for setting up a virtual private network (VPN) via an encrypted TLS connection. VT AIR supports OpenVPN as a client or as a server and enables you to set up a VPN for your employees quickly and easily.

WireGuard2020-08-25T12:06:08+02:00

WireGuard is free software for setting up a virtual private network (VPN) via an encrypted connection. WireGuard enables a very fast and modern VPN. VT AIR supports WireGuard natively, whether for clients, site to site or mesh.

WebVPN2020-11-20T12:24:52+01:00

WebVPN allows you to access an RDP / VNC / SSH or Telnet server via a WebVPN portal via the browser. VT AIR allows your users to access the devices with the browser without a client.

WebGUI2020-08-25T12:06:33+02:00

The modern, easily understandable and dynamic web interface, which is created in numerous languages, allows you to make all settings conveniently and easily – in the interests of the user.

REST API2020-08-25T12:08:13+02:00

VT AIR comes with a modern REST API interface, via which all settings can be made conveniently and easily. Regardless of whether you have 1 or 1000 devices, with the REST API, the settings on all devices can be changed in seconds.

Central Management Portal2020-11-20T12:21:02+01:00

VT AIR offers a central management portal where you can see all devices in one place and thus easily access them. With our secure and innovative connector, you can directly access the web interface or the command line in the portal or run updates directly.

Firewall Performance

Firewall Gb/s

5.10 

VT AIR 100

14.88 

VT AIR 500

37.74 

VT AIR 1200

37.74 

VT AIR 1500 

VT AIR Family. Top Appliances

 

  VT AIR 100 VT AIR 600 VT AIR 1200 VT AIR 1500
  Desktop Desktop
Rack Rack
  VT AIR 100 Front Straight Business Firewall
Nutzer
Business    
Enterprise    
Geeignet für
 
  • Small Offices
  • Medium Offices
  • VPN Endpoint
  • Medium Offices
  • IPS Anforderungen
  • VPN Endpoint
  • Zweigstelle
  • Medium Office
  • IPS Anforderungen
  • Datencenter mit Rack
  • VPN Server
  • Large Office
  • IPS Anforderungen
  • Datencenter
  • VPN Server
Performance
Packages Per Second XDP ~775.000 pps ~2.850.000 pps ~9.500.000 pps ~13.500.000 pps
Packages Per Second ~450.000 pps ~1.300.000 pps ~4.900.000 pps ~7.000.000 pps
Max. Connections ~1.000.000 ~10.000.000 ~20.000.000 ~40.000.000
iPerf3
Firewall 5.10 Gb/s 16.00 Gb/s 37.74 Gb/s 37.74 Gb/s
App Control/
Intrusion Protection
565 Mb/s 1.50 Gb/s 2.92 Gb/s 4.32 Gb/s
IPSec VPN 520 Mb/s
(AES-256 CBC, SHA256)
1.36 Gb/s
(AES-256 GCM)
3.83 Gb/s
(AES-256 GCM)
4.21 Gb/s
(AES-256 GCM)
OpenVPN 125 Mb/s
(AES-256 GCM)
320 Mb/s
(AES-256 GCM)
1.34 Gb/s
(AES-256 GCM)
1.41 Gb/s
(AES-256 GCM)
Wireguard 500 Mb/s 1.06 Gb/s 4.92 Gb/s 5.78 Gb/s
IMIX
Firewall XDP 2,40 Gb/s 5.20 Gb/s 28.02 Gb/s 35.21 Gb/s
Firewall 1.39 Gb/s 2.60 Gb/s 14.49 Gb/s 18.38 Gb/s
App Control/
Intrusion Protection
290 Mb/s 772 Mb/s 3.79 Gb/s 4.79 Gb/s
IPSec VPN 208 Mb/s
(AES-256 CBC, SHA256)
520 Mb/s
(AES-256 GCM)
1.70 Gb/s
(AES-256 GCM)
1.90 Gb/s
(AES-256 GCM)
OpenVPN 50 Mb/s
(AES-256 GCM)
96 Mb/s
(AES-256 GCM)
560 Mb/s
(AES-256 GCM)
663 Mb/s
(AES-256 GCM)
Wireguard 230 Mb/s 425 Mb/s 1.42 Gb/s 2.12 Gb/s
Hardware
CPU ARM v7 Cortex-A9 @ 1.6 GHz 4 Core ARM64 Intel Xeon D 2123IT, 2.2 GHz, 4 Core Intel Xeon D 2146NT, 2.3 GHz, 8 Core, Intel Quick Assist
Storage 8GB eMMC 64GB eMMC 256GB M.2 MLC SSD SATA 2x 240GB Datacenter SSD SATA Hot Swap (RAID1)
Memory 1GB DDR3 8GB DDR4 16GB DDR4 ECC Reg 32 GB DDR4 ECC Reg
Netzwerkports

2x 1Gb RJ45
1x 1Gb SFP

2x 10Gb SFP+
4x 1Gb RJ45

2x 10Gb Intel SFP+
2x 10Gb Intel RJ45
4x 1Gb Intel RJ45
2x 10Gb Intel SFP+
2x 10Gb Intel RJ45
9x 1Gb Intel RJ45
Anderes
  • Optional:
    • 2x VDSL
    • 1x 5G/LTE/3G
  • IPMI
  • IPMI
  • Optional:
    • 2x 4 Port 10GB SFP+
Go to Top