Cambium NSE 3000 - Security & SD-WAN Gateway
SME Security & SD-WAN Appliance, 100 VPN
The Network Service Edge (NSE) delivers advanced security, network and WAN services for small and medium enterprise networks. These services are integrated into Cambium’s ONE Network solution that enables organizations to deploy and manage security policy across the wireless and wired network, all fully managed and controlled as part of a single framework using cnMaestro cloud.
NSE 3000 features two Gigabit WAN ports, four Gigabit LAN ports and offers reliable connectivity with WAN throughputs of up to 1 Gbps. An industry-leading IDS/IPS engine, advanced application and Geo-IP firewalls, a network security scanner, anti-malware protection and SD-WAN for cutting edge application visibility and control.
Security
- With a single click, enable intrusion detection or prevention and let the industry-leading IDS/IPS engine protect your network against threats. This engine supports both community and paid premium rules.
- Create advanced firewall layer-3 and application based rules to protect your network. Use Geo-IP filters to deny or allow traffic to/from specific countries
- Create Secure tunnels between multiple sites or connect securely to a central site with site-to-site VPN
- Audit security vulnerabilities for devices on your network with always-on scans and get notified when critical vulnerabilities are discovered and reported.
- Filter malware and undesired content with DNS content filter. Options to block from over 88+ categories of domain names.
SD-WAN & Traffic Engineering
- Set up WAN-links to share traffic or configure them in an active-backup fashion
- Share traffic on both WAN-links and specify the traffic load
- Tracks WAN link health and automatically fails over traffic to the performing link
- Prioritize business-critical applications and restrict bandwidth for non-critical apps
- Easily prioritize and allot reserved bandwidth for time-sensitive voice applications
Network Services
- Create separate networks for employees, guests and IoT devices with ease.
- Enable traffic shaping and rate-limiting policies to cap internet bandwidth for guests
- Use the on-box RADIUS server to create user accounts and setup secure network authentication for all users and devices on your network
- NSE includes and on-box DNS-server. Can be used to block content granularly from over 88 categories.
- NSE supports Dynamic DNS updates for WAN-interfaces. Create easy to remember hostnames to expose on-premise services
- NSE keeps all databases current and always updated - intrusion rules, vulnerability reports, device signatures, GEO-IP databases, malware sites database
Remote Connectivity
- Enable remote workers to log in to your network securely from any device. The NSE supports industry standard Wireguard, L2TP-IPsec and IKEv2-EAP protocols for remote access VPN
- Turn on Multi-Factor Authentication to enhance password-based authentication. Offers MFA via Google Authenticator
- Create secure IPSec tunnels between multiple sites with the easy to use site-to-site VPN feature
Analytics
- Get a comprehensive overview and security analysis of all the devices on your network via the cnMaestro cloud management platform
- Use the IPS dashboard o gain insight on intrusion attempts. Use the insight to refine prevention policy and enhance intrusion rule sets
- Get a network security audit of all devices on your network. Patch and remediation measures are provided to help you secure your devices
- Get deep insight into all the application traffic on your network. Use the insight to craft granular policies to prioritize and allocate sufficient bandwidth to business-critical apps
Cloud Management
- NSE 3000 is completely managed by the easy-to-use, secure and cloud-hosted Cambium Networks cnMaestro Management System. A single-pane-of-glass platform to operate and manage all Cambium enterprise products - NSE, Enterprise Wi-Fi and cnMatrix switches
- NSE 3000 requires a subscription to funciton, but it is not restricted to the licensed cnMaestro X. Users of the free cnMaestro essentials will also be able to benefit from the NSE 3000. It can also be used as a stand alone, cloud-managed NGFW.
- Zero-touch provisioning. Power on the device and have it automatically managed and configured
- Reusable configuration groups allow easy onboarding of multiple sites
- Dashboard widgets that give you a comprehensive overview of device and network health
- Insight and stats on all connected devices on your network
- Easy to consume data on intrusion attempts - severity, details, country of origin and remedial measures
- Network Security audit of all device on your network. Patch and remediation measures are provided to help you secure your devices
Hardware Features
- 2 x 1 GbE WAN interfaces (RJ45 or SFP)
- 4 x 1 GbE LAN ports
- 2 x USB 3.0
- 1 x console port
- Up to 945 Mbps Layer 3 forwarding throughput
- Up to 917 Mbps Advanced firewall throughput NAT+AVC)
- Up to 911 Mbps Throughput with NAT + AVC + IDS + ACL
- Up to 300 Mbps VPN client throughput
- Up to 600 Mbps for site-to-site VPN
- Up to 100 concurrent IPsec tunnels