Sei sulla pagina 1di 78

THE CASE BOOK

Unified Security. Delivered.


Contact us:

Fortinet India
Bangalore Chennai
18/10 Cunningham Road DBS Corporate Services Pvt Ltd.
302 Saleh Center “Suit No.322”, 31 A, Cathedral Garden Road
Bangalore 560052 Near Palmgrove Hotel, Nungambakkam
Tel: +91-80-4132-1699 Chennai 600 034, India
Fax: +91-80-4132-1689 Tel: +91-44-2827-5191 / +91-44-4212-3364

Delhi Mumbai
B-3/17,(Basement) Zear’s Centre, God Gift Tower
Safdarjung Exclave 4th Floor, Near Lucky Hotel
New Delhi - 110029, India Hill Road, Bandra(W)
Tel: +91-11-3200-1054 Mumbai - 400 050, India
Tel: +91-22-2642-5461/2/3/4/5
Fax: +91-22-2642-5460

www.fortinet.com
introduction
Fortinet is a leading provider of network security
appliances and the leader of the unified threat
management (UTM) market worldwide.
Fortinet's award-winning portfolio of security
gateways, subscription services, and
complementary products delivers the highest
level of network, content and application
security for enterprises of all sizes, managed
service providers and telecommunications
carriers, while reducing total cost of ownership
and providing a flexible, scalable path for
expansion. Fortinet's flagship F - rtiGate®
security platforms offer a powerful blend of
ASIC-accelerated performance, integrated
multi-threat response and constantly-updated,
in-depth threat intelligence. Employing
innovative technologies for networking, security
and content analysis, Fortinet systems integrate
the industry's broadest suite of security
technologies, including firewall, VPN, antivirus,
intrusion prevention (IPS), Web filtering,
antispam and traffic shaping, all of which can be
deployed individually to complement legacy
solutions or combined for a comprehensive
threat management solution. The company
complements these solutions with an array of
management, analysis, e-mail, database and
end-point security products.
Amrita Vishwa Vidyapeetham.
Less intrusions, virus outbreaks and security incidents and
improved network performance after the deployment of
Fortinet solutions.
Business Challenge
Amrita Vishwa Vidyapeetham is a university According to Anoop VK, Manager Systems and
started in 2003 and established under the Networks, Amrita Vishwa Vidyapeetham, “The
University Grants Commission (UGC) Act of biggest perceived threat to our network has
1956. In its second year, Amrita became the been spam and viruses in email. Virus
nation's first multi-campus university to be outbreaks frequently paralyzed the mail server
inter-networked via satellite. This enables live for hours. The real challenge was to counter
interactive inter-campus classrooms. With this, these threats, while maintaining internet
Amrita is strategically positioned to lead the connectivity and fast response times on
way in multi-disciplinary higher eduction, complex networked systems and applications.
research The rising popularity of peer-to-peer (P2P)
Amrita's campuses are connected by networks and applications such as Kazaa and
heterogeneous networks compose of eDonkey, and the proliferation of instant
redundant broadband internet connections. messaging (IM) applications, posed a new set
A data center in each campus hosts more that of challenges for the network administration
provides critical services, such as an online team. Another challenge was the detection
admission system with tracking and an and prevention of Distributed Denial of Service
intranet portal for staff, students and faculty (DDoS) attacks, both from inside the campus
members, web, email, digital library, course and outside it that could cripple various
management system, etc. The institution services. Bandwidth shaping and Quality of
stores critical data pertaining to admissions, Service (QoS), managing multiple ISP
examinations, results, research and connections and ensuring the connection
assignments on its systems. It has a varied doesn't go down even if one ISP failed, were
user base, with different requirements for other major concerns for the institution.
students, faculty members, staff and While the university could stop traffic
administrative employees. between various points, there was no
mechanism in place to scan for threats in real
time inside the network.

1
All Fortinet products have a clear, easy to navigate and
consistent administrative interface. Its management
and policy creation are simple and set through a
single console. - Anoop VK
Manager Systems and Networks

This left systems that allowed entry and exit the university's assets in a single hardware
points for the internet potentially vulnerable to implementation, including intrusion detection
infection.The university was looking for a and prevention systems, anti-virus, automated
security system that had ISP load balancing, push updates and firewall functions.” Amrita
failover redirection and bandwidth shaping for deployed two FortiGate-1000A boxes as
different services. It also needed a gateway level perimeter security for the Coimbatore and Kollam
firewall, antivirus, antispam and IPS, web campuses. Each box is a complete security
filtering, VPN, active directory authentication, solution which includes bandwidth control, ISP
P2P control and logging and analysis. load balancing and failover, spam, web and virus
Deployment filtering, IPS, P2P control, authentication, VPN etc.
VPN is enabled between the campuses and SSL
Amrita evaluated solutions from Sonic Wall, VPN is enabled for mobile users. There are many
Juniper, Cisco ASA, Watch Guard, Radware features that Amrita's networks use extensively.
and Cyberoam. The university chose Fortinet The firewall can be set to automatically close a
for several reasons. According to Anoop, port if the intrusion prevention mechanism
“FortiGate came top on our feature-wise detects an attack. “All Fortinet products have a
comparison matrix. The cost effective solution clear, easy to navigate and consistent
met our primary requirements. It has unique administrative interface. Its management and
features like https filtering, IPS and P2P application policy creation are simple and set through a
control.” The university gave more preference to single console,” says Anoop. FortiGate-1000A
FortiGate as it doesn't have any per-user license, so scans gigabit speed network traffic in real time
it found the solution to be quite flexible. It for viruses, worms and other threats. It also
evaluated FortiGate on the live network for three automatically updates virus and intrusion
weeks and found that the solution was more signature database, detects and blocks the
effective than its competitors. Anoop says, “What latest malware using FortiProtect and
impressed us about Fortinet was its ability to FortiGuard services.
provide many of the features required to protect

BENEFITS
• Reduced in network intrusions, virus
outbreaks
• Improved network performance

2
Artha Money.

With an innovative security architecture in place, financial


services company Artha Eon finds Fortinet to be the best fit.
Business Challenge
Artha Eon Financial Services is a financial The company handles a huge amount of
services company focused on the Indian personal investment information for the retail
consumer. Bennett, Coleman & Co, publisher customers. So it is important to have tight
of The Times of India, currently holds a security. And with the brand name of The
majority stake in the company. The company Times of India, it becomes even more critical to
has a multi-channel setup to deliver financial have a state-of-the-art security system in place.
services. This includes a team of relationship “When you look at the technology space, the
professionals, call-in trading facility, assisted and most effective and efficient way of deploying
online trading. The company plans to have security architecture is to go with multiple UTM
presence in 50 locations. devices. We prevailed on UTM as we are in the
Situation Internet space. You need to be agile in terms of
finding faults and fixing it,” says Phenany. Artha
Artha Eon has set up some revolutionary Eon looked at lot of solutions including those
technology systems in place. This includes front from Fortinet. Adds Phenany, “It's not that we
office solutions hosted at the Internet Data chose Fortinet; it's more like Fortinet suited our
Center at VSNL in Mumbai. “This is a security architecture better. We have a spiral
service-oriented architecture initiative. It is model of security architecture, which is a
revolutionary, as nobody has done it in India so different way of handling security and
far. We are integrating a whole lot of products Fortinet's was the best fit.”
in the personal finance space,” says Anant
Phenany, CTO, Artha Eon.

3
We have a spiral model of security architecture, which
is a different way of handling security and Fortinet's
was the best fit. —Anant Phenany, CTO, Artha Eon

Artha Eon has based its security around this Deployment


spiral concept. The entire computing Artha Eon has deployed two FortiGateTM-800,
infrastructure revolves around services that will two FG300A, one FL800B, and one FL100B. The
be accessed both from the inside and outside. implementation is still under way, though the
The paths on which these services will be closed user group is already up and running.
accessed are etched in stone, and no other Outside access also has been given to some
paths are allowed to access them. The next step users, and it has been a smooth ride. “It's very
is to authenticate the users of the services. “We easy to configure,” says Phenany. “We are
also wanted coarse-grained management and exploring the use of the bandwidth shaping
fine-grained control. When I look at the services feature and the SSL-VPN aspect as well.” The
as a group I should be able to manage each part solution will serve 200,000 transactions and
individually but the specific details are managed 300 concurrent users.
minutely without my having to getting into it,”
he says. With these requirements in place,
Fortinet's was the most appropriate solution as
it also reduced the overheads involved in
deploying the best-of-breed products and then
managing them.

BENEFITS
• Easy to deploy
• Best fit for innovative security
architecture designed for the company
• Single box makes monitoring very easy
• Easy to upgrade

4
Amity Business School.
Better network performance, decrease in intrusions and
attacks - after the deployment of Fortinet solutions.
Business campus grounds, while still assuring
Amity Business School is part of Amity sufficient security, so that confidential data
University, which is headquartered in Noida does not leak out, nor hackers get in.
and has 88 institutions over 22 campuses Challenge
across India. This business school was the first Amity had faced network intrusions and
institution to have a wireless campus and gateway-level attacks. A review of the security
provide wireless notebooks to its students. infrastructure decided that the best approach
Situation to deal with these network threats was a
Various Amity campuses are connected by a gateway-level security solution. Amity
heterogeneous network of redundant Internet evaluated solutions from several security
connections. Its data center in Noida hosts vendors before eventually deciding on
more than 15 servers that provide critical Fortinet. They were looking for an all-in-one
services, such as an online admission system solution with scalability, performance,
with tracking, and an intranet portal for staff, bandwidth management and optimization.
students and faculty members. The challenge They also needed conventional security
for Amity’s 50-strong IT team was how to features such as firewall, antivirus and
maintain open access to information intrusion prevention. Hence, Amity chose
resources both inside and outside the Fortinet.

5
We deployed the FortiGate-200A at the headquarter,
where our management sits. There is zero tolerance for
downtime there and Fortinet has helped keep it that
way. - J. S. Sodhi ,
Senior Manager – IT

Deployment After the deployment of the FortiGate units,


Amity deployed a FortiGate-500A at its Noida Amity Business School has seen a drop in
campus and a FortiGate-200A at its network intrusions, virus outbreaks and
headquarter in Delhi. Different products were security incidents, and a significant
deployed because of the number of improvement in network performance.
concurrent network users. Amity’s IT team also uses up-to-the- minute
The FortiGate units gave Amity the capability reporting facilities in FortiReporter to gain
to support dual redundant ISP connections. insights into the state of the network at any
Amity has a 4Mbps pipe from Reliance and a time, as well as important information that
1Mbps connection to Primus, both may help in responding to network
connected to the same gateway device. incidents. After the deployment of the
Amity also deployed FortiReporter, a FortiGate-500A and observing its performance,
browser-based analysis, reporting and Amity decided to deploy the FortiGate-200A
monitoring solution for FortiGate antivirus at the headquarter, where the management
firewalls. This utility generates nearly 300 sits. There is zero tolerance for downtime
pages of reports on bandwidth utilization on there and Fortinet has helped them keep it
the Amity network, attack attempts and virus that way
incidents. Special personnel are assigned the
responsibility of reviewing those reports and
developing recommendations or responses to
situations that may arise.

BENEFITS

• No downtime anymore
• Drop in intrusions and virus outbreaks
• Significant improvement in performance
• Close monitoring of network possible

6
Biocon.
Biocon has obtained an immediate ROI after deployment of
Fortinet Solution.
Business components in a single solution suite, including
Established in 1978, Biocon is India’s leading firewall, content filtering, anti-virus, intrusion
biotechnology enterprise. It delivers products detection system (IDS) and traffic-shaping features
and solutions to partners and customers in according to G Radhakrishnan, senior manager,
over 50 countries. systems, Biocon, this leads to ease of use.
Further, Fortinet’s FortiGate- 800 provided
Situation bandwidth management, which was not
Biocon has a network of 700 machines and 12 available from Checkpoint.
servers, spread over the facilities of Biocon Unlike Fortinet, Checkpoint software was a
and its subsidiaries, Syngene and Clinigene. point solution that did not offer as many
The data generated by R&D within the features. Checkpoint also requires the
company is critical and network attacks from purchase of per-user licenses. “This is not the
viruses, worms and trojans over the internet case with Fortinet solutions where user-based
would be disastrous. licenses need not be purchased, ”explains
Challenge Radhakrishan.“ Here, network capacity is the
only constraint.” Another security option
For past five years, Biocon has been using
considered was Sonicwall. However, Fortinet
Checkpoint software for its firewall and
proved more attractive because it offered
network security functions. The company
reporting tools and combined more features
decided to consider Fortinet’s solutions as an
in one package.
option because it provided three to four

7
If the security equipment can help
implement the security policies, then the data
is protected - G Radhakrishnan
senior manager, systems, Biocon

Deployment implementation at Biocon was challenging


It took Biocon a month to decide on which because of the mission-critical applications
security product to use but it took only two or and the uptime commitment. Also the system
three days to put the security policies in engineer at Biocon was able to manage the
place. Radhakrishnan explains, “Data box from day one of the evaluation till the
protection depends on the security policies final implementation. This speaks highly for
defined.” If the security equipment can help the ease of implementation.” explains Ashok
implement the security policies, then the Prabhu, GM Sales of Kinfotech.
company’s data is protected. Around August Since Biocon interacted directly with Fortinet
2004, the Fortinet security solution was during the implementation process, no
implemented over Biocon’s entire campus, problems or no compatibility issues came up
including the Syngene and Clinigene during that stage. Within a week of the
facilities. There are now 250 users over the implementation, Biocon felt the need for VPN
network covered by Fortinet’s FortiGate connectivity, which was also easily
platforms. accomplished with the Fortinet solution in place.
“The FortiGate-800 solution was tested
against the best of breed anti-virus scanning
and URL filtering solutions. The

BENEFITS
• Biocon could restrict spam mail over the
network with the use of Fortinet’s
solutions as also the incidence of
virus-infected files
• Internet access is now better, in terms
of increased available bandwidth and
better browsing and file download
performance
• Since security is a high-priority item,
Biocon has obtained an immediate ROI

8
CNBC-TV18.
Behind the scenes, Fortinet provides Media network security
to CNBC-TV18.
Business bureaus in India and abroad. The company has
CNBC-TV18, a joint venture of Television grown from only 200 employees and 70-80
Eighteen (TV18) and CNBC Asia, is an computers to around 1500 employees. The
emerging media powerhouse with business new office in Delhi has more than 1500 nodes
interests in content, broadcasting and new while Mumbai has a capacity of about 1000
media. It is among the fastest growing media nodes. The 12 mbps pipeline between the
companies in India with a CAGR of almost Mumbai and Delhi offices handles a lot of video
100% since its inception in 1993. In addition and data every day.
to running the premier Business News Challenge
Channel it owns moneycontrol.com, a The security infrastructure for such a large setup
business portal, and other channels such as could not adequately be managed by the
Awaaz, South Asia World and CNN-IBN. company’s IT team alone and a year ago, the
Situation company decided to implement a new security
Growing business brought more content, solution. After looking at both appliance and
applications and users into the computer software security solutions from a number of
networks at offices in Mumbai, Delhi and other vendors, the company eventually chose
FortiGate for two main reasons.

9
The Fortinet box could be configured to take inputs
from multiple service providers, unlike most others
which couldn’t
- Rajesh Sharma
Senior Manager Systems, CNBC-TV18

First, Fortinet’s FortiGate UTM platforms engineers installed two FortiGate-800A boxes
could be configured for inputs from different at its Mumbai office, two more FortiGate-
service providers. CNBC-TV18 has redundant 400A boxes were installed at Delhi office in
network connections from 2-3 providers so January 2005. Both deployments were
that if one link goes down, the other takes completed at night and users experienced no
over. Most of the security products in the downtime. Entry-level FortiGate Unified
company’s solution and product evaluation Threat Management (UTM) devices were also
could not be configured for inputs from deployed at 17 other bureaus of CNBC-TV18
multiple service providers. Second, all the in India and abroad, which connect to
security functions the company was looking Mumbai and Delhi offices through either
for—IPS, IBS, firewall and content filtering— leased lines or VSAT. The Fortinet units have
were available in one box, making FortiGate been operating successfully in CNBC-TV18’s
an easily manageable solution. network for around a year now, protecting
Deployment the media company’s information assets.
CNBC-TV18 is now a satisfied Fortinet
In December 2004, the company contracted customer.
Sify, a Fortinet solutions provider, to deploy
its new security infrastructure. Sify’s

BENEFITS
• Multiple layers of security implemented
in the company’s computer network
• Fortinet solution has solved the network
of internal problems
• A Single UTM appliance solution has
made it easy to manage security

10
Cambridge Solutions.

Cambridge Solutions uses Fortinets appliances for total


security and optimized bandwidth usage.
Cambridge Solutions offers a range of IT and capabilities. The platform enables
business process outsourcing services, administrators to segment their network into
including IT services, BPO services and claims zones for granular control of network traffic
and risk management services. These services and an internal four-port switch for direct
are combined with strong onshore presence connectivity with the FortiGate-500A.
in the client’s home country and expertise in FortiGate-300A also has similar features as the
knowledge-based processing. Cambridge has 500A and is ideal for medium - sized
presence in more than sixty locations enterprise networks. FortiGate-100A is
worldwide. In India, Cambridge is present in suitable for small offices. It features dual WAN
five locations—Bengaluru, Cbennai, Shimoga, link support for redundant Internet
Mumbai and Pune. connections and an integrated four-port
Situation switch that can be used to provide networked
devices a direct connection to the security
Cambridge began using Fortinet’s solutions device. FortiGate-1000A is suitable for large
about four years ago, when the need for networks. It features ten 10/100/1000
unified threat management (UTM) devices tri-speed interfaces. All FortiGate platforms
was felt to secure the company’s networks. integrate enterprise firewall, virtual private
The appliances deployed at that time were network (VPN), intrusion prevention,
FortiGate-500A, 300A and 100A. For the antivirus/antimalware, Web filtering,
Bengaluru office that has close to 1,300 antispam and application control features to
employees, the company is planning to keep enterprise networks secure.FortiGate
upgrade to FortiCate-1000A. The units are designed to meet the most stringent
FortiGate-500A platform features two requirements for performance and reliability
10/100/1000 tri-speed Ethernet ports and include redundant, hot-swappable
providing flexibility for networks running at power supplies and fans to minimize
or upgrading to gigabit speeds, four user- single-point failures and also support
definable 10/100 ports for redundant WAN active/active redundant failover for
links, high availability and multi-zone uninterrupted service.

11
We find the devices very useful in controlling Internet
access, in order to optimize bandwidth usage for our
operations
-Pradeesh Karunakaran ,
Senior Technical Support Engineer, Cambridge Solutions

Their high capacity, reliability and easy Deployment


management are factors that work in their “Fortinet is really good in UTM” says
favour, when it comes to enterprise’s security Karunakaran. “We find the devices very useful
infrastructure. in controlling Internet access, in order to
Challenge optimize bandwidth usage for our
“Implementation took hardly two days.” says operations” he explains. He adds that for their
Pradeesh Karunakaran, senior technical setup, content filtering and VPN are among
support engineer, Cambridge Solutions. the most useful features of the solution. “It is
Initially, when Cambridge began using an effective solution with respect to cost and
Fortinet’s appliances, they were based on working principles” says Karunakaran. “It is
LDAP authentication. Later, however, a easy to deploy and new users can learn to use
firmware upgrade by Fortinet added Active it easily” he concludes.
Directory authentication capabilities to these
devices.

BENEFITS
• Controlled Internet access, better management
of Internet bandwidth through policies
• The solution is easy to deploy and easy for new
users or administrators to learn
• The solution is cost-effective

12
eClerx.

The deployment of a unified threat management solution


from Fortinet helped eClerx completely secure its network
and data-center.

Business solution for a month on trial basis, before


eClerx provides data analytics and heading for a full- scale deployment.
customized process solutions to global clients Challenge
from its offshore centers in India. Its portfolio Both for its offices and data-centers, eClerx
of services comprises data analytics, has used Fortinet’s solution. The products
operations management, data audits, metrics and services comprise FG1000Ax4, FG400A,
management and reporting services. FG310B, FL100B, FL800Bx2, FM400 and FC
Situation 450 for three years. Migration from the earlier
eClerx began considering various vendors for UTM solution and deployment of the
security solutions, when its existing UTM enterprise - wide Fortinet solution took about
(unified threat management) solution six months. A team of five people, including
exhibited limitations. The organization and from Fortinet, the vendor and eClerx’s in-
thereby, the network and users were growing house team, were involved. Deployment
rapidly and the security solution seemed threw up several challenges, including some
unable to take the load. eClerx evaluated downtime, as the system did not work as
solutions from a number of vendors and expected. “It was a complex installation. We
finally decided on Fortinet’s solutions. “We had a set of rules on the earlier system and we
didn’t find any other solution as holistic as were looking from additional features from
Fortinet’s” says Ritesh Pothan, CIO, eClerx. He the new system. The upgrade caused some
states that the extensive set of features and instability. A lot of challenges came up during
policies also promised that the solution would setting policies, Active Directory
be able to take care of any future authentication and so on” says Ritesh.
requirements at eClerx. eClerx used the

13
It is a holistic solution with a comprehensive set of
features. Its future promise is very high
-Ritesh Pothan,
CTO Eclerx

Deployment profiles, though this feature is not working


eClerx has used the system for over a year too smoothly as of now. Through
now and Ritesh describes the experience as FortiAnalyzer, it is easier to generate and
“Very decent, We are expecting it to get manage logs. ”Fortinet has the most
better.” Apart from securing the network, comprehensive set of policies, which will be
data-center and email, Fortinet’s solution has of use to us today and tomorrow. We haven’t
enabled eClerx to deploy security, even when used all the features and policies yet, because
an employee is outside the network. Through we have opted for a systematic, slow
security clients for laptops, users can keep transition” Ritesh concludes.
them secure and continue to be as productive
as within company premises. “Another good
feature is SSL based proxy capabilities, which
have simplified proxy management” states
Ritesh. He also finds Active Directory
integration useful in creating protection

BENEFITS
• Performance and business productivity have
increased
• eClerx has been able to move from an IP based
to a user based configuration
• Apart from the data center network and email
security can also be deployed on laptops
moving outside the network

14
Eicher Motors.
Eicher Motors’ has deployed a UTM device for the protection
of one of its critical sites.
Business general manager – IT, Eicher Motors. He cites
Part of the Eicher Group since 1982, Eicher that the device is a transparent application
Motors has world-class expertise in designing, proxy, an anti-virus solution, an anti-spam
developing and manufacturing commercial solution, an intrusion-prevention system, and
vehicles. It uses state-of-the-art technology to much more, so that the company’s threat
manufacture and market fuel-efficient protection needs are completely taken care
commercial vehicles with a gross vehicle of. He also states that since it is not OS-based,
weight (GVW) of 5-25 tons. These include a they didn’t need to procure any hardware for
range of trucks and buses, and custom-built it. In other softwarebased solutions, the
automobiles for specialized applications. It company would have needed to procure
has also debuted in the Heavy Commercial hardware, install an operating system, and
Vehicle segment with Eicher 20.16. then use the software.

Situation Deployment

Eicher Motors’ manufacturing facility is Eicher Motors has been using Forti- Gate-800
located in Pithampur, Madhya Pradesh and at their Pithampur site for about
the company decided to create its disaster one-and-a-half years. Bhat says that the
recovery site also at that location. This also appliance is “simple to configure and
required the need to increase protection of manage, and easy to understand”. Rules and
the site, since the services had increased and configurations can be changed easily; the GUI
many users were connecting to the site. After provides easy access to all the features; and it
a requirements-analysis exercise and studying doesn’t need dedicated staff for
the solutions available with various vendors, management. Alerts have been set on the
the company decided to go with appliance to report any violations of the
FortiGateTM-800, an enterprise UTM (unified security policies, and the administrator
threat management) device from Fortinet. “It receives email to report such violations. “It
is a single box that gives so much more than a only needs half-an-hour daily for someone to
basic firewall,” says Venkat Bhat, deputy check the logs,” states Bhat.

15
FortiGate-800 has met our requirements and suited our
purpose. It does all the things that we had planned
- Venkat Bhat, deputy general ,
manager – IT, Eicher Motors

Bhat also states that the device allows to use the appliance. Bhat says that internal
administrators to divide the network into planning of the deployment, policies to set,
zones and apply different security policies for and so on took about a week—while Eicher
each zone. It has four user-definable ports Motors came up with its specific
(10/100) that enable granular control over requirements, Fortinet and Sify provided
security policies. It also has four trispeed value additions to the planning process. The
(10/100/1000) Ethernet ports for networks implementation took about two days, mainly
that run on gigabit speeds. Besides, it can also because Eicher didn’t want any break in
be used as a VPN solution, though Eicher network services. “FortiGate-800 has met our
doesn’t use it for that purpose. A team from requirements and suited our purpose,” says
Sify did the initial setup, understood the Bhat. “It does all the things that we had
requirements, deployed the solution and planned,” he adds.
trained the people at Eicher Motors on how

BENEFITS
• Threat protection needs met—firewall,
anti-virus, anti-spam, intrusion
prevention and so on are part of the
solution
• Easy to configure and manage
• GUI-based access to all features makes it
easy to understand and use
• Administrators can create different zones
on the network and apply different
security policies for each zone

16
Forbes Marshall.
Fortinet provided Forbes Marshall a customized solution that
fully understands and meets the company’s requirements
and does not compromise on utility and security.
Business energy generation, energy efficiency, control
In the last five decades Forbes Marshall has and instrumentation for the process industry.
grown from a modest Mumbai based trading Situation
company to a multi-divisional, ISO 9001 Forbes Marshall runs Oracle eBusiness Suite for
certified global company manufacturing its business process. All orders and service
advanced engineering products for the world’s requests are entered from all over India. This
process industries. Forbes Marshall claims to be application is running on an IBM server in its
probably the only company in the world to have Pune office. The company had two key
extensive expertise in both steam and control challenges in mind when it decided to go for the
instrumentation. The dual expertise has allowed Fortinet solution: one was to protect its ap
it to engineer industry specific systems that focus plication suite and server, which needed to be
on energy efficiency and utilities management accessed from all its branches, from outside
for sectors as diverse as textiles, food processing, attacks and ensure business process is smooth,
paper, power and chemicals.“Forbes Marshall’s reachable and secure, the second important
goal is to provide solutions in energy, efficiency factor was to ensure support for multiple lines
and process automation, using the best cost effectively without compromising on
technology the world has to offer,” says Sharat security. The company has two premises in Pune
M Airani, Manager – IT, Forbes Marshall. 50 with distance of seven kilometres between them.
years ago it started out with steam generation It has one RF Link, one 2 MB leased line and one
solutions. Today it has seven business divisions; 100MB OFC connecting both these units. There
each one partnering the world technology is one Internet link at each of these locations.
leaders in their respective fields, manufacturing “These two premises are connected by means of
products that cover the entire spectrum of different links of different speed.

17
Fortinet provided full cooperation in understanding the requirement
and designing the solution that made us comfortable. We do expect
the new solutions from Fortinet in different areas like: network,
security, monitoring and management - Sharat M Airani,
IT, Forbes Marshall

We wanted to have an automatic fail over and been able to discontinue manual intervention for
load balancing between these links,” informs shifting the links which used to take longer time.
Airani, adding that the company was looking for “Now even if any one link fails, it does not create
a single box to avoid administration and any inconvenience to users. The changeover
maintenance overheads. takes place within 4 seconds,” he says. Forbes
Challenge Marshall evaluated products from three other
vendors before finally deciding on Fortinet.
These links are very critical as large numbers of Emphasizing that customised solution is a very
users depend on these links for business process. important factor without compromising on the
As such, securing these links from any outside utility and security, Airani says that Fortinet
attack or intrusion is a top priority with Forbes provided full cooperation in understanding the
Marshall. With that priority in mind, the company requirement and designing the solution that
deployed two boxes of FGT-200A, one at each made the company comfortable.
location. All the links terminate on these boxes.
The company has security-enabled the Internet Deployment
links also. “Before entering the network it checks Airani describes his experience with Fortinet as
for all controls. For other links between our own really good. “We have the comfort level with
two units, we have not enabled any such Fortinet partner we worked with,” he says. A key
security,” Airani says, adding that for the 3 links factor in Airani decision was to ensure that the
between the company’s two units both the units, investment is wise enough to withstand change
it provides automatic fail over and load balancing in technologies. “These technologies changes in
for the entire traffic. Talking about the benefits of two years of span. Before investing, one really
going for the Fortinet solution Airani points out needs thinks about the investment also,” he
that with the deployment of the solution, it has remarks.

BENEFITS
• A customized solution that fully
understands and meets the company’s
requirements and does not compromise on
utility and security
• Lower suppor t and maintenance costs
• Provides automatic fail over and load
balancing for the entire traffic

18
Geojit.
Fortinet provides a competent & secure platform for
smoother transaction.
Business components of security solutions at multiple
Geojit, a joint venture with Kerala State levels, but managing them became an issue
Industrial Development Corporation (KSIDC), and company management realized that an
offers complete wealth management solutions integrated platform of security solutions was
through 850 trained professionals and a necessary.
pan-India network of over 175 offices to over Challenge
1.75 lakh clients in India. Geojit has more than At Geojit, all the trading transactions done
Rs 1,500 crore worth of assets under its custody across India is dependent on the server at
and management. Cochin and securing that server was a critical
Situation issue. The features of the FortiGate-800 suited
Geojit has a hybrid network, which comprises Geojit’s requirements. One major consideration
of VSAT links, leased lines, VPN, etc. All the in favor of the FortiGate-800 was the Intrusion
branches are networked to the head office for Detection System (IDS) and integrated
online information dissemination and risk antivirus solution bundled into a single
management. The total number of platform. For the deployment of the
transactions executed daily over the FortiGate-800, Geojit roped in Axcenta as its
company’s network is almost 1,00,000. It also implementation partner. A team of about five
has a comprehensive trading website. When IT professionals from Geojit and three
Geojit started offering its services online, technical engineers from Axcenta were
various information security issues came to the involved in the implementation, with remote
fore. Geojit had implemented multiple support from one Fortinet engineer.

19
There is always a trade off between performance and
surveillance. Now, we are in a much more comfortable
situation than before and we expect a better rate of
customer satisfaction - Balakrishnan
CTO, Geojit Securities, Cochin

Since Geojit is an online trading business, any Deployment


downtime during the implementation was For Fortinet, Geojit was one of the most
absolutely unwanted. At present, the solution challenging deployments. Downtime on this
has been implemented at one location, Cochin. network would have cost millions in online
Geojit did not exceed the budget planned for this trade. To deal with this, the implementation
exercise. Satisfied with the results and the was done over a weekend, when no online
support from Fortinet, Geojit is planning to trading activity In India takes place. The entire
deploy FortiGate-300 platforms at the three deployment of the FortiGate-800 was done in
remaining locations, Geojit will be purchasing a day and a half, though this process would
another FortiGate-800 box at its data center at typically have taken about 10 days.
Cochin to provide load-balancing and
high-availability in case of a crisis.

BENEFITS

• Since Fortigate is an integrated platform


for security solutions, managing and
controlling it is easy
• The management has instant access to
information about intrusions in the
security system and can take immediate
action accordingly
• Filtering content is much more
streamlined now
• There is a competent secure platform
for smooth transaction execution

20
GMR.
Fortinet’s solution at Hyderabad’s airport helped GMR
to logically separate the network, without affecting
performance.
Business been built from the ground up and provides
GMR Group is a rapidly growing multiple layers of protection and easy
infrastructure organization, with interests in management. This also helps to increase
airports, highways, energy and urban flexibility in deployment, better security
infrastructure. Among the airports that the through integration and scalability with
group is responsible for is the Rajiv Gandhi changing business requirements. GMR has
International Airport, Hyderabad. deployed FG3600A at the Rajiv Gandhi
International Airport, Hyderabad. FortiGate
Situation platforms provide essential network defenses
To design the network and security at the by integrating enterprise firewall, Virtual
Hyderabad airport, GMR required a device Private Network (VPN), intrusion prevention,
that would help them logically separate the antivirus/antimalware, Web filtering, anti
networks of the customers—airlines, ground spam and application control features. The
handlers, concessionaire, and so on—-and at FG-3000 series, which includes FG 3600A,
the same time, provide them connectivity to integrates multiple security services into a
the common network. ”We chose Fortinet’s modular appliance-based platform. It offers
device because it has the capability of Virtual flexible network interface options, including
Domains (VDOMs) with good performance, hardware-accelerated Gigabit and 10-Gigabit
which is very useful for airport environments” Ethernet support. FG3600A has one AMC
says M Rajesh, AGM, IT, GMR. expansion slot, eight 10/100/1000 interfaces
and two SFP (SX/LX/ TX) interfaces. “The
Challenge
deployment took about a week and there was
Fortinet provides Unified Threat Management no downtime” states Rajesh. A team of two
(UTM) security systems. Its range of security people was involved onsite. A system
solutions are flexible enough to help integrator was involved as well.
businesses of all sizes meet their security
challenges. Fortinet’s security platform has

21
Without this solution, we may not able to run the show. It
has fulfilled our business requirements almost 100%”
-M Rajesh ,
AGM, IT, GMR

The challenge, says Rajesh, was to ensure every customer of the Airport connects to the
high availability (active/passive) common network for their operations. At the
implementation without network downtime. same time, each customer’s network is
The solution has been in use for the past eight logically separated from the other networks,
months at the airport. Rajesh informs that all to ensure protection. Fortinet’s device is
pending activities have been completed indispensable for achieving this complex
successfully. connectivity. Rajesh states that it gives good
Deployment performance as well. “We have really
benefited with the box for logical separation
The Airport’s network has been designed as a of the network” says Rajesh.
common infrastructure platform, so that

BENEFITS
• Logical separation of the airport network has
been achieved
• There is no compromise on network
performance or security

22
Hindustan Times.
Hindustan Times wanted a solution to not only help prevent
attacks or intrusions but also a solution to better utilize the
Internet resources. It achieved both these goals with Fortinet.
Business as Internet bandwidth terminating in New
Hindustan Times today operates in a highly Delhi to satisfy the end user requirements.The
competitive business environment that is Challenge Hindustan Times has users spread
marked by hyper growth potential, entry of across 15 locations in India who access
new players and diversification of media application like emails, Intranet and Internet
companies into new areas. The Hindustan resources through the corporate data center
Times group itself is on an expansion mode. located in New Delhi. It has a huge pool of
The company has not only a new edition of its WAN as well as Internet bandwidth
flagship newspaper Hindustan Times from terminating in New Delhi to satisfy the end
Mumbai but has also diversified into FM radio user requirements.
broadcast. The group recently launched FM Challenge
radio channel “Fever 104 FM”. It is also close With these challenges in mind, Hindustan
to launching a new business daily in Delhi Times wanted a solution that will not only
and Mumbai. With networking and IT playing help prevent attacks or intrusions in its
a critical role in its daily operations as well in network but also a solution that will help it
its growth, it is obvious that protection of IT better utilize the Internet resources. “In mid
assets from malicious attacks and threats will 2006 when we looked at the Fortinet product
always be of paramount importance for the profile it appeared to suit our requirements.
group. We underwent tests and PUC at various levels
Situation to justify our needs,” Khanna says. According
Hindustan Times has users spread across 15 to Khanna, the Fortinet solution after being
locations in India who access application like deployed helped Hindustan Times achieve
emails, Intranet and Internet resources what it desired. “The solution helped us
through the corporate data center located in provide a mechanism to minimize attacks in
New Delhi. It has a huge pool of WAN as well

23
Fortinet solutions has helped Hindustan Times prevent all
kinds of threats from virus and worms, check intrusion
threats and vulnerabilities from entering our internal
environment - Amit Khanna ,
Hindustan Times

respect threats specified above at the points out Khanna. He says that the solution
gateway level. It also provided us with a tool which was designed in a high availability
to implement a global content filtering mode intends to provide 100% uptime to
solution to help us use our Internet resources prevent any such future attacks.
in a better way,” points out Khanna. He says Deployment
that the solution which was designed in a
high availability mode intends to provide The Fortinet solution has helped Hindustan
100% uptime to prevent any such future Times prevent all kinds of threats from virus
attacks.The Solution With these challenges in and worms, and check intrusion and
mind, Hindustan Times wanted a solution vulnerabilities from entering its internal
that will not only help prevent attacks or environment. Overall, with Fortinet, Khanna
intrusions in its network but also a solution is confident of handling all attacks or threats
that will help it better utilize the Internet at the gateway level itself. “Any such threat is
resources. “In mid 2006 when we looked at killed in the DMZ before it hits our internal
the Fortinet product profile it appeared to suit resources. The primary benefit that we
our requirements. We underwent tests and desired from such a solution was to provide a
PUC at various levels to justify our needs,” layer of security to our end user’s from new
Khanna says. According to Khanna, the attacks at the gateway level itself. This goal
Fortinet solution after being deployed helped we have achieved after the Fortinet
Hindustan Times achieve what it desired. implementation,” Khanna says. Talking
“The solution helped us provide a about future, Khanna says that he is looking
mechanism to minimize attacks in respect at security architecture at branch level and is
threats specified above at the gateway level. It looking forward to implement solutions in a
also provided us with a tool to implement a similar manner at various levels on the
global content filtering solution to help us company’s Intranet.
use our Internet resources in a better way,”

BENEFITS
• Prevention of all kinds of threats from virus and worms, check on intrusion
threats and vulnerabilities from entering the internal environment.
• All attacks handled at the gateway level
• Better utilization of Internet resources

24
IIMK.

The Fortinet solution helped lIM Kozhikode build a infallible


defence against intrusions, viruses, worms, Trojans and
other malware.
Business Challenge
The Indian Institute of Management IIMK has deployed a Fortinet enterprise-class
Kozhikode is a part of the IIM family of security and management platform to protect
institutions that have earned a reputation its campus-wide network. Fortinet partner
worldwide for academic excellence. IIMK is an Nortech was instrumental in the deployment,
institute of higher learning that conducts which included a FortiGate” -500 multi-threat
post-graduate management programs and security appliance and FortiReporter’TM
executive management education programs security reporting and analysis software. The
for working professionals. The management FortiGate-500, together with Fortinet’s
programs cover a wide range of subjects, FortiReporter software provided for all of
such as finance, IT, marketing, strategy and IIMK’s security, reporting and audit
organizational behavior. compliance needs. Before deciding on
Situation Fortinet to replace the existing Linux firewall
on their network, IIMK’s technology staff
IIMK’s campus connects to the Internet and evaluated solutions from SonicWall,
research and academic networks such as WatchGuard and Cyber Roam.
RENNIC and ERNETviaa5l2Kbps leased circuit
from BSNL, with a 2MB ISDN line from BSNL Deployment
and a 64 Kbps VSAT link as backup. IIMK’s “To achieve our security goals, we needed a
technology department needed to design solution that could defend against external
and deploy a comprehensive security solution and internal threats,” says Ashok Pathak,
that would not only provide necessary systems manager, IIMK. “We also needed
defenses against intrusions, viruses, worms, additional features such as bandwidth
Trojans and other malware, but also to detect management and strong reporting
abuse within the network and provide reports capabilities so that we could have a good idea
of incidents and network audit purposes.

25
To achieve our security goals, we needed a solution that could defend against
external and internal threats… we also needed additional features such as bandwidth
management ad strong reporting capabilities so that we could have a good idea of
how the network performed and how it was being used. Fortinet’s FortiGate 500
and FortiReporter addressed al our requirements -Ashok Pathak ,
System manager, IIMK

of how the network performed and how it services, which provide continuous updates
was being used. Fortinet’s FortiGate-500 and to ensure protection against the latest viruses,
FortiReporter addressed all our worms, Trojans and other threats-around the
requirements.” Fortinet’s FortiGate-500A clock and around the world. Fortinet’s
multi-threat security appliances provide FortiReporter Security Analyzer provides
performance, flexibility, and security security professionals with real-time security
necessary to protect today’s growing intelligence to help identify and understand
enterprises. The FortiGate- 500A platform hacker, virus and SPAM/spyware behavior to
features two 10/100/1000 tri-speed Ethernet combat security threats and meet compliance
ports, 4 user-definable 10/100 ports for auditing requirements. “More organizations
redundant WAN links, high availability and and businesses are deploying our products to
multi-zone capabilities and an internal 4-port provide of the array of functions necessary to
switch. All Fortinet FortiGate systems provide maintain corporate security,” said Mr.
comprehensive network and content Hansen Chang, Fortinet’s VP for Asia Pacific.
protection through the integration of eight “Fortinet provides a full range of security
essential security applications and services -- products that allow administrators to protect
including antivirus, firewall, VPN, intrusion every part of their network, from the
prevention (IPS), anti-spam, anti-spy- ware, gateway, to the data center, to desktops, as
web filtering and traffic shaping. The systems well as solutions for logging, management,
are kept up to date automatically by analysis and reporting.”
Fortinet’s FortiGuardTM subscription

BENEFITS
• Provides performance, flexibility and security
necessary to protect today’s growing enterprises
• Full range of security products that allow
administrators to protect every part of their
network

26
IDFC.
After Fortinet impletation, IDFC has covered the possibilities
of virus attacks, hacking, and thus protected the company’s
data and network.
Business solutions. According to V.C. Kumanan, head,
Incorporated on January 30, 1997, Infrastructure information management, the concept of
Development Finance Company Limited (IDFC) is integrated implementation was quite
a specialized financial intermediary for interesting because you could get “Three or
infrastructure. IDFC has approved financial four major features in one device.” All teething
assistance for 156 projects aggregating over problems could then be “Handled in one cycle
Rs181,868.20 mn and has broadened its initial instead of in three or four different cycles.”
focus on power, roads, ports and They considered two vendors: Fortinet and
telecommunications to include energy, telecom Symantec, eventually choosing Fortinet. In
and IT, integrated transportation, urban addition to firewall and IDS, the capabilities of
infrastructure, healthcare, food & agri-business, the integrated security appliance included
infrastructure, education and tourism. network traffic-shaping, VPN, and antivirus
functions. Although IDFC already had
Situation Symantec AntiVirus on the network, the
Though the network at IDFC already had antivirus feature in Fortinet’s solution provided
routers, anti-virus software, access lists, and additional protection and came at 60% of the
other server-based controls, the IT team felt cost of the Symantec solution. Gabriel Durai,
that unless a firewall and an intrusion manager, IT, added that Fortinet offered
detection system (IDS) were present, the level bandwidth management and traffic shaping
of security was inadequate. for VoIP calls and this was important since they
needed improved quality in VoIP calls.
Challnege
Symantec did not offer this. Also, Fortinet
IDFC considered the options of integrated as offered them 24x7 service, including next day
well as point implementations of security replacements, etc.

27
They [Fortinet] have delivered on their promises

- VC Kumanan, head,
information management, IDFC

Deployment changing some security policies. “With this


By June 2004, Fortinet solutions were new version the reporting facility is really
implemented at two locations, Chennai and good” feels Gabriel.
Mumbai. The entire process took three to One concern that IDFC had was that there was
four months. Two personnel from IDFC and no other similar implementation done in the
one from Veeras Infotech representing country. This was a major risk, along with
Fortinet were involved in the questions about delivery and implementation.
implementation. The total cost of the security The latter was because dealers were also new
solution was Rs 6.2 lakhs. “Today we are and unfamiliar with this technology. This was
reasonably happy with this implementation.” also a slightly complex deployment as there
says Kumanan. In June 2004, IDS was was already an existing VPN along with an IP
implemented on the network. Later that year, firewall from Cisco and IDFC wanted the new
when Fortinet began offering an intrusion implementation to sit on top of currently
prevention system (IPS) in newer versions of existing security infrastructure.
its solutions, IDFC upgraded to it. All that was
involved was downloading the upgrade and

BENEFITS

• With Fortinet’s security solution in


place, IDFC feels that to a large extent,
it has covered the possibilities of virus
attacks, hacking and thus protected the
company’s data and the network. The
IDFC team feels they are in better
control of their network than before
• The company has been protected from
losses due to attacks on the network

28
Jet Airways.

Low TCO and better ROI, while ensuring a secure


environment that’s easy to manage with Fortinet delivers
huge benefits to the airline.
Business filtering of URLs visited to prioritize the traffic,
Jet Airways, India's leading airline, operates and simplicity in the management of the
domestic and international services. It has entire solution. According to Satish Joshi,
over 385 daily flights to 64 destinations Senior General Manager - Communications,
within India and overseas including New York Jet Airways, “We were looking for an
(both JFK and Newark) Toronto, Brussels, easy-to-manage, comprehensive and unified
London (Heathrow), Kuala Lumpur, security system that could ensure 24x7x365
Bangkok, Colombo, Singapore, Kathmandu, defense against network and perimeter level
Dhaka, Kuwait, Bahrain, Muscat and Doha. It threats.”
is one of the fastest growing airlines in the Challenge
world. With the acquisition of Jet Lite, Jet The company was in search of a security
Airways has a combined fleet strength of 109 solution that would have features like firewall,
aircraft and schedules over 526 flights daily. SSL VPN, antivirus, anti-malware, anti-spyware,
Situation authentication, web filtering, instant
Jet Airways had deployed point-based messaging/peer-to-peer blocking and
security systems for its various offices. There intrusion prevention system (IPS). Jet Airways
was no perimeter level security at the evaluated security solutions from CheckPoint
branches. The company also wanted to and Sonicwall. But the company chose Fortinet
implement a corporate level internet access for several reasons. Satish Joshi says, “Fortinet
policy at its branches. This would include has a comprehensive unified security solution
scanning of internet traffic for malicious data, that gives ease of management, local support
bandwidth management, authentication, and training. Also the solution provides low
TCO and better ROI.”

29
Defining policies on the FortiGate boxes is really simple

- Satish Joshi
Senior General Manager - Communications,
Jet Airways

Deployment
Jet Airways deployed FortiGate-800 for firewall It also provides integrated traffic shaping
and SSL VPN services. This system helps the functions, which makes it a cost effective,
roaming users and small offices of Jet Airways convenient and powerful network protection
to securely access the reservation system. solution. Jet Airways has also deployed
FortiGate 800 is a complete security solution FortiGate-50B and 60B in the branch offices to
which includes firewall, SSL VPN, antivirus, provide perimeter security and defense from
antimal-ware, antispyware, authentication, external attacks. According to Satish Joshi, “Each of
web filtering and IPS. It controls instant the Fortinet devices with its security features and
messenger and peer-to-peer network activities prevailing security concerns provides value for
to prevent blended threats. money. The devices are complete and have
comprehensive security defense.”

BENEFITS
• Easy to deploy
• Secured and hassle free remote access
with SSL VPN
• Better manageability of essential services
• Reduced intrusion & virus attacks
• Easy monitoring of network

30
Larsen & Toubro.
After the Fortinet implementation there has been an increase
in the volume of business, lessened project times and
lowered communication costs.
Business East and Asia. Each location is connected to
Larsen & Toubro is India’s largest engineering the central server in Chennai. Their network is
and construction conglomerate with additional a heterogeneous one, comprising leased
interests in IT and electrical business. The lines, VSATs, mobile links to PDAs used by
company has revenues of Rs 6,000 crores this engineers at remote sites and Multi-Protocol
fiscal year from its seven divisions. One of its Label Switching (MPLS). Network infrastructure
divisions, the ECC (Engineering Construction control includes strategies such as antivirus,
and Contracts division), is headquartered in firewall, spam filtering and VPN. One of their
Chennai. network security policies required the frequent
changing of passwords. The software used in
Situation their network security infrastructure included
Half of ECC’s operations take place outside CheckPoint firewall, configured to block
the boundary of the company. This includes specific information and spam filtering.
interactions with suppliers, contractors, However, the infrastructure department soon
contract employees, clients and client felt the need for a unified security solution, as
consultants. Because of this and also because the separate applications for anti-spam,
the construction industry is a nomadic one, anti-virus and firewall functions became
the business applications used by the ECC difficult to manage.
must also be available to all stakeholders of Deployment
ECC’s projects. The ECC standardized on a
single platform - the Web and this necessarily ECC initially thought of using Norton
meant providing security over a network that AntiVirus but this only provided protection
is open to virus infiltration, hacker attacks, etc. against viruses that were already out “in the
wild.” A year ago, they decided on Fortinet’s
Challenge solutions because of the integrated anti-virus,
The ECC network currently controls 378 automated online updates of virus signatures
project sites, seven domestic regional offices, and anti-spam features.
and 12 international area offices in the Middle

31
We were able to demonstrate the effectiveness of our
FortiGate based solution at the proof of concept stage
itself - N C Ananthasayanam,
Country Business Manager—RADAR ISS,
Ramco Systems

“Now we have a hybrid, unified security solution security among its employees. Further,
in place,” says Bhaumik. ECC took only about a many of the 22,000 employees were
month to deploy the Fortinet software and the uncomfortable with using computers, so
total cost involved was Rs 9.5 lakh. training programs had to be organized to
One of the challenges faced by ECC was the educate employees about the network
need to enforce the discipline of network security systems.

BENEFITS

• Fortinet is helping ECC integrate the


earlier diverse security solutions in
place. The security policy is showing
good results
• ROI for the IT infrastructure as a whole is
that it has increased the volume of
business, lessened project times and
lowered communication costs from
Rs 10.5 crore to Rs 8 crore
• The processes have become
cost-effective. Larsen & Toubro is now
completing big projects with less
manpower and in lesser time. Budgets
for projects are made in lesser time,
there is timely output and the figures
are more reliable

32
Lason India.
Protecting customer’s data has been taken care of with the
deployment of FortiGate.
Business multiple products. Fortinet offers these features
Lason India, earlier known as Vetri Software, in a single integrated network security
undertakes BPO operations in vertical appliance. According to M S Kannan, GM, IT
industry segments such as healthcare and support and member, executive leadership
financials. It is a wholly-owned subsidiary of team, Lason has tried both hardware and
Lason, a US-based business process software point security solutions. Fortinet offers
outsourcing (BPO) company. Lason reported an integrated hardware, software and firmware
a turnover of $170 mn in 2002, to which security platform, which makes it interesting.
Lason India contributed $30 mn. Lason India has two networks, one connecting
the management center to the production
Situation sites, the other to the overseas corporate office.
Protecting the workflow environment, from Challenges
start to finish, that is, back to the customer, in
a processed form, requires multiple levels of One of the main concerns that Lason India had
checks and balances, in the areas of physical was that they may be the first adopters of
and IT security. The network security solution Fortinet’s technology in India. According to
that Lason India wanted had to fulfill the Kannan, their worries were eased when they
criteria of reliability, availability, scalability, found that Fortinet was quick to respond to all
serviceability and service support. Lason’s aspects of support during the implementation
security requirements included a firewall, of the platform. There were some firmware
intrusion detection and prevention facilities, issues, which were resolved by Fortinet. The
VPN, traffic-shaping and access control implementation also had to overcome some
functions, virus protection, spam and content initial resistance from employees to the
filters, either in a combined product, or in restrictions imposed by the FortiGate solution.

33
We wanted to be pioneers in the industry,
in handling data securely
- MS Kannan
GM, IT support, and member,
executive leadership team, Lason India

Deployment “The security solution was up and running


The initial strategy was to implement a almost immediately.” said Kannan. VPN services
Checkpoint firewall at their international gateway. offered by the FortiGate platform, were deployed
For Lason’s intranet sites, the considerations of at production and management sites. This feature
cost-effectiveness, compliance to global standards ensured secure data transmission and was also
and interoperability led to a decision to use easy to customize. The FortiGate security platform
Fortinet products. Fortinet India trained Lason’s was also compatible with the existing
engineers and a test bed was set up to ensure infrastructure, which included Lason’s own
that they were capable of supporting the Linux-based VPN and an existing server-based
Fortinet solution. Installation of the devices content filter for e-mail.
was then simply, a matter of plug and play.

BENEFITS

• Lason’s biggest worry was protecting


customer’s data. That’s been taken care
of with the deployment of FortiGate
• The customers are also more confident
in doing business with Lason since they
are assured of data security and privacy
• Being both cost-effective and scalable,
this combo product will protect Lason’s
investment for three years. It doesn’t
need augmentation for next two years.
Any enhancements required will only
be for firmware

34
Malayala Manorama.
The media house uses Fortinet boxes and three other layers
of solutions to repel intruders and Media to stay virus-free

Business According to V V Jacob, Manager - Systems,


Malayala Manorama was established in 1888, the networks have to be continuously
and has become one of the leading running at all hours. The situation can get
newspapers in Malayalam today. The critical, especially when the newspaper goes
company publishes many well-regarded for printing and when no support can be
periodicals such as The Week, Vanitha, expected from vendors. Downtime would
Vanitha Hindi, Magic Pot, English Year Book, severely impact the operations and revenues
Amar chitra katha and Balarama among of the company.
others. Malayala Manorama has 75 offices Challenge
and 15 printing locations across India. To deal with the risks of an “always on”
Situation connection to the internet, Malayala
Malayala Manorama gets news, photos, Manorama decided to put in place a security
advertisements from all over the country and infrastructure that could effectively protect
the world. Previously, the mode of collection their data assets. The company evaluated
was very manual and a lot of work went into products from many vendors and eventually
converting material into digital format. selected Fortinet. What tipped the decision in
Currently, the internet is used as the primary Fortinet’s favor were the integrated security
medium for collecting and publishing news functions, such as antivirus and firewall and
stories and getting advertisement revenue. the ability of Fortinet’s FortiGate products to
The company thus needed the flexibility to operate in transparent mode.
stay connected to the internet all the time.

35
Most security products operate on a per-user basis.
In the case of Fortinet, the product secures the whole
network. It requires only a one-time investment and has
no license restriction on the number of users.
- V V Jacob
Manager- Systems

Deployment
The company decided to deploy the Jacob says that the number of virus attacks
FortiGate units at the outer most perimeter has dropped dramatically and is very
and just in front of the mail server to screen infrequent now. The number of intrusions
incoming mail for viruses before they have has also come down considerably. Fortinet
had a chance to break into the network. In all, boxes have been able to deliver the
two FortiGate-200s, one FortiGate-400 and bandwidth QoS required and network
one FortiGate-500 are deployed in three performance has also improved because of
locations, including their main uplink facility. the improved security. Malayala Manorama
All units have real-time antivirus, firewall, was so impressed with the FortiGate products
VPN, network intrusion detection and that it is now in the process of evaluating
prevention and traffic-shaping services FortiMail spam control software. Explains
turned on. Supporting this infrastructure is Jacob, “Most security products operate on a
FortiAnalyzer which provides reporting per-user basis. In the case of Fortinet, the
functions. The security infrastructure has product secures the whole network. It
been operating successfully for a little over 2 requires only a one-time investment and has
years now. The deployment was done by the no license restriction on the number of
company’s IT team and it went very users.” All Fortinet products deployed by
smoothly, without any problems or Malayala Manorama are automatically
downtime during the installation. updated through FortiGuard, a
subscription-based service

BENEFITS
• Zero downtime during installation
• Dramatically reduced number of virus
outbreaks and intrusions
• Improvement in network performance
• No per-user licensing, so the solution is
cost effective

36
Maharashtra
Mantralaya

Maharashtra Mantralaya.
A complete overhaul which included using a FortiGate box
solved the issues with a slow and vulnerable Mantralaya
network
Business increasingly frustrated as the network was down
The Local Area Network (LAN) in Mumbai’s nearly everyday and applications were either
Mantralaya started with around 600 systems inaccessible or slow. The objective, thus, was to
in 1988-89. In 2005, it had more than 3,500 get the network back on its feet and to make it
systems located in different buildings. Apart faster and more secure.
from the Mantralaya building and the New Challenge
Administrative Building, the network is also The evaluation and appraisal process took
accessed by the PWD, Vidhan Bhavan, the nearly six months, where the department of IT
Treasury Office and offices in Nagpur—which consulted its in-house experts and experts from
are part of the Wide Area Network (WAN) and other public sector undertakings such as the
Mahanet, the network of Maharashtra’s State Bank of India, Unit Trust of India and
district offices. HPCL. They did a complete review of the
Situation network and then evaluated solutions from
Network usage within the Mantralaya’s LAN and various vendors that would satisfy their
from the various offices connected to it had requirements. Having faced problems with
increased over the years. The deployment of more multiple vendors in the past, Dr. Pandey says
process-intensive applications on the network they decided to appoint a single party this
increased the traffic many folds. To compound time.” After a competitive bidding process,
matters, the network had no security systems CMS Computers was given this contract. The
deployed. It was open to threats—viruses, worms, upgrade involved some major changes. The
Trojans, hacker attacks - from outside as well as earlier IBM switches, which had become
from users within the LAN. All these factors had led obsolete, were replaced with Cisco 6500 series
to the network slowing down. Bandwidth was switches. The network was also redesigned by
choked with heavy usage, switches were running segregating it into virtual LANs (VLANs) for
at 80-90 percent of their capacity leading to better management. The other critical upgrade
frequent breakdowns and users were getting was the installation of Fortinet’s FortiGate-3600
Antivirus Firewall at the gateway.

37
Users have begun to rely on the network and
to believe that it will always be available.
- Dr Ajaybhushan Pandey
Secretary (I.T.), Government of Maharashtra

This box, which has a throughput of 4 Gbps installed on all desktops. Updates for antivirus
(gigabytes per second), includes Intrusion solutions on the Fortinet box and on all
Detection System (IDS), Intrusion Prevention desktops and servers are programmed to
System (IPS), gateway-level antivirus solution, happen automatically. It took about eight days
content filtering to safeguard against spam and for the actual installation and upgrade of the
a log generator. network. The cost was about Rs 1 crore.
Deployment However, downtime was minimal—on
Fortinet’s solution was tested for six months weekends and nights—and end users did not
before the actual implementation and was even realize the changes that had happened in
found to be better than similar solutions from the network. According to Dr Pandey, the
other vendors, mainly because it included virus upgrade and the transition to the new network
protection at the gateway level, which other were smooth. They have not faced any
solutions did not provide. In addition, problems in the two months since the new
Symantec’s Norton AntiVirus solution was network has been operational.

BENEFITS
• The network is running smoothly, there
is ample bandwidth, applications are
running at good speed and there have
been no security threats so far
• Users confidence in the network has
increased. There are no complaints of
the network being inaccessible
• Since FortiGate scans both incoming
and outgoing traffic, threats of the
network being compromised from
outside have reduced
• The redesign of the network has made it
easier for other offices to connect to the
network.

38
Ma Foi.
Ma Foi opts for Fortinet’s UTM solutions and sees better
manageability and security despite being on island networks.
Business cost.It also has a customizable load balancing
Ma Foi Management Consultants is one of the feature, and can support SSL and IPSec based
leading HR services provider in India. After its VPN. “Unlike other products, the graphical
merger with Vedior N. V, a Euro 6.85 bn user interface of Fortinet is much simpler and
staffing company, the organization now has a designed very well,” says Ananthakrishnan.
strong global presence across Europe, Middle Challenge
East, South Asia and Southeast Asia. It offers a The solution Ma Foi opted for is a complete
diverse range of HR services and HR Unified Threat Management system. It chose
outsourcing solutions. FortiGateTM-200A, 100A and 60A depending
Situation on the number of seats at each location. The
Ma Foi has presence across India in various solution includes policy based firewalling,
locations. All these locations have been policy based routing, traffic management,
running on island networks. This posed a anti-spam, antivirus, and host-based intrusion
major manageability and information security protection system (HIPS). This feature is a plus
challenge. “We decided to address these as conventional network based IPSs look for
issues first before tackling the entire array of signatures and HIPS looks for patterns. It has
information systems management,” says an extensive Web filtering system where can
Ananthakrishnan K, manager - Information handle exceptions. The organization can
Security & Business Continuity at Ma Foi. block an entire set of websites falling under a
category and still provide exceptions as per
Ma Foi evaluated several products including business needs. “This places a crucial role in
Cisco, WatchGuard, Sonicwall and Fortinet. business like ours. For example, we don’t
Fortinet stood out on several accounts. It want our users to shop online, but still allow
scored better on interface to interface them to browse a few sites which enable our
throughput, ease of defining and revoking consultants to research on specific retail
policies, and routing capabilities and the companies,” Ananthakrishnan says.

39
The solution has made the administrator’s job simpler
as the network segmentation and prioritybased routing
is much easier to handle
- Ananthakrishnan K, manager
Information Security & Business Continuity, Ma Foi

Other features like protocol based filtering, spam related issues. The bandwidth usage is
and the ability to create separate profiles for also more optimized. “The ability to connect
different user groups is an added advantage. major offices across the country and our
“IM, P2P and VoIP filters enable us to control overseas office gives us better manageability
Internet traffic on potentially bandwidth on essential services,” he says. Users do
consuming services. And it allows for better complain that they can’t browse or use IMs.
network segmentation,” he adds. Fortinet This suggests the system is working without
conducted a features-based training, which any deviation. The Fortinet solution has made
involved being briefed on every menu and the network administrator’s job simpler as
options available on the box. This was the entire network segmentation along with
location specific and was done in our running a DHCP server and prioritybased
headquarters. routing is much easier to handle with the GUI.
Deployment
It’s been a year and a half since the
deployment. According to Ananthakrishnan,
Ma Foi has seen an immediate fall in virus and

BENEFITS
• Immediate fall in virus and spam
• Bandwidth usage optimized
• Better network segmentation
• Simple policy definitions and revoking
• Easy to use interface makesmanageability
simpler

40
Mahanagar Gas limited.
Fortinet helps protecting the network that protects the
environment.
Business connection to the Internet. Rapid growth in
Mahanagar Gas Ltd (MGL) was incorporated the company has also introduced some
from a joint venture between the Gas unique challenges for the company’s IT
Authority of India Limited (GAIL), the BG department: With the recent proliferation of
Group UK (formerly British Gas), and the network threats from viruses, Trojans, spam
Government of Maharashtra. MGL supplies and intrusion techniques, the IT staff soon
Piped Natural Gas (PNG) directly to over found themselves frenetically plugging holes
600,000 homes and 500 commercial and putting out fires. With a planned
establishments and industries in Mumbai. The Enterprise Resource Planning (ERP) project
company also operates a network of 100 implementation in the pipeline, the company
Compressed Natural Gas (CNG) filling recognized that security had become a top
stations. priority item and decided to conduct an IT
Security Audit to identify loopholes and
Situation vulnerabilities in the network.
MGL corporate network has similarly grown Challenge
in size and sophistication since 1995. The
company, headquartered in Bandra Kurla The security audit defined a list of features
complex in a Mumbai suburb is connected to that MGL needed in a security solution, and
a nearby billing and call center and the these included comprehensive firewalling,
emergency control room via a 2 Mbps leased antivirus functionality for detecting and
line. Five distribution offices around the city destroying viruses, Trojans and other threats
and two satellite offices each have 128 Kbps at the gateway between the corporate
dedicated connections to the headquarters. network and the Internet, and tracking
The company maintains nearly 15 servers and bandwidth utilization. ‘The organization was
more than 200 workstations, and runs reeling tinder constant virus attacks. This kind
applications for inventory management, of situation restricted MGL from letting its
workflow and an employee intranet. remote users access the corporate network, or
Numerous technical libraries are hosted on even, for that matter, mails.” Prashant
the servers and the company depends on a Mudbidri, Director of Logix Consultancy
mission critical database on Oracle 9i. The Group Pvt. Ltd, said.
company also had a 128Kbps broadband
41
Unsecured access to the internet resulted in security mayhem in our
organization with a plethora of virii, spyware and other malware
creating dangerous bottlenecks in our network and bringing day to
day activities in our enterprises to a grinding halt
-Hemant Joshi ,
Deputy Manager (IT)

The Logix Consultancy Group Pvt. Ltd is a deployment, and network performance and
reseller of Fortinet products, who assisted user experience has improved significantly.
Mahanagar Gas Ltd in evaluating security “This has phenomenally improved the
solutions. “Fortinet’s product functionalities performance of our Internet connection,”
mapped to the audit report’s suggestions.” said Mr. Joshi. With security now in place, the
“We wanted a solution that conformed to the imminent rollout of the ERP suite can
suggestions in the IT Security Audit report. continue and plans have already been made
We zeroed in on Fortinet, because, besides to deploy a mail server in- house. The
offering all the features that we needed, they company now has plans to expand the use of
had achieved all 4 ICSA certifications, and had Fortinet products as its network expands.
an Intrusion Prevention System (IPS) feature. “We haven’t yet used the ability to create
Fortinet provided us with a FortiGate-300 for DMZs or the feature for traffic- shaping, and
testing for a couple of days, and we were when the mail server is installed, we will need
impressed with how easy it was to install, its the antispam feature,” says Mr. Joshi, “we will
outstanding wire-line performance and also need to provide access to the Internet for
robust security features,” explained Mr. Joshi. our Kalina office. Fortinet is a natural choice.
‘All broadband traffic now filters through the We are a very satisfied customer.” The
Fortinet firewall. We have also enabled NAT FortiGate-300 antivirus firewall platform
(Network Address Translation) for our mail provides complete real-time network
and Citrix servers.” Mahanagar Gas Ltd protection through a combination of
purchased and deployed one unit of the network- based antivirus, web and email
FortiGate300 antivirus firewall platform in content filtering, firewall, VPN, dynamic
mid-2004. The implementation was smooth, intrusion detection and prevention, traffic
with minimum difficulties, and it now secures shaping, and anti-spam. All FortiGate-series
225 users in all offices for email and 25 users firewalls eliminate viruses, worms, and
in headquarters for Internet access. grayware/ spyware from email, file transfer,
and real-time Web traffic without degrading
Deployment
network performance, through its innovative
Mahanagar Gas Ltd. has seen a dramatic hardware-accelerated ASIC-based architecture.
reduction in the number of virus attacks and
other network intrusion incidents since the

BENEFITS
• Easy to deploy
• Cost effective
• Comprehensive security solution

42
Nilgiris.
Integrated threat management from Fortinet helps the
super market chain bring down spam and virus attack
levels and increase employee productivity.

Business management. According to Mr.Venkataraman ,


Nilgiris is a century-old company based in CIO, Nilgiris, “The prevalent solutions were
South India, and is known for its fresh cakes, working fine in their own areas, but we were
other bakery and confectionery items, and looking at a single box from where we could
supermarkets. It has around 70 retail outlets manage the entire security system.”
across South India. Nilgiris has its own Challenge
manufacturing units for baking and Also like any other progressive organization
confectionery and is a trusted brand for Nilgiris desired that the time spent by the
hygiene and quality products. employees was more productive. Viruses was
Situation affecting the company productivity as a
The company had deployed separate whole. Spam was another big challenge for
solutions to handle the various aspects of Nilgiris, which was impacting productivity as
security. They had multiple tools catering to well. Says Venkataraman, “Spam was taking
their anti-spamming, antivirus & intrusion too much of space and wasting the company's
detection systems. On their own, they all resources and time.” Nilgiris decided to opt for a
worked fine for the company. But Nilgiris Unified Threat Management system to tackle
wanted a single solution to handle all their all these challenges.
security challenges to bring in ease of

43
The Fortinet box is a modern day solution for security
woes that IT brings with it. Use of IT has multiple
advantages. But to deal with the flipside of IT, products
like those from Fortinet are a great help.
—Mr.Venkataraman , CIO, Nilgiris,

Deployment FortiManager Centralized Management and


Nilgiris evaluated other solutions available in FortiAnalyzer Centralized Reporting.
the market and short listed Fortinet. The FortiGate-400A is a complete security solution
company chose Fortinet because of several which includes content inspection firewall, IPSEC
reasons. According to Venkataraman, & SSL VPN, intrusion prevention, web filtering,
“Fortinet is a reliable name and has proven antispam, antivirus and antispyware. It has
solutions in the industry. It is a leader in the controls to monitor instant messenger and
UTM market.” Fortinet has a clear road map peer-to-peer network activities to prevent blended
for its products, and brings in newer threats. It also has integrated traffic shaping
technology faster than others, he adds. At the functions, to ensure that employees visit
same time, Nilgiris found that Fortinet's authorized website during office hours and that
solutions are also cost effective. Nilgiris opted the company's bandwidth is optimally used.
for the FortiGate-400A box along with

BENEFITS

• Cost effective
• Increased employee productivity
• Reduced spam & virus attacks

44
Jubilant Organosys.
Multi-vendor servicing woes have been replaced with a
single-box solution which takes care of all the operational IT
issues.
Business issues. An effective solution was needed for
Jubilant Organosys, a leading giant in custom these problems and to meet the increasing
research and manufacturing services, is a demands of such a big organization.
composite enterprise with a major presence in Challenges
the pharmaceuticals industry. With revenue of It took about three months for Jubilant
Rs 1176 crore in 2003-2004, the company has Organosys to conduct a thorough and
around 2000 employees in India and abroad. exhaustive industry survey. “Since using a
Jubilant Organosys has subsidiaries in USA, multi-vendor approach had not been a very
Europe and China. Domino’s and Hot Breads feasible solution, this time, we were looking
are some of their prominent brands in the for a single-box solution from a single
non-pharmaceuticals segment. vendor,” shared Mr Satya, Chief (IT), Jubilant
Situation Organosys. In 2004, FortiGate-1000 turned
The security infrastructure previously in place out to be the answer. This appliance could
at Jubilant Organosys was not adequately satisfy all their security needs, such as anti-virus
effective in stopping current network threats, features, junk mail filtering, content inspection
from virus attacks to intrusion. Since they have and load balancing. The company was looking
a B2B and B2C setup, performance was for a one-time investment in security solution
important and became an issue when the because IT was not their core business.
vendors and the clients became dissatisfied Deployment
with the time it took to access information on When it came to implementing
these sites. At that time, Jubilant Organosys FortiGate-1000, Jubilant Organosys was a little
was using solutions from different providers to apprehensive. Being one of the first few
address their security needs. The different organizations to use the Fortinet product, they
solution providers often blamed each other for had to wait for the product to be launched.
network failures without addressing the real Moreover, since FortiGate-1000 was a very

45
We used IT for our business success and not to build
a museum of IT products
- Mr. Satya
head IT, Jubilant Organosys

new product, they didn’t have many was initially expected to be 80 hours, actually
references that could vouch for the turned out to be 60 hours. Apart from the
performance of the product. Jubilant support given by Fortinet, Jubilant Organosys
Organosys could not afford to have their also kept a team of 9 people in house to roll
networks down for long periods due to real out the application to safeguard against any
time B2B/B2C transactions. Therefore, risks. Jubilant Organosys claims that there
instead of implementing the technology in have been no technical snags so far.
2-3 weeks, the entire exercise was phased out
in 6 months. As a result, the downtime, which

BENEFITS

• All the content, which passes through


the network, is safe and there is no
downtime involved because of network
jamming
• No manpower time is wasted in
clearing junk and spam mails
• Multi-vendor servicing woes have been
replaced with a single-box solution,
which takes care of all the operational
IT issues
• FortiGate-1000 blended well with the
existing infrastructure and practically
no additional costs were incurred
• By adopting the single vendor approach
instead of a multi vendor approach, the
costs decreased significantly

46
Spice.
The Fortinet solution provide the performance, flexibility
and security necessary to protect enterprise networks.
Business company was also seeking a solution that
Launched nine years ago as a cellular phone would support High Availability (HA) and
service operator, Spice Telecom currently Load Balancing operations to eliminate any
serves 1.5 million subscribers in Punjab and possibility of a single point of failure.
Karnataka regions with wide coverage in Deployment
urban areas and road networks. After evaluating solutions from several
Situation vendors, Spice Telecom purchased and
Spice Telecom's IT department was deployed two FortiGate-300A systems in a HA
continuously challenged with trying to configuration to provide comprehensive,
manage and maintain a large assortment of non-stop multi-threat security. The
point security products from numerous deployment of the FortiGate-300A platforms
vendors. This challenge was compounded has resulted in dramatic improvements in the
every time a computer was added to the integrity and flexibility of Spice Telecom's
network. network security infrastructure and a marked
increase in IT staff efficiency. The
Challenge ASIC-accelerated FortiGate systems provide a
As Spice Telecom's network grew, the IT full suite of network security capabilities --
department found it increasingly difficult to including firewall, antivirus, intrusion
keep virus and spam signatures up-to-date prevention systems (IPS), VPN, Web filtering,
and to effectively enforce security policies. anti-spam and traffic shaping – to protect
Spice Telecom recognized the need for a against content and blended threats in
comprehensive, streamlined network security real-time. Tests performed on the
solution to meet its critical and diverse FortiGate-300A systems by Spice Telecom
security requirements. IT administrators were indicated that scanning of inbound and
eager for a solution that would be easy to outbound traffic achieved throughputs in
manage, grow with the network as necessary excess of 300 Mbps, highlighting Fortinet's
and ensure up-to-the-minute security excellent performance.
updates to virus and spam signatures. The

41
47
Fortinet's unified threat management systems provided us
the best functional range of security applications and services,
most of which are ICSA certified and offered the best total
cost of ownership. - Navin Kaul, COO
Spice Telecom, Karnataka

According to Navin Kaul, COO - Spice around the clock and around the world. Navin
Telecom Karnataka, Fortinet's robust Kaul continued, “With Fortinet's UTM systems
capabilities and ease-of-use made it the clear in place, we've reduced our administration
choice for network security “Fortinet's unified complexities and management headaches, as
threat management systems provided us the well as improved the robustness of our
best functional range of security applications network security. Additionally, we no longer
and services, most of which are ICSA certified have to worry about a single point of failure in
and offered the best total cost of ownership. our network, which was previously our only
Additionally, we liked the high performance gateway to the Internet. The other real plus
the systems delivered, made possible by we've experienced with Fortinet is the fact that
ASIC-based hardware acceleration." The we only bear a one-time acquisition cost versus
FortiGate-300A systems provide the the huge annual maintenance and licensing
performance, flexibility and security costs for other solutions. Overall, this has been
necessary to protect enterprise networks. The an exceptional value proposition for us.”
FortiGate-300A systems are kept up to date
automatically by Fortinet's FortiGuard
Network, which provides continuous updates
that ensure protection against the latest
viruses, worms, Trojans and other threats -

BENEFITS

• Easy to deploy
• Protection against virus, worms &
trojans
• Better manageability
• One time acquisition cost versus huge
annual maintenance and licensing costs
for other solutions
• Reduced network complexity

42
48
SAIL.
Multiple security features in one solution is what SAIL found
most appealing in Fortinet.
Business That’s one of the reason the industry has
Steel Authority of India Limited (SAIL) is the witnessed a spate of consolidation driven by
leading steel-making company in India. It is a mergers and acquisitions. Stressing that in the
fully integrated iron and steel maker, present scenario of cutthroat competition
producing both basic and special steels for right decision at right time is most important
domestic construction, engineering, power, not for competitive advantage, Deo Murti
railway, automotive and defence industries Thakur, Joint Director (CC&C), SAIL, points
and for sale in export markets. Ranked out that IT is the biggest facilitator in this
amongst the top ten public sector companies endeavour. “The IT group is always trying to
in India in terms of turnover, SAIL put its sincere efforts so that SAIL should have
manufactures and sells a broad range of steel all the relevant information to take right
products, including hot and cold rolled sheets decision at right time,” he says, informing that
and coils, galvanised sheets, electrical sheets, SAIL’s IT department had commissioned
structural, railway products, plates, bars and some major projects in the past year.
rods, stainless steel and other alloy steels. The Situation
Indian steel industry has been going through Ensuring a continuous flow of information
a very dynamic phase. Driven by the and high availability of the network is one of
unprecedented boom in the economy that the key tasks before Thakur and his team.
has created a huge demand for steel in sectors “The IT department has to ensure that failure
like infrastructure and real estate, the steel in IT system should be minimum or almost
industry is witnessing a new phase of zero,” he says. And one of the serious
modernisation and expansion. While there challenges posed to the availability of the
has been no dearth of demand for steel for the SAIL’s network is from virus attacks and other
past few years, there has been no lack of pulls types of intrusions. “These threats are serious
and pressure too. Growing cost of production whether they are virus attacks and or
has led many steel companies to look for something else,” Thakur says.
ways to achieve new economies of scale.

49
SAIL analysed almost all types of security systems and
Fortinet proved to be the best for us. After installation of the
Fortinet solution, SAIL’s LAN at its two corporate offices in
New Delhi is now completely secured - Deo Murti Thakur ,
Joint Director (CC&C),
Steel Authority of India Limited

Challenge according to Thakur is that it is a


In order to control all kinds of threats to SAIL’s hardware-based system with multiple
network posed either by Internet or by a mail, security features in one solution. “It meets all
SAIL decided to go for a solution that can our security requirements as it has Firewall,
ensure that all threats are controlled at the IDS/ IPS, anti-virus, Spam control, User
gateway level itself. “We decided to install a authentications for Internet and more
system at the gateway level of the LAN and importantly for more than one Internet lease
WAN of SAIL,” says Thakur. However finding line connections,” he points out.
the right solution wasn’t an easy job given Deployment
the fact that the market is flooded with scores After installation of the Fortinet solution,
of security solutions. “There are many types SAIL’s LAN at its two corporate offices in New
of security system. Some are software based Delhi is now completely secured. “No virus
and some are hardware based,” he observes. threat that can disrupt work or mail has been
The other challenge was to ensure that experienced. Our interaction with plants and
deploying a security system should not affect outside never got hampered. No data loss or
network performance. “Putting different mail loss as occured. This has created smooth
security system for different applications working environment at our corporate office,”
create lot of problems which slow down the says Thakur of his experience after deploying
network,” Thakur adds. With all these factors the Fortinet solution. Moreover, the Fortinet
in mind, SAIL analysed a number of solutions solution has also given SAIL better Internet
available in the market before finalising management capabilities. “Now we are able
Fortinet. “SAIL analysed almost all types of to connect and disconnect Internet users as
security systems and Fortinet proved to be per requirement. Every thing can be
the best for us,” Thakur says. The most controlled through a consol only,” he adds.
appealing feature of the Fortinet solution

BENEFITS
• Unified solution that meets all security
requirement
• Better Internet usage management
• Threats controlled at the gateway level

50
SIBM.

Fortinet’s solution has helped Symbiosis Institute of Business


Management to manage Internet bandwidth and create
security policies for its gigabit network.
Business listed the criteria for selection of vendor. As a
Symbiosis Institute of Business Management result of this process, Fortinet’s products were
(SIBM), Pune is counted among the best selected.
business schools in India. Established in 1978, Challenge
it received permanent affiliation from the SlBM decided to deploy FortiGate 800 and
Pune University in 1996. In 2006, the UGC FortiAnalyzer. ile Fortigate 800 is a UTM
recognized it as a full-fledged university, and appliance, FortiAnalyzer is a dedicated
SIBM became part of Symbiosis International hardware solution that securely aggregates
University (SIU). Apart from two-year MBA and analyzes log data from the FortitGate
programs for residential students, SIBM offers appliance. The FortiAnalyzer appliance
one-year MBA programs for working accepts and processes a range of log records
professionals and customized MBA programs provided by FortiGate, including traffic,
for corporates. event, virus, attack, content filtering, and
Situation email filtering data. It also provides advanced
SIBM has a gigabit network with multiple security management functions such as
virtual LANs spread across the campus. For quarantine archiving, event correlation,
securing this network, SIBM decided to vulnerability assessments, traffic analysis, and
deploy an appliance based UTM (unified content archiving. It also provides more than
threat management) product. “The product 300 customizable reports, whether scheduled
had to support the following features: or on-demand. Network administrators thus
firewall, IDS/IPS, anti-virus, web filtering, get a comprehensive and detailed view of
spam control, user authentications for network usage and security information,
Internet, Internet load balancing and failover which helps them to discover and address
lease line connections,” states Rajesh B vulnerabilities faster.
Bagewadi, senior network administrator. A
project consultant for the network project
51
The FortiGate 800 solution has fulfilled our requirement in
terms of user authentication, Internet load balancing,
antivirus, Web filtering, firewall, and so on”
-Rajesh B Bagewadi ,
Psenior Network Administrator, Symbiosis Institute Of Business Management

With the help of a system implementer, the ports for networks running at gigabit speeds
project consultant and the Fortinet team, the and four user-definable 10/100 ports that
installation and implementation took about a provide granular security through multi-zone
week and did not involve any downtime. capabilities. The platform has allowed
However, challenges came up during administrators at SIBM to segment the gigabit
installation in Internet network load network into zones and create unique
balancing, failover of Internet and web security policies between zones. This helps to
content filtering, as well as in Active Directory manage the Internet bandwidth and user
integration. authentication with Active Directory. The
Deployment system is easy to manage through a Web
console and has enabled SIBM to manage
The FortiGate-800 network security system Internet usage in a better way through
features four 10/100/1000 tri-speed Ethernet policies.

BENEFITS
• Better management of Internet bandwidth
through policies
• Network can be segmented into zones and
unique policies for each zone created. User
authentication with Active Directory
data about viruses, traffic, violations and so on
• Easier management of the system through Web
console
• Security from multiple threats through antivirus,
Web filtering, firewall, IDS/IRS, etc.

52
Sodexo.
With a UTM solution, Sodexo now has a secure centralized
setup, which has resulted in multifaceted savings.
Business only external but also internal intrusions, and
Established in 1966 in France, Sodexo has internal abuse of privileges, which could lead
operations in more than 80 countries and to lower productivity levels. Adds Sequeira, “I
revenues exceeding 13.4 bn Euros. Sodexo also wanted a comprehensive logs and
started off with its operations in India a reporting mechanism, because we will soon
decade ago. Sodexho Meal and Gift Vouchers have audits for certification of our processes,
have become the prominent tool for controls and security.” The solution had to be
motivating employees in all sectors of able to give a dashboard analysis of the
industry. The head office is in Mumbai, and information. Not only would this aid in audit
there are seven branches in the major cities. compliance but also help in the bandwith
optimization.
Situation
“I wanted the solution to have an easy-to-use
Sodexo had deployed SonicWall in a interface. We also needed good service and
decentralized manner. There were separate support after implementation,” says
clients for IDS, IPS, antivirus and antispam Sequeira.
from various vendors. Sodexo needed a
unified solution so that there was only vendor Challenge
to manage. When the organization moved to Sodexo evaluated Sonicwall, Cisco,
a centralized network setup, it wanted to Checkpoint and Fortinet. Global policy
explore a centralized security solution as well. dictated the use of Checkpoint and Cisco, but
According to Charmaine Sequeira, head-IS&T the Indian team dared to change that and
of Sodexo India, “I needed a good security chose Fortinet’s solution as the market
solution which was scalable with the feedback was excellent. Also, since
network, and would have an assured uptime. Checkpoint was partnering with various
And it had to be cost effective as well.” vendors to deliver unified solutions, Sodexo
Sodexo was looking for a unified and was not confident of a roadmap for their
comprehensive security solution to detect not products.

53
I needed a good security solution which was scalable with
the network, and would have an assured uptime
- Charmaine Sequeira,
head-IS&T, Sodexo India

Fortinet has SSN VPN certification, so Sodexo granular logging is excellent which helps the
did not have to go for third party certification. organization gets reports on top ten users of
The box comes with its own ASIC processors bandwidth, time spent on browsing, and so
thus taking the load off the network’s servers. on. Bandwidth management has become
“We deployed two boxes of FortiGateTM- easy. The box prevents internal and external
800 in the high availability mode in our head threats and vulnerabilities very well. As two
office along with FortiAnalyzer. Internal boxes are deployed, there is automatic
auditors were happy with the tests failover and load balancing, which ensures a
conducted on the security setup,” says high uptime. The Fortinet solution delivers
Sequeira. The deployment was done in good return on investment on many
October 2007. It was seamless and there was accounts. “It’s a single box, which means
absolutely no problem, she says. The system there is a definite RoI compared to multiple
administrator received basic training. boxes all over the place,” says Sequeira. Also,
Deployment now that bandwidth consumption is
optimized, there are cost savings there as
Ever since the deployment, there are no well. And there is a lower support and
issues related to viruses or spam. The maintenance cost.

BENEFITS
• Unified threat prevention
• No more issues related to spam and virus
• Better management of bandwidth
• High uptime
• Good return on investment—lower
product and support costs, bandwidth
savings

54
South Indian Bank.

South Indian Bank opts for Fortinet’s solution to deliver


secure services without having to worry about growth or
obsolescence.
Business The application proxy, IDS (intrusion
South Indian Bank is one of the leading detection system) and gateway antivirus were
scheduled commercial banks in India with a from Symantec, and Stateful Inspection from
strong focus on technology and service. It has Checkpoint. However, when Symantec
presence in 23 states and union territories of announced end-of-life for some of its
India. The bank has 489 branches, 26 products, the bank opted to go with a Unified
extension counters and 204 ATMs across the Threat Management solution as the
country. technology had matured. The key concern
during evaluation was that management of
Situation different products, even from the same
The bank was working in a decentralized vendor, was not without issues. “So the idea
manner, with inhouse standalone of using a single box was accepted to enable
applications running in the various branches. the comfort of deployment, ease of operation
On the advice of its IT consultant, the bank and better management for the bank,” says
decided to move to the core banking solution Sreekumar Chengath, chief manager-Networks &
from Infosys, Finacle. This was done in 2001. IS Security. Among the available UTM solutions,
With this came the option to deliver Internet the bank evaluated those from Checkpoint and
banking services to the customers. This was Fortinet. “The market feedback on the Fortinet
the only service where the bank’s systems had solution was very good. Fortinet is a pioneer in the
to be accessed from the outside. This was a UTM solutions space. That is why we went with
huge security concern for the bank. In 2002, Fortinet,” says Sreekumar. He also adds that
the bank opted to go for the best of breed Fortinet’s products have a clear roadmap, which
applications for its various levels of security. most other rivals do not.

55
Fortinet is a pioneer in the UTM solutions space. That is
why we went with Fortinet
- Sreekumar Chengath,
chief manager-Networks & IS Security,
South Indian Bank

Another criteria for selecting Fortinet was Deployment


expandability and enhancement options “The benefit we immediately saw after the
available in the solution. It has boxes built for deployment was that of better spam
small organizations, enterprises, carriers and control,” Sreekumar says. Earlier, they used to
large organizations. “With Enterprise receive lots of spam mail. Now there is
solutions, we get a lot of expandability. We absolute control over spam. “We used to get
don’t have to worry about scaling up for the 150-200 spam mails per day, now that has
next 5-7 years, says Sreekumar. reduced to less than 10!,” he adds. Deploying
Challenge the Fortinet solution also has opened up a
The bank opted for two boxes of secure way of providing PCs at each branch
FortiGateTM- 800 deployed in redundancy office. Currently the bank has provided
mode and the FortiAnalyzerTM which separate Internet connected PCs in each
monitors the boxes setup as a cluster in bank, so it is not part of the bank’s closed user
active-passive mode. The solution basically group. A pilot is on to ensure that using the
has firewall, anti-spam, antivirus and Fortinet firewall, it will be safe to provide PCs
intrusion prevention system modules. The with Internet access as part of the bank’s
deployment was done in October 2007. The network without needing a dedicated proxy.
UTM solution is deployed in the bank’s data This will ensure that parallel infrastructure is
center in Kochi. It controls all the branches not required at each branch.
and 2700 users across the country.

BENEFITS
• Better spam control
• Safe way to enable Internet access in
branches without needing a dedicated
proxy
• Clear road map of products ensures
obsolescence is not an issue
• Expandability of solutions ensures that
growth will not be a challenge

56
THE TIMES OF INDIA

Times of India.

Application-level security from a single box keeps TOI secure.


Business Challenge
Bennett, Coleman & Co. Ltd is India’s largest The TOI group had been using various
media house. The Times of India Group has firewalls and security boxes to ensure
many leading publications, some of which security. According to Akhil Chandra, GM,
have many editions. The group also is into the Systems Modernization, there were some
entertainment media through Radio Mirchi, problems with that. It was difficult to manage
Planet M, Times Music and Times Multimedia. a fragmented system. More importantly, they
Situation wanted an application layer control (layer 7).
What they had could only monitor and
With about 15 centers across India housing 300 protect up to the network layer (layer 3).
or more employees at each center and with Various products were evaluated and at the
round-the-clock Internet access to all, it is no time of evaluation, only Fortinet could give
wonder that the media house has a security most of the features they wanted in a single
policy which ensures protection at gateway appliance as well as provide layer 7 control.
level as well as at the desktop level. All aspects
of content delivery are digital and incorporated Deployment
into a single workflow. This includes: News That was in October 2004. Now the media
gathering, editing, photos/image collection, group has various units of FortiGate deployed
layout, advertisement sign up collection, at eight locations. These include FortiGate
approval and so on. 2 mbps lines are provided 100-A, 200-A and 500-A. The management
for each center for Internet access. There are tool FortiManager is also being used, which
120 such lines in all. With so many users over according to Chandra is not an expensive
the network and using the Internet, it becomes option at all. Deployment was easy, as the
imperative to have intrusion boxes are very user-friendly.
detection—external as well as internal.

57
The trend now is to go for single appliances that also
provide layer 7 or application-level security. Fortinet
has given us a single box that takes care of our intrusion
prevention requirements - Akhil Chandra
General Manager, Systems Modernization,
The Times of India Group

Deployment of the units and the training of the backup option, they have set up a proxy also
team onsite did not take up more than 2 days at to detect intrusions and malicious attacks.
all the location. The deployment of units was This is in case the Fortinet units ever fail, but
managed centrally by IT department. Support of that instance has not cropped up yet, and the
the units is also not an issue, because the units group is happy with the performance of the
are robust and the team itself is able to handle boxes and software. The reporting tool is
problems if they crop up. quite comprehensive and easy to use. Both
Things have been pretty smooth after the Internet and network performance have
installation of the FortiGate units and there become better, according to Chandra. What
have been no intrusions so far. There was no he misses is the option of a redundant power
downtime during the changeover from supply for low-end units
legacy applications to the Fortinet solution,
nor has there been any instance of downtime
since the deployment. Chandra says that as a

BENEFITS
• Has provided application level security
to mission- critical workflow and data
• Network perfrmance has improved ; no
downtime
• Single box makes monitoring very easy
• User friendly boxes and software that
require little training and support
solution

58
TATA Communications.

Fortinet Powers Tata Communications vUTM Services

Tata Communications recently selected of customer premise equipment and


Fortinet's FortiGate carrier-class systems as providing monitoring and management
the backbone for its new virtualized UTM services to enhance the security value beyond
(vUTM) service. This is the first time that what many enterprises are accustomed to.
vUTM services are being offered in India. For organizations with remote locations
Virtualized UTM integrates critical security requiring secure Internet connectivity, our
functions including firewall, intrusion vUTM service delivers high value and very low
detection & prevention, anti-virus, anti-spam cost of ownership.” vUTM is targeted at
and Web content filtering as part of its customers who require a secure Internet
Managed Security Services portfolio. gateway with a preference for a hosted
“Businesses that depend on the Internet for security appliance instead of a self procured
operations are struggling to balance the need and locally installed firewall in their premises.
to adequately address security issues with The physical hardware based on Fortinet
budget realities,” said Adam Rice, Vice security technology is logically partitioned
President of Global Managed Security into multiple virtual domains with each
Services for Tata Communications. “Tata domain serving as a distinct firewall with
Communications vUTM service changes the unique policies for that respective customer.
whole cost equation by eliminating the cost

59
Our systems provide unique virtualization capabilities
and carrier-grade security that go beyond other
security solutions.
—Patrice Perche, VP, EMEA, Fortinet

Tata Communications vUTM service is fueled carrier-grade security that go beyond other
by four Fortinet's FortiGate-5140 carrier-class security solutions. By leveraging our virtualized
security systems, which provide a complete security technology, Tata Communications will
suite of security functions at multi-gigabit be able to offer strong and flexible security that
performance. “With its new virtual UTM service can scale to the current and future needs of its
offering, Tata Communications addresses an customers, thereby increasing the profitability
increasing demand from enterprises to benefit of their managed security service.”
from true value added services from their telco
providers,” said Patrice Perche, vice president of
EMEA at Fortinet. “Our FortiGate-5000 systems
provide unique virtualization capabilities and

60
TAFE.
Scalability, reliability, and easier management are some of
the advantages that TAFE has seen after deploying a
unified threat management solution from Fortinet.
Business environment for evaluating the UTM boxes
TAFE (Tractors and Farm Equipment) is a and measured the UTM throughput, VPN
US$750 tractor major based in Chennai, configuration, firewall capability in blocking
Tamil Nadu. It is among the top five tractor unwanted traffic, log management and
manufacturers in the world. Through its other reports, firewall rule management complexity
divisions and wholly owned subsidiaries, and support feedback in forums.” says
TAFE also makes diesel engines, gears, panel Valavan of TAFE.“Fortinet was selected based
instruments, hydraulic pumps, engineering on f ire- wall performance, bandwidth,
plastics, plantations and passenger car support, VPN compatibility, license terms,
distribution. pricing, and existing customers’ feedback.”
he adds.
Situation
Challenge
TAFE used a firewall and other security
measures, but the growing number of threats TAFE has deployed two FortiGate 300A boxes,
in an Internet-enabled world prompted the along with FortiAnalyzer. A team of four
organization to invest in a standardized people—three from TAFE and one from their
security product that would provide partner—were involved in the
protection from the entire range of security implementation. A Fortinet representative
threats.TAFE decided to deploy unified threat also assisted in the process. Implementation
management (UTM) technology, which took about fifteen days. Most of the tasks,
would encompass antivirus, Web filtering, such as creation of rules and objects, were
content filtering, spam filtering, IDS, IPS, and done in offline mode. TAFE took a day’s
VPNs. To this end, TAFE explored the features downtime, in order to move the FortiGate
of UTM products available in the market with boxes to the live environment.
various vendors. “We created a test

61
We are satisfied on the implemented UTM features

- A Amirtha Valavan ,
Principal Consultant, Network Security, Tafe

Valavan recalls one challenge that came up system went live in March 2008.
during implementation. When FortiGate was Deployment
implemented on the network, the mail
service failed completely, because the IMSS Valavan acknowledges it’s early days yet, but
server failed to communicate with TAFE’s says he’s satisfied with the UTM features of
internal mail server. This was because of the boxes, though TAFE is still figuring out the
existing configurations on the IMSS intricacies of licensing in the FortiGate
server—when the fire- wall was implemented system.
on this server, the server could not He says that reliability, scalability, and ease of
communicate with internal and external mail management of the system have increased
servers at the same time, because of these considerably, compared to their earlier
configurations. A change in configuration firewall.
had the system working smoothly. The

BENEFITS
• Better scalability, able to monitor all
network traffic based on bandwidth, as
well as type of traffic
• Improved reliability, availability of accurate
data about viruses, traffic, violations and so on
• Easier management

62
United Telecoms Limited

United Telecoms Limited


Savings have been seen in terms of manpower, additional
resources and the cost of implementation.
Business task as traditional software solutions,
United Telecoms Limited (UTL) is the flagship requiring separate purchases—for anti-virus,
company of the UTL Group, whose main intrusion detection system (IDS), firewall and
business areas are telecommunications, VPN products, would increase costs
networking, turnkey solutions, software significantly.
development and technology services, and Challenge
training. It has recently entered the BPO arena UI-CL was very satisfied with the performance
with the setting up of UI-CL, an India-based of Fortinet’s products during evaluation.
BPO services provider operating from India While other products have one cost for the
USA and UK, delivering customer services base product and additional user licensing
ranging from technical-support help-desk costs, this was not the case with Fortinet
services to BPO. which has no per—user licensing charges.
Situation Deployment
Being a start-up company, information For Internet connectivity, the company chose
security was very important to UI-CL to the FortiGate-200, to deal with network
protect its data assets and intellectual capital threats such as virus attacks, spam and
from increased attacks from viruses and intrusions. The FortiGate 800, a high-end
network intrusions. A BPO company such as ASIC-based appliance was set up on the server
UI-CL has customer-confidential information, farm for IDS fuctions. Planning took a few
which cannot be allowed to be lost, or weeks, while configuring and adapting the
tampered with. It was necessary to choose FortiGate platform to the network took two to
one single product that would offer the three days, Rajagopalan Karthikeyan, Senior
required security services and perform Manager, IT, UI-CL, adds
efficiently at the same time. This was a difficult

63
Biggest menace on a network are spam,
viruses, and intrusions—they can
drive an IT team crazy,
- Rajagopalan Karthikeyan
Senior Manager, IT, UI-CL

“The solution was deployed in a couple of go in pretty easily. Fortinet’s higher-end boxes
hours over the network, once planning was have a lot of scalability.”
over.” However, things didn’t stop here since UI-CL faced no major challenges during the
security devices need to be fine-tuned implementation of Fortinet boxes since
continually. The boxes were set up in planning was thorough and implementation
July-August 2004 and one person from UI-CL smooth. Regarding its performance,
and two from Fortinet’s partners were involved Karthikeyan says “The login system is fantastic.
in the process. Since the network had to be set The Fortinet box can handle available patterns
up from scratch, there were no compatibility and signatures.” UTL is happy with the clean
issues involved in setting up the Fortinet boxes. network, as they haven’t had any virus attacks
Adds Rajagopalan Karthikeyan, Senior or intrusions since the system was operational.
Manager, IT, UI-CL “If you have an existing
network, this network security appliance can

BENEFITS

• With the security solution in place, BPO


processes are now more efficient, now
the company is more comfortable and
so are the customers
• The maximum benefit will be derived
over the next six to nine months, for a
small segment box like Fortinet 200 and
the ROI can then be measured
• Savings have been seen in terms of
manpower, additional resources and
the cost of implementation. This is
because Fortinet offered UI-CL provision
for unlimited number of users

64
United Breweries Limited.
FortiGate 300 provides the beer company with firewall,
antispam and intrusion detection and prevention features.
Business primarily for email and to allow remote users
United Breweries Limited (UBL) is the leading beer access to the corporate portal applications.
company in India. Founded in 1915 with the Previously, the company had deployed a
merger of five breweries in India, the company is software-based firewall that doubled as a proxy
headquartered in Bangalore and commands 50% server. Though this solution was sufficient at the
of the domestic market with brands such as time that it was deployed, the increasing
Kingfisher, UB Export, London Pilsner, Zingaro, sophistication and virus attacks, and the deluge of
Sandpiper, Ice, Kalyani Black Label and Jaguar. spam mail in the past year compelled the IT team
to re-visit its security infrastructure.
Situation
Challenge
The beer manufacturing giant owns 14 factories
and has five regional offices, which are connected S Ramakrishnan, controller-IT (Breweries Division)
to the headquarters through 128 Kbps leased for United Breweries explains that UBL had several
lines running over MPLS. The headquarters hosts requirements in mind as they reviewed the
email servers and portal applications, which current threats on the Internet and gaps in the
feature employee self-help applications and company’s security. The new security solution
facilities for tracking sales, promotions and had to protect UBL’s network and mail
advertising. The head office has a 512 Kbps infrastructure from virus attacks, it also needed to
internet connection, which is used in UB’s have good web filtering features to restrict the use
Network was ideally suited for Fortigate of Internet bandwidth to authorized activities only
implementation. Even though challenging, it and have bandwidth optimization
turned out to be very smooth and UB today relies capabilities.The new security solution also needed
on Fortinet as the first line of defense into their to have antispam and firewall features. In
network and we feel proud to be associated with evaluation tests, UBL found that Fortinet’s
UB as the security solutions FortiGate-300 outclassed the competition on cost
effectiveness, manageability and user-friendliness.

65
The user interface [of the FortiGate 300] was
quite simple, so the learning curve for my team
was not steep. - S Ramakrishnan
Controller-IT (Breweries Division), United Breweries Ltd

Explains Ramakrishanan. “The user interface performance and scalability. “Performance


[of the FortiGate 300] was quite simple, so the and scalability were high priority criteria
learning curve for my team was not steep. It during our evaluation of security products.
was more like a plug-and-play box - with all Fortinet has also proven itself there, because
the security options fully integrated. It helped of its unique ASIC-based hardware
us manage our organization’s security acceleration. As we grow our infrastructure,
effortlessly. “Apart from the strong antivirus licensing can be an issue with some vendors,
gateway features, the firewall and antispam but with Fortinet, we do not have to worry
capabilities, the FortiGate 300 also provides about compliance issues because there are no
intrusion detection and prevention features. restrictions on the number of nodes behind
We had more peace of mind.” the firewall.” Implementing an SSL VPN
Deployment network that connects the many offices,
contract manufacturing units and depots is
After the deployment in October 2004, UBL next for UBL. “The encryption methodology
has seen a dramatic drop in virus attacks on implemented by Fortinet’s product and its
the network and mail systems. With the basic firewall features will definitely supplement the
security requirements met, the company has SSL VPN and the token-based authentication
now moved on to activating additional system we are planning to roll out,” says
features, such as antispam, on the FortiGate Ramakrishnan. “So far, Fortinet has effectively
platform and rolling out an organization-wide addressed our needs. I’m sure we can count
ERP suite. Ramakrishnan expects that the IT on them in future, too.”
infrastructure in UBL will consolidate and
applications will become more centralized in
the near future. The challenge then will be

BENEFITS

• Cost effective
• Better manageability
• User friendly
• Greater intrusion detection &
preventation features

66
Virtusa.
Virtusa banks on Fortinet’s technology expertise to ensure
that its outer layer of the networks is secure.
Business Challenge
Virtusa Corporation is a global information Virtusa had existing point solutions for its
technology services company that provides IT safety on the network. These included
consulting, technology and outsourcing firewalls, antivirus, antispam, IDS and IPS
services. The organization serves Global 2000 solutions. The organization wanted to add a
enterprises and the leading software vendors perimeter layer of security to this to be able to
in communications and technology, banking, handle all the threats. This would ensure that
financial services & insurance and media & with multiple layers of security in place, the
information industries. threats to the organization’s security could be
Situation brought down significantly. That was almost
three years ago. At That time Unified Threat
Virtusa delivers a range of services to its Management was a fairly new technology
customers. These include IT Consulting and there were not many players in That
Services, Technology Implementation space. “Fortinet’s was the only credible story
Services and Application Outsourcing at the time, which was the reason for us to go
Services. It has product partnerships with with Fortinet’s solutions,” says Vikram
edocs, Microsoft, FAST, Pegasystems, BMC Dhanda, head-global IT operations, Virtusa.
Remedy and Vignette. Virtusa has also “Secondly, Fortinet is the only company, as
evangelized the concept of Productization, far as I know, that has all the parts done
which is its unique methodology to create inhouse and thus offers a fully integrated
and consolidate technology assets in solution. The others work in partnerships or
organization specific platforms. Virtusa is have third party licenses. So we were not keen
headquartered in Massachusetts and has on outsourcing more solutions, in addition to
offices in U.S., U.K. and Asia. In India, the our existing point solutions,” he adds.
organization has presence in Hyderabad and
Chennai.

67
The focus of Fortinet on constant improvements is a
definite benefit. Over the years, we have seen continuous
improvements in the product and delivery
- Vikram Dhanda, head-global IT
operations, Virtusa

Deployment Dhanda. Since it was all done in a planned


Depending on the capacity of different manner, there was no downtime. As for
locations, Virtusa opted for multiple training, the organization received training
FortiGateTM- 3600A, 1000A, 400 and 200A. from Fortinet and continues to receive it as and
FortiGate-3600A delivers high performance when required.
protection against network level and content With the Fortigate boxes securing the
level threats, while FortiGate-1000A handles perimeter layer, the load on the inner layers
large enterprise requirements and 400 and has come down. With URL filtering, which is
200A are for smaller networks. These have again, Fortinet’s inhouse expertise, and not
been deployed in replicated environments in all an outsourced service, the pressure on the
locations. The deployment was done in a inner points has been reduced. “The focus of
phased manner. “We started with one location Fortinet on constant improvements is a
and we implemented different services at definite benefit. Over the years, we have seen
different points in time and we made sure we continuous improvements in the product and
were getting the required benefit of that delivery. This is good for us, as it shows our
approach before we went to the next level. investments also bring in value.”
Then we replicated it across locations,” says

BENEFITS
• Load on the inner security layers has
decreased
• Continuous improvement in product
and delivery, which brings great value
to the company

68
WNS.
Fortinet solution has been good on ROI and other benchmarks
yielding expected results for WNS.
Business the Fortinet implementation, WNS Nashik, is
WNS Global Services is a leading provider of primarily into health claims processing as well
offshore BPO services. It delivers value to its as caters to other enterprise service
customers by bringing operational excellence requirements. WNS Nashik is certified for ISO
and deep industry and functional knowledge 9001:2000, BS7799:2002 security standard
to their critical business processes. It provides and also complies with the HIPAA regulations.
high-quality execution of client processes, Situation
monitors these processes against multiple WNS is in a business where data protection
performance metrics, and seeks to improve and confidentiality of information is of prime
them on an ongoing basis. The company importance. All WNS delivery centers,
serves clients in multiple industries that including the Nashik one, operate 24x7, thus
include travel, banking, financial services, high availability of systems and security is of
insurance, manufacturing, retail, logistics, prime importance. Viruses, malicious scripts,
utilities and professional services. In addition intrusion attempts are the prime threats from
to industryspecific services, WNS also offers a Internet. “To protect all underlying
range of services across multiple industries, in infrastructure and ensuring data protection,
areas such as finance and accounting; human WNS has put in significant investments
resources; supply-chain management; towards information security enablers
market, business and financial research, and keeping abreast with the changing dynamics
analytical services. of the security domain,” says Arup Chatterjee,
WNS’ provides end-to-end support to its CSO-Information Security Risk Management,
clients across consulting services, BPO WNS Global Services. At WNS, all information
delivery and IT solutions. WNS has multiple processing is carried out over secure and
operation centers in India at Mumbai, Pune, private data circuits VPN over Internet.
Nashik and Gurgaon. The location utilizing

69
Fortinet is helping us to protect from Virus threats, the past
results shows that virus detection in local network is now
completely negligible. Overall, Fortinet has given WNS
desired performance and is yielding expected results

However, some of the operational activities system, gateway antivirus and Internet
and corporate use bring in the need for content filtering,” says Chatterjee. WNS had
access to the Internet. Talking about the evaluated other solutions prior to deploying
challenges faced by a service provider like the Fortinet solution benchmarking them
WNS, Chatterjee points out that virus, DoS against operational requirement, VPN
attacks are the key challenges in an open capability, intrusion prevention, support and
Internet environment. However, he adds, ROI. “On most of these parameters, Fortinet
intruders go beyond this and new hacking provided us the expected results packaged in
techniques in the form of manual automated one solution,” says Chatterjee.
intrusion attempts over the Internet have Deployment
become commonplace and frequent.
Since the deployment of the Fortinet
Challenge solution, virus detection has come down to
To protect its IT system from such attacks and negligible level at WNS. “Fortinet is helping
intrusions WNS needed a unified security us to protect from Virus threats, the past
solution that can not only detect but prevent results shows that virus detection in local
attacks from reaching internal networks from network is now completely negligible,”
external sources without impacting network points out Chatterjee, observing that overall,
performance and ensuring accuracy of Fortinet has given WNS desired performance
detection / prevention. Even though all and is yielding expected results. On further
computing systems are protected with expectations from Fortinet, Chatterjee
anti-virus solution, perimeter security is emphasises that secure tunnelling
essential too for ensuring that all data management needs to be easier to build and
transactions are filtered at the perimeter. understand. “Ability to incorporate SSL VPN
“Fortinet has provided us a unified security technology would be an added advantage,”
solution that incorporates perimeter security he adds.
in the form of firewall, intrusion prevention

BENEFITS
• Uni f ied secur i ty solut ion that incorporates perimeter security in the form of
firewall, intrusion prevention system, gateway antivirus and Internet
content filtering
• Virus detection has come down to negligible level in local network

70
Pantaloon Retail (India) Limited.
After implementation of Fortinet solution Pantaloon
expects number of business benefits from the enhanced
network.
Business retail business was kicked off with the first
Pantaloon Retail (India) [PRIL] is a successful Pantaloon retail store in Kolkata in 1997. It
retailing company and plans to grow its ventured into other retail business lines and
business in a big way this year, with the help now has 13 Pantaloon stores, nine
of new outlets and business ventures. IT will hypermarket discount stores (Big Bazaars), 13
play a critical role in the organisation’s Food Bazaars and one Central mall in various
productivity, and the company has crafted a nationwide locations. The Central mall has
roadmap to ensure that its information restaurants, shopping arcades, toys, books
infrastructure will scale as required to support and lifecycle products all under one roof. As
business growth. Going by its IT strategy we read, the actual number of the outlets is
roadmap, as a key effort, PRIL plans to deploy rising at a good pace. The company owns
secure nationwide connectivity links. It has brands like John Miller and Anabelle and has
also built a sizeable server infrastructure, also purchased a few companies such as
created a security architecture from scratch Indigo Nation and Scullers to add to its
and deployed a financial management business portfolio. It plans to build 20-odd
software. The company also plans to deploy outlets more in the next few months as a part
an ERP, set up a B2B portal, put up a Disaster of its business expansion plans.
Recovery (DR) site, use Business Intelligence Situation
(BI) tools, implement VoIP, and install CCTVs The IT strategy has been framed keeping in
at all locations that can be monitored from a mind its ambitious growth plans. The
central console and location. highlights are:
The company began as a textile and fabrics
• Create a robust and reliable information
manufacturer in 1987 and its foray into the
infrastructure.

71
We had to design the network so that the ge graphi-
cally dispersed workforce would have uninterrupted
access to the enterprise applications from any corner
of the country - Jitendra Sarode,
Senior Manager, IT infrastructure, PRIL

• Keep the large base of customer and financial Jitendra Sarode, Senior Manager, IT
information secure with no scope of infrastructure, PRIL has taken up the
unauthorised access. responsibility of creating a nationwide secure
connectivity.
• Network all offices and outlets of the company
to exchange information in real-time. Deployment
• Use tools to simplify operations and accounting Earlier all locations including retail outlets and
processes across the entire organisation. warehouses were not connected directly to
the HO. A group of three or four outlets in a
• Build the IT infrastructure with special emphasis
particular vicinity were connected to the
on scalability to allow growth on a large scale.
nearest regional or zonal office, which, in turn
• Keep looking at ways in which the business was connected to the HO. “We had to design
can reduce costs. the network so that the geographically
In line with the IT strategy the company has dispersed workforce would have
made a number of deployments and has uninterrupted access to the enterprise
plans to introduce large scale deployments in applications from any corner of the country.
areas like connectivity, security, server As we grow, it is necessary that information
infrastructure, networked storage and from locations is constantly updated to the
enterprise applications. central servers” explained Sarode. Keeping in
mind the need for scalability and complexity
Challenge
that may arise from an organisation that’s
The key to the success of the IT strategy lies in growing at a fast pace, Sarode created the
the ability to network all nationwide blueprint of a VPN architecture to link all the
company locations in a secure and organised company’s offices to the HO. The VPN
manner. PRIL has a head office (HO) in network will link all company locations
Mumbai, has regional offices in Kolkata and including retail outlets and the
Bangalore, a manufacturing unit and central manufacturing unit in phases. “In the first
warehouse in Tarapur (Thane district), zonal phase, we have connected around 24
offices and retail outlets in various nationwide locations.
locations. Due to the company’s
geographical spread and critical nature of
business, the most significant need laid out in
the IT strategy was that of connectivity.

72
“In any store if a particular shirt has high demand,
requisition can be made from a central location to ensure
the particular item is available. Functionalities like this saves
cost and provides transparency in the supply chain,”
—Sarode

In the second phase, we plan to connect 25 the evaluation of products from companies
more, depending on the growth pattern. The such as Fortinet CheckPoint, NetScreen and
last mile connectivity will be on Radio CyberGuard, PRIL chose to deploy a solution
Frequency (RF),” explained Sarode. from Fortinet called FG500A. “The device
Information security is a very important allows unified capabilities and is easy to
consideration in the IT strategy because the manage and monitor. It is used at the
network has to handle a large amount of perimeter,” said Vishak Raman, Country
company and customer information. After Manager India, Fortinet.
careful consideration, the company decided to
use multi-function device (MFD) - based
security rather than point solutions. Following

BENEFITS
• The company expects a number of
business benefits from the enhanced
network
• Free flow of information between the
head office and various nationwide
locations
• Easier to create sales and
analysis reports

73

Potrebbero piacerti anche