บทความนี้จำลอง LAB การป้องกัน Malware และ Ransomware เข้าถึง NAS/SERVER ด้วย Cybrey Firewall...
- ใหม่
RG-CF10S Ruijie Cybrey Next-Generation Firewall สำหรับสำนักงานและองค์กร รองรับ Firewall 6-8Gbps, IPS, Threat Protection, Application Control, URL Filtering, SSL VPN, IPsec VPN, Security Policy, Port Scan และ Cloud Management
สอบถามข้อมูลสินค้าเพิ่มเติม
LINE ID: @sysnet โทร: 02 102 4284
Ruijie Cybrey RG-CF10S Datasheet
Ruijie Cybrey RG-CF series next-generation high-performance firewalls NGFW_NTOS 1.0R13 User Manual
Forward Port เข้า NAS และ RDP เสี่ยงโดนแฮก? Firewall ช่วยป้องกันระบบ Office ได้อย่างไร
VLAN และ Policy บน Cybrey Firewall แยกวง Network ป้องกันการโจมตีในสำนักงาน
RG-CF10S เป็น Ruijie Cybrey Next-Generation Firewall สำหรับติดตั้งที่ Internet egress, ขอบเขตของระบบ Network, Data Center boundary และ Branch uplink เหมาะกับสำนักงาน โรงเรียน โรงแรม บริษัท และองค์กรที่ต้องการควบคุม Traffic พร้อมเพิ่มการป้องกันด้าน Cyber Security จาก Internet
RG-CF10S รองรับ Firewall Throughput 6 Gbps ถึง 8 Gbps, IPS Throughput 1.1 Gbps ถึง 1.7 Gbps, NGFW Throughput 900 Mbps ถึง 1.5 Gbps และ Threat Protection 600 Mbps ถึง 1.2 Gbps โดยค่าประสิทธิภาพแต่ละแบบเป็นคนละเงื่อนไขการทดสอบตามประเภทการใช้งาน รองรับ Concurrent Sessions 700,000 และ New Sessions 105,000 ต่อวินาที เหมาะกับระบบที่มีผู้ใช้งานจำนวนมากและต้องการ Firewall ที่รองรับ Traffic ระดับองค์กร
RG-CF10S มีความสามารถด้าน Security หลายส่วน เช่น Intrusion Prevention, Antivirus, Port Scan, Traffic Learning, Application Control, URL Filtering, WAF, SSL Decryption, DNS Inspection, Threat Intelligence และ AI-based unknown threat detection ช่วยให้ผู้ดูแลระบบควบคุม Traffic ตรวจสอบความเสี่ยง และกำหนด Security Policy ได้ละเอียดขึ้น
ระบบ Intrusion Prevention ของ RG-CF10S รองรับการใช้ Template และการกรอง Rule ตาม Object, Severity, Protocol และ Threat Type ช่วยลดความเสี่ยงจาก Traffic ที่มีลักษณะโจมตี เช่น Port Scan, Exploit, Brute Force และ DoS/DDoS Attack โดยสามารถใช้ร่วมกับ Security Policy, Blocklist และ Allowlist เพื่อควบคุมการรับส่งข้อมูลในระบบ Network
RG-CF10S รองรับ Antivirus, Virus Protection Template, Threat Protection, Threat Intelligence จาก Google และ Kaspersky รวมถึง AI Detection Engine สำหรับตรวจจับ Stealthy Attack และ Abnormal Behavior จึงช่วยลดความเสี่ยงจาก Malware Traffic และพฤติกรรมผิดปกติที่อาจเกี่ยวข้องกับภัยคุกคามจาก Internet การใช้งานจริงควรกำหนด Policy ให้เหมาะกับ Zone, VLAN, Server และกลุ่มผู้ใช้งาน
RG-CF10S รองรับ Application Control, Application Group, URL Category และ Keyword Configuration ช่วยให้องค์กรควบคุมการใช้งาน Internet ตามประเภท Application และ Website ได้ เช่น Social Media, Streaming, Remote Access, File Sharing หรือ Website ที่ไม่เหมาะกับนโยบายขององค์กร เหมาะกับสำนักงาน โรงเรียน และธุรกิจที่ต้องการจัดระเบียบการใช้งาน Internet ภายใน
RG-CF10S รองรับ SSL VPN Throughput 1.5 Gbps, Concurrent SSL VPN Users แนะนำสูงสุด 500 Users แบบ Tunnel Mode, IPsec VPN Throughput 3.5 Gbps และ Gateway-to-Gateway IPsec VPN Tunnels 200 ชุด เหมาะสำหรับพนักงาน Remote, การเชื่อมต่อ Site-to-Site VPN และสำนักงานหลายสาขาที่ต้องการเชื่อมระบบเข้าหากันอย่างปลอดภัย
RG-CF10S รองรับ Security Zone, Sub-interface พร้อม VLAN ID, Address Object, Service Object, Application Object และ Security Policy ที่กำหนดตาม Object, Content และ Zone ได้ เหมาะกับการแยก Network ภายใน เช่น Office, Guest Wi-Fi, CCTV, Server, NAS และ Management Network เพื่อควบคุมว่าแต่ละส่วนของระบบสามารถเข้าถึงกันได้แค่ไหน
RG-CF10S สามารถกำหนด Interface เป็น LAN หรือ WAN ได้ และรองรับ WAN IP Assignment แบบ PPPoE, DHCP และ Static IP พร้อม Static Route, Policy Based Routing, Link Detection, VRRP และ High Availability สำหรับระบบที่ต้องการความต่อเนื่องของ Internet และลดผลกระทบเมื่อ Link หรืออุปกรณ์หลักมีปัญหา
RG-CF10S รองรับ Traffic Learning Log, Link Detection Log, Security Policy Lifecycle, Policy Change Record, Cloud Analysis, Report, Remote Monitoring และ O&M ช่วยให้ผู้ดูแลระบบตรวจสอบย้อนหลัง วิเคราะห์เหตุการณ์ และติดตามพฤติกรรมการใช้งานในระบบได้ง่ายขึ้น
RG-CF10S มี 8 x 10/100/1000BASE-T Port สำหรับใช้งานเป็น LAN หรือ WAN, 2 x GE SFP Port, 1 x RJ45 MGMT Port, 1 x RJ45 Console Port และ USB 3.0 ใช้ติดตั้งเป็น Internet Gateway, Firewall หน้า Core Switch, เชื่อมต่อ Uplink ไปยังระบบ Fiber, Switch, Server หรือ NAS ได้ตามโครงสร้าง Network ขององค์กร
RG-CF10S เหมาะสำหรับสำนักงาน บริษัท โรงเรียน โรงแรม ร้านค้า Chain Store โรงงาน และองค์กรหลายสาขาที่ต้องการ Firewall สำหรับควบคุม Internet, แยก Network, ใช้งาน VPN, ตรวจสอบ Traffic, ลดความเสี่ยงจากการโจมตี และบริหาร Security Policy ผ่านระบบ Cloud Management
| Product Information | |
| Model | RG-CF10S |
| Product Type | Ruijie Cybrey Next-Generation Firewall |
| Product Category | Firewall / NGFW / VPN Firewall / Cyber Security Firewall |
| Recommended Use | Internet egress, area boundary, data center boundary และ branch uplink |
| Firewall Performance | |
| Firewall Throughput | 6 Gbps - 8 Gbps |
| IPS Throughput | 1.1 Gbps - 1.7 Gbps |
| NGFW Throughput | 900 Mbps - 1.5 Gbps |
| Threat Protection Throughput | 600 Mbps - 1.2 Gbps |
| SSL Inspection Throughput | 530 Mbps |
| Concurrent Sessions | 700,000 TCP Sessions |
| New Sessions per Second | 105,000 TCP Sessions/s |
| Firewall Policies | 3,000 |
| Recommended Users | ไม่ระบุใน Datasheet |
| Hardware Specifications | |
| CPU | ไม่ระบุใน Datasheet |
| RAM | ไม่ระบุใน Datasheet |
| Storage | No hard disk for factory delivery |
| Port Specifications | |
| RJ45 Ports | 8 x 10/100/1000BASE-T Ports |
| SFP Ports | 2 x GE SFP Ports |
| SFP+ Ports | ไม่ระบุใน Datasheet |
| MGMT Port | 1 x RJ45 MGMT Port |
| Console Port | 1 x RJ45 Console Port |
| USB Port | 2 x USB 3.0 Ports |
| Port Speed | 1G RJ45 / 1G SFP |
| Cyber Security Features | |
| IPS / Intrusion Prevention | รองรับ Intrusion Prevention Template และ IPS Library |
| Threat Protection | รองรับ Threat Protection, Threat Intelligence และ Malware Protection |
| Attack Defense | Port Scan, DoS/DDoS Attack Defense, ARP Attack Defense, Local Defense, Blocklist/Allowlist |
| Antivirus / Anti-Malware | รองรับ Antivirus, Virus Protection Template และ Malware Protection |
| URL Filtering / Web Filtering | รองรับ URL Filtering, URL Category และ Keyword Configuration |
| Application Control | รองรับ Application และ Application Group |
| SSL Inspection | รองรับ SSL Inspection Throughput 530 Mbps และ SSL Proxy Policy |
| Security Policy | รองรับ Security Policy, Batch Import, Policy Simulation, Policy Optimization และ Policy Lifecycle |
| Security Zone | รองรับ Security Zone |
| WAF | รองรับ WAF |
| AI Detection Engine | รองรับ AI-powered stealthy attack และ abnormal behavior detection |
| VPN Features | |
| IPsec VPN Throughput | 3.5 Gbps |
| SSL VPN Throughput | 1.5 Gbps |
| SSL VPN Users | 500 Users recommended maximum, tunnel mode |
| Site-to-Site VPN | รองรับ Gateway-to-Gateway IPsec VPN Tunnels 200 |
| Remote Access VPN | รองรับ SSL VPN |
| VPN Protocols | SSL VPN, IPsec VPN |
| Network / Routing Features | |
| VLAN | รองรับ Sub-interface และ VLAN ID |
| Static Route | รองรับ IPv4 Static Route |
| Dynamic Routing | ไม่ระบุใน Datasheet |
| NAT | รองรับ NAT, NAT Policy, NAT ALG, Server Mapping และ Address Pool |
| Policy Based Routing | รองรับ PBR |
| Multi-WAN | รองรับการกำหนด Interface เป็น LAN หรือ WAN พร้อม PPPoE, DHCP และ Static IP สำหรับ WAN |
| Load Balance | ไม่ระบุใน Datasheet |
| WAN Failover | รองรับ Link Detection, VRRP และ High Availability |
| SD-WAN | รองรับ Integration with cloud platforms สำหรับ unified orchestration และ monitoring ของหลายสาขา |
| Log / Report / Management | |
| Traffic Log | รองรับ Traffic Learning Logs |
| Threat Log | รองรับ Cloud Analysis และ Security Incident Analysis |
| Security Report | รองรับ Dashboards และ Reports สำหรับ Network และ Asset Security Posture |
| Syslog | ไม่ระบุใน Datasheet |
| Cloud Management | รองรับ Unified Management on Cloud Platform, Remote Monitoring, Remote O&M และ Mobile App |
| Web Management | รองรับ Web UI |
| SNMP | ไม่ระบุใน Datasheet |
| Fault Diagnosis | รองรับ One-click Fault Analysis, Packet Tracing และ Firewall Diagnosis Center |
| High Availability / Reliability | |
| High Availability | รองรับ Redundancy และ Automatic Switchover ระหว่าง Active และ Passive Devices |
| HA Mode | Active / Passive |
| Link Failover | รองรับ Link Detection และ Link Detection Logs |
| Power / Physical / Environment | |
| Power Supply | 1 x External Power Adapter, Rated Input 12 V / 3 A |
| Maximum Power Consumption | RG-CF10S: < 15 W |
| Dimensions | 260 mm x 170 mm x 43.6 mm |
| Weight | 1.6 kg |
| Mounting | 1 RU Rack |
| Operating Temperature | 0°C to 45°C |
| Operating Humidity | 10% RH to 90% RH, non-condensing |
| Package Contents | |
| Device | RG-CF10S Series Chassis x 1 |
| Accessories | Power Cord x 1, Power Cord Retention Clip x 1, Grounding Wire x 1, Rubber Pad x 4 |
| Manual / Warranty Card | User Manual x 1, Warranty Card x 1 |
| Warranty | รับประกันศูนย์ Ruijie Thailand 3 ปี |
The RG-CF10 series is tailored for small-scale deployment. With software licenses, the RG-CF10 series delivers full threat protection throughput ranging from 600 Mbps to 800 Mbps, and supports up to 500 free SSL VPN clients at no extra cost.

With an elegant and compact industrial design, it fits seamlessly into tight spaces while delivering powerful protection for any environment

The CPU and SPU architecture enables full threat protection with low performance overhead. The SPU, a programmable decryption chip, delivers 90%+ encrypted traffic inspection with rich security features, enabling maximum protection while minimizing CPU consumption.

Effortless Visibility and Control, Designed for non-professionals
Skip the commercial analytics platform. Our cloud AI correlates massive alerts, auto-generates high-precision incidents, and auto-traces the root cause across the network, assets, and origin, slashing response time from days to hours. Gain global visibility into your network’s security posture, trends, and ROI— no manual data wrangling.

No extra license, rich SD-WAN features are supported by CF series firewalls. AnyLink is a Reyee cloud technology that helps small and medium businesses route traffic across multiple WAN links more efficiently, securely, and cost-effectively. It uses software-defined networking to automate and optimize data flow between multiple locations, such as branch CCTV and retail chain cashier systems.
Policy Execution After Simulation,Policy Optimization Anytime
Verify policies using real traffic in Policy Simulation Space without affecting actual services or compromising network performance. Apply policies to the live network with one click after verification

All-in-One Capabilities: One firewall delivers built-in app control and URL filtering, IPS, AV, Google & Kaspersky threat intelligence, WAF, and AI-based unknown threat detection.

firewall delivers over 20% higher decryption and threat protection performance, and seamlessly scales with your business. There is no need to rip and replace infrastracture, saving 10% in procurement costs and over 20% in hardware upgrade costs.
