Product

Overview 

GFI LANguard™ is an award-winning network security scanner and patch management solution used by thousands of customers. GFI LANguard provides a complete network security overview with minimal administrative effort.

Your own ‘Virtual Security Consultant’

Easy to set up and use, GFI LANguard acts as a virtual consultant to give you a complete picture of your network set-up, provide risk analysis and help you to maintain a secure and compliant network state faster and more effectively. GFI LANguard assists you in these key areas:

- Patch management
- Vulnerability management
- Network and software auditing
- Assets inventory
- Change management
- Risk analysis and compliance

Patch Management

Missing security patches are one of the main reasons for network security breaches. GFI LANguard helps eliminate this risk by providing on-demand or fully automated detection, downloading and deployment of missing patches. GFI LANguard helps you fix vulnerabilities before they are exploited and reduces the time required to patch machines on your network.

Patch Microsoft operating systems and applications

GFI LANguard enables administrators to manage Microsoft patches and service packs for all languages supported by Microsoft.  It also provides features like patch rollback and uses an existing WSUS patch repository. Click here for a list of supported Microsoft bulletins

Patch non-Microsoft applications 

GFI LANguard also offers patch management support for non-Microsoft software, enabling administrators to detect, download and deploy missing patches for supported applications in the same way as is done for Microsoft updates. GFI LANguard offers patch management support for many popular applications like Apple QuickTime,  Adobe Acrobat, Adobe Flash Player, Adobe Reader, Mozilla Firefox, Java Runtime and others (click here for a full list).

Deploy custom software and scripts 

Besides providing automatic patch management, GFI LANguard permits the network-wide deployment of any custom software and scripts that can run silently.

Spotlight on PCI DSS and the Security Curve

Discover what the Payment Card Industry Data Security Standard (PCI DSS) is and why organizations that hold, process or exchange credit card info need to comply. This webinar will walk you through GFI's understanding of the PCI DSS requirements, and how the GFI product line can assist you to meet PCI compliance.
Click here for more information.

Vulnerability Management

GFI LANguard performs over 15,000 checks on your operating system, virtual environments and installed applications using vulnerability check databases such as OVAL and SANS Top 20. GFI LANguard allows you to analyze the state of your network security, what the risks are, how exposed your network is and how to take action before it is compromised.

Network and Software Auditing

GFI LANguard’s network auditing functionality gives you a detailed analysis of what is happening on your network – which applications or default configurations are posing a security risk. With GFI LANguard, you get a complete picture of what applications are installed, the hardware on your network, the state of security applications (AV, anti-spam, firewalls, etc.), what ports are open, any existing shares and services running on your machines.

Assets Inventory

GFI LANguard allows you to create an assets inventory of every device on your network; be they servers and workstations, virtual machines or IP-based hardware such as routers, printers, switches and so on. Asset inventories help you identify devices attached to your network that you were unaware of or had forgotten and these, unless properly patched and secure, could become entry points for hackers and malware.

Change Management

The best way to maintain a secure network over time is to know exactly what’s happening on your network. Changes to configurations that could have security implications, new applications that are installed, services that are started/stopped are all events that an administrator needs to know about. GFI LANguard gives you a complete history of network changes that are relevant to the security of your network and sends notifications when these occur.

Risk Analysis and Compliance

GFI LANguard makes it easier for the administrator to know what needs to be fixed with urgency. Security issues are rated by their severity level and each computer is given a risk and vulnerability rating so that you know where the main problems on your network are. GFI LANguard provides numerous executive, technical and statistical reports that help you to understand what is happening on the network, to prioritize remediation operations efficiently and to prove, if required, that the network is secure.

Why use GFI LANguard?

  • Automated patching for Microsoft and other application software
  • Deployment of custom software and scripts
  • Over 15,000 vulnerability assessments carried out across your network, including virtual environment
  • Reduces the total cost of ownership by centralizing vulnerability scanning, Patch Management and Network Auditing
  • Can assist with PCI DSS compliance; learn more.

Features 

GFI offers a freeware version of GFI LANguard™ for non-commercial use. The freeware version allows you to scan up to five IPs for free using the product’s full feature set, with the exception of patch management for non Microsoft applications, which is only available in the commercial version.

Patch Management and Remediation Across Different Microsoft OSs and Products 

GFI LANguard performs a scan of your network and gives you all the functionality and tools you need to effectively install and Manage Patches on all machines across different Microsoft operating systems and products in 38 languages. Click here to view a full list.

GFI LANguard also allows auto-downloads of missing patches as well as patch roll-back and custom software can be deployed, resulting in a consistently configured environment that is secure against vulnerabilities.

Patch Management for Non-Microsoft Software 

GFI LANguard also offers patch management support for non-Microsoft software, enabling administrators to detect, download and deploy missing patches for supported applications in the same way as is done for Microsoft updates. GFI LANguard offers patch management support for many popular applications like Apple Quicktime,  Adobe Acrobat, Adobe Flash Player, Adobe Reader, Adobe Shockwave Player, Mozilla Firefox, Mozilla Thunderbird, Java Runtime and others. Click here for a full list

With GFI LANguard, it is possible not just to patch third party applications, but also to upgrade to their latest versions (i.e. if an old version of Adobe Flash is detected, GFI LANguard will provide an option to either upgrade to the latest version or to apply all patches for that version).

GFI LANguard is the first solution that automates patching for all major web browsers running on Windows systems: Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Apple Safari and Opera Browser.

Automatically Deploy Network-wide Patch and Service Pack Management 

With GFI LANguard you can easily deploy missing service packs and patches network-wide. GFI LANguard is the ideal tool to ensure that Microsoft WSUS is working properly and it performs tasks WSUS does not, such as patching third party applications and deploying custom software patches. GFI LANguard also provides you with new features such as patch auto-download and patch rollback. It is also Unicode compliant and able to support patch management in all languages supported by Microsoft. The network administrator has the option to either manually approve each patch or set all Microsoft updates as approved. If patches are approved manually the network administrator can choose to receive email notifications when new Microsoft updates are available.

Automatic Remediation of Unauthorized Applications 

Remediation operations can be triggered automatically at the end of scheduled scans. Apart from reporting on all installed applications, GFI LANguard allows the user to define which applications are authorized or not authorized to be installed on the network. This list of applications can be easily defined for each scanning profile using the Applications Inventory Tool. During a scan, any unauthorized applications are identified and (optionally) uninstalled automatically by GFI LANguard. An integrated Auto-Uninstall Validation tool is provided to help identify which of the detected applications support silent uninstall and can thus be safely and automatically uninstalled.

Remote Desktop Connection 

GFI LANguard allows the useful option of a remote desktop connection to fix security issues on scanned computers that cannot be fixed automatically.

Deploys Custom and Third Party Software and Patches Network-wide 

Besides Deploying Patches and Service Packs, GFI LANguard enables you to easily deploy third party software or patches network-wide. You can use this feature to deploy client software, update custom or non-Microsoft software, virus updates and more; practically any application that can run silently can be pushed in the network using GFI LANguard. This custom software deployment feature means you can do without Microsoft SMS, which is complex and too expensive for small to medium-sized networks.

Vulnerability Scanning

During security audits, over 15,000 vulnerability assessments are made - scanning the network IP by IP. GFI LANguard gives you the capability to perform multi-platform scans (Windows, Mac OS, Linux) across all environments - including Virtual Machines and to analyze your network’s security set-up and status. GFI LANguard gives you the power to identify and correct any threats before hackers can exploit them.

Set up your own Custom Vulnerability Checks 

GFI LANguard allows you to easily create custom vulnerability checks through simple wizard-assisted set-up screens. The wizard is powerful enough to allow building of complex vulnerability checks and the scripting engine is compatible with Python and VBScript. GFI LANguard includes a script editor and debugger to help with script development.

Extensive, Industrial Strength Vulnerabilities Database 

GFI LANguard ships with a complete and thorough vulnerability assessment database, including standards such as OVAL (2,000+ checks) and SANS Top 20. This database is regularly updated with information from BugTraq, SANS Corporation, OVAL, CVE and others. Through its auto-update system, GFI LANguard is always kept up-to-date with information about newly released Microsoft security updates as well as new vulnerability checks issued by GFI Software and other community-based information repositories such as the OVAL database.

Identify Security Vulnerabilities and Take Remedial Action 

GFI LANguard scans computers, identifies and categorizes security vulnerabilities, recommends a course of action and provides tools that enable you to solve the problem. GFI LANguard comes with a graphic threat level indicator that provides an intuitive, weighted assessment of the vulnerability status of a scanned computer or group of computers. Wherever possible, a web link or more information on a particular security issue is provided - such as a BugTraq ID or a Microsoft Knowledge Base article ID.

Ensures Third Party Security Applications (Antivirus and Anti-Spyware) Offer Optimum Protection 

GFI LANguard ensures that supported security applications such as antivirus and anti-spyware software are updated with the latest definition files and are functioning correctly. For example, you can check to be certain that supported security applications have all key features (such as real-time scanning) enabled.

Easily Creates Different Types of Scans and Vulnerability Tests 

You can easily configure scans for different types of information, such as open shares on workstations, security audit and password policies, and machines missing a particular patch or service pack. You can scan for different types of vulnerability to identify potential security issues. These include:

  • Open ports: GFI LANguard scans for unnecessary open ports and checks that no port hijacking is in force
  • Unused local users and groups: GFI LANguard removes or disables User Accounts which are no longer in use
  • Blacklisted applications: With GFI LANguard, you can identify unauthorized or dangerous software and add to blacklists of applications you want to associate with a high security vulnerability alert
  • Dangerous USB devices, wireless nodes and links: GFI LANguard scans all devices connected to USB or wireless links and alerts you of any suspicious activity

And much more!

Easily Analyze and Filter Scan Results 

GFI LANguard enables you to easily analyze and filter scan results by clicking on one of the default filter nodes. This enables you to identify, for example, machines with high security vulnerabilities or machines that are missing a particular service pack. Custom filters can also very easily be created from scratch or customized from and existing script. Also, you can export scan results data to XML.

Network and Software Auditing

GFI LANguard’s Network Auditing gives you a comprehensive view of  your network - what USB devices are connected, what software is installed, any open shares, open ports and weak passwords in use, and hardware information. The solution's in-depth reports give you an important and real-time snapshot of your network's status. Scan results can be easily analyzed using filters and reports, enabling you to proactively secure the network by closing ports, deleting users or groups which are no longer in use, or disabling wireless access points.

Hardware Auditing 

GFI LANguard shows detailed information about the hardware configuration of all the scanned machines on your network. All devices from the Device Manager tool from Windows operating systems are retrieved, including motherboard, processors, memory, storage devices, display adapters and much more. Using baseline comparisons you can now check whether any hardware was added or removed since the last scan.

Automatically Receive Alerts of New Security Holes 

GFI LANguard can perform routine scheduled scans and can automatically compare results to previous scans. Any new security holes or security set-up changes discovered on your network are emailed to you for analysis. This enables you to quickly identify newly-created shares, installed services, installed applications, added users, newly-opened ports and more. GFI LANguard will generate specific reports and email notification whenever there are software or hardware changes detected within the audited network. Our reports also show what remediation operations were performed.

Check to Ensure Security Auditing is Enabled Network-wide

GFI LANguard checks if each NT/2000/XP/2003/VISTA/2008/2008 R2/7 machine has security auditing enabled. If not, GFI LANguard alerts you and allows you to enable auditing remotely. Security event auditing is highly recommended as it detects intruders in real time.

Scan and Retrieve OS data from Linux Systems 

It is possible to remotely extract OS data from Linux-based systems and scan results are presented in the same way as for Windows-based computers. This means that both Linux and Windows-based computers can be analyzed in a single scanning session! GFI LANguard includes numerous Linux security checks including rootkit detection. GFI LANguard can use SSH Private Key files instead of the conventional password string credentials to authenticate to Linux-based target computers.

Additional Features

Dashboard 

The GFI LANguard dashboard shows summarized results of all scans from the database and provides an overview of the most vulnerable computers and security status trends of the network.

Multiply the Value of GFI LANguard with Powerful Reporting 

Reports are designed to satisfy the requirements of both management and technical staff. GFI LANguard delivers a graphical snapshot of the security status of your network. From trend reports for management (ROI) to daily drill-down reports for technical staff, GFI LANguard provides you with the easy-to-view information you need to fully keep on top of your network’s security environment. Executive reports are now available directly from within GFI LANguard.

Helps You Comply with PCI DSS and Other Regulations 

All businesses handling cardholder data, regardless of size, have to be fully compliant with strict security standards drawn up by the world’s major credit card companies. GFI LANguard provides complete vulnerability management coupled with an extensive reporting ReportPack add-on. That makes GFI LANguard an essential, highly cost-effective solution for your organization to safeguard your network and gauge the effectiveness of your PCI compliance program.

Silent Installation Support 

You can perform an unattended default installation of GFI LANguard on multiple computers in the background without any user interaction or intervention.

Predefine Authentication Details 

GFI LANguard allows you to store separate authentication details for every target computer on your network, avoiding the need to specify authentication credentials prior to every scan. In a single scanning session, it is possible to audit all the targets in your network, even if they require different authentication details and/or methods.

Support for Virtual Environments 

Organizations that use or plan to use virtualization on their network can install and use a range of GFI products with confidence. GFI LANguard supports and runs on the most common virtualization technologies in use, namely VMware, Microsoft Virtual Server and Microsoft Hyper-V. It also offers detection of virtual machines hosted by the scanned computer.

New! News Section 

GFI LANguard features a news section – an easy way to find out about product updates. This section informs you about any new patches that will be supported by GFI LANguard, any new applications that have become available for patch management, and any new vulnerabilities that have been added to the database.

Localization 

GFI LANguard is also available in Italian and German.

Other Features:

  • Automatically checks the password policy for all machines on the network
  • Checks for programs that run automatically (potential trojans)
  • Finds out if the OS is advertising too much information
  • Performs simultaneous scans through the multithread scan engine
  • Provides NetBIOS hostname, currently logged username and MAC address
  • Provides a list of shares, users (detailed info), services, sessions, remote TOD (time of day) and registry information from remote computer (Windows)
  • SNMP device detection, SNMP Walk for inspecting network devices like routers, network printers and more
  • Offers alternative command line deployment tool
  • Identifies all installed Windows services
  • Supports Microsoft Windows 7 and Microsoft Windows Server 2008 R2

System Requirements

Hardware

Hardware requirements depend on network size. Refer to table below for the minimum specifications according to your network size.

  1 to 10 scan targets 10 to 500 scan targets 500 to 1500 scan targets
Processor 1 GHz 2 GHz 2 X 3 GHz Quad Core
Physical Storage 1 GB 2 GB 10 GB
Memory 1 GB 2 GB 4 GB
Network bandwidth usage 256 kbps 256 kbps to 550 kbps 256 kbps to 550 kbps

Software

Supported operating systems (x86 or x64)

  • Microsoft Windows Server 2008 Standard/Enterprise
  • Microsoft Windows Server 2003 Standard/Enterprise
  • Microsoft Windows 2000 Professional/Server/Advanced Server (SP4 or higher)
  • Microsoft Windows 7 Ultimate
  • Microsoft Windows Vista Business/Enterprise/Ultimate
  • Microsoft Windows XP Professional (SP2 or higher)
  • Microsoft Small Business Server 2008 Standard
  • Microsoft Small Business Server 2003 (SP1)
  • Microsoft Small Business Server 2000 (SP2)

Supported databases

  • Microsoft Access
  • Microsoft SQL Server 2000 or later, MSDE/SQL Server Express Edition

Other server components

The following components are required to be installed on the server where GFI LANguard is installed:

  • Microsoft .NET Framework 2.0

Target computer components

The following components are required to be installed on target computers for GFI LANguard to be able to scan them:

  • Secure Shell (SSH) - Required for UNIX based scan targets. Commonly included as part of all major Unix/Linux distributions.
  • Windows Management Instrumentation (WMI) - Required to scan Windows-based scan targets. Included in all Windows 2000 or newer operating systems.

Looking for pricing information?

Want to speak to a sales expert?

If you are an end user looking for pricing information please click here to send us an email.

If you are a reseller/partner please visit our home page to login in to the Partner Area.

GFI FAXmaker v.2013

GFI FaxMaker™ is a leading fax server for small to medium-sized businesses (SMBs). It makes sending and receiving faxes an efficient, simple and cost effective process and solves the problems with manual faxing: printing out the document, walking to the f...

GFI MailEssentials v.2012

The most effective way to beat spammers at their game is to use GFI MailEssentials™, a leading anti-spam solution that has won several awards. GFI MailEssentials features not one, but two anti-spam engines to give administrators an ultra high spam capture...

GFI Network Server Monitor

GFI Network Server Monitor™ scans your network for failures or irregularities. GFI Network Server Monitor scans automatically so you can identify issues and fix unexpected problems before your users (or managers) even know they've happened....

GFI EndPointSecurity v.2013

According to the Ponemon Institute, 59% of people who lost their job admitted to taking confidential company information with them either on DVD or using USB drives. The proliferation of consumer devices such as iPods, USB devices, Smart Phones and more, ...

GFI EventsManager v.2013

The enormous volume of system event logs generated daily is of growing importance to organizations that are required to record information for forensic purposes and due to the ever-growing reach of regulatory compliance. Increased threats to business cont...

GFI MAX RemoteManagement

Award-winning GFI MAX RemoteManagement™ is an IT Managed Services software solution which makes it easy to stay on top of your customers' servers, desktops, networks, hardware, software, antivirus, inventory tracking, automated server and desktop maintena...

GFI MailArchiver 2012 SR2

GFI MailArchiver is an email archiving software that solves your email management problems on Exchange Server. With thousands of customers, it is a leading email archiving solution for small to medium-sized businesses (SMBs). GFI MailArchiver is used by a...

GFI WebMonitor for ISA Server/Standalone v.2013

Research by IDC shows that up to 40% of employee Internet access is non-work related. While shutting off Internet access is impractical, Internet monitoring and access control software enables network administrators to reduce unproductive Internet use: GF...