Juniper SSG320M Datasheet Download Page 1

DATASHEET

1

Product Description 

The Juniper Networks

®

 SSG300 line of secure services gateways comprises high-

performance security platforms that help businesses stop internal and external attacks, 
prevent unauthorized access, and achieve regulatory compliance. The Juniper Networks 
SSG350M Secure Services Gateway provides 500 Mbps of stateful firewall performance 
and 225 Mbps of IPsec VPN performance, while the Juniper Networks SSG320M Secure 
Services Gateway provides 400 Mbps of stateful firewall performance and 175 Mbps of 
IPsec VPN performance. 

These products focus on three key disciplines:

Security

: Protection against worms, viruses, trojans, spam, and emerging malware 

is delivered by proven Unified Threat Management (UTM) security features that are 
backed by best-in-class partners. To address internal security requirements and facilitate 
regulatory compliance, the SSG300 line supports an advanced set of network protection 
features such as security zones, virtual routers, and VLANs that allow administrators to 
divide the network into distinct, secure domains, each with their own unique security 
policy. Policies protecting each security zone can include access control rules and 
inspection by any of the supported UTM security features.

The SSG350M deployed at a branch office for secure Internet connectivity and site-to-site 

VPN to corporate headquarters. Internal branch office resources are protected with unique 

security policies applied to each security zone.

Product Overview

The Juniper Networks SSG300 line 
consists of purpose-built security 
appliances that deliver the ideal 
blend of performance, security, 
routing, and LAN/WAN connectivity 
for large, regional branch offices and 
medium-size, standalone businesses. 
Traffic flowing in and out of a regional 
office or business is protected 
from worms, spyware, trojans, and 
malware by a complete set of Unified 
Threat Management security features, 
including stateful firewall, IPsec VPN, 
intrusion prevention system (IPS), 
antivirus (includes antispyware, 
antiadware, antiphishing), antispam, 
and Web filtering. The SSG300 line 
comprises the SSG350M and the 
SSG320M Secure Services Gateways.

SSG320M ANd 
SSG350M SecUre 
SerVIceS 
GATeWAyS

Regional Office

Headquarters

Zone A

Zone B

Zone C

SSG350M

NetScreen-5400

M7i

Internet

Summary of Contents for SSG320M

Page 1: ...ork into distinct secure domains each with their own unique security policy Policies protecting each security zone can include access control rules and inspection by any of the supported UTM security features The SSG350M deployed at a branch office for secure Internet connectivity and site to site VPN to corporate headquarters Internal branch office resources are protected with unique security pol...

Page 2: ...nnually licensed IPS engine is available with Juniper Networks Deep Inspection Firewall Signature Packs Prevents application level attacks from flooding the network Fixed Interfaces Four fixed 10 100 1000 interfaces two USB ports one console port and one auxiliary port are standard on all SSG300 line models Provides high speed LAN connectivity future connectivity and flexible management Network se...

Page 3: ...ial ADSL2 G SHDSL 10 100 1000 and SFP SSG350M SSG320M Specifications SSG320M SSG350M Maximum Performance and Capacity 1 ScreenOS version tested ScreenOS 6 3 ScreenOS 6 3 Firewall performance Large packets 450 Mbps 550 Mbps Firewall performance IMIX 2 400 Mbps 500 Mbps Firewall Packets Per Second 64 byte 175 000 PPS 225 000 PPS AES256 SHA 1 VPN performance 175 Mbps 225 Mbps 3DES SHA 1 VPN performan...

Page 4: ... URL filtering 4 Yes Yes VoIP Security H 323 ALG Yes Yes SIP ALG Yes Yes MGCP ALG Yes Yes SCCP ALG Yes Yes NAT for VoIP protocols Yes Yes IPsec VPN Concurrent VPN tunnels 500 500 Tunnel interfaces 100 300 DES 56 bit 3DES 168 bit and AES 256 bit Yes Yes MD 5 and SHA 1 authentication Yes Yes Manual key IKE IKEv2 with EAP PKI X 509 Yes Yes Perfect forward secrecy DH Groups 1 2 5 1 2 5 Prevent replay ...

Page 5: ...ic routes 10 000 10 000 Source based routing Yes Yes Policy based routing Yes Yes ECMP Yes Yes Multicast Yes Yes Reverse Path Forwarding RPF Yes Yes IGMP v1 v2 Yes Yes IGMP Proxy Yes Yes PIM SM Yes Yes PIM SSM Yes Yes Multicast inside IPsec tunnel Yes Yes Encapsulations PPP Yes Yes MLPPP Yes Yes MLPP max physical interfaces 6 10 Frame Relay Yes Yes MLFR FRF 15 FRF 16 Yes Yes MLFR max physical inte...

Page 6: ...es Yes Device failure detection Yes Yes Link failure detection Yes Yes Authentication for new HA members Yes Yes Encryption of HA traffic Yes Yes System Management WebUI HTTP and HTTPS Yes Yes Command line interface console Yes Yes Command line interface telnet Yes Yes Command line interface SSH Yes v1 5 and v2 0 compatible Yes v1 5 and v2 0 compatible Network and Security Manager NSM Yes Yes All ...

Page 7: ...herwise noted Actual results may vary based on ScreenOS release and by deployment For a complete list of supported ScreenOS versions for SSG Series gateways please visit the Juniper Customer Support Center www juniper net customers support and click on ScreenOS Software Downloads 2 IMIX stands for Internet mix and is more demanding than a single packet size as it represents a traffic mix that is m...

Page 8: ... Line I O Options JX 2T1 RJ48 S 2 port T1 PIM with integrated CSU DSU JX 2E1 RJ48 S 2 port E1 PIM with integrated CSU DSU JX 2Serial S 2 port Synchronous Serial PIM JX 1ADSL A S 1 port ADSL 2 2 Annex A PIM JX 1ADSL B S 1 port ADSL 2 2 Annex B PIM JX 2SHDSL S 2 port 2 wire or 1 port 4 wire G SHDSL PIM JX 1BRI ST S 1 port ISDN BRI S T PIM JXU 6GE SFP S 6 port SFP Gigabit Ethernet Universal PIM2 JXU ...

Reviews: