Juniper SSG320M Datasheet Download Page 2

2

Connectivity and Routing:

 The SSG300 line provides four onboard 

10/100/1000 interfaces complemented by I/O expansion slots that 
can house a mix of LAN or WAN interfaces, making the SSG300 
line an extremely flexible platform. The broad array of I/O options 
coupled with WAN protocol and encapsulation support makes the 
SSG300 line of gateways easily deployable as traditional branch 
office routers or as consolidated security and routing devices, which 
can help reduce capex and Opex.

Access Control Enforcement: 

The SSG300 line of gateways can act 

as enforcement points in a Juniper Networks Unified Access control 
deployment with the simple addition of the Juniper Networks Ic 
Series UAc Appliances. The Ic Series functions as a central policy 

management engine by interacting with the SSG300 line to augment 
or replace the firewall-based access control. It grants/denies access 
based on more granular criteria, including endpoint state and user 
identity in order to accommodate the dramatic shifts in attack 
landscape and user characteristics.

In addition, Juniper Networks Professional Services will collaborate 
with your team to identify goals, define the deployment process, 
create or validate the network design, and manage the deployment 
to its successful conclusion. Whether it involves simple lab testing 
or a major network implementation, Juniper Networks Professional 
Services is there to help you ensure success.

Features and Benefits

Feature

Feature Description

Benefit

High performance

Purpose-built platform is assembled from custom-built 
hardware, powerful processing and a security-specific 
operating system.

delivers performance headroom required to protect 
against internal and external attacks now and into 
the future.

Best-in-class UTM security features

UTM security features (antivirus, antispam, Web 
filtering, IPS) stop all manner of viruses and malware 
before they damage the network. 

ensures that the network is protected against all 
manner of attacks.

Integrated antivirus

Annually licensed antivirus engine, provided by Juniper, 
is based on Kaspersky Lab engine.

Stops viruses, spyware, adware and other malware.

Integrated antispam

Annually licensed antispam offering, provided by 
Juniper, is based on Sophos technology.

Blocks unwanted email from known spammers and 
phishers.

Integrated Web filtering

Annually licensed Web filtering solution, provided by 
Juniper, is based on Websense Surfcontrol technology.

controls/blocks access to malicious Web sites.

Integrated intrusion prevention  
system (IPS) (deep Inspection)

Annually licensed IPS engine is available with Juniper 
Networks deep Inspection Firewall Signature Packs.

Prevents application-level attacks from flooding the 
network.

Fixed Interfaces

Four fixed 10/100/1000 interfaces, two USB ports, one 
console port and one auxiliary port are standard on all 
SSG300 line models.

Provides high-speed LAN connectivity, future 
connectivity and flexible management.

Network segmentation 

Bridge groups, security zones, virtual LANs and virtual 
routers allow administrators to deploy security policies 
to isolate guests, wireless networks and regional servers 
or databases.*

Powerful capabilities facilitate deploying security for 
various internal, external and dMZ sub-groups on the 
network, to prevent unauthorized access.

Interface modularity

Six interface expansion slots support optional T1, e1, 
Serial, AdSL/AdSL2/AdSL2+, G.SHdSL, 10/100/1000, 
and SFP connectivity.

delivers combination of LAN and WAN connectivity 
on top of unmatched security to reduce costs and 
extend investment protection.

robust routing engine

Proven routing engine supports OSPF, BGP and rIP v1/2 
along with Frame relay, Multilink Frame relay, PPP, 
Multilink PPP and HdLc. 

enables the deployment of consolidated security 
and routing device, thereby lowering operational and 
capital expenditures. 

Juniper Networks Unified Access 
control enforcement point

Interacts with the centralized policy management 
engine (Ic Series) to enforce session-specific access 
control policies using criteria such as user identity, 
device security state and network location. 

Improves security posture in a cost-effective 
manner by leveraging existing customer network 
infrastructure components and best-in-class 
technology.

Management flexibility

Use any one of three mechanisms, cLI, WebUI or Juniper 
Networks Network and Security Manager (NSM), to 
securely deploy, monitor and manage security policies.  

enables management access from any location, 
eliminating on-site visits thereby improving response 
time and reducing operational costs.

Auto-connect VPN

Automatically sets up and takes down VPN tunnels 
between spoke sites in a hub-and-spoke topology.

Provides a scalable VPN solution for mesh 
architectures with support for latency-sensitive 
applications such as VoIP and video conferencing.

World-class professional services

From simple lab testing to major network 
implementations, Juniper Networks Professional 
Services will collaborate with your team to identify 
goals, define the deployment process, create or validate 
the network design and manage the deployment.

Transforms the network infrastructure to ensure that 
it is secure, flexible, scalable and reliable.

*Bridge groups supported only on uPIMs in Juniper Networks ScreenOS

®

 Software 6.0 and higher releases.

Summary of Contents for SSG320M

Page 1: ...ork into distinct secure domains each with their own unique security policy Policies protecting each security zone can include access control rules and inspection by any of the supported UTM security features The SSG350M deployed at a branch office for secure Internet connectivity and site to site VPN to corporate headquarters Internal branch office resources are protected with unique security pol...

Page 2: ...nnually licensed IPS engine is available with Juniper Networks Deep Inspection Firewall Signature Packs Prevents application level attacks from flooding the network Fixed Interfaces Four fixed 10 100 1000 interfaces two USB ports one console port and one auxiliary port are standard on all SSG300 line models Provides high speed LAN connectivity future connectivity and flexible management Network se...

Page 3: ...ial ADSL2 G SHDSL 10 100 1000 and SFP SSG350M SSG320M Specifications SSG320M SSG350M Maximum Performance and Capacity 1 ScreenOS version tested ScreenOS 6 3 ScreenOS 6 3 Firewall performance Large packets 450 Mbps 550 Mbps Firewall performance IMIX 2 400 Mbps 500 Mbps Firewall Packets Per Second 64 byte 175 000 PPS 225 000 PPS AES256 SHA 1 VPN performance 175 Mbps 225 Mbps 3DES SHA 1 VPN performan...

Page 4: ... URL filtering 4 Yes Yes VoIP Security H 323 ALG Yes Yes SIP ALG Yes Yes MGCP ALG Yes Yes SCCP ALG Yes Yes NAT for VoIP protocols Yes Yes IPsec VPN Concurrent VPN tunnels 500 500 Tunnel interfaces 100 300 DES 56 bit 3DES 168 bit and AES 256 bit Yes Yes MD 5 and SHA 1 authentication Yes Yes Manual key IKE IKEv2 with EAP PKI X 509 Yes Yes Perfect forward secrecy DH Groups 1 2 5 1 2 5 Prevent replay ...

Page 5: ...ic routes 10 000 10 000 Source based routing Yes Yes Policy based routing Yes Yes ECMP Yes Yes Multicast Yes Yes Reverse Path Forwarding RPF Yes Yes IGMP v1 v2 Yes Yes IGMP Proxy Yes Yes PIM SM Yes Yes PIM SSM Yes Yes Multicast inside IPsec tunnel Yes Yes Encapsulations PPP Yes Yes MLPPP Yes Yes MLPP max physical interfaces 6 10 Frame Relay Yes Yes MLFR FRF 15 FRF 16 Yes Yes MLFR max physical inte...

Page 6: ...es Yes Device failure detection Yes Yes Link failure detection Yes Yes Authentication for new HA members Yes Yes Encryption of HA traffic Yes Yes System Management WebUI HTTP and HTTPS Yes Yes Command line interface console Yes Yes Command line interface telnet Yes Yes Command line interface SSH Yes v1 5 and v2 0 compatible Yes v1 5 and v2 0 compatible Network and Security Manager NSM Yes Yes All ...

Page 7: ...herwise noted Actual results may vary based on ScreenOS release and by deployment For a complete list of supported ScreenOS versions for SSG Series gateways please visit the Juniper Customer Support Center www juniper net customers support and click on ScreenOS Software Downloads 2 IMIX stands for Internet mix and is more demanding than a single packet size as it represents a traffic mix that is m...

Page 8: ... Line I O Options JX 2T1 RJ48 S 2 port T1 PIM with integrated CSU DSU JX 2E1 RJ48 S 2 port E1 PIM with integrated CSU DSU JX 2Serial S 2 port Synchronous Serial PIM JX 1ADSL A S 1 port ADSL 2 2 Annex A PIM JX 1ADSL B S 1 port ADSL 2 2 Annex B PIM JX 2SHDSL S 2 port 2 wire or 1 port 4 wire G SHDSL PIM JX 1BRI ST S 1 port ISDN BRI S T PIM JXU 6GE SFP S 6 port SFP Gigabit Ethernet Universal PIM2 JXU ...

Reviews: