Juniper SSG320M Datasheet Download Page 6

6

SSG320M

SSG350M

Address Translation

Network Address Translation (NAT)

yes

yes

Port Address Translation (PAT)

yes

yes

Policy-based NAT/PAT (L2 and L3 mode)

yes

yes

Mapped IP (L3 mode)

4,000

4,000

Virtual IP (L3 mode)

32

32

MIP/VIP Grouping (L3 mode)

yes

yes

IP Address Assignment

Static

yes

yes

dHcP, PPPoe client

yes

yes

Internal dHcP server

yes

yes

dHcP relay

yes

yes

Traffic Management Quality of Service (QoS) 

Guaranteed bandwidth

yes - per policy

yes - per policy

Maximum bandwidth

yes - per policy

yes - per policy

Ingress traffic policing 

yes

yes

Priority-bandwidth utilization

yes

yes

diffServ marking

yes - per policy

yes - per policy

High Availability (HA)

Active/Active - L3 mode

yes

yes

Active/Passive - Transparent & L3 mode

yes

yes

configuration synchronization

yes

yes

Session synchronization for firewall and VPN

yes

yes

VrrP

yes

yes

Session failover for routing change

yes

yes

device failure detection

yes

yes

Link failure detection

yes

yes

Authentication for new HA members

yes

yes

encryption of HA traffic

yes

yes

System Management

WebUI (HTTP and HTTPS)

yes

yes

command line interface (console)

yes

yes

command line interface (telnet)

yes

yes

command line interface (SSH)

yes v1.5 and v2.0 compatible

yes v1.5 and v2.0 compatible

Network and Security Manager (NSM)

yes

yes

All management via VPN tunnel on any interface

yes

yes

rapid deployment

No

No

Administration

Local administrator database size

20

20

external administrator database support

rAdIUS, rSA SecurId, LdAP

rAdIUS, rSA SecureId, LdAP

restricted administrative networks

50

50

root Admin, Admin and read Only user levels

yes

yes

Software upgrades

TFTP, WebUI, NSM, ScP, USB

TFTP, WebUI, NSM, ScP, USB

configuration rollback

yes

yes

Logging/Monitoring

Syslog (multiple servers)

yes - up to 4 servers

yes - up to 4 servers

email (two addresses)

yes

yes

NetIQ WebTrends

yes

yes

SNMP (v3)

yes

yes

SNMP full custom MIB

yes

yes

Traceroute

yes

yes

VPN tunnel monitor

yes

yes

Specifications 

(continued)

Summary of Contents for SSG320M

Page 1: ...ork into distinct secure domains each with their own unique security policy Policies protecting each security zone can include access control rules and inspection by any of the supported UTM security features The SSG350M deployed at a branch office for secure Internet connectivity and site to site VPN to corporate headquarters Internal branch office resources are protected with unique security pol...

Page 2: ...nnually licensed IPS engine is available with Juniper Networks Deep Inspection Firewall Signature Packs Prevents application level attacks from flooding the network Fixed Interfaces Four fixed 10 100 1000 interfaces two USB ports one console port and one auxiliary port are standard on all SSG300 line models Provides high speed LAN connectivity future connectivity and flexible management Network se...

Page 3: ...ial ADSL2 G SHDSL 10 100 1000 and SFP SSG350M SSG320M Specifications SSG320M SSG350M Maximum Performance and Capacity 1 ScreenOS version tested ScreenOS 6 3 ScreenOS 6 3 Firewall performance Large packets 450 Mbps 550 Mbps Firewall performance IMIX 2 400 Mbps 500 Mbps Firewall Packets Per Second 64 byte 175 000 PPS 225 000 PPS AES256 SHA 1 VPN performance 175 Mbps 225 Mbps 3DES SHA 1 VPN performan...

Page 4: ... URL filtering 4 Yes Yes VoIP Security H 323 ALG Yes Yes SIP ALG Yes Yes MGCP ALG Yes Yes SCCP ALG Yes Yes NAT for VoIP protocols Yes Yes IPsec VPN Concurrent VPN tunnels 500 500 Tunnel interfaces 100 300 DES 56 bit 3DES 168 bit and AES 256 bit Yes Yes MD 5 and SHA 1 authentication Yes Yes Manual key IKE IKEv2 with EAP PKI X 509 Yes Yes Perfect forward secrecy DH Groups 1 2 5 1 2 5 Prevent replay ...

Page 5: ...ic routes 10 000 10 000 Source based routing Yes Yes Policy based routing Yes Yes ECMP Yes Yes Multicast Yes Yes Reverse Path Forwarding RPF Yes Yes IGMP v1 v2 Yes Yes IGMP Proxy Yes Yes PIM SM Yes Yes PIM SSM Yes Yes Multicast inside IPsec tunnel Yes Yes Encapsulations PPP Yes Yes MLPPP Yes Yes MLPP max physical interfaces 6 10 Frame Relay Yes Yes MLFR FRF 15 FRF 16 Yes Yes MLFR max physical inte...

Page 6: ...es Yes Device failure detection Yes Yes Link failure detection Yes Yes Authentication for new HA members Yes Yes Encryption of HA traffic Yes Yes System Management WebUI HTTP and HTTPS Yes Yes Command line interface console Yes Yes Command line interface telnet Yes Yes Command line interface SSH Yes v1 5 and v2 0 compatible Yes v1 5 and v2 0 compatible Network and Security Manager NSM Yes Yes All ...

Page 7: ...herwise noted Actual results may vary based on ScreenOS release and by deployment For a complete list of supported ScreenOS versions for SSG Series gateways please visit the Juniper Customer Support Center www juniper net customers support and click on ScreenOS Software Downloads 2 IMIX stands for Internet mix and is more demanding than a single packet size as it represents a traffic mix that is m...

Page 8: ... Line I O Options JX 2T1 RJ48 S 2 port T1 PIM with integrated CSU DSU JX 2E1 RJ48 S 2 port E1 PIM with integrated CSU DSU JX 2Serial S 2 port Synchronous Serial PIM JX 1ADSL A S 1 port ADSL 2 2 Annex A PIM JX 1ADSL B S 1 port ADSL 2 2 Annex B PIM JX 2SHDSL S 2 port 2 wire or 1 port 4 wire G SHDSL PIM JX 1BRI ST S 1 port ISDN BRI S T PIM JXU 6GE SFP S 6 port SFP Gigabit Ethernet Universal PIM2 JXU ...

Reviews: