1-1
1
Firewall Overview
Introduction
The H3C SecPath F5000-A5 firewall (hereinafter referred to as the F5000-A5) is a high-end core
firewall product developed by Hangzhou H3C Technologies Co., Ltd. (hereinafter referred to as H3C) to
deliver extremely high-performance security solutions for large-sized enterprises, carriers and data
center networks.
The F5000-A5 delivers the following features based on its powerful multi-core processor and
FPGA-based hardware acceleration technologies:
z
Adopts dual-power input, passive backplane, switch architecture, and distributed modular
architecture.
z
Separates the control plane from the data plane: At the control plane, a powerful multi-core
processor is used for service scheduling and application identification. At the data plane, a
dedicated field programmable gate array (FPGA) is used for rapid forwarding of data streams.
Moreover, additional service cards can be used to expand the process capability at the data plane.
z
In addition to traditional firewall functions, the F5000-A5 supports virtual firewall, attack defense,
and content filtering, thus delivering more effective network protection.
z
Uses the application specific packet filter (ASPF) status detection technology to monitor
connection processes, detect illegal operations, and implement dynamic packet filtering with ACLs.
z
Supports server load balancing and link load balancing functions.
z
Supports high-performance virtual private network (VPN) services, such as IPSec VPN, GRE, and
L2TP.
z
Provides abundant routing capabilities and supports multiple routing protocols including Routing
Information Protocol (RIP), Open Shortest Path First (OSPF), and Border Gateway Protocol
(BGP).
z
Supports Web-based configuration and management.
z
Collects and conducts statistics of audit information such as NAT and security events through
H3C’s audit systems (e.g. SecCenter, Xlog, and QuidView).
z
Conforms to both international and national standards to ensure interoperability with products of
different manufacturers at every layer.