Juniper SSG320M Скачать руководство пользователя страница 4

4

SSG320M

SSG350M

Firewall

Network attack detection

yes

yes

doS and ddoS protection

yes

yes

TcP reassembly for fragmented packet protection

yes

yes

Brute force attack mitigation

yes

yes

SyN cookie protection

yes

yes

Zone-based IP spoofing

yes

yes

Malformed packet protection

yes

yes

Unified Threat Management

(3)

IPS (deep Inspection firewall)

yes

yes

   Protocol anomaly detection

yes

yes

   Stateful protocol signatures

yes

yes

   IPS/dI attack pattern obfuscation

yes

yes

Antivirus

yes

yes

   Signature database

200,000+

200,000+

   Protocols scanned

POP3, HTTP, SMTP, IMAP, FTP, IM

POP3, HTTP, SMTP, IMAP, FTP, IM

   Antispyware

yes

yes

   Antiadware

yes

yes

   Anti-keylogger

yes

yes

   Instant message AV

yes

yes

Antispam

yes

yes

Integrated UrL filtering

yes

yes

external UrL filtering

(4)

yes

yes

VoIP Security 

H.323 ALG 

yes

yes

SIP ALG 

yes

yes

MGcP ALG

yes

yes

SccP ALG

yes

yes

NAT for VoIP protocols 

yes

yes

IPsec VPN

concurrent VPN tunnels

500

500

Tunnel interfaces

100

300

deS (56-bit), 3deS (168-bit) and AeS (256-bit)

yes

yes

Md-5 and SHA-1 authentication

yes

yes

Manual key, IKe, IKev2 with eAP, PKI (X.509)

yes

yes

Perfect forward secrecy (dH Groups)

1,2,5

1,2,5

Prevent replay attack 

yes

yes

remote access VPN

yes

yes

L2TP within IPsec

yes

yes

IPsec NAT traversal

yes

yes

Auto-connect VPN

yes

yes

redundant VPN gateways

yes

yes

User Authentication and Access Control

Built-in (internal) database - user limit

500

500

Third-party user authentication

rAdIUS, rSA SecureId, LdAP

rAdIUS, rSA SecureId, LdAP

rAdIUS Accounting

yes – start/stop

yes – start/stop

XAUTH VPN authentication

yes

yes

Web-based authentication

yes

yes

802.1X authentication

yes

yes

Unified Access control enforcement point

yes

yes

Specifications 

(continued)

Содержание SSG320M

Страница 1: ...ork into distinct secure domains each with their own unique security policy Policies protecting each security zone can include access control rules and inspection by any of the supported UTM security features The SSG350M deployed at a branch office for secure Internet connectivity and site to site VPN to corporate headquarters Internal branch office resources are protected with unique security pol...

Страница 2: ...nnually licensed IPS engine is available with Juniper Networks Deep Inspection Firewall Signature Packs Prevents application level attacks from flooding the network Fixed Interfaces Four fixed 10 100 1000 interfaces two USB ports one console port and one auxiliary port are standard on all SSG300 line models Provides high speed LAN connectivity future connectivity and flexible management Network se...

Страница 3: ...ial ADSL2 G SHDSL 10 100 1000 and SFP SSG350M SSG320M Specifications SSG320M SSG350M Maximum Performance and Capacity 1 ScreenOS version tested ScreenOS 6 3 ScreenOS 6 3 Firewall performance Large packets 450 Mbps 550 Mbps Firewall performance IMIX 2 400 Mbps 500 Mbps Firewall Packets Per Second 64 byte 175 000 PPS 225 000 PPS AES256 SHA 1 VPN performance 175 Mbps 225 Mbps 3DES SHA 1 VPN performan...

Страница 4: ... URL filtering 4 Yes Yes VoIP Security H 323 ALG Yes Yes SIP ALG Yes Yes MGCP ALG Yes Yes SCCP ALG Yes Yes NAT for VoIP protocols Yes Yes IPsec VPN Concurrent VPN tunnels 500 500 Tunnel interfaces 100 300 DES 56 bit 3DES 168 bit and AES 256 bit Yes Yes MD 5 and SHA 1 authentication Yes Yes Manual key IKE IKEv2 with EAP PKI X 509 Yes Yes Perfect forward secrecy DH Groups 1 2 5 1 2 5 Prevent replay ...

Страница 5: ...ic routes 10 000 10 000 Source based routing Yes Yes Policy based routing Yes Yes ECMP Yes Yes Multicast Yes Yes Reverse Path Forwarding RPF Yes Yes IGMP v1 v2 Yes Yes IGMP Proxy Yes Yes PIM SM Yes Yes PIM SSM Yes Yes Multicast inside IPsec tunnel Yes Yes Encapsulations PPP Yes Yes MLPPP Yes Yes MLPP max physical interfaces 6 10 Frame Relay Yes Yes MLFR FRF 15 FRF 16 Yes Yes MLFR max physical inte...

Страница 6: ...es Yes Device failure detection Yes Yes Link failure detection Yes Yes Authentication for new HA members Yes Yes Encryption of HA traffic Yes Yes System Management WebUI HTTP and HTTPS Yes Yes Command line interface console Yes Yes Command line interface telnet Yes Yes Command line interface SSH Yes v1 5 and v2 0 compatible Yes v1 5 and v2 0 compatible Network and Security Manager NSM Yes Yes All ...

Страница 7: ...herwise noted Actual results may vary based on ScreenOS release and by deployment For a complete list of supported ScreenOS versions for SSG Series gateways please visit the Juniper Customer Support Center www juniper net customers support and click on ScreenOS Software Downloads 2 IMIX stands for Internet mix and is more demanding than a single packet size as it represents a traffic mix that is m...

Страница 8: ... Line I O Options JX 2T1 RJ48 S 2 port T1 PIM with integrated CSU DSU JX 2E1 RJ48 S 2 port E1 PIM with integrated CSU DSU JX 2Serial S 2 port Synchronous Serial PIM JX 1ADSL A S 1 port ADSL 2 2 Annex A PIM JX 1ADSL B S 1 port ADSL 2 2 Annex B PIM JX 2SHDSL S 2 port 2 wire or 1 port 4 wire G SHDSL PIM JX 1BRI ST S 1 port ISDN BRI S T PIM JXU 6GE SFP S 6 port SFP Gigabit Ethernet Universal PIM2 JXU ...

Отзывы: