Juniper SSG320M Скачать руководство пользователя страница 5

5

SSG320M

SSG350M

PKI Support

PKI certificate requests (PKcS 7 and PKcS 10)

yes

yes

Automated certificate enrollment (SceP)

yes

yes

Online certificate Status Protocol (OcSP)

yes

yes

certificate Authorities supported

VeriSign, entrust, Microsoft, rSA Keon, iPlanet 

(Netscape) Baltimore, dod PKI

VeriSign, entrust, Microsoft, rSA Keon, iPlanet 

(Netscape) Baltimore, dod PKI

Self-signed certificates

yes

yes

Virtualization

Maximum number of security zones

40

40

Maximum number of virtual routers

8

8

Bridge groups*

yes

yes

Maximum number of VLANs 

125

125

Routing

BGP instances

BGP peers

36

48

BGP routes

10,000

10,000

OSPF instances

OSPF routes

10,000

10,000

rIP v1/v2 instances

128 

128 

rIP v2 routes

10,000

10,000

Static routes

10,000

10,000

Source-based routing

yes

yes

Policy-based routing

yes

yes

ecMP

yes

yes

Multicast

yes

yes

   reverse Path Forwarding (rPF)

yes

yes

   IGMP (v1, v2)

yes

yes

   IGMP Proxy

yes

yes

   PIM SM

yes

yes

   PIM SSM

yes

yes

   Multicast inside IPsec tunnel

yes

yes

Encapsulations

PPP

yes

yes

MLPPP

yes

yes

   MLPP max physical interfaces 

6

10

Frame relay

yes

yes

MLFr (FrF .15, FrF .16) 

yes

yes

   MLFr max physical interfaces 

6

10

HdLc

yes

yes

IPv6

dual stack IPv4/IPv6 firewall and VPN

yes

yes

IPv4 to/from IPv6 translations and encapsulations

yes

yes

Syn-cookie and Syn-Proxy doS Attack detection

yes

yes

SIP, rTSP, Sun-rPc, and MS-rPc ALG’s

yes

yes

rIPng

yes

yes

BGP

yes

yes

Transparent mode

yes

yes

NSrP

yes

yes

dHcPv6 relay

yes

yes

Mode of Operation

Layer 2 (transparent) mode

(5)

 

yes

yes

Layer 3 (route and/or NAT) mode 

yes

yes

Specifications 

(continued)

*Bridge groups supported only on uPIMs in ScreenOS 6.0 and higher releases.

Содержание SSG320M

Страница 1: ...ork into distinct secure domains each with their own unique security policy Policies protecting each security zone can include access control rules and inspection by any of the supported UTM security features The SSG350M deployed at a branch office for secure Internet connectivity and site to site VPN to corporate headquarters Internal branch office resources are protected with unique security pol...

Страница 2: ...nnually licensed IPS engine is available with Juniper Networks Deep Inspection Firewall Signature Packs Prevents application level attacks from flooding the network Fixed Interfaces Four fixed 10 100 1000 interfaces two USB ports one console port and one auxiliary port are standard on all SSG300 line models Provides high speed LAN connectivity future connectivity and flexible management Network se...

Страница 3: ...ial ADSL2 G SHDSL 10 100 1000 and SFP SSG350M SSG320M Specifications SSG320M SSG350M Maximum Performance and Capacity 1 ScreenOS version tested ScreenOS 6 3 ScreenOS 6 3 Firewall performance Large packets 450 Mbps 550 Mbps Firewall performance IMIX 2 400 Mbps 500 Mbps Firewall Packets Per Second 64 byte 175 000 PPS 225 000 PPS AES256 SHA 1 VPN performance 175 Mbps 225 Mbps 3DES SHA 1 VPN performan...

Страница 4: ... URL filtering 4 Yes Yes VoIP Security H 323 ALG Yes Yes SIP ALG Yes Yes MGCP ALG Yes Yes SCCP ALG Yes Yes NAT for VoIP protocols Yes Yes IPsec VPN Concurrent VPN tunnels 500 500 Tunnel interfaces 100 300 DES 56 bit 3DES 168 bit and AES 256 bit Yes Yes MD 5 and SHA 1 authentication Yes Yes Manual key IKE IKEv2 with EAP PKI X 509 Yes Yes Perfect forward secrecy DH Groups 1 2 5 1 2 5 Prevent replay ...

Страница 5: ...ic routes 10 000 10 000 Source based routing Yes Yes Policy based routing Yes Yes ECMP Yes Yes Multicast Yes Yes Reverse Path Forwarding RPF Yes Yes IGMP v1 v2 Yes Yes IGMP Proxy Yes Yes PIM SM Yes Yes PIM SSM Yes Yes Multicast inside IPsec tunnel Yes Yes Encapsulations PPP Yes Yes MLPPP Yes Yes MLPP max physical interfaces 6 10 Frame Relay Yes Yes MLFR FRF 15 FRF 16 Yes Yes MLFR max physical inte...

Страница 6: ...es Yes Device failure detection Yes Yes Link failure detection Yes Yes Authentication for new HA members Yes Yes Encryption of HA traffic Yes Yes System Management WebUI HTTP and HTTPS Yes Yes Command line interface console Yes Yes Command line interface telnet Yes Yes Command line interface SSH Yes v1 5 and v2 0 compatible Yes v1 5 and v2 0 compatible Network and Security Manager NSM Yes Yes All ...

Страница 7: ...herwise noted Actual results may vary based on ScreenOS release and by deployment For a complete list of supported ScreenOS versions for SSG Series gateways please visit the Juniper Customer Support Center www juniper net customers support and click on ScreenOS Software Downloads 2 IMIX stands for Internet mix and is more demanding than a single packet size as it represents a traffic mix that is m...

Страница 8: ... Line I O Options JX 2T1 RJ48 S 2 port T1 PIM with integrated CSU DSU JX 2E1 RJ48 S 2 port E1 PIM with integrated CSU DSU JX 2Serial S 2 port Synchronous Serial PIM JX 1ADSL A S 1 port ADSL 2 2 Annex A PIM JX 1ADSL B S 1 port ADSL 2 2 Annex B PIM JX 2SHDSL S 2 port 2 wire or 1 port 4 wire G SHDSL PIM JX 1BRI ST S 1 port ISDN BRI S T PIM JXU 6GE SFP S 6 port SFP Gigabit Ethernet Universal PIM2 JXU ...

Отзывы: