 |
 |  |
Features |  |  |
Range of supported values / options |  |
 |
 |  |
Processor |  |  |
133 MHz - 3.2 GHz |  |
 |
 |  |
RAM |  |  |
256MB - 1GB |  |
 |
 |  |
Interfaces |  |  |
3-8 Ethernet 10/100 base-T autosensing or 2 GB 1000Baset-T Ethernet, 2 Serial port RS-232 |  |
 |
 |  |
Firewall Performance |  |  |
600Mbps -1.6 Gbps |  |
 |
 |  |
Number of firewall users (nodes) |  |  |
Unlimited licence |  |
 |
 |  |
Concurrent connections |  |  |
Unlimited licence, only hardware specific limits |  |
 |
 |  |
3DES (168-bit) |  |  |
16-140 Mbps |  |
 |
 |  |
VPN tunnels |  |  |
> 5000 per unit |  |
 |
 |  |
Hard disk |  |  |
40GB - 120 GB, FlashMemory disk option |  |
 |
 |  |
Protocol support |  |  |
TCP/IP, UDP, ICMP, HTTP, IPSEC, IKE, SNMP, FTP, DHCP, PPPoE, others |  |
 |
 |  |
Antivirus filtering for http, smtp and ftp |  |  |
Yes. Plug in for Sophos, Kaspersky, McAfee, other FreeBSD demons |  |
 |
 |  |
URL filtering |  |  |
Yes |  |
 |
 |  |
DNS and mail server proxy |  |  |
Yes |  |
 |
 |  |
Intrusion detection and blocking system |  |  |
Yes. Built-in denial-of-service filters. Optional Snort IDS module. |  |
 |
 |  |
PowerSupply |  |  |
Single-Double |  |
 |
 |  |
Interface Expansion options |  |  |
up to 16 10/100Base-T or 3 1000Base-T support |  |
 |
 |  |
Encryption algorithms, autentication and certificates support |  |  |
DES, 3DES, AES, BLOWFISH, CIPE, CAST, MD5, SHA-1, RSA, X.509 version 3, PKCS #7, #10 and #12, , IKE, Kerberos |  |
 |
 |  |
Public key encryption key length for VPN and user authentication |  |  |
2046-16 384 bit (RSA). Government encryptions supported. |  |
 |
 |  |
Filtering rules |  |  |
Packet, stateful, application, router and bridge modes |  |
 |
 |  |
Operation system |  |  |
Secured OS version based on FreBSD v.4.7 |  |
 |
 |  |
Content filtering |  |  |
email content and attachment filtering, anti-spam filtering and third-party antivirus filtering integration support |  |
 |
 |  |
Administration |  |  |
WEB (over SSL), CLI over SSH, or console |  |
 |
 |  |
Centralized VPN and security network management |  |  |
Yes |  |
 |
 |  |
Configuration and security policy management |  |  |
Yes. Multiple configurations supported. |  |
 |
 |  |
Security policy |  |  |
Named groups for network addresses, protocols. Groups can be defined by users. Centralized security policy management. |  |
 |
 |  |
Backup/restore |  |  |
Configuration, Security policy and Full backup |  |
 |
 |  |
Secure remote update mode |  |  |
Updates security profiles after time delayed manual confirmation, or restores previous profile |  |
 |
 |  |
Logging |  |  |
Rotating per date logs for 1) Security, 2) Audit, 3) Traffic accounting, 4) Interface throughoutput and uptime, 5) Intrusion detection and blocking, 6) E-mail content filtering security events, 7) Antivirus, 8) Email proxy processor log, 9) http proxy URL filtering log |  |
 |
 |  |
VPN modes |  |  |
Transport or tunnel |  |
 |
 |  |
VPN compatibility |  |  |
IPSEC, IKE, supports third party X.509 certificates |  |
 |
 |  |
VLAN support |  |  |
Yes |  |
 |
 |  |
Antivirus compatibility |  |  |
All packages supporting FreeBSD OS. Tested with Sophos, McAfee, Kaspersky. |  |
 |
 |  |
Requirements for management terminal |  |  |
Network connection to management server and any web browser software supporting HTTPS protocol and X.509 certificates encription (MSIE 5.0, Netscape 4.x, Opera, Mozilla) |  |
 |
 |  |
Network address translation |  |  |
Static NAT, dynamic NAT and port translation (one-many and many-many) |  |
 |
 |  |
Selective VPN routing (traffic policy) |  |  |
protocol based, source and destination based |  |
 |
 |  |
Routing protocol support |  |  |
RIPv1/2, BGP, OSPF, VRRP |  |
 |
 |  |
Multiple administrators |  |  |
Yes |  |
 |
 |  |
Different access rights for node administration |  |  |
Per user, per node, read-only/update modes |  |
 |
 |  |
User based authentication |  |  |
Yes |  |
 |
 |  |
System status monitoring |  |  |
Disk, memory, interfaces, processes, free resources, shutdown/restart. |  |
 |
 |  |
Address discovery options |  |  |
DNS lookup, traceroute, ping, whois database records access, internal policy database |  |
 |
 |  |
Traffic accounting |  |  |
Per groups, per networks, per interfaces, between address pairs, chronological |  |
 |
 |  |
Reporting |  |  |
Reporting by date and groups
Security events monitoring
Traffic accounting summary
Email and antivirus summary
Email alerts |  |
 |
 |  |
Warranty |  |  |
1-3 years |  |
 |
 |  |
Environment |  |  |
Temperature 40-105 " F, 5-40" C, humidity 5-90% non-condensing |  |
 |
 |  |
Size |  |  |
19" Rack 2U |  |
 |