Content. Initial Contact. Further Follow-Up. Bidding Guidance

Size: px
Start display at page:

Download "Content. Initial Contact. Further Follow-Up. Bidding Guidance"

Transcription

1 USG5500 How to Beat

2 Content Initial Contact Further Follow-Up Bidding Guidance 1

3 Multi-Service Security Gateway USG5500 USG5560 USG5550 USG5530 USG5530S USG5520S 2 Key selling points: Comprehensive unified treat management (UTM) features Anti-virus (AV), intrusion protection system (IPS), anti-spam (AS), and URL filtering Various VPN access modes Layer 2 Tunneling Protocol (L2TP) VPN, Generic Routing Encapsulation (GRE) VPN, Multiprotocol Label Switching (MPLS) L3 VPN IP Security (IPSec) VPN, and Secure Sockets Layer (SSL) VPN IPv6 routing and security 10GE interface expansion Highest performance A maximum of 32 Gbit/s throughput A maximum of 200,000 new connections per second A maximum of 4,000,000 concurrent connections A maximum of 7 Gbit/s IPSec VPN processing capability Maximum interface density 14 x 10GE+64 x GE

4 Full Protection Solution Internal threats USG5500 External threats Illegitimate and phishing websites Network behavior management IM and P2P Viruses, Trojan horses, and spyware Viruses and Trojan horses Worms, viruses, and attacks Worms and viruses Network attacks and DoS attacks Router/VPN Network attacks and DoS attacks Network interconnection 3

5 Product Positioning Regions and Languages Regions: China, Europe, Middle East, Africa, South America, North America, and Russia Languages: Chinese and English Price China: RMB 30,000 to 180,000 Outside China: USD 5,000 to 30,000 Performance Application Scope Firewall performance: 10 Gbit/s to 40 Gbit/s Target Market China Outside China Vertical Large and Medium-sized Enterprise Other Mid-Market Enterprise Large Enterprise Telecommunications, government, finance, and energy industries Large enterprises, education, and broadcast and TV industries Internet data center (IDC)

6 Target Market Purchase Drive Analysis Drive Government Finance Energy Education 5 Public Services and Facilities Large and Medium- Sized Enterprise Compliance Low TCO Virus External network attack Spam Intrusion protection Security zone division VPN interconnection Summary: The government sector, financial industry, and energy enterprise pay much attention to the compliance. The government compliance requirements indicate the class-based protection and cascade protection. The finance or energy compliance requirements indicate the classbased protection, Sarbanes-Oxley act, or industry specifications (for example, State Electricity Regulatory Commission Order 5 for the electricity industry). The basic requirements of each industry are external attack protection and security zone division. Government, public services and facilities, and large and medium-sized enterprises place high requirements on VPN interconnection. Enterprise customers require lower TCO. SMB

7 Product Selection Factor Analysis Drive Government Finance Energy Education Public Services and Facilities Large and Medium- Sized Enterprise SMB Compliance Price Reliability Availability Integrated management Usability Anti-DDoS capability UTM Performance QoS Virtualization Energy saving and environment protection (power consumption) 10GE uplink interface Summary: The government sector, financial industry, and energy enterprise pay much attention to the compliance. The government sector, public services and facilities, education industry, and SMB customers are more sensitive to the price. The financial and energy industries place high requirements on device reliability. Product usability is an important factor in all industries. The financial industry and large and medium-sized enterprises place high requirements on device performance. 6

8 Vendor Selection Factor Analysis Drive Government Finance Energy Education Public Services and Facilities Large and Medium-Sized Enterprise Compliance Chinese brand International brand SMB Timely threaten and vulnerability update After-sales service Price Financial status Purchased brand Series Technology advantage Summary: The government sector, financial industry, and energy enterprise pay much attention to the compliance. The government sector, public services and facilities, and energy industry prefer Chinese brand because of the admittance mechanism. The financial industry, energy enterprise, and large and medium-sized enterprise pay much attention to the after-sale services and tend to purchase device from the same vendor. 7

9 Competition Analysis Regarding Counterparts Top N vendors Juniper Cisco Fortinet Checkpoint Government Finance Education Energy Enterprise Outside China 8

10 Map of USG5500 and Rival Products SRX5800* Products with * provide 10GE interfaces. 20 Gbit/s USG9500 SRX5600* SRX3600* ASA * FG3040B* Power11085* Power11075* FG1240B USG5560 P11065* 15 Gbit/s SRX3400* ASA * Power9075* USG5550 FG1000C IP1285* 12Gbps SRX1400* FG800C USG5530 USG5530S ASA * FG600C P5075* IP695* 8 Gbit/s USG5520S SRX650 ISG2000 ASA * ASA5555-X FG300C IP565 UTM Juniper Cisco Fortinet CheckPoint 9

11 Advantages Powerful and reliable UTM Advanced Symantec IPS and AV engines and industry-leading detection ratio Various mail and URL filtering functions UTM virtualization and independent security protection policies configured for each virtual firewall Complete Service awareness Identification of application protocols Massive security policies and large-capacity data center Isolation between multiple security zones Large-capacity NAT (large-capacity NAT sessions and unlimited times of NAT) Egress of campus network, large-scale campus network, metropolitan area network (MAN) of the broadcast and TV network, and the Internet IPv6 Institutions of higher learning, large-scale scientific research institution, test network, and telecom carriers 10

12 Product Highlights (Based on Product Selection Factors) IPS: AV: UTM The IPS is developed using the core engine technology developed by Symantec. Symantec has developed more than 8000 IPS features. The IPS provides security protection based on vulnerabilities in operating systems. The IPS can detect the redirection during data download from malicious websites. The IPS supports pseudo application program detection, script-based system detection, spyware detection, and advertisement software detection. The IPS also supports the analysis of application protocol resolution. The AV is developed using the core engine technology developed by Symantec. Symantec AV provides more than 7,000,000 virus feature libraries. In 2009, Symantec IPS and AV engines detected more than 3 billion attacks. Symantec AV engine has detected more than 73 billion new malicious software. The AV supports the following technologies: application independence scanning, detection mode independence, platform independence, deployment position independence, local language independence, engine version independence, and multi-thread scanning. Application protocol analysis: Huawei has the industry-leading protocol analysis teams and has accumulated rich experience in Service awareness, URL, and IP credit library. The USG5500 series can identify network protocols, support 65 million URL feature libraries, and monitor 9 million domain names in real time. Usability Zero configurations of IPS and AV engines (automatic identification technology) IPv6 The USG5500 series lead the industry in supporting IPv6. The USG5500 series have obtained the gold certificate for IPv6 ready evaluation and support all mainstream evolution schemes towards IPv6. High density and various interfaces The USG5500 series support 10GE interfaces and support a maximum of 64 x GE+12 x 10GE interfaces. 11

13 Content Initial Contact Further Follow-Up Bidding Guidance 12

14 Juniper Product Specifications Product Model SRX650 SRX1400 SRX3400 Price 80% discount for China market 50% discount for international market RMB 70,000 (China) USD 8000 (outside China) Unknown RMB 460,000 (20 Gbit/s processing capacity and single NTC/STC per SPC for China market) USD 47,000 (20 Gbit/s processing capacity and single NTC/STC per SPC for the international market) Product throughput (bit/s) 7 Gbit/s 10 Gbit/s 20 Gbit/s (maximum) New connections per second 30,000 45, ,000 Number of concurrent connections 512, ,000 3,000,000 Fixed interface 4 x GE 6 x GE+4 x SFP (GE system) 3 x FP+6 x GE+1 x SFP (XGE system) 6 x GE+4 x FP 10GE interface Supported Supported Supported Maximum number of interfaces 48 x GE 8 x 10GE Power supply Dual power supplies in the standard configuration Dual power supplies in the standard configuration Dual power supplies in the standard configuration VPN throughput 1.5 Gbit/s 2 Gbit/s 6 Gbit/s Number of VPN tunnels 3000 Unknown 10,000 IPS throughput 900 Mbit/s 2 Gbit/s 6 Gbit/s AV throughput 350 Mbit/s Not supported Not supported SSL VPN Not supported Not supported Not supported IPv6 Supported Supported Supported URL filtering Supported Not supported Not supported AS Supported Not supported Not supported Application security Not supported Supported Supported Virtual firewall Supported Supported Supported User-based policy integration 13 Not supported Not supported Not supported

15 How to Beat Juniper From the Vendor Dimension General Beating Methods Beating point - low performance: Juniper SRX series are weak in the following aspects: small-sized packets of the firewall, number of new connections established per second, and number of supported VPN tunnels. Beating point - high power consumption: The power consumption of Juniper SRX series is high (the power consumption of the SRX650 reaches 650 W). Beating point - poor serialization: The serialization of Juniper SRX series is poor. Juniper provides only two products at the GE level. Beating point - loose-coupling user: The security policies used by Juniper SRX series are IP-based and are not closely associated with users. Juniper SRX series do not support user-based QoS, routing, and firewall policies. Beating point - only SRXs later than 1400 support the application-based management control: Juniper SRX series support 700+ applications while Huawei USG5500 series support applications. Beating point - Juniper SRX series do not support the SSL VPN: Juniper SRX series do not support the SSL VPN and the SSL VPN deployment requires dedicated VPN devices. Beating point - SRXs later than 1400 do not support certain functions: SRXs later than 1400 do not support the AV, AS, and URL filtering. Beating point - Juniper SRX series support less URL filtering addresses: Juniper SRX series supports only 26 million addresses in the address library while Huawei USG5500 series support 65 million addresses in the address library. General Defending Methods Defending point - Layer-2 links, QoS, virtualization, and routing: Juniper SRX series inherit the software advantages of NetScreen and MX routers and have a clear lead in Layer-2 links, QoS, virtualization, and routing. Lead the customers to focus on simple security deployment. Defending point - Layer-2 links, QoS, virtualization, and routing: Accumulated experience in data communications and NetScreen security make Juniper become an industry-leading company in network technology and security technology fields. Emphasize that the security product line (SRX) and Ethernet switch (EX), and routers are mainstream products of Juniper. 14 Product Selection Factor-Based Beating Points Industry-Based Beating Points Government Finance Energy Education General beating points Specific beating points - compliance: International brands cannot be used in government industry in China. Genera l beatin g points General beating points Specific beating point - usability: The GUI language is English, which Public Services and Facilities Use the standard dimensional high. decreases the terms to usability. describe Specific beating point - after-sales service: The aftersales services of Juniper devices are provided by agents. Compared with direct after-sales services provided by vendors, the service quality cannot be ensured. Enterprise General beating points Specific beating point - price: The price is Specific beating point - usability: The GUI language is English, which decreases the usability. Specific beating point - after-sales service: The after-sales services of Juniper devices are provided by agents. Compared with direct after-sales services provided by vendors, the service quality cannot be ensured. Industry-Based Defending Points Finance Energy Education Public Services and Facilities Product Selection Factor-Based Defending Points General defending points Specific defending point - Good data communications technology: Juniper is good at data communications field. Lead the customers to focus on security features. Enterprise General defending points Specific defending point - deployed Juniper products: Juniper switching routes are widely used on enterprise networks. Lead the customers to focus on Juniper security products.

16 How to Beat Juniper From the Product Dimension 20 Gbit/s USG9500 SRX3600* 1. The SRX3600 and SRX3400 are developed on the 3000 platform. The SRX3600 supports a maximum of three NPCs and seven SPCs. The minimum product performance is 10 Gbit/s and the maximum product performance is 30 Gbit/s. 2. The standard configuration of the SRX3600 is 8GE and 4SFP. The SRX3600 supports 16GE, 16SFP, and 2x10G plug-in cards and a maximum of seven interface slots support the IPS. 3. For 20 Gbit/s applications, the sale price is RMB 640,000 in China and USD 36,000 in international market; For 30 Gbit/s applications, the sale price is RMB 860,000 in China and USD 48,000 in international market; 4. It is recommended that Huawei USG9500 be used to compete with the SRX Gbit/s USG5560 SRX3400* 1. The SRX3400 is a distributed product with high cost-effective. The SRX3400 supports a maximum of two NPCs and four SPCs. The minimum product performance is 10 Gbit/s and the maximum product performance is 20 Gbit/s. 2. The standard configuration of the SRX3400 is 8GE and 4SFP. The SRX3400 supports 16GE, 16SFP, and 2x10G plug-in cards and a maximum of four interface slots support the IPS. 3. For 20 Gbit/s applications, the sale price is RMB 570,000 in China and USD 41,000 in international market; For 10 Gbit/s applications, the sale price is RMB 350,000 in China and USD 25,000 in international market; 4. Huawei USG5560 is an integrated device and has great price advantages. The interface performance of the USG5560 is at the same level with the SRX3400 while the USG5560 supports more UTM features than the SRX3400. USG Juniper does not provide specific products at this level. At present, the SRX1400 and SRX3400 can be used at this level. 2. Huawei products have great advantages in interface density, performance, and price. 12 Gbit/s USG5530 USG5530S SRX1400* 1. The SRX1400 was launched at the end of 2010 and is used to serve data centers. The announced performance is 10 Gbit/s and the SRX1400 supports two types of GE and XGE bundle packages. The SRX1400 supports the IPS. 2. The GE bundle package includes 6xGE and 4xSFP and the XGE bundle package includes 6xGE, 1xSFP, and 3x10G. At present, the price information about the SRX1400 is not available. 3. Huawei USG5530S can be used to compete with the SRX1400. The USG5530S has great advantages in price, interfaces, and firewall performance. At present, the price information about the SRX1400 is limited. 8 Gbit/s USG5520S SRX650 ISG The SRX650 is an oldest product of the SRX series. The announced performance is 7 Gbit/s. In standard configurations, the SRX650 provides 4xGE electrical interfaces and eight extension slots. The SRX650 supports POE, SFP, T1, and E1 and the full range of UTM features. 2. The ISG2000 is an oldest firewall product. The announced performance is 4 Gbit/s. The ISG2000 provides a maximum of 8xGE, 28xFE, or 4xFP interfaces. The ISG2000 supports the IPS. 3. The sale price of the SRX650 is RMB XXX in China and USD 8000 in international markets. The sale price of the ISG2000 is RMB XXX in China and USD XXX in international markets. 15

17 Cisco Product Specifications Product Model ASA 5585-SSP10 ASA 5585-SSP20 ASA 5585-SSP40 Price 70% discount for China market 50% discount for international market USD 15,000 (outside China) USD 30,000 (outside China) USD 70,000 (outside China) Product throughput (bit/s) 4 Gbit/s 10 Gbit/s 20 Gbit/s New connections per second 50, , ,000 Number of concurrent connections 750,000 1 million 2 million Fixed interface 8xGE+2xFP 8xGE+2xFP 6xGE+4xFP 10GE interface Supported Supported Supported Maximum number of interfaces Power supply 16xGE+4xFP (SSP+IPS SSP) Single power supply in the standard configuration 16xGE+4xFP (SSP+IPS SSP) Single power supply in the standard configuration 12xGE+8xFP (SSP+IPS SSP) Single power supply in the standard configuration Number of VPN tunnels SSL VPN Supported Supported Supported IPv6 Supported Supported Supported IPS Supported Supported Supported AV Not supported Not supported Not supported URL filtering Not supported Not supported Not supported AS Not supported Not supported Not supported Virtual firewall Supported Supported Supported 16

18 How to Beat Cisco From the Vendor Dimension General Beating Methods Beating point - low performance: Cisco ASA series have low performance in terms of firewall throughput, VPN performance, new connections, and concurrent connections. Beating point - less UTM features: Cisco ASA series support only the IPS. Other UTM features are supported by deploying extension boards. Beating point - poor scalability: Cisco ASA series provide only two slots and the scalability is poor. The extension boards can only be firewall boards, IPS boards and CSC boards. Beating point - high price: The price of Cisco ASA series is high. Industry-Based Beating Points Government Finance Energy Education Beating points based on product or vendor selection factors General beating points Specific beating points - compliance: International brands cannot be used in government industry in China. General beating points General beating points Specific beating point - usability: The GUI language Public Services and Facilities Use the standard dimensional terms to describe is English, which decreases the usability. Specific beating point - after-sales service: Similar to Juniper, the after-sales service provided by Cisco in China is poor. The customers are not satisfied with the after-sales service. Enterprise General beating points Specific beating point - price: The price is high. Specific beating point - usability: The GUI language is English, which decreases the usability. Specific beating point - after-sales service: Similar to Juniper, the after-sales service provided by Cisco in China is poor. The customers are not satisfied with the after-sales service. Industry-Based Defending Points General Defending Methods Public Services Energy Education Finance Enterprise and Facilities Defending points based on product or vendor selection factors Defending point - high stability: Cisco products are well known as good stability. Lead the customers to focus on the performance. Defending point - strong data communications capability: Cisco ASA series inherit the data communications features of the IOS system. Lead the customers to focus on security features. Defending point - high IPS performance: Cisco ASA series support the IPS with extension boards and support high IPS performance. Lead the customers to focus on the threaten detection rate. Defending point - industry-leading brand: Cisco leads the industry in the switching route field and has a good brand effect. 17 General defending points General defending points Specific defending point - deployed Cisco products: Cisco switching routes are widely used on enterprise networks. Lead the customers to focus on Cisco security products.

19 20 Gbit/s How to Beat Cisco From the Product Dimension USG9500 ASA * 1. The promotional performance of the ASA is 35 Gbit/s. The number of concurrent connections is 2 million. In firewall mode, the ASA supports 6xGE+4x10G. In IPS mode, the specifications are twice higher than those in firewall mode. 2. The sale price of bare equipment is about RMB 500,000 in China and USD 113,000 in international markets. Huawei 9300 can be used to compete with the ASA Huawei USG5560 can be used to compete with the ASA The USG5560 has great advantages in price, interfaces, and UTM. USG5560 ASA * 1. The promotional performance of the ASA is 20 Gbit/s. The number of concurrent connections is 2 million. In firewall mode, the ASA supports 6xGE+4x10G. In IPS mode, the specifications are twice higher than those in firewall mode. 2. Huawei USG5560The sale price of bare equipment is about RMB 308,000 in China and USD 70,000 in international markets. 3. can be used to compete with the ASA The USG5560 has great advantages in price, interfaces, and UTM. 15 Gbit/s USG5550 Cisco does not subdivide products at this level and may use the ASA or ASA at this level. Compared with the ASA , Huawei USG5550 has great advantages in price. 12 Gbit/s USG5530 USG5530S ASA * 1. The promotional performance of the ASA is 10 Gbit/s. The number of concurrent connections is 1 million. In firewall mode, the ASA supports 8xGE+2x10G. In IPS mode, the specifications are twice higher than those in firewall mode. 2. The sale price of bare equipment is about RMB 130,000 in China and USD 30,000 in international markets. 3. Huawei USG5530/USG5530S can be used to compete with the ASA The USG5530/USG5530S has great advantages in price, interfaces, and UTM. 8 Gbit/s USG5520S ASA * ASA5555-X 1. The promotional performance of the ASA is 4 Gbit/s. The number of concurrent connections is 750,000. In firewall mode, the ASA supports 8xGE+2x10G. In IPS mode, the specifications are twice higher than those in firewall mode. 2. The sale price of bare equipment is about RMB 63,000 in China and USD 15,000 in international markets. 3. Huawei USG5520S can be used to compete with the ASA The USG5520S has great advantages in price, interfaces, and UTM. 18

20 Fortinet Product Specifications Product Model 300C 600C 800C 1000C 1240B 3040B Price 89% to 86% discount (China) 45% discount of the transaction price (outside China) (outside China) (outside China) (outside China) (outside China) 26958(outside China) (outside China) Product throughput (bit/s) 8 Gbit/s 16 Gbit/s 20 Gbit/s 20 Gbit/s 40 Gbit/s 40 Gbit/s New connections per second 50,000 70, , , , ,000 Number of concurrent connections 2 million 3 million 7 million 7 million 5 million 10 million Fixed interface 10xGE 18x GE,4x Shared Port Pairs, 2x Bypass Pairs 14x GE,8x Shared Port Pairs, 2x Bypass Pairs 14x GE,8x Shared Port Pairs, 2x Bypass Pairs 16x GE, 24x GE SFP 2x GE RJ45, 10x GE SFP 10GE interface Not supported Not supported 2x 10GE SFP+ 2x 10GE SFP+ Not supported 8x 10GE SFP+ Maximum number of interfaces The interface cannot be expanded. The interface cannot be expanded. The interface cannot be expanded. The interface cannot be expanded. The interface cannot be expanded. The interface cannot be expanded. Power supply Single power supply in the standard configuration Single power supply in the standard configuration 19 Single power supply in the standard configuration Dual power supplies in the standard configuration Dual power supplies in the standard configuration Dual power supplies in the standard configuration IPsec throughput 4.5Gbit/s 8 Gbit/s 8 Gbit/s 8 Gbit/s 16~18.5 Gbit/s 17 Gbit/s SSL VPN throughput 200 Mbit/s 1 Gbit/s 1.3 Gbit/s 1.3 Gbit/s 370 Mbit/s 500 Mbit/s SSL user IPS performance 1.4Gbit/s 4 Gbit/s 6 Gbit/s 6 Gbit/s 5~8 Gbit/s 6 Gbit/s AV (flow or proxy) 550 Mbit/s or 200 Mbit/s 2.8 Gbit/s or 1.3 Gbit/s 3.1 Gbit/s or 1.7 Gbit/s 3.1 Gbit/s or 1.7 Gbit/s 1.6 Gbit/s or 1.2Gbit/s 4.5 Gbit/s or 2.3 Gbit/s URL filtering Supported Supported Supported Supported Supported Supported AS Supported Supported Supported Supported Supported Supported Virtual firewall /250 10/250 10/250

21 How to Beat Fortinet From the Vendor Dimension General Beating Methods Beating point - pseudo performance: The performance of FortiGate ASIC is high. However, for inter-asic data stream forwarding (for example, communications between ETH1 and ETH5), the performance of FortiGate ASIC greatly deteriorates due to the bandwidth limit of the x86 bus. Beating point - poor data communications performance: FortiGate products do not have good performance in data communications field. For example, FortiGate products do not support the STP, NATPT, ISIS, and GRE. Beating point - low coupling with users: FortiGate products support application-based firewall security policies instead of user-based security policies. Beating point - poor after-sales service: The after-sales services of Fortinet devices are provided by agents. Compared with direct aftersales services provided by vendors, the service quality cannot be ensured. General Defending Methods Defending point - usability: FortiGate products have high usability and the Web UI is simple. However, the CLI configuration is complex and out of order. Lead the customers to focus on disadvantages of the CLI. Defending point - rich features: By default, the firewall, VPN (IPsec or SSL), WAN optimization, DLP, and Service awareness functions are enabled on the FortiGate products. Lead the customers to focus on other functions such as the AV, AS, IPS, URL, and virtual firewall. Defending point - product serialization: FortiGate product series cover 100 Mbit/s and 10GE levels. Lead the customers to focus on the requirement compliance of single product. 20 Industry-Based Beating Points Government Education Finance Energy Beating points based on product or vendor selection factors General beating points Specific beating points - compliance: International brands cannot be used in government industry in China. General beating points Specific beating points - less new connections: Fortinet UTM products use the x86 architecture. The new connection capability of the CPU is low, which cannot satisfy the requirements for complex traffic and a large number of new connections on the campus network. General beating points Public Services and Facilities Enterprise Specific beating points - reliability: Fortinet UTM products use the x86+fpga architecture. The stability and reliability of the x86 architecture are lower than those of products that use dedicated multi-core network processors. Specific beating points - less new connections: Fortinet UTM products use the x86 architecture. The new connection capability of the CPU is low. Beating point - poor after-sales service: The after-sales services of Fortinet devices are provided by agents. Compared with direct after-sales services provided by vendors, the service quality cannot be ensured. Industry-Based Defending Points Finance Energy Education Defending points based on product or vendor selection factors General defending points Specific defending point - high performance: The UTM devices that use ASIC acceleration scheme work with a high performance in the test environment. Lead the customer to focus on other beating points. Public Services and Facilities Enterprise General defending points Specific defending point - UTM features: The UTM products support various features such as the AV, IPS, AS, URL filtering, Service awareness, and DLP. Lead the customers to focus on the AV, IPS, and URL filtering. Specific defending point - advanced UTM technology: FortiGate develops the UTM technology and provides various UTM features. Customers have deep impressions on the advanced UTM technology provided by FortiGate. Lead the customers to focus on the threaten detection rate.

22 How to Beat Fortinet From the Product Dimension 40 Gbit/s FG3040B* 1. The FG3040B is a new product launched in The promotional performance is 40 Gbit/s. The number of new connections is 100,000. In standard configuration, the product supports 2xGE, 10xSFP, and 8x10G. The product does not support interface expansion. 2. This product is not available in China or international markets and the price information is not obtained. 3. Huawei USG5560/USG5550 can be used to compete with the FG3040B. The USG5560/USG5550 has great advantages in interface density and price. 20 Gbit/s USG5560 USG5550 FG1240B FG1000C 1. The FG1240B is a new product launched in The promotional performance is 40 Gbit/s and reaches 44 Gbit/s after acceleration. In standard configuration, the product supports 16xGE and 24xSFP. The product supports one SW-AMC and six FSMs. 2. The FG1240B does not support 10GE interfaces and a maximum of 100,000 new connections. In standard configuration, the FG1240B uses multiple accelerator cards. 3. The FG1240B is not widely used in China. Therefore, the price information in China is not available. The sale price in international markets is about USD 16, Huawei USG5550 can be used to compete with the FG1240B. The USG5550 has great advantages in price and interfaces. The performance of the USG5550 and FG1240B is at the same level. If tests are required, accelerator cards can be applied. 10 Gbit/s USG5530 USG5530S FG800C FG600C 1. The FG600C and FG800C does not support the expanded interface. The FG600C does not support 10GE interfaces. The FG600C supports only 70,000 new connections. In the standard configuration, the FG600C and FG800C is configured with accelerator cards. Therefore, the performance of the hybrid packet is not high. 2. The FG300C targets the medium-ranged GE market. The sale price is about in international markets. 3. Huawei USG5530S can be used to compete with the FG600C. The USG5530S has great advantages in performance, price, and interfaces. 4. Huawei USG5530 can be used to compete with the FG800C. The USG5530 has great advantages in performance, price, and interfaces. USG5520S FG300C 1. The FG300C does not support the expanded interface and 10GE interfaces. The FG300C supports only 50,000 new connections. In the standard configuration, the FG300C is configured with accelerator cards. Therefore, the performance of the hybrid packet is not high. 2. The FG300C targets the medium-ranged GE market. The sale price is about in international markets. 3. Huawei USG5520S can be used to compete with the FG300C. The USG5520S has great advantages in performance, price, and interfaces. 21

23 Checkpoint Product Specifications Product Model P5075 P9075 P11065 P11075 P11085 Price 60% discount for international market USD 15,000 USD 21,000 USD 24,000 USD 30,000 USD 38,000 Product throughput (bit/s) 9 Gbit/s 16 Gbit/s 15 Gbit/s 20 Gbit/s 30 Gbit/s Number of concurrent connections 1.2 million 1.2 million 1.2 million 1.2 million 1.2 million Fixed interface 10xGE 14xGE 14xGE 14xGE 14xGE 10GE interface Supported Supported Supported Supported Supported Maximum number of interfaces Power supply Four SFP can be expanded. A maximum of four XFPs are supported. Dual power supplies in the standard configuration Four SFP can be expanded. A maximum of four XFPs are supported. Dual power supplies in the standard configuration Four SFP can be expanded. A maximum of four XFPs are supported. Dual power supplies in the standard configuration Four SFP can be expanded. A maximum of four XFPs are supported. Dual power supplies in the standard configuration Four SFP can be expanded. A maximum of four XFPs are supported. Dual power supplies in the standard configuration IPsec throughput 2.4 Gbit/s 3.7 Gbit/s 3.7 Gbit/s 4 Gbit/s 4.5 Gbit/s SSL VPN Supported Supported Supported Supported Supported IPv6 Supported Supported Supported Supported Supported IPS Supported Supported Supported Supported Supported AV Supported Supported Supported Supported Supported URL filtering Supported Supported Supported Supported Supported AS Supported Supported Supported Supported Supported Virtual firewall Supported Supported Supported Supported Supported 22

24 How to Beat Checkpoint From the Vendor Dimension General Beating Methods Industry-Based Beating Points Government Education Finance Energy Beating points based on product or vendor selection factors Beating point - pseudo performance: Based on the analysis of CPU models, the performance of Checkpoint UTM-1 series is exaggerated. Lead the customers to perform device tests. Beating point - low performance: The performance of VPN and concurrent connections of Checkpoint UTM-1 series is lower than that of Huawei products. Beating point - not supporting DC power supplies: The Power- 1 series support only AC power supplies. Beating point - small number of features in the IPS feature library: The Checkpoint UTM-1 series support only 1000 features, which is lower than 2500 features supported by Huawei products. Beating point - poor after-sales service: The after-sales services of Checkpoint devices are provided by agents. Compared with direct after-sales services provided by vendors, the service quality cannot be ensured. General beating points Specific beating points - compliance: International brands cannot be used in government industry in China. General beating points Specific beating point - low interface density: The interface density of Checkpoint UTM-1 series is low and interface extension is not supported. This feature is limited in multi-server application scenarios on the campus network. Public Services and Facilities Enterprise General beating points Specific beating points - reliability: Checkpoint UTM products use the x86 architecture. The stability and reliability of the x86 architecture are lower than those of products that use dedicated multi-core network processors. Industry-Based Defending Points General Defending Methods Public Services Finance Energy Education and Facilities Defending points based on product or vendor selection factors Defending point - complete UTM features: The UTM features supported by Checkpoint products are equivalent with those supported by Fortinet products. Checkpoint products support complete UTM features. Lead the customers to focus on the AV, General defending points General defending points IPS, and URL filtering features. Defending point - high IPS performance: The IPS performance of Checkpoint products is high. Lead the customers to focus on the IPS detection rate and false detection rate. 23 Enterprise

25 How to Beat CheckPoint From the Product Dimension 1. CheckPoint products are categorized as medium-end and high-end products. The IP series are Nokia products and are mainly sold to telecom carriers. 2. The Power series have five models and 9075 are old models and support full UTM features and 10GE interfaces. The IPS performance of 5075 and 9075 is excellent. The Power series are new model products and target at the medium-end and high-end markets. The upgrade service from low-end models to high-end models within the series is provided. The Power series support three types of plug-in boards and support 2x10G optical interfaces, 4xGE optical interfaces (single mode or multi-mode), and 4xGE Copper interfaces. Three types of plug-in boards are universal for the entire Power series. 3. The performance of CheckPoint medium-end and high-end products is high. The license for UTM features is cheap. Lead the customer to consider when the UTM features are professional and IPS performance is real. Power The promotional performance of the is 30 Gbit/s. The provides 14xGE interfaces and can be expanded to 18xGE interfaces. The supports a maximum of 4x10GE interfaces. The sale price of bare equipment is USD 38, Huawei USG5560 can be used to compete with the The USG5560 has great advantages in price, performance, and interface density. 20 Gbit/s 15 Gbit/s USG5560 Power The promotional performance of the is 20 Gbit/s. The provides 14xGE interfaces and can be expanded to 18xGE interfaces. The supports a maximum of 4x10GE interfaces. The sale price of bare equipment is USD 30, Huawei USG5560 can be used to compete with the The USG5560 has great advantages in price, performance, and interface density. 12 Gbit/s USG5550 Power11065 Power9075 IP The promotional performance of the is 15 Gbit/s. The provides 14xGE interfaces and can be expanded to 18xGE interfaces. The supports a maximum of 4x10GE interfaces. The sale price of bare equipment is USD 24, The promotional performance of the 9075 is 16 Gbit/s. The 9075 provides 14xGE interfaces and can be expanded to 18xGE interfaces. The 9075 supports a maximum of 4x10GE interfaces. The sale price of bare equipment is USD 21, The promotional performance of the IP1285 is 10.3 Gbit/s to 17.5 Gbit/s. The IP1285 provides 4xGE interfaces and can be expanded to 28xGE interfaces. The IP1285 supports a maximum of 10x10GE interfaces. The sale price of bare equipment is USD 21, Huawei USG5550 can be used to compete with these products. The USG5550 has great advantages in price, performance, and interface density. 8 Gbit/s USG5530 USG5530S P5075 IP The promotional performance of the 5075 is 9 Gbit/s. The 5075 provides 10xGE interfaces and can be expanded to 14xGE interfaces. The 5075 supports a maximum of 2x10GE interfaces. The sale price of bare equipment is USD 16, The promotional performance of the IP695 is 7.2 Gbit/s to 11.7 Gbit/s. The IP695 provides 4xGE interfaces and can be expanded to 16xGE interfaces. The IP695 supports 10GE interfaces. The sale price of bare equipment is USD 15, Huawei USG5530/USG5530S can be used to compete with these products. The USG5530/USG5530S has great advantages in price, performance, and interface density. USG5520S IP565 UTM The UTM has the highest performance among the low-end products. The promotional performance is 4.5 Gbit/s. The UTM provides a maximum of 10xGE interfaces and does not support interface extension. 2. The promotional performance of the IP565 is 7 Gbit/s. The IP565 provides 4xGE interfaces in the standard configuration and can be expanded to 12xGE interfaces. The IP565 does not support 10GE interfaces. 3. The sale price of the UTM and IP565 bare equipment is about USD 11, Huawei E2003 can be used to compete with these products. 24

26 SonicWall Product Specifications Product Model NSA E5500 NSA E6500 NSA E7500 NSA E8500 NSA E10200 NSA E10400 NSA E10800 Price $4,998 $8,998 $14,998 $19,998 $27,720 $38,500 $83,000 Product throughput (bit/s) New connections per second Number of concurrent connections 3.9 Gbit/s 5 Gbit/s 5.6 Gbit/s 8 Gbit/s 10 Gbit/s 20 Gbit/s 40 Gbit/s 15,000 20,000 25,000 80, , , , ,000 1 million 1.5 million 1.5 million 3 million 6 million 12 million Fixed interface 8xGE 8xGE 4xGE+4xSFP 4xGE+4xSFP 16xGE+6x10GE 16xGE+6x10GE 16xGE+6x10GE 10GE interface Not supported Not supported Not supported Not supported Supported Supported Supported Maximum number of interfaces Power supply xGE+6x10GE 16xGE+6x10GE 16xGE+6x10GE Single power supply in the standard configuration Single power supply in the standard configuration Dual power supplies in the standard configuration Dual power supplies in the standard configuration Dual power supplies in the standard configuration Dual power supplies in the standard configuration Dual power supplies in the standard configuration IPsec throughput 1.7 Gbit/s 2.7 Gbit/s 3 Gbit/s 4 Gbit/s 5 Gbit/s 10 Gbit/s 20 Gbit/s SSL VPN Supported (50) Supported (50) Supported (50) Supported (50) Supported (2000) Supported (4000) Supported (8000) IPv6 Supported Supported Supported Supported Supported Supported Supported IPS Supported Supported Supported Supported Supported Supported Supported AV Supported Supported Supported Supported Supported Supported Supported URL filtering Supported Supported Supported Supported Supported Supported Supported AS Supported Supported Supported Supported Supported Supported Supported Virtual firewall Supported Supported Supported Supported Supported Supported Supported 25

27 Competition Analysis SonicWall 1. SonicWall is a traditional UTM vendor and leads the UTM industry. The major markets of SonicWall are in North America and Europe. 2. The number of interfaces supported by SonicWall products is small and SonicWall products do not support interface extension. 40 Gbit/s USG5560 NSA E The E10000 series support 10GE interfaces. The promotional performance of the E10800 is 40 Gbit/s. The E10800 provides 16xGE and 6x10GE interfaces and does not support interface extension. 2. Huawei USG5560 can be used to compete with the E10000 series and has great advantages in price. 20 Gbit/s USG5550 USG5530 NSA E10400 NSA E The E10000 series support 10GE interfaces. The promotional performance of the E10200/E10400 is 10/20 Gbit/s. The E10200/E10400 provides 16xGE and 6x10GE interfaces and does not support interface extension. 2. Huawei USG5550/5530 can be used to compete with the E10000 series and has great advantages in performance. 8 Gbit/s 5 Gbit/s USG5530S NSA E8500 NSA E The E8500 is a new product launched in The promotional performance of the E8500 is 8 Gbit/s. The E8500 provides 4xGE and 4xSFP interfaces and does not support 10GE interfaces. 2. The E7500 is the mainstream product of the E Class solution. The promotional performance of the E7500 is 5.6 Gbit/s. The E7500 provides 4xGE and 4xSFP interfaces and does not support 10GE interfaces. 3. The E6500 is the mainstream product of the E Class solution. The promotional performance of the E6500 is 5 Gbit/s. The E6500 provides 8xGE in the standard configuration and does not support 10GE interfaces. 4. Huawei USG5530S can be used to compete with these products and has great advantages in performance, interface density, and price. USG5520S NSA E6500 NSA E The E5500 is the mainstream product of the E Class solution. The promotional performance of the E5500 is 3.9 Gbit/s. The E5500 provides 8xGE in the standard configuration and does not support 10GE interfaces. 2. Huawei USG5520S can be used to compete with these products and has great advantages in performance, interface density, and price. 26

28 Content Initial Contact Further Follow-Up Bidding Guidance 27

29 USG5500 Product Specifications Product Model USG5520S USG5530S USG5530 USG5550 USG5560 Application scenarios Product throughput (bit/s) New connections per second Number of concurrent connections Fixed interface Large and medium-sized enterprise, campus, DCN, and data center Large and medium-sized enterprise, campus, DCN, and data center Large and medium-sized enterprise, campus, DCN, and data center Large and medium-sized enterprise, campus, DCN, and data center Large and medium-sized enterprise, campus, DCN, and data center 6 Gbit/s 10 Gbit/s 15 Gbit/s 25 Gbit/s 32 Gbit/s 100, , , , ,000 2 million 3 million 4 million 4 million 4 million 4xGE electrical interfaces+4xge Combo interfaces 4xGE electrical interfaces+4xge Combo interfaces 4xGE electrical interfaces+4xge Combo interfaces 4xGE electrical interfaces+4xge Combo interfaces 4xGE electrical interfaces+4xcombo interfaces+8xge optical interfaces Number of slots 2xFIC 2xFIC 1xDMIC+6xFIC 1xDMIC+5xFIC 5xFIC Types of interface modules 8xGE, 2x10G, and 2x10G+8xGE 8xGE, 2x10G, and 2x10G+8xGE 8xGE, 2x10G, and 2x10G+8xGE 8xGE, 2x10G, and 2x10G+8xGE 8xGE, 2x10G, and 2x10G+8xGE Number of ACLs Number of VPN tunnels VPN performance (bit/s) 4 Gbit/s 5 Gbit/s 7 Gbit/s 7 Gbit/s 7 Gbit/s IPS 1 Gbit/s (UDP) 1.5 Gbit/s (UDP) 2 Gbit/s (UDP) 2 Gbit/s (UDP) 2 Gbit/s (UDP) AV 700 MB (HTTP 100 KB) 800 MB (HTTP 100 KB) 900 MB (HTTP 100 KB) 900 MB (HTTP 100 KB) 900 MB (HTTP 100 KB) URL filtering Supported Supported Supported Supported Supported Virtual firewall

30 USG5520S Guidance Strategy Guidance Item Cisco ASA5585-X SSP10+IPS SSP10 Juniper ISG2000 Checkpoint UTM /2076 Checkpoint UTM /3076 The performance of the integrated system is higher than or equal to 6 Gbit/s. competitors use higher product models for bidding. competitors use higher product models for bidding. competitors use higher product models for bidding. competitors use higher product models for bidding. The performance of small packets must be higher than or equal to 1.5 Gbit/s. competitors use higher product models for bidding. No guidance effect competitors use higher product models for bidding. competitors use higher product models for bidding. The number of new connections must be larger than or equal to 100,000 per second. competitors use higher product models for bidding. competitors use higher product models for bidding. competitors use higher product models for bidding. competitors use higher product models for bidding. The number of concurrent connections must be larger than or equal to 200,000. competitors use higher product models for bidding. competitors use higher product models for bidding. competitors use higher product models for bidding. competitors use higher product models for bidding. The number of IPsec VPN tunnels must be larger than or equal to 15,000. competitors use higher product models for bidding. competitors use higher product models for bidding. competitors use higher product models for bidding. competitors use higher product models for bidding. The encryption and decryption performance of the IPsec VPN must reach 4 Gbit/s. competitors use higher product models for bidding. competitors use higher product models for bidding. competitors use higher product models for bidding. competitors use higher product models for bidding. The SSL VPN must be supported. No guidance effect No guidance effect No guidance effect Full UTM functions (AV, IPS, URL filtering, and AS) must be supported. The GTP function must be supported. The number of 10GE interfaces must be larger than or equal to 4. competitors use higher product models for bidding. No guidance effect competitors use higher product models for bidding. No guidance effect No guidance effect No guidance effect competitors use higher product models for bidding. No guidance effect 29

31 USG5530S Guidance Strategy Guidance Item Juniper SRX650 Cisco ASA CheckPoint Power5075 Fortinet 620B SonicWall E8500 Price Advantages Advantages Advantages Advantages Advantages Multi-core network processor No guidance effect The firewall throughput is higher than or equal to 10 Shield the Gbit/s. The number of new connections is larger than or equal to 150, GE interfaces are supported. 24xGE and 4x10GE interfaces are provided. Dual-power supplies are provided. competitors in China. No guidance effect 30 No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect Raise the price. No guidance effect No guidance effect The IPS is supported. No guidance effect Raise the price. No guidance effect No guidance effect No guidance effect The AV is supported. No guidance effect The URL filtering library is supported. No guidance effect The AS is supported. No guidance effect The SSL VPN must be supported. No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect

32 USG5530 Guidance Strategy Guidance Item Juniper SRX650 Cisco ASA CheckPoint Power5075 Fortinet 620B SonicWall E8500 Price Advantages Advantages Advantages Advantages Advantages Multi-core network processor No guidance effect The firewall throughput is higher than or equal to 15 Gbit/s. The number of new connections is larger than or equal to 200, GE interfaces are supported. 64xGE and 14x10GE interfaces are provided. Dual-power supplies are provided. No guidance effect competitors in No guidance effect Shield the China. No guidance effect Shield the No guidance effect No guidance effect Raise the price. No guidance effect No guidance effect The IPS is supported. No guidance effect Raise the price. No guidance effect No guidance effect No guidance effect The AV is supported. No guidance effect No guidance effect No guidance effect No guidance effect The URL filtering library is supported. No guidance effect No guidance effect No guidance effect No guidance effect The AS is supported. No guidance effect No guidance effect No guidance effect No guidance effect The SSL VPN must be supported. No guidance effect No guidance effect No guidance effect No guidance effect 31

33 USG5550 Guidance Strategy Guidance Item Juniper SRX1400 Cisco ASA CheckPoint Power9075 Fortinet 3016B Fortinet 3040B Price Advantages Advantages Advantages Advantages Advantages Multi-core network processor No guidance effect No guidance effect No guidance effect The firewall throughput is higher than or equal to 25 Gbit/s. The number of new connections is larger than or equal to 200,000. No guidance effect No guidance effect No guidance effect 10GE interfaces are supported. No guidance effect No guidance effect No guidance effect 56xGE and 12x10GE interfaces are provided. Dual-power supplies are provided. No guidance effect No guidance effect No guidance effect Raise the price. No guidance effect No guidance effect No guidance effect Virtual firewall is supported. No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect IPv6 is supported. No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect The SSL VPN must be supported. No guidance effect No guidance effect No guidance effect No guidance effect The IPS is supported. No guidance effect Raise the price. No guidance effect No guidance effect No guidance effect The AV is supported. No guidance effect No guidance effect No guidance effect No guidance effect The URL filtering library is supported. No guidance effect No guidance effect No guidance effect No guidance effect The AS is supported. No guidance effect No guidance effect No guidance effect No guidance effect 32

34 USG5560 Guidance Strategy Guidance Item Juniper SRX3400 Cisco ASA CheckPoint Power11065 Fortinet 3600A Fortinet 3810B Price Advantages Advantages Advantages Advantages Advantages Multi-core network processor No guidance effect No guidance effect No guidance effect The firewall throughput is higher than or equal to 32 Gbit/s. The number of new connections is larger than or equal to 200, GE interfaces are supported. 56xGE and 12x10GE interfaces are provided. Dual-power supplies are provided. No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect Virtual firewall is supported. No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect IPv6 is supported. No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect The SSL VPN must be supported. No guidance effect No guidance effect No guidance effect No guidance effect The IPS is supported. No guidance effect Raise the price. No guidance effect No guidance effect No guidance effect The AV is supported. The URL filtering library is supported. The AS is supported. No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect No guidance effect 33 Shield the No guidance effect No guidance effect No guidance effect

35 HUAWEI ENTERPRISE A BETTER WAY Copyright 2012 Huawei Technologies Co., Ltd. All Rights Reserved. The information in this document may contain predictive statements including, without limitation, statements regarding the future financial and operating results, future product portfolio, new technology, etc. There are a number of factors that could cause actual results and developments to differ materially from those expressed or implied in the predictive statements. Therefore, such information is provided for reference purpose only and constitutes neither an offer nor an acceptance. Huawei may change the information at any time without notice.

USG2110 Unified Security Gateways

USG2110 Unified Security Gateways USG2110 Unified Security Gateways The USG2110 series is Huawei's unified security gateway developed to meet the network security needs of various organizations including the small enterprises, branch offices,

More information

Copyright Huawei Technologies Co., Ltd All rights reserved. Trademark Notice General Disclaimer

Copyright Huawei Technologies Co., Ltd All rights reserved. Trademark Notice General Disclaimer Copyright Huawei Technologies Co., Ltd. 2011. All rights reserved. No part of this document may be reproduced or transmitted in any form or by any means without prior written consent of Huawei Technologies

More information

Networking Drivers & Trends

Networking Drivers & Trends NSA Series Overview Agenda Networking Drivers & Trends New Risks & Challenges Current Solutions Introducing SonicWALL S NSA Series Product Specs Competition Launch Notes Networking Drivers & Trends Business

More information

Huawei Cloud Fabric Data Center Security and Application Optimization Solution

Huawei Cloud Fabric Data Center Security and Application Optimization Solution Huawei Cloud Fabric Data Center and Application Highly Secure s and High-Performance, High-Efficiency Networks Emerging new technologies such as cloud computing, Big Data, and virtualization drive data

More information

Eudemon200E-X Series Unified Security Gateway

Eudemon200E-X Series Unified Security Gateway Product Overview As a new-generation unified security gateway, Huawei Eudemon200E-X Series product family transforms today s Small Business and Enterprise s workspace experience by delivering them high

More information

HUAWEI TECHNOLOGIES CO., LTD. HUAWEI Secospace USG2000&5000 Datasheet

HUAWEI TECHNOLOGIES CO., LTD. HUAWEI Secospace USG2000&5000 Datasheet HUAWEI TECHNOLOGIES CO., LTD. 1 2 Products Overview The USG2000/5000 series is Huawei's unified security gateway developed to meet the network security needs of various organizations including the government,

More information

Document Number. Huawei AR G3 Enterprise Router Channel Sales Guide. Issue V1.0. Date HUAWEI TECHNOLOGIES CO., LTD.

Document Number. Huawei AR G3 Enterprise Router Channel Sales Guide. Issue V1.0. Date HUAWEI TECHNOLOGIES CO., LTD. Document Number Huawei AR G3 Enterprise Router Channel Sales Guide Issue V1.0 Date 2014-8-18 HUAWEI TECHNOLOGIES CO., LTD. Content 1 AR G3 PRODUCT POSITIONING... 3 1.1 MARKET OVERVIEW... 3 1.2 AR G3 SERIES

More information

NIP6000 Next-Generation Intrusion Prevention System

NIP6000 Next-Generation Intrusion Prevention System NIP6000 Next-Generation Intrusion Prevention System Thanks to the development of the cloud and mobile computing technologies, many enterprises currently allow their employees to use smart devices, such

More information

Venusense UTM Introduction

Venusense UTM Introduction Venusense UTM Introduction Featuring comprehensive security capabilities, Venusense Unified Threat Management (UTM) products adopt the industry's most advanced multi-core, multi-thread computing architecture,

More information

Data Sheet. DPtech IPS2000 Series Intrusion Prevention System. Overview. Series IPS2000-MC-N. Features

Data Sheet. DPtech IPS2000 Series Intrusion Prevention System. Overview. Series IPS2000-MC-N. Features Data Sheet DPtech IPS2000 Series DPtech IPS2000 Series Intrusion Prevention System Overview With the rapid development of network, application layer attacks emerge endlessly, such as worms, Trojan horses,

More information

Next-Generation Firewall Series Datasheet

Next-Generation Firewall Series Datasheet RUIJIE NETWORKS COMPANY LIMITED www.ruijienetworks.com Ruijie 1600 Next-Generation Firewall Series Datasheet Ruijie 1600 Firewall Series is a collection of nextgeneration firewall offering security, routing

More information

Quick Sales Guide. Security

Quick Sales Guide. Security Quick Sales Guide Security Security Quick Finder Product/Segment Model Unified Security Gateway USG 100/USG 100-PLUS USG 20/20W ZyWALL 1100 VPN Firewall ZyWALL 310 ZyWALL 110 ZyWALL OTPv2/OTP-MOBI Security

More information

Cisco ASA 5500 Series IPS Solution

Cisco ASA 5500 Series IPS Solution Cisco ASA 5500 Series IPS Product Overview As mobile devices and Web 2.0 applications proliferate, it becomes harder to secure corporate perimeters. Traditional firewall and intrusion prevention system

More information

Data Sheet. DPtech Anti-DDoS Series. Overview. Series

Data Sheet. DPtech Anti-DDoS Series. Overview. Series Data Sheet DPtech Anti-DDoS Series DPtech Anti-DDoS Series Overview DoS (Denial of Service) leverage various service requests to exhaust victims system resources, causing the victim to deny service to

More information

STONESOFT. New Appliances2012

STONESOFT. New Appliances2012 STONESOFT New Appliances2012 FW-315 WLAN Visibility and control to remote locations WLAN networks! Availability: April 2012 FW-315L WLAN Interfaces 4 x 10/100/1000 Mbps Throughput 100Mbps, 25Mbps VPN Management

More information

Eudemon 1000E. Eudemon 1000E Series Product Quick Reference. Huawei Technologies Co., Ltd.

Eudemon 1000E. Eudemon 1000E Series Product Quick Reference. Huawei Technologies Co., Ltd. Eudemon 1000E Eudemon 1000E Series Product Quick Reference Huawei Technologies Co., Ltd. Eudemon 1000E The Eudemon 1000E series product is a new generation security gateway of multiple functions, which

More information

Next-Generation Firewall Series Datasheet

Next-Generation Firewall Series Datasheet RUIJIE NETWORKS COMPANY LIMITED www.ruijienetworks.com Ruijie 1600 Next-Generation Firewall Series Datasheet Ruijie 1600 Firewall Series is a collection of nextgeneration firewall offering security, routing

More information

Security Quick Sales Guide

Security Quick Sales Guide Security Quick Sales Guide Security Quick Finder Product/Segment Model 200 ~ 500 PC Users USG 2000 75 ~ 200 PC Users USG 1000 50 ~ 75 PC Users USG 300 Unified Security Gateway 25 ~ 50 PC Users USG 200

More information

WatchGuard s New XTM 2 Series and XTM 5 Series Appliances for Business Security

WatchGuard s New XTM 2 Series and XTM 5 Series Appliances for Business Security WatchGuard s New XTM 2 Series and XTM 5 Series Appliances for Business Security Wick Hill Update März 2010 2009 WatchGuard Technologies Meeting Today s Needs with New Security Solutions 2009 WatchGuard

More information

ISG-600 Cloud Gateway

ISG-600 Cloud Gateway ISG-600 Cloud Gateway Cumilon ISG Integrated Security Gateway Integrated Security Gateway Cumilon ISG-600C cloud gateway is the security product developed by Systrome for the distributed access network

More information

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. PA-5050 PA-5020 Feature Performance *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Threat prevention throughput measured with App-ID, User-ID,

More information

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Feature PA-7000-20G-NPC PA-5060 Performance *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Threat prevention throughput measured with App-ID,

More information

Juniper Networks Switching: EX & QFX Series

Juniper Networks Switching: EX & QFX Series Sales Guide straight to the point Juniper Networks Switching: EX & QFX Series Juniper Sales team: juniper@westconsecurity.be tel. +32 2 461 01 703 Juniper Product Manager: bart.degroote@westconsecurity.be

More information

Huawei NIP2000/5000 Intrusion Prevention System

Huawei NIP2000/5000 Intrusion Prevention System Huawei 2000/5000 Intrusion Prevention System Huawei series is designed for large- and medium-sized enterprises, industries, and carriers to defend against network threats and ensure proper operations of

More information

All-in one security for large and medium-sized businesses.

All-in one security for large and medium-sized businesses. All-in one security for large and medium-sized businesses www.entensys.com sales@entensys.com Overview UserGate UTM provides firewall, intrusion detection, anti-malware, spam and content filtering, and

More information

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Feature PA-7080 PA-7050 PA-7000-20GQXM-NPC Performance *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Threat prevention throughput measured

More information

DPX17000 Deep Service Core Switch

DPX17000 Deep Service Core Switch DPX17000 Deep Service Core Switch Product Brochure DPX17000 series Overview DPX17000 series is a new generation deep service core switch self-developed by Hangzhou DPtech, Co., Ltd. Based on DPtech APP-X

More information

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. PA-500 PA-220 Feature Performance *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Threat prevention throughput measured with App-ID, User-ID,

More information

Future-ready security for small and mid-size enterprises

Future-ready security for small and mid-size enterprises First line of defense for your network Quick Heal Terminator (UTM) (Unified Threat Management Solution) Data Sheet Future-ready security for small and mid-size enterprises Quick Heal Terminator is a high-performance,

More information

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. PA-3060 PA-3050 PA-3020 Feature Performance *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Threat prevention throughput measured with App-ID,

More information

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. PA-3020 PA-500 PA-200 Feature Performance *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Threat prevention throughput measured with App-ID,

More information

Choosing Switches and Routers for the Campus

Choosing Switches and Routers for the Campus Choosing Switches and Routers for the Campus Campus Network Design & Operations Workshop These materials are licensed under the Creative Commons Attribution-NonCommercial 4.0 International license (http://creativecommons.org/licenses/by-nc/4.0/)

More information

Cisco SR 520-T1 Secure Router

Cisco SR 520-T1 Secure Router Secure, High-Bandwidth Connectivity for Your Small Business Part of the Cisco Small Business Pro Series Connections -- between employees, customers, partners, and suppliers -- are essential to the success

More information

HikCentral V1.3 for Windows Hardening Guide

HikCentral V1.3 for Windows Hardening Guide HikCentral V1.3 for Windows Hardening Guide Contents Introduction... 1 1. The Operating System - Microsoft Windows Security Configuration... 2 1.1Strict Password Policy... 2 1.2Turn Off Windows Remote

More information

DPX19000 Next Generation Cloud-Ready Service Core Platform

DPX19000 Next Generation Cloud-Ready Service Core Platform DPX19000 Next Generation Cloud-Ready Service Core Platform Data Sheet DPtech DPX19000 Series Overview DPX19000 is a next generation cloud-ready service core platform self-developed by Hangzhou DPtech,

More information

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. PA-200 Feature Performance *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Threat prevention throughput measured with App-ID, User-ID, IPS,

More information

High End SRX. Overview of the SRX in the datacenter

High End SRX. Overview of the SRX in the datacenter High End SRX Overview of the SRX in the datacenter Agenda 1 HE SRX Overview 2 Architecture What makes an High End an High End? 3 Architecture Session Setup / Packet Flow / SOF 4 New Components (RE/SCBE)

More information

Corrigendum 3. Tender Number: 10/ dated

Corrigendum 3. Tender Number: 10/ dated (A premier Public Sector Bank) Information Technology Division Head Office, Mangalore Corrigendum 3 Tender Number: 10/2016-17 dated 07.09.2016 for Supply, Installation and Maintenance of Distributed Denial

More information

Feature. *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

Feature. *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Performance Feature *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Threat prevention throughput measured with App-ID, User-ID, IPS, antivirus

More information

Business Strategy Theatre

Business Strategy Theatre Business Strategy Theatre Security posture in the age of mobile, social and new threats Steve Pao, GM Security Business 01 May 2014 In the midst of chaos, there is also opportunity. - Sun-Tzu Security:

More information

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. PA-3020 PA-850 PA-820 Feature Performance *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Threat prevention throughput measured with App-ID,

More information

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. VM-300 VM-200 VM-100 Feature Performance *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Threat prevention throughput measured with App-ID,

More information

Juniper Security Update. Karel Hendrych Juniper Networks

Juniper Security Update. Karel Hendrych Juniper Networks Juniper Security Update Karel Hendrych Juniper Networks khe@juniper.net Agenda High End SRX security gateways Overview, SRX1400 JunOS update AppSecure Competitive 2 Copyright 2009 Juniper Networks, Inc.

More information

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. PA-220 PA-200 Feature Performance *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Threat prevention throughput measured with App-ID, User-ID,

More information

Cisco Next Generation Firewall and IPS. Dragan Novakovic Security Consulting Systems Engineer

Cisco Next Generation Firewall and IPS. Dragan Novakovic Security Consulting Systems Engineer Cisco Next Generation Firewall and IPS Dragan Novakovic Security Consulting Systems Engineer Cisco ASA with Firepower services Cisco TALOS - Collective Security Intelligence Enabled Clustering & High Availability

More information

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2.

*1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. PA-3020 PA-500 PA-200 Feature Performance *1. Firewall throughput measured with App-ID and User-ID features enabled utilizing 64KB HTTP transactions. 2. Threat prevention throughput measured with App-ID,

More information

Huawei Enterprise Network esight Channel Sales Guide HUAWEI TECHNOLOGIES CO., LTD. Issue 3.2. Date

Huawei Enterprise Network esight Channel Sales Guide HUAWEI TECHNOLOGIES CO., LTD. Issue 3.2. Date Huawei Enterprise Network esight Channel Sales Guide Issue 3.2 Date 2013-11-20 HUAWEI TECHNOLOGIES CO., LTD. 2013. All rights reserved. No part of this document may be reproduced or transmitted in any

More information

Cisco ASR 1000 Series Ethernet Line Cards

Cisco ASR 1000 Series Ethernet Line Cards Data Sheet Cisco ASR 1000 Series Ethernet Line Cards Product Overview The Cisco ASR 1000 Series Fixed Ethernet Line Cards (ASR1000-2T+20X1GE and ASR1000-6TGE) are fixed-port Ethernet line cards for the

More information

USG9500 Series Terabit Level Next-Generation Firewall

USG9500 Series Terabit Level Next-Generation Firewall USG9500 Series Terabit Level Next-Generation Firewall Big data and the Internet brings convenience and possibilities for people's work and life. Cloud is seen as an important change that will shape the

More information

We are Network Security. Enterprise Solutions.

We are Network Security. Enterprise Solutions. We are Network Enterprise Solutions. We are Network Clavister delivers the security solutions required for market leaders to optimize their networks... now and tomorrow. We are Network We are securing

More information

HikCentral V.1.1.x for Windows Hardening Guide

HikCentral V.1.1.x for Windows Hardening Guide HikCentral V.1.1.x for Windows Hardening Guide Contents Introduction... 1 1. The Operating System - Microsoft Windows Security Configuration... 2 1.1 Strict Password Policy... 2 1.2 Turn Off Windows Remote

More information

FEATURE OVERVIEW. FGX Series firewall. Last updated February 2012

FEATURE OVERVIEW. FGX Series firewall. Last updated February 2012 FEATURE OVERVIEW FGX Series firewall Last updated February 2012 Celestix FGX Features Deep Packet Firewall VPN Virtual system DoD/DDoS attach defense Intrusion protection Anti-virus Anti-spam URL iltering

More information

Juniper SRX Services Gateway Performance Testing

Juniper SRX Services Gateway Performance Testing Juniper SRX Services Gateway Performance Testing June 2017 DR170517D Miercom.com www.miercom.com Contents Executive Summary... 3 Products Tested... 5 SRX300 Series... 5 SRX550... 5 SRX1500... 6 How We

More information

Network. Arcstar Universal One

Network. Arcstar Universal One Network Universal One ARCSTAR UNIVERSAL ONE Universal One Enterprise Network NTT Communications' Universal One is a highly reliable, premium-quality network service, delivered and operated in more than

More information

The SonicWALL PRO Series

The SonicWALL PRO Series The SonicWALL PRO Series NETWORK SECURITY Dynamic Multi-function Network Security Appliances Powerful re-assembly free deep packet inspection engine Real-time gateway anti-virus, anti-spyware, anti-spam

More information

USG9500 Series Terabit Level Next-Generation Firewall

USG9500 Series Terabit Level Next-Generation Firewall USG9500 Series Terabit Level Next-Generation Firewall A fully connected world is becoming a reality. Glasses, watches, and even home appliances and health check products are going smart and digitally connected.

More information

Cisco Systems Korea Cisco Systems, Inc. All rights reserved. 1

Cisco Systems Korea Cisco Systems, Inc. All rights reserved. 1 10 (yonghkim@cisco.com) Cisco Systems Korea 2008 Cisco Systems, Inc. All rights reserved. 1 10G (UTM) 2008 Cisco Systems, Inc. All rights reserved. 2 10G 2008 Cisco Systems, Inc. All rights reserved. 3

More information

CISCO EXAM QUESTIONS & ANSWERS

CISCO EXAM QUESTIONS & ANSWERS CISCO 650-179 EXAM QUESTIONS & ANSWERS Number: 650-179 Passing Score: 800 Time Limit: 120 min File Version: 85.5 http://www.gratisexam.com/ CISCO 650-179 EXAM QUESTIONS & ANSWERS Exam Name: SMB Solutions

More information

Firewalls for Secure Unified Communications

Firewalls for Secure Unified Communications Firewalls for Secure Unified Communications Positioning Guide 2008 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 1 of 12 Firewall protection for call control

More information

Appliance Comparison Chart

Appliance Comparison Chart Security Gateway Appliances 300 300 500 500 5400 5600 5800 5900 Branch Office Small Enterprise Mid-Size Enterprise Real-World Production Conditions Security 60 50 340 45 600 950 750 400 Firewall (Gbps)..

More information

Selling the Total Converged Solution Module #1: Nortel Enterprise Networking Overview of the 4 Pillars and Why Nortel Tom Price Nortel HQ Sales

Selling the Total Converged Solution Module #1: Nortel Enterprise Networking Overview of the 4 Pillars and Why Nortel Tom Price Nortel HQ Sales Selling the Total Converged Solution Module #1: Nortel Enterprise Networking Overview of the 4 Pillars and Why Nortel Tom Price Nortel HQ Sales Engineer 1 Nortel Value Proposition >Nortel has an End-to-End

More information

Eudemon8000E-X Series

Eudemon8000E-X Series Comprehensive High-End Security Gateway Overview As networks enter the IP era, more applications are integrated into the traditional broadband network. The network bandwidth, threats, and network attack

More information

Securing the Next Generation Data Center

Securing the Next Generation Data Center Securing the Next Generation Data Center Petr Kadrmas SE Eastern Europe 2012 Check Point Software Technologies Ltd. [PROTECTED] All rights reserved. 2012 Check Point Software Technologies Ltd. [PROTECTED]

More information

Cisco Firepower Thread Defence. Claudiu Boar

Cisco Firepower Thread Defence. Claudiu Boar Cisco Firepower Thread Defence Claudiu Boar Security everywhere Stop threats at the edge Control who gets onto your network Find and contain problems fast Protect users wherever they work Simplify network

More information

QUESTION: 1 You have been asked to establish a design that will allow your company to migrate from a WAN service to a Layer 3 VPN service. In your des

QUESTION: 1 You have been asked to establish a design that will allow your company to migrate from a WAN service to a Layer 3 VPN service. In your des Vendor: Cisco Exam Code: 352-001 Exam Name: ADVDESIGN Version: Demo www.dumpspdf.com QUESTION: 1 You have been asked to establish a design that will allow your company to migrate from a WAN service to

More information

Exam: : VPN/Security. Ver :

Exam: : VPN/Security. Ver : Exam: Title : VPN/Security Ver : 03.20.04 QUESTION 1 A customer needs to connect smaller branch office locations to its central site and desires a more which solution should you recommend? A. V3PN solution

More information

Appliance Comparison Chart

Appliance Comparison Chart Security Gateway Appliances 00 00 500 500 5400 5600 5800 5900 Branch Office Small Enterprise Mid-Size Enterprise Real-World Production Conditions Security 60 50 40 45 600 950 750 400 Firewall (Gbps)..

More information

Cisco Security Manager 4.1: Integrated Security Management for Cisco Firewalls, IPS, and VPN Solutions

Cisco Security Manager 4.1: Integrated Security Management for Cisco Firewalls, IPS, and VPN Solutions Data Sheet Cisco Security Manager 4.1: Integrated Security Management for Cisco Firewalls, IPS, and VPN Solutions Security Operations Challenges Businesses are facing daunting new challenges in security

More information

SRX als NGFW. Michel Tepper Consultant

SRX als NGFW. Michel Tepper Consultant SRX als NGFW Michel Tepper Consultant Firewall Security Challenges Organizations are looking for ways to protect their assets amidst today s ever-increasing threat landscape. The latest generation of web-based

More information

Customer Advantage Program

Customer Advantage Program Customer Advantage Program Straightforward upgrades and competitive trade-ins for current and new SonicWall customers The SonicWall Customer Advantage Program offers an upgrade path from current SonicWall

More information

NSG50/100/200 Nebula Cloud Managed Security Gateway

NSG50/100/200 Nebula Cloud Managed Security Gateway NSG50/100/200 Managed The Zyxel Managed is built with remote management and ironclad security for organizations with growing numbers of distributed sites. With the extensive suite of security features

More information

Cisco ASR 1000 Series Ethernet Line Cards

Cisco ASR 1000 Series Ethernet Line Cards Data Sheet Cisco ASR 1000 Series Ethernet Line Cards Product overview The Cisco ASR 1000 Series Fixed Ethernet Line Cards (ASR1000-2T+20X1GE and ASR1000-6TGE) are fixed port Ethernet line cards for the

More information

Surat Smart City Development Ltd. Surat Municipal Corporation 1

Surat Smart City Development Ltd. Surat Municipal Corporation 1 Surat Smart City Development Ltd. Surat Municipal Corporation 1 Surat Smart City Development Limited (SSCDL) ADDENDUM AND CORRIGENDUM-1 Name of the work: - [SSCDL-Network-01-2018] The Bidders are requested

More information

Huawei Symantec Corporate Overview

Huawei Symantec Corporate Overview Huawei Symantec Corporate Overview Huawei Symantec Joint Venture Targeted Synergies Huawei Strengths Top 3 Comprehensive telecom solutions providers International reach to over 100 countries Partner with

More information

Customer Advantage Program

Customer Advantage Program Customer Advantage Program Straightforward upgrades and competitive trade-ins for current and new SonicWall customers The SonicWall Customer Advantage Program offers an upgrade path from current SonicWall

More information

Cisco Self Defending Network

Cisco Self Defending Network Cisco Self Defending Network Integrated Network Security George Chopin Security Business Development Manager, CISSP 2003, Cisco Systems, Inc. All rights reserved. 1 The Network as a Strategic Asset Corporate

More information

JUNIPER PRODUCT UPDATE. Jukka Piirainen Stallion Winter Seminar

JUNIPER PRODUCT UPDATE. Jukka Piirainen Stallion Winter Seminar JUNIPER PRODUCT UPDATE Jukka Piirainen Stallion Winter Seminar 13.2.2010 SETTING THE AGENDA FOR THE NEXT DECADE JUNIPER NETWORKS IS TRANSFORMING THE EXPERIENCE AND ECONOMICS OF NETWORKING 2 Copyright 2010

More information

Deployment Scenarios

Deployment Scenarios This chapter describes and shows some typical deployment scenarios for the Cisco 860, Cisco 880, and Cisco 890 series Intergrated Services Routers (ISRs): About the, page 1 Enterprise Small Branch, page

More information

Customer Advantage Program

Customer Advantage Program Customer Advantage Program Straightforward upgrades and competitive trade-ins for current and new SonicWall customers The SonicWall Customer Advantage Program offers an upgrade path from current SonicWall

More information

Training UNIFIED SECURITY. Signature based packet analysis

Training UNIFIED SECURITY. Signature based packet analysis Training UNIFIED SECURITY Signature based packet analysis At the core of its scanning technology, Kerio Control integrates a packet analyzer based on Snort. Snort is an open source IDS/IPS system that

More information

Securing the Empowered Branch with Cisco Network Admission Control. September 2007

Securing the Empowered Branch with Cisco Network Admission Control. September 2007 Securing the Empowered Branch with Cisco Network Admission Control September 2007 Presentation_ID 2006 Cisco Systems, Inc. All rights reserved. 1 Contents 1 The Cisco Empowered Branch 2 Security Considerations

More information

QUICKSTART GUIDE FOR BRANCH SRX SERIES SERVICES GATEWAYS

QUICKSTART GUIDE FOR BRANCH SRX SERIES SERVICES GATEWAYS APPLICATION NOTE QUICKSTART GUIDE FOR BRANCH SRX SERIES SERVICES GATEWAYS Configuring Basic Security and Connectivity on Branch SRX Series Services Gateways Copyright 2009, Juniper Networks, Inc. Table

More information

NSG50/100/200 Nebula Cloud Managed Security Gateway

NSG50/100/200 Nebula Cloud Managed Security Gateway NSG50/100/200 The Zyxel is built with remote management and ironclad security for organizations with multiple distributed sites. With an extensive suite of security features including ICSAcertified firewall,

More information

Extending Enterprise Security to Multicloud and Public Cloud

Extending Enterprise Security to Multicloud and Public Cloud Extending Enterprise Security to Multicloud and Public Cloud Paul Kofoid Sr. Consulting Engineer: Security & Cloud This statement of direction sets forth Juniper Networks current intention and is subject

More information

USG 50/20/20W Sales Kits

USG 50/20/20W Sales Kits USG 50/20/20W Sales Kits Why do more than 400,000 small and mediumsized businesses (SMB) choose ZyWALL in Europe? ZyWALL understand SMBs need "I was impressed with the ZyWALL's high performance while handling

More information

2 ZyWALL UTM Application Note

2 ZyWALL UTM Application Note 2 Application Note Threat Management Using ZyWALL 35 UTM Forward This support note describes how an SMB can minimize the impact of Internet threats using the ZyWALL 35 UTM as an example. The following

More information

*Performance and capacities are measured under ideal testing conditions using PAN-OS 8.0. Additionally, for VM

*Performance and capacities are measured under ideal testing conditions using PAN-OS 8.0. Additionally, for VM VM-300 VM-200 VM-100 Feature Performance *Performance and capacities are measured under ideal testing conditions using PAN-OS 8.0. Additionally, for VM models please refer to hypervisor, cloud specific

More information

Preconfigured Audio/Video Bridging System

Preconfigured Audio/Video Bridging System Preconfigured Audio/Video Bridging System RSB-KIT Gateway Security Appliance (Router) with Rack Mount Bracket and VLAN switch The popularity and affordability of IP networking has driven audio/video and

More information

Spirent Avalanche. Applications and Security Testing Solutions. Application. Features & Benefits. Data Sheet. Network Performance Testing

Spirent Avalanche. Applications and Security Testing Solutions. Application. Features & Benefits. Data Sheet. Network Performance Testing Data Sheet Spirent Avalanche Spirent s Avalanche Layer 4-7 testing solution provides capacity, security and performance testing for network infrastructures, cloud and virtual environments, Web application

More information

*Performance and capacities are measured under ideal testing conditions using PAN-OS.0. Additionally, for VM

*Performance and capacities are measured under ideal testing conditions using PAN-OS.0. Additionally, for VM PA-820 PA-500 Feature Performance *Performance and capacities are measured under ideal testing conditions using PAN-OS.0. Additionally, for VM models please refer to hypervisor, cloud specific data sheet

More information

Choosing Routers for the Campus

Choosing Routers for the Campus Choosing Routers for the Campus Campus Network Design & Operations Workshop These materials are licensed under the Creative Commons Attribution-NonCommercial 4.0 International license (http://creativecommons.org/licenses/by-nc/4.0/)

More information

DPX8000 Series Deep Service Switching Gateway User Configuration Guide Firewall Service Board Module v1.0

DPX8000 Series Deep Service Switching Gateway User Configuration Guide Firewall Service Board Module v1.0 DPX8000 Series Deep Service Switching Gateway User Configuration Guide Firewall Service Board Module v1.0 i Hangzhou DPtech Technologies Co., Ltd. provides full- range technical support. If you need any

More information

SECURING THE NEXT GENERATION DATA CENTER. Leslie K. Lambert Juniper Networks VP & Chief Information Security Officer July 18, 2011

SECURING THE NEXT GENERATION DATA CENTER. Leslie K. Lambert Juniper Networks VP & Chief Information Security Officer July 18, 2011 SECURING THE NEXT GENERATION DATA CENTER Leslie K. Lambert Juniper Networks VP & Chief Information Security Officer July 18, 2011 JUNIPER SECURITY LEADERSHIP Market Leadership Data Center with High-End

More information

Max sessions (IPv4 or IPv6) 500, , ,000

Max sessions (IPv4 or IPv6) 500, , ,000 PA-3060 PA-3050 PA-3020 Feature Performance App-ID firewall throughput 4 Gbps 4 Gbps 2 Gbps Threat prevention throughput 2 Gbps 2 Gbps 1 Gbps IPSec VPN throughput 500 Mbps 500 Mbps 500 Mbps Connections

More information

MX Sizing Guide. 4Gon Tel: +44 (0) Fax: +44 (0)

MX Sizing Guide. 4Gon   Tel: +44 (0) Fax: +44 (0) MX Sizing Guide FEBRUARY 2015 This technical document provides guidelines for choosing the right Cisco Meraki security appliance based on real-world deployments, industry standard benchmarks and in-depth

More information

NSG100 Nebula Cloud Managed Security Gateway

NSG100 Nebula Cloud Managed Security Gateway Managed Security Gateway The Zyxel Nebula Cloud Managed Security Gateway is built with remote management and ironclad security for organizations with growing numbers of distributed sites. With the extensive

More information

New Cisco 2800 And 3800 Series Integrated Services Router Wan Optimization Bundles

New Cisco 2800 And 3800 Series Integrated Services Router Wan Optimization Bundles Q&A New Cisco 2800 And 3800 Series Integrated Wan Optimization Bundles Q. What are the components of the new Cisco 2800 and 3800 series integrated services router WAN optimization bundles? A. There are

More information

Cisco NAC Network Module for Integrated Services Routers

Cisco NAC Network Module for Integrated Services Routers Cisco NAC Network Module for Integrated Services Routers The Cisco NAC Network Module for Integrated Services Routers (NME-NAC-K9) brings the feature-rich Cisco NAC Appliance Server capabilities to Cisco

More information

Systrome Next Gen Firewalls

Systrome Next Gen Firewalls N E T K S Systrome Next Gen Firewalls Systrome s Next Generation Firewalls provides comprehensive security protection from layer 2 to layer 7 for the mobile Internet era. The new next generation security

More information

Cisco SCE 2020 Service Control Engine

Cisco SCE 2020 Service Control Engine Data Sheet Cisco SCE 2000 Series Service Control Engine The Cisco SCE 2000 Series Service Control Engine is a network element specifically designed for carrier-grade deployments requiring high-capacity

More information