QuickSpecs. Models. Features and Benefits Industry-leading warranty. HP ProCurve Threat Management Services zl Module

Similar documents
HP ProCurve MultiService Controller Series

QuickSpecs. Models. Key features Enhanced WLAN architecture reduces LAN traffic IEEE n capable Rock-solid WLAN security

HP ProCurve MultiService Controller Series Overview. Models HP ProCurve MSM760 Access Controller HP ProCurve MSM765zl Mobility Controller

HP ProCurve MultiService Controller Series

QuickSpecs. Models HP ProCurve MSM760 Access Controller HP ProCurve MSM765zl Mobility Controller

QuickSpecs. Models. Features and Benefits Connectivity. HP ProCurve Switch 1800 Series. Overview. Retired. HP ProCurve Switch G

HP ProCurve Network Access Controller 800

HP ProCurve Switch 1800 Series

HP ProCurve Mobility Access Point Series

HP AllianceONE Services zl Module for Avaya Aura Session Border Controller powered by Acme Packet

QuickSpecs HP ProCurve Manager Plus 3.1

Models HP ProCurve M110 Access Point WW

HP ProCurve Manager Plus 3.0

QuickSpecs. Models. Features and benefits Application highlights. HP 7500 SSL VPN Module with 500-user License Overview

Retired. Models HP U200-A UTM Appliance

Sample excerpt. Virtual Private Networks. Contents

HP U200 Unified Threat Management (UTM) Appliance Series

HP ProCurve a/b/g MultiService Access Point Series

HP V-M n Access Point Series

HP V1700 Switch Series

HP V1410 Switch Series Overview. Models HP V G Switch

QuickSpecs ProCurve Identity Driven Manager 2.2

QuickSpecs. Model. Features and benefits Firewall. HP 9500 VPN Firewall Module. Overview

HP E-PCM Plus Network Management Software Series Overview

ProCurve Wireless Edge Services xl Module

HP ProCurve MultiService Controller Series

QuickSpecs. Models. Features and Benefits Mobility. ProCurve Wireless Edge Services xl Module. ProCurve Wireless Edge Services xl Module.

QuickSpecs. Models HP V1810-8G Switch

HP ProCurve Switch 6400cl Series

ProCurve Wireless Edge Services xl Module

HP ProCurve Switch 2610 Series

QuickSpecs. Models HP V110 Cable/DSL Wireless-N Router HP V110 ADSL-B Wireless-N Router

HP ProCurve MultiService Access Device Series

Sample excerpt. HP ProCurve Threat Management Services zl Module NPI Technical Training. NPI Technical Training Version: 1.

ProCurve Manager Plus 2.3

QuickSpecs. HPE Firewall Series. Overview. HPE Firewall Series. Models. Key features. Product overview. Features and benefits.

HP S1500 SSL Appliance. Product overview. Key features. Data sheet

HP A a/b/g Access Point Series Overview

HP E-MSM317 Access Device Series Overview. Models HP E-MSM317 Access Device US

ProCurve Switch 1400 Series

HP ProCurve Switch 2610 Series

QuickSpecs. Models HP 110 ADSL-B Wireless-N Router

QuickSpecs. Models HP ProCurve MSM335 Access Point WW

HP MSM Controller Series

HP ProCurve MultiService Access Point Series

HP V1410 Switch Series. Product overview. Key features. Data sheet

ProCurve Switch 1400 Series

QuickSpecs. HPE OfficeConnect M n Access Point Series. Overview. HPE OfficeConnect M n Access Point Series

HP V110 Wireless-N Router Series

VPN Routers DSR-150/250/500/1000AC. Product Highlights. Features. Overview. Comprehensive Management Capabilities. Web Authentication Capabilities

NSG100 Nebula Cloud Managed Security Gateway

QuickSpecs. Models HP TippingPoint S8010F Next Generation Firewall Appliance

Numerics I N D E X. 3DES (Triple Data Encryption Standard), 48

Unified Services Routers

PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

Alcatel OmniAccess 200 Series

Retired. Models HP 1405C-5 Switch* IEEE 802.1p prioritization: delivers data to devices based on the priority and type of traffic

Retired. HP ProCurve Switch HP ProCurve Switch HP ProCurve Switch HP ProCurve Switch 2824

HP ProCurve Switch 2610 Series Overview. Models HP ProCurve Switch /12PWR. Accessories HP ProCurve 100-BX-U SFP-LC Transceiver

Retired. For more information on HP's ProLiant Security Server visit:

ProCurve Switch 2500 Series

ZyWALL VPN2S VPN Firewall

HP Identity Driven Manager Software Series

NSG50/100/200 Nebula Cloud Managed Security Gateway

QuickSpecs. Models HP RF Manager Controller with 50-sensor License HP MSM415 RF Security Sensor

Wireless Controller DWC-1000

NSG50/100/200 Nebula Cloud Managed Security Gateway

QuickSpecs. Models HP V1405C-8 Switch

Gigabit SSL VPN Security Router

Vendor: HP. Exam Code: HP2-Z32. Exam Name: Implementing HP MSM Wireless Networks. Version: Demo

AIR-WLC K9 Datasheet. Overview. Check its price: Click Here. Quick Specs

QuickSpecs. Models. Key features Access layer Layer 2 and Layer 3 lite feature set Scalable 10/100/1000 connectivity 10-GbE uplinks

HP ProCurve Switch 2900 Series

16-Port Serial Console Server. 48-Port Serial Console Server

AC3000 Tri-Band Wireless Gigabit Dual-WAN VPN SMB Router TEW-829DRU (v1.0r)

XR DUAL RADIO INDOOR ACCESS POINTS

HP V1905 Switch Series. Product overview. Key features. Data sheet

ProCurve Switch 2510 Series Overview. ProCurve Switch 2510G-48. ProCurve Switch 2510G-24

QuickSpecs. Models. Features and benefits Additional information. HP 620 Redundant/External Power Supply Overview

QuickSpecs. Models. Features and benefits Quality of Service (QoS) HP 5800 Access Controller Module for Access Points

Firepower Threat Defense Site-to-site VPNs

HIGH DENSITY ACCESS POINT

Cisco RV180 VPN Router

Fundamentals of Network Security v1.1 Scope and Sequence

Configuring a Hub & Spoke VPN in AOS

Cisco NAC Network Module for Integrated Services Routers

ProCurve Routing Switch 9300m Series. Overview. ProCurve Routing Switch 9315m. DA Worldwide Version 5 August 18, 2006 Page 1

Security Quick Sales Guide

QuickSpecs. HP enterprise access point WL520. Overview

QuickSpecs. HP MSM317 Access Device Series. Models. Key features. HP MSM317 Access Device Series. Overview. Retired. HP MSM317 Access Device US

QuickSpecs. HP M111 Client Bridge Series (Retired) Model. Key features

Retired. HPE R120 Wireless ac VPN WW Router

ACADEMIA LOCAL CISCO UCV-MARACAY CONTENIDO DE CURSO CURRICULUM CCNA. SEGURIDAD SEGURIDAD EN REDES. NIVEL II. VERSION 2.0

QuickSpecs. HP MSM Controller Series. Overview. HP MSM720 Access Controller (WW) HP MSM760 Premium Mobility Controller/HP MSM760 Access Controller

QuickSpecs. Models. ProCurve Switch 2600 Series. Overview. ProCurve Switch ProCurve Switch 2650-PWR. ProCurve Switch 2626

Request for Proposal (RFP) for Supply and Implementation of Firewall for Internet Access (RFP Ref )

Wireless Controller DWC Product Highlights. Features. Robust and Optimised Network. Comprehensive Security

XR-630 DUAL RADIO INDOOR ACCESS POINT

Distributed Systems. 27. Firewalls and Virtual Private Networks Paul Krzyzanowski. Rutgers University. Fall 2013

Secure Access Configuration Guide For Wireless Clients

Transcription:

Models J9155A Key features Stateful firewall Intrusion detection/prevention system (IDS/IPS) Virtual private network (VPN) Module form factor Industry-leading warranty Introduction The HP ProCurve Threat Management Services (TMS) zl Module is a multifunction security system for the HP ProCurve Switch 5400zl and Switch 8200zl Series. It is comprised of a stateful firewall, an intrusion detection/prevention system (IDS/IPS), and a virtual private network (VPN) concentrator. It enables network administrators to compartmentalize department traffic, protect the network from malware, and provide secure remote access and site-to-site connectivity. Features and Benefits Industry-leading warranty ProCurve Lifetime Warranty* Data center protection Server protection: stateful firewall controls traffic to the data center; intrusion protection system (IPS) detects and blocks threats such as worms and viruses to maintain service and application availability Application support HP ProCurve ONE application support: is compatible with ProCurve ONE applications; non-procurve ONE applications will not run on the services module, which prevents rogue applications in mission-critical network environments Compartmentalization Departmental protection: allows organizations to define departmental security policies to protect local resources with a stateful firewall and IPS while at the same time allowing high-performance access to common resources VPN concentration Firewall Site-to-site connectivity: IPSec-encrypted tunnels help ensure privacy between sites with optional Generic Routing Encapsulation (GRE) tunneling, which is available for full deployment flexibility; intersite links can be deployed quickly and controlled with tunnel policies Secure remote access: can be delivered for remote users via securely authenticated IPSec tunnels Stateful firewall: enforces firewall policies to control traffic and filter access to network services; maintains session information DA - 13376 Worldwide Version 2 March 9, 2010 Page 1

for every connection passing through it, enabling the firewall to control packets based on existing sessions Zone-based access policies: logically groups virtual LANs (VLANs) into zones that share common security policies; allows both unicast and multicast policy settings by zones instead of by individual VLANs Application-level gateway (ALG): deep packet inspection in the firewall discovers the IP address and service port information embedded in the application data; the firewall then dynamically opens appropriate connections for specific applications NAT/PAT: choice of dynamic or static network address translator (NAT) preserves a network's IP address pool or conceals the private address of network resources, such as Web servers, made accessible to users of a guest or public wireless LAN DoS attack prevention: firewall is able to detect various denial-of-service attacks and take appropriate action to mitigate the threat Authenticated network access: firewall can authenticate the user at a given IP address using RADIUS or a local user directory before allowing connections from that location Intrusion detection/prevention system (IPS/IDS) Deep packet inspection: module supports deep packet inspection and examines the packet payload as well as the frame and packet headers; packets are dropped if attacks or intrusions are detected using signature-based or protocol anomaly-based detection Signature-based detection: detects known attacks that have known attack patterns; IPS maintains a signature database that contains the pattern definitions for known attacks that can be automatically updated via a subscription service Protocol anomaly-based detection: detects attacks that use anomalies in application protocol payloads Severity-based action policies: involve action taken against attacks based on their severity; available actions are allow, block, and terminate connection to provide appropriate mitigation Signature update service: provides regular updates to the signature database, helping to ensure that the latest available signatures are installed Virtual private network (VPN) IPSec: provides secure tunneling over an untrusted network such as the Internet or a wireless network; offers data confidentiality, authenticity, and integrity between two endpoints of the network Layer 2 Tunneling Protocol (L2TP): an industry standard-based traffic encapsulation mechanism supported by many common operating systems; will tunnel the PPP traffic over the IP and non-ip networks; may use the IP/UDP transport mechanism in IP networks Generic Routing Encapsulation (GRE): can be used to transport Layer 2 connectivity over a Layer 3 path in a secured way; enables the segregation of traffic from site to site Manual or automatic key exchange (IKE): provides both manual or automatic (IKE) key exchange required for the algorithms used in encryption or authentication; Auto-IKE allows automated management of the public key exchange, providing the highest levels of encryption Network Address Translation-Traversal (NAT-T): enables IPSec-protected IP datagrams to pass through a network address translator (NAT) Digital certificate management: digital certificates can be utilized to authenticate to an IPSec VPN gateway; this also supports certificate revocation list (CRL) and importing certificates through a Simple Certificate Enrollment Protocol (SCEP) server Remote access VPN client: provides the flexibility to use either the ProCurve VPN client or a Microsoft Windows XP or Vista native VPN client Site-to-site connectivity: two IPSec VPN gateways can be configured to provide secure site-to-site communication between offices, partners, or suppliers; both IPSec or GRE tunnels are available Secure remote access: allows remote users to connect to the VPN gateway for secure communication to the corporate network over the public network Operating Modes Route Mode: provides the deployment of the firewall, VPN, and IPS in line with traffic for deep packet inspection to control and filter traffic; supports static routes, RIP, RIPv2, OSPF, IGMP, and PIM DA - 13376 Worldwide Version 2 March 9, 2010 Page 2

Monitor Mode: provides the deployment of the intrusion detection system (IDS) to monitor traffic passively out of band with the traffic Management Remote configuration and management: through secure Web browser or command-line interface (CLI) Secure Web GUI: provides a secure, easy-to-use graphical interface for configuration of the module via HTTPS Command-line interface (CLI): provides a secure, easy-to-use command-line interface for configuration of the module via SSH or switch console; provides direct real-time session visibility HP ProCurve Manager: central management through HP ProCurve Manager Plus for discovery, logging, and status management Logging: local and remote logging of events via SNMP (v2c and v3) and syslog; provides log throttling and log filtering to reduce the number of log events generated Connectivity Two 10-GbE connections to the switch (for MSM765zl mobility controller): two 10-GbE wire-speed internal connections help ensure that the network connections from application to switch backplane will not limit the performance of the application Performance High-performance network bandwidth: includes two internal wire-speed 10-GbE ports to the switch backplane High-performance processor system: Intel Core 2 Duo T7500 Processor with 2.2 GHz, 4 MB cache provides a highperformance compute environment in a small footprint using a single switch slot Memory subsystems: 4 GB of DDR2-667 dual-channel memory provides for quick application performance Disk drive: 250 GB SATA II 7200 rpm hard disk drive (210 GB application space plus 40 GB diagnostic/maintenance space) allows quick data read/writes to speed applications along Resiliency and high availability Redundant power supplies: services module has the same level of power supply redundancy as the switch in which it is installed Redundant network connections: two internal 10-GbE connections are provided between the switch and the services module; applications can take advantage of both links to provide a redundant network connection to the switch backplane High availability: two modules can work together to provide high availability and redundancy; modules in the high-availability cluster share connection state information to provide stateful failover; active-standby failover is supported Manageability Console port: application console is available as a pass-through to the switch console function Ease of use Locator LED: allows users to set the locator LED on a specific module to either turn on, blink, or turn off; simplifies troubleshooting by making it easy to locate a specific module among other identical or similar modules Technical features Firewall features: Stateful Packet Inspection: filters based on destination and source IP address, port number, and protocol filter selector Logging/Alerts: logs messages in the WebTrends Enhance Log Format (WELF); logs are sent to syslog server and are sent via e-mail messages Enhanced Firewall Features: port triggering, resource reservation, service-based time-outs, traffic rate limiting, and DA - 13376 Worldwide Version 2 March 9, 2010 Page 3

connection rate limiting IPS/IDS Features: Anomaly Engine: patternless attack detection (ICMP, UDP smurf, DNS spoofing), protocol header integrity checks (mandatory fields, duplicate fields, buffer limits), SMTP, MIME, SMTP, FTP, DNS, NNTP, IP, UDP, and TCP Intrusion Protection: intrusion protection mechanisms, TCP buffering, and signature updates VPN Features: IPSec: AH, ESP, DES-CBC, 3DES-CBC, AES-128/192/256, HMAC-SHA1, HMAC-MD5, AES-XCBC, Tunnel mode, Transport mode, Extended Sequence Number Support, and UDP encapsulation for NAT traversal IKEv1: Main mode; Aggressive mode; Quick mode; Config mode; Diffe-Hellman Group 1, 2, and 5 support; SHA1; MD5; Pre-shared keys; RSA/DSA signatures; Xauth; and PFS PKI: SCEP client with PKCS#7 support Warranty and support ProCurve Lifetime Warranty: for as long as you own the product, with next-business-day advance replacement (available in most countries) Electronic and telephone support: limited electronic and telephone support is available from HP; refer to the HP Web site at www.procurve.com/support for details on the support provided and the period during which support is available * For as long as you own the product, with next-business-day advance replacement (available in most countries). The following hardware products and their related series modules have a one-year hardware warranty with extensions available: HP ProCurve Routing Switch 9300m Series, HP ProCurve Switch 8100fl Series, HP ProCurve Network Access Controller 800, and HP ProCurve DCM Controller. The following hardware mobility products have a one-year hardware warranty with extensions available: HP ProCurve M111 Client Bridge, HP ProCurve MSM3xx-R Access Points, HP ProCurve MSM7xx Mobility and Access Controllers, HP ProCurve RF Manager IDS/IPS Systems, HP ProCurve MSM Power Supplies, HP ProCurve 1-Port Power Injector, and HP ProCurve CNMS Appliances. Disk drives in the HP ProCurve ONE Services zl Modules have a five year hardware warranty. Standalone software, upgrades, or licenses may have a different warranty duration. For details, refer to the ProCurve Software License, Warranty, and Support booklet at www.procurve.com/warranty. DA - 13376 Worldwide Version 2 March 9, 2010 Page 4

Technical Specifications Physical characteristics Performance Environment Electrical characteristics Notes Dimensions Weight Firewall throughput IPS/IDS throughput VPN throughput 9.75(d) x 8.13(w) x 1.75(h) in. (24.77 x 20.65 x 4.45 cm) 3.25 lb. (1.47 kg) 3.0 Gbps 1.5 Gbps Dedicated IPsec VPN tunnels 4800 Concurrent sessions 600,000 New sessions/second 15,000 Number of policies 20,000 Number of users Number of VLANs 256 300 Mbps AES and 70 Mbps 3DES Unrestricted Operating temperature 32ºF to 122ºF (0ºC to 50ºC); important: see note for 50 C temperature specification rules Operating relative humidity Non-operating/Storage temperature Non-operating/Storage relative humidity Altitude Maximum heat dissipation Power consumption Notes 15% to 90% @ 122ºF (50ºC), non-condensing 14ºF to 149ºF (-10ºC to 65ºC) 15% to 95% @ 149ºF (65ºC), non-condensing up to 10,000 ft. (3 km) 272 BTU/hr (287 kj/hr) 80 W Maximum power rating and maximum heat dissipation are the worst-case theoretical maximum numbers provided for planning the infrastructure with fully loaded PoE (if equipped), 100% traffic, all ports plugged in, and all modules populated. Following are chassis operating temperature specifications of the 5400zl/8212zl switch when services modules are installed: 40 C when any services module is installed in the right side of the chassis 50 C when all services modules are installed in the left side of the chassis Up to four services modules can be installed in a 5400zl/8212zl chassis simultaneously. Up to three services modules are supported (all installed in the left half of the chassis) in the 5406zl chassis if a 50 C temperature specification is desired. Services When the services module is installed, the maximum relative humidity for the switch drops from 95% to 90%. 3-year, 4-hour onsite, 13x5 coverage for hardware (UQ589E) 3-year, 4-hour onsite, 24x7 coverage for hardware (UQ590E) 3-year, 4-hour onsite, 24x7 coverage for hardware, 24x7 software phone support (UQ591E) 3-Year, 9x5 SW phone support, software updates (UQ592E) 3-year, 24x7 SW phone support, software updates (UQ593E) 1-year, post-warranty, parts only, global next-day advance exchange (UQ594PE) 1-year, post-warranty, 4-hour onsite, 13x5 coverage for hardware (UQ595PE) 1-year, post-warranty, 4-hour onsite, 24x7 coverage for hardware (UQ596PE) 1-year, post-warranty, 4-hour onsite, 24x7 coverage for hardware, 24x7 software phone support DA - 13376 Worldwide Version 2 March 9, 2010 Page 5

Technical Specifications (UQ597PE) Installation with HP-provided configuration, system-based pricing (US668E) Refer to the HP Web site at www.procurve.com/services for details on the service-level descriptions and product numbers. For details about services and response times in your area, please contact your local HP sales office. DA - 13376 Worldwide Version 2 March 9, 2010 Page 6

Accessories Appliance HP ProCurve Threat Management Services 1-year IPS subscription J9157A HP ProCurve Threat Management Services 2-year IDS/IPS subscription J9158A HP ProCurve Threat Management Services 3-year IDS/IPS subscription J9159A with 1-year IDS/IPS subscription J9156A Software HP ProCurve Network Immunity Manager 2.0 software--50-device license J9161A HP ProCurve Network Immunity Manager 2.0 software--+100-device license J9162A HP ProCurve Network Immunity Manager 2.0 software--unlimited-device license J9163A To learn more, visit www.hp.com/go/procurve Copyright 2010 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein. Intel, Core, Pentium, and Xeon are trademarks of Intel Corporation in the U.S. and other countries. Microsoft, Windows, Windows NT, and Windows Vista are U.S. registered trademarks of Microsoft Corporation. DA - 13376 Worldwide Version 2 March 9, 2010 Page 7