USG2110 Unified Security Gateways

Similar documents
HUAWEI TECHNOLOGIES CO., LTD. HUAWEI Secospace USG2000&5000 Datasheet

Eudemon200E-X Series Unified Security Gateway

Huawei Cloud Fabric Data Center Security and Application Optimization Solution

NIP6000 Next-Generation Intrusion Prevention System

Next-Generation Firewall Series Datasheet

Venusense UTM Introduction

Copyright Huawei Technologies Co., Ltd All rights reserved. Trademark Notice General Disclaimer

ISG-600 Cloud Gateway

Next-Generation Firewall Series Datasheet

Data Sheet. DPtech IPS2000 Series Intrusion Prevention System. Overview. Series IPS2000-MC-N. Features

NetDefend Firewall UTM Services

HUAWEI USG6330/6350/6360 Next-Generation Firewalls ---Securely and Reliably Connect Smalland Medium-Sized Businesses

NetDefend UTM Firewall Series

DPX17000 Deep Service Core Switch

Eudemon 1000E. Eudemon 1000E Series Product Quick Reference. Huawei Technologies Co., Ltd.

HUAWEI USG6620/6630 Next-Generation Firewalls ---Best-in-Class Security for Mediumsized

HUAWEI USG6370/6380/6390 Next-Generation Firewalls ---Comprehensive Protection for Medium- Sized Businesses

Eudemon8000E-X Series

DPX19000 Next Generation Cloud-Ready Service Core Platform

Security Quick Sales Guide

Secospace USG5000 Series Unified Security Gateway

Huawei NIP2000/5000 Intrusion Prevention System

Quick Sales Guide. Security

Future-ready security for small and mid-size enterprises

Training UNIFIED SECURITY. Signature based packet analysis

HUAWEI USG6650/6660/6670/6680 Next-Generation Firewalls ---High-Performance Security for Small Data Centers and Large or Medium-sized Enterprises

NETWORKING &SECURITY SOLUTIONSPORTFOLIO

Huawei USG5500 Unifies Security Gateway Specification reference

Symantec Protection Suite Add-On for Hosted Security

Systrome Next Gen Firewalls

Data Sheet. DPtech Anti-DDoS Series. Overview. Series

UTM Content Security Gateway

Data Sheet. DPtech FW1000 Series Firewall. Overview

Secure and Always Online Networking for Small- to Medium-sized Businesses

2 ZyWALL UTM Application Note

Content. Initial Contact. Further Follow-Up. Bidding Guidance

Security Assessment Checklist

SteelGate Overview. Manage perimeter security and network traffic to ensure operational efficiency, and optimal Quality of Service (QoS)

Cisco ASA 5500 Series IPS Solution

DATA SHEET MODEL AXC1000 HIGHLIGHTS OVERVIEW. Redefining Enterprise Wireless Management

ZyWALL USG100-PLUS Unified Security Gateway. Security on a New Level. Benefits. - The Future Is Ahead. Stay Ahead with ZyXEL USG100-PLUS

USG9500 Series Terabit Level Next-Generation Firewall

Take Back Control: Increase Security, Empower Employees, Protect the Business

Medium / Large Enterprises Next-Generation UTM NU-850C

Medium / Large Enterprises Next-Generation UTM NU-850C

AT&T Endpoint Security

HiPER 518W-Plus. 300Mbps Wireless 3G VPN Router. Overview. Features DATA SHEET. Highlights

Klaudia Bakšová System Engineer Cisco Systems. Cisco Clean Access

USG9500 Series Terabit Level Next-Generation Firewall

Security on a New Level -The Future Is Ahead. Stay Ahead with ZyXEL USGs.

Hardening the Education. with NGFW. Narongveth Yutithammanurak Business Development Manager 23 Feb 2012

Surat Smart City Development Ltd. Surat Municipal Corporation 1

AC750GW 750Mbps. Dual band Gigabit Wireless Router. Overview DATA SHEET. Highlights

NETWORK THREATS DEMAN

HUAWEI USG6305/6310S/6320 Next-Generation Firewalls ---Best-in-Class Access Security for Small Businesses

Unified Threat Management Systems

Exam: : VPN/Security. Ver :

HUAWEI USG6000 Series Next-Generation Firewall Intelligent Aware Engine (IAE) Technical White Paper HUAWEI TECHNOLOGIES CO., LTD. Issue V1.

Data Sheet. DPtech FW1000 Series Firewall. Overview

Chapter 1 B: Exploring the Network

HUAWEI USG6000 Series Next-Generation Firewall Technical White Paper VPN HUAWEI TECHNOLOGIES CO., LTD. Issue 1.1. Date

UTM Firewall Registration & Activation Manual DFL-260/ 860. Ver 1.00 Network Security Solution

Synchronized Security

Business Strategy Theatre

Symantec Client Security. Integrated protection for network and remote clients.

SECURITY FOR SMALL BUSINESSES

Unified Services Routers

ASA/PIX Security Appliance

The SonicWALL PRO Series

Evaluation criteria for Next-Generation Firewalls

Corrigendum 3. Tender Number: 10/ dated

Gigabit SSL VPN Security Router

Cyberoam. Unified Threat Management. Comprehensive Network Security

Configuration Example

GDPR Get Secured, Be Compliant

System Architecture Overview for THE Juniper Networks SSG500 Line

AlliedWare Plus UTM FIREWALL OVERVIEW

BUFFERZONE Advanced Endpoint Security

Anti-DDoS. FAQs. Issue 11 Date HUAWEI TECHNOLOGIES CO., LTD.

USG310/210/110. Benefits. Always online. Protection and optimization. Next Generation Firewall (NGFW) for small and medium-sized businesses

VPN Routers DSR-150/250/500/1000AC. Product Highlights. Features. Overview. Comprehensive Management Capabilities. Web Authentication Capabilities

Defense-in-Depth Against Malicious Software. Speaker name Title Group Microsoft Corporation

NSG50/100/200 Nebula Cloud Managed Security Gateway

PineApp Mail Secure SOLUTION OVERVIEW. David Feldman, CEO

Introduction to Information Security Dr. Rick Jerz

FEATURE OVERVIEW. FGX Series firewall. Last updated February 2012

Securing the Empowered Branch with Cisco Network Admission Control. September 2007

All-in one security for large and medium-sized businesses.

Unified Services VPN Routers

Passit4Sure (50Q) Cisco Advanced Security Architecture for System Engineers

Data Communication. Chapter # 5: Networking Threats. By: William Stalling

Symantec Endpoint Protection 14

FIREWALL PROTECTION AND WHY DOES MY BUSINESS NEED IT?

Cisco 5921 Embedded Services Router

BUFFERZONE Advanced Endpoint Security

Understanding Networking Fundamentals

Ethical Hacking and Prevention

IxLoad-Attack TM : Network Security Testing

Endpoint Protection : Last line of defense?

Cisco ASA 5500 Series IPS Edition for the Enterprise

Transcription:

USG2110 Unified Security Gateways The USG2110 series is Huawei's unified security gateway developed to meet the network security needs of various organizations including the small enterprises, branch offices, operating nodes, and SOHOs. Based on industry-leading software and hardware architectures, the USG2110 series offers user-based security policies which integrate the professional security technologies including IPS, antivirus (AV), URL filtering, application control, and anti-spam (AS). This series supports IPv6 protection and related transition technology, and provides powerful, scalable, and sustainable security capabilities for customers. USG2110 Product Features Exceptional performance and high stability Superior performance for mass service processing: Provides 180 Mbit/s of firewall throughput, 40 Mbit/s of VPN throughput, and the multi-thread processing technology to ensure fast data and security service processing and improve user experience. Super-long MTBF, ensuring service continuity: Provides a stable VSP software platform and continuous fault-free operation to ensure the stability and reliability of your business network. 6-22

Professional security for secure networks Industry-leading AV engine with 99% identification accuracy: Based on extensive experience in AV technology, the AV engine features file-class content scanning. The USG2110 series integrates the AV technology with global-leading emulation environment and virtual execution technology to provide a 99% identification ratio, acknowledged by numerous international assessment organizations. Professional IPS engine, disabling attack variants: With traditional attack code-based defenses, a huge signature database needs to be maintained and updated to defend against attack variants. This overloads the IPS engine and leads to substandard detection performance and a high rate of false negatives and false positives. The USG2110 series is backed by advanced vulnerability defense technology and delivers virtual patches for vulnerabilities (instead of attack code), disabling various attack variants. Comprehensive AS capabilities: ensures the security of enterprise mail servers. Employees' emails are filtered based on the mail body, subject, keyword, or attachment to avoid information leak and the import of insecure factors. Real-time updates by a professional team, defending against zero-day attacks: A globally deployed honeynet system, together with a professional team of over 300 people, make it possible to keep abreast of the latest, hottest, and most dangerous system and software vulnerabilities. You get rapid defense against zero-day attacks and a more secure office network. Online behavior management, improving employee productivity Plentiful website categories, building a green Internet access environment: The URL database containing 85 million website URLs and over 130 content categories helps to shield against Trojan horse-embedded and phishing sites, block pornographic and gambling sites, delivers green network environment, regulate employee online behaviors and prevent them from engaging in activities that would harm internal network security, and avoid lawful risks. Sophisticated application management, creating an efficient office network: The USG2110 series identifies over 1200 application protocols. Multi-dimensional control measures based on the time, applications, users, bandwidth, and connection numbers ensure bandwidth for mission-critical services and improve the bandwidth usage. You can work more efficiently and have P2P, IM, game sites, and other websites under control. Various reports: The USG2110 series displays user behaviors by user, application, traffic, and behavior to help you learn about network status. Flexible configuration and quick deployment User-oriented security policy: The USG2110 series provides authority control of fine granularity based on technologies such as user-based access control, traffic limiting, application control and content security, and policy-based routing. Free from the complexity of IP-based configuration, the USG2110 series is easy and flexible to configure and provides more accurate authority control. Unified policy configuration: You can configure all policies on a centralized configuration interface, which simplifies, speeds up, and ensures the completeness of the configuration. Professional configuration wizard: The USG2110 series provides a Web-based configuration wizard and a friendly user interface to guide administrative operations. 6-23

Application Scenarios Network Isolation and VPN Interconnection Challenges for customers: Network areas are not clearly divided, access control is insufficient, and the data transmitted between mobile employees or branches and the headquarters is likely to be intercepted or tampered. Highlights of the solution: delivers high throughput to avoid bottleneck at network borders, supports security zones to clearly divide networks, offers flexible packet filtering policies to accurately control communication, and decapsulates and checks packets of VPN users to ensure the security of data communication. External Threat Prevention Challenges for customers: Coming along with the abundant Internet resources are threats such as DDoS attacks, malicious intrusions and viruses. Highlights of the solution: The capabilities of supporting large numbers of concurrent connections and new connections per second help to combat the numerous DDoS attacks. Empowered by Symantec's advanced IPS and anti-virus technologies as well as vulnerability-based and real-time updated signature database, the USG2000/5100 series implements near-zero false positives and negatives and a detection ratio of higher than 99%; defends against diversified threats from the Internet, and ensures the security of the intranet. 6-24

Online Behavior Management Challenges for customers: None-work-related Internet surfing, P2P download, online games, and stock transaction waste bandwidths for business, reduce employee productivity, and pose potential risks from malicious codes and hacker attacks. Highlights of the solution: The USG2000/5100 series provides over 1000 kinds of identifiable applications, providing visibility into the applications running on your network. The URL database containing 6.5 million website URLs helps to shield against Trojan horse-embedded and phishing sites, block pornographic and gambling sites, regulate employee online behaviors and prevent them from engaging in activities that would harm internal network security. Multi-dimensional control measures based on users, applications, time, and bandwidth ensure bandwidth for mission-critical services and improve the bandwidth usage. You can work more efficiently and have P2P, IM, game sites, and other websites under control. Product Specifications Model USG2110-F USG2110-F-W Fixed WAN Ports 2*10/100 WAN 2*10/100 WAN Fixed LAN Ports 8*10/100 LAN 8*10/100 LAN Maximum Ethernet density 10FE 10FE Expansion slots / / Throughput (bps) 180M 180M New connections 2000 2000 Con-current connections 100,000 100,000 ACL 3000 3000 Number of Virtual Firewalls 10 10 6-25

Model USG2110-F USG2110-F-W USB 1 (v2.0) 1 (v2.0) Wi-Fi N Y 3G Y Y IPS Y Y AV Y Y URL Filtering Y Y AS Y Y IPv6 Y Y Hardware Acceleration Y Y Expansion Cards N N Dimensions (H x W x D) 280x190x35mm 280x190x35mm Weight (full configuration) <2.0 kg <2.0 kg Power Supply AC:100~240V No redundancy AC:100~240V No redundancy MTBF 12.67 year 12.67 year Feature IPS AV AS URL Filtering Application Control VPN Anti-DDoS Routing Deployment and Reliability Defends system vulnerabilities, defends against unauthorized download, spoofing software, and spyware/adware, and provides protocol identification. Supports file identification and filtering, efficient virus scanning, and can detects more than 7,000,000 viruses. Supports local whitelist, local blacklist, remote real-time blacklist, content filtering, keyword filtering, and mail filtering based on the types, sizes, and numbers of attachments. Identifies more than 85 million URLs (blacklist/whitelist filtering, remote category filtering, user-defined category filtering, search engine keyword filtering, malicious URL filtering, and phishing site filtering). Identifies and manages over 1200 application protocols covering all mainstream applications, such as QQ, NetEase PoPo, AliTalk, PPStream, PPLive, Thunder, emule, StongHuaShun, DaZhiHui, MSN, GoogleTalk, Youtube, Facebook, BitTorrent, and Skype. IPSec VPN SSL VPN MPLS VPN GRE VPN L2TP VPN Defends against various DoS and DDoS attacks, such as SYN flood, ICMP flood, and UDP flood attacks. IPv4:Static RIP OSPF BGP IS-IS IPv6:RIPng OSPFv3 BGP4+ IPv6 IS-IS IPv6RD ACL6 Supports transparent, routing, and composite deployment modes, and active/active and active/standby backup modes. 6-26