下载
Juniper 网络公司 SSG 520(M) / SSG 550(M) 系列产品资料
概述
Juniper网络公司的安全业务网关500系列(SSG)是一种新型的专用安全设备,这些设备将高性能、安全性和局域网/广域网连接完美地组合起来,可以用于地区和分支办事处部署。产品提供一套全面的统一威胁管理(UTM)安全特性,包括状态防火墙、IPSec VPN、IPS、防病毒(包括防间谍软件、防广告软件、防网页仿冒)、防垃圾邮件和 Web 过滤等,可防止出入分支办事处的流量免遭蠕虫、间谍软件、特洛伊木马和恶意软件等安全攻击。
SSG 500 系列产品还提供强劲的路由引擎来补充强大的 UTM 安全特性,可以作为传统的分支办事处路由器部署,也可部署成防火墙和路由的综合产品,以降低前期购置和后期运行成本。
- SSG 520/SSG 520M:SSG 520 和 SSG 520M提供超过 650Mbps 的防火墙流量和 300Mbps 的IPSec VPN。
- SSG 550/SSG 550M:SSG 550 和 SSG 550M提供超过1Gbps的IMIX防火墙流量和 500Mbps的IPSec VPN。SSG 550支持冗余电源,并兼容NEBS。
对地区/分支办事处、中型企业和服务供应商来说,如果他们希望拥有一个安全平台,能够保护他们的WAN和高速内部网络,而同时还要通过高级别的系统和接口模块化扩展该平台的投资回报,那么,SSG 500 系列便是理想的选择。
特性与优势
Juniper网络公司SSG 500系列解决方案的关键特性与优势包括:
- 高性能专用平台,提供广域网连接性与安全性,还可以保护高速局域网免受内部网络层和应用层攻击
- 将安全和局域网/广域网路由功能组合在一起,可以提供合并设备并降低IT成本的能力
- 一套全面的统一威胁管理 (UTM) 安全特性,可防止网络和应用层攻击,同时阻断基于内容的攻击。UTM 安全特性包括:
- 状态检测防火墙,可进行接入控制并阻断网络层攻击
- IPS(深层检测防火墙),可阻断应用层攻击
- 基于卡巴斯基实验室扫描引擎的最佳防病毒特性,包括网页仿冒、间谍软件和广告软件防护等功能,可在病毒、特洛伊木马和其他恶意软件损害网络之前阻断它们
- 与赛门铁克合作阻断已知的垃圾邮件和网页仿冒攻击的发送方,提供防垃圾邮件功能
- 通过SurfControl 提供Web 过滤,阻止访问已知的恶意下载网站或其他不适当的 web 内容
- 站点间 IPSec VPN,可在办事处之间建立安全通信
- 拒绝服务(DoS) 攻击牵制功能
- 面向H.323、SIP、SCCP 和 MGCP 的应用层网关,用于检测并保护VoIP 流量
- 全面的局域网和广域网接口,支持串行、T1/E1、DS3、10/100/1000、SFP和FE
- 接口与路由灵活性,应对不断变化的网络连接性需求和未来的增长需求
- 多种高可用性选项,可以在一秒钟之内在接口或设备之间进行故障切换
- 可自定义的安全区,能够在不增加额外的硬件开销的情况下提高接口密度,降低策略创建成本,控制未经验证的用户和攻击,并简化防火墙/VPN的管理
- 通过图形Web UI、CLI或NetScreen-Security Manager 集中管理系统进行管理
- 基于策略的管理,允许集中的端到端生命周期管理
接口模块
在Juniper网络公司SSG 500系列上,支持下列模块:
技术规格
|
特性/容量
|
SSG 520
|
SSG 550
|
| 接口数 |
4x 10/100/1000 |
4x 10/100/1000 |
| 可信接口中的最多IP地址数 |
无限 |
无限 |
| 物理接口模块(PIM)扩展插槽 |
6 |
6 |
| 增强的PIM扩展插槽 |
2 |
4 |
| 广域网接口选项 |
串口, T1, E1, DS3 |
串口, T1, E1, DS3 |
| 局域网接口选项 |
SFP, FE, 10/100/1000 |
SFP, FE, 10/100/1000 |
| 最大吞吐量 |
650+ Mbps FW
600 Mbps IMIX FW
300 Mbps VPN
300 Mbps IPS |
1+ Gbps FW
1 Gbps IMIX FW
500 Mbps VPN
500 Mbps IPS |
| 每秒传输的防火墙数据包数 (64 字节) |
300,000 |
600,000 |
最多会话数
|
64,000 |
128,000 |
最多VPN隧道数
VPN Tunnels
|
500 |
1,000 |
最多策略数
|
1,000 |
4,000 |
最多虚拟局域网数
|
125 |
150 |
最多安全区数
|
60 |
60 |
| 最多虚拟路由器数 |
5 |
8 |
| 支持的广域网封装 |
帧中继、多链路帧中继、PPP、多链路PPP、HDLC |
帧中继、多链路帧中继、PPP、多链路PPP、HDLC |
| 支持的路由协议 |
OSPF, BGP, RIPv1/v2 |
OSPF, BGP, RIPv1/v2 |
| 支持的高可用性模式 |
主用/备用 |
主用/备用
主用/主用
|
| 升级到JUNOS 8.0 |
仅SSG 520M (需付费) |
仅SSG 520M (需付费) |
| 统一威胁管理 / 内容安全性(1) |
| IPS(深层检测防火墙) |
是 |
是 |
| 防病毒功能(1) |
是 |
是 |
| 特征数据库 |
100,000+ |
100,000+ |
| 扫描的协议 |
POP3, SMTP, HTTP, IMAP, FTP |
POP3, SMTP, HTTP, IMAP, FTP |
| 防间谍软件 |
是 |
是 |
| 防广告软件 |
是 |
是 |
| 防键盘记录 |
是 |
是 |
| 防垃圾邮件 |
是 |
是 |
| 集成 Web 过滤 |
是 |
是 |
| 外部 Web 过滤(2) |
是 |
是 |
(1) 统一威胁管理(UTM)安全特性(IPS/深层检测、防病毒防垃圾邮件和Web 过滤)需按年度从 Juniper 网络公司单独订购。年度订购提供特征更新及相关支持。UTM安全特性需要采用高配置内存选项。
(2) 重定向 Web 过滤将流量发送到副服务器,因此需要从Websense 或 SurfControl 单独购买 Web 过滤许可
SSG500系列配置组件,根据实际需求选购
| SSG 500 Series Base Systems |
| SSG-520B-001 |
SSG 520 System, 256 MB DRAM, AC Power |
| SSG-520-001 |
SSG 520 System, 1GB DRAM, AC Power |
| SSG-520-001-DC |
SSG 520 System, 1GB DRAM, DC Power |
| SSG-550B-001 |
SSG 550 System, 256 MB DRAM, 1 AC Power supply |
| SSG-550-001 |
SSG 550 System, 1GB DRAM, 1 AC Power Supply |
| SSG-550-001-DC |
SSG 550 System, 1GB DRAM, 1 DC Power Supply |
| SSG-550-001-NEBS |
SSG 550 System, 1GB DRAM 1 AC Power Supply, NEBS Compliant |
| SSG-550-001-NEBS-DC |
SSG 550 System, 1GB DRAM, 1 DC Power Supply, NEBS Compliant |
| SSG 500 Series Modules |
| JX-1DS3-S |
1xDS3 PIC - Spare |
| JX-2E1-RJ48-S |
2 Port E1 PIM with integrated CSU/DSU - Spare |
| JX-2Serial-S |
2 Port Serial PIM - Spare |
| JX-2T1-RJ48-S |
2 Port T1 PIM with integrated CSU/DSU - Spare |
| JXE-1GE-SFP-S |
1 Port Fiber Gigabit Ethernet Enhanced PIM, SFP sold separately - Spare. |
| JXE-1GE-TX-S |
1 Port Gigabit Ethernet 10/100/1000 Copper Enhanced PIM - Spare |
| JX-SFP-1GE-LX |
SFP 1000Base-LX Gigabit Optical Module for JXE-1GE-SFP-S |
| JX-SFP-1GE-SX |
SFP 1000Base-SX Gigabit Optical Module for JXE-1GE-SFP-S |
| JXE-4FE-TX-S |
SFP 1000Base-LX Gigabit Optical Module for JXE-1GE-SFP-S |
| SSG 500 Series Accessories |
| CBL-JX-PWR-AU |
J-Series Power Cable, Australia |
| CBL-JX-PWR-CH |
J-Series Power Cable, China |
| CBL-JX-PWR-EU |
J-Series Power Cable, Europe |
| CBL-JX-PWR-IT |
J-Series Power Cable, Italy |
| CBL-JX-PWR-JP |
J-Series Power Cable, Japan |
| CBL-JX-PWR-UK |
J-Series Power Cable, UK |
| CBL-JX-PWR-US |
J-Series Power Cable, US |
| JX-Blank-FP-S |
Blank Spare plate for J-Series |
| JX-CBL-EIA530-DCE |
EIA530 cable (DCE) for J-series |
| JX-CBL-EIA530-DTE |
EIA530 cable (DTE) for J-series |
| JX-CBL-RS232-DCE |
RS232 cable (DCE) for J-series |
| JX-CBL-RS232-DTE |
RS232 cable (DTE) for J-series |
| JX-CBL-RS449-DCE |
RS449 cable (DCE) for J-series |
| JX-CBL-RS449-DTE |
RS449 cable (DTE) for J-series |
| JX-CBL-V35-DCE |
V.35 cable (DCE) for J-series |
| JX-CBL-V35-DTE |
V.35 cable (DTE) for J-series |
| JX-CBL-X21-DCE |
X.21 cable (DCE) for J-series |
| JX-CBL-X21-DTE |
X.21 cable (DTE) for J-series |
| SSG-PS-AC |
Spare Power Supply for SSG 550, AC Power |
| SSG-PS-DC |
Spare Power Supply for SSG 550, DC Power |
| SSG-500-MEM-1GB |
1 Gigabyte DRAM Upgrade for the SSG 500 series |
| SSG-500-FLTR |
Replacement air filter for SSG 550 |
JUNIPER内容描述产品清单,根据实际需要选购(年付)
| First Year Subscriptions |
| Juniper-Kaspersky Anti-Virus |
| NS-K-AVS-HSC |
First year subscription for Juniper-Kaspersky AV updates on HSC |
| NS-K-AVS-HSCP |
First year subscription for Juniper-Kaspersky AV updates on HSC Plus |
| NS-K-AVS-5GT |
First year subscription for Juniper-Kaspersky AV updates on 5GT |
| NS-K-AVS-5GTP |
First year subscription for Juniper-Kaspersky AV updates on 5GT Plus |
| NS-K-AVS-5GTE |
First year subscription for Juniper-Kaspersky AV updates on 5GT Extended |
| NS-K-AVS-SSG520 |
First year subscription for Juniper-Kaspersky AV updates on SSG520 |
| NS-K-AVS-SSG550 |
First year subscription for Juniper-Kaspersky AV updates on SSG550 |
| Trend Anti-Virus |
|
| NS-AVS-HSC |
First year subscription for Trend AV, DI and ScreenOS updates on HSC |
| NS-AVS-5GT |
First year subscription for Trend AV, DI and ScreenOS updates on 5GT |
| NS-AVS-5GTP |
First year subscription for Trend AV, DI and ScreenOS updates on 5GT Plus |
| NS-AVS-5GTE |
First year subscription for Trend AV, DI and ScreenOS updates on 5GT Extended |
| Anti-Spam |
|
| NS-SPAM-HSC |
First year subscription for Anti-Spam updates on HSC |
| NS-SPAM-HSCP |
First year subscription for Anti-Spam updates on HSC Plus |
| NS-SPAM-5GT |
First year subscription for Anti-Spam updates on 5GT |
| NS-SPAM-5GTP |
First year subscription for Anti-Spam updates on 5GT Plus |
| NS-SPAM-5GTE |
First year subscription for Anti-Spam updates on 5GT Extended |
| NS-SPAM-25 |
First year subscription for Anti-Spam updates on NS-25 |
| NS-SPAM-50 |
First year subscription for Anti-Spam updates on NS-50 |
| NS-SPAM-ISG1000 |
First year subscription for Anti-Spam updates on ISG1000 |
| NS-SPAM-ISG2000 |
First year subscription for Anti-Spam updates on ISG2000 |
| NS-SPAM-SSG520 |
First year subscription for Anti-Spam updates on SSG520 |
| NS-SPAM-SSG550 |
First year subscription for Anti-Spam updates on SSG550 |
| Web Filtering |
|
| NS-WF-HSC |
First year subscription for Web Filtering on HSC |
| NS-WF-HSCP |
First year subscription for Web Filtering on HSC Plus |
| NS-WF-5GT |
First year subscription for Web Filtering on 5GT |
| NS-WF-5GTP |
First year subscription for Web Filtering on 5GT Plus |
| NS-WF-5GTE |
First year subscription for Web Filtering on 5GT Extended |
| NS-WF-25 |
First year subscription for Web Filtering on NS-25 |
| NS-WF-50 |
First year subscription for Web Filtering on NS-50 |
| NS-WF-ISG1000 |
First year subscription for Web Filtering on ISG1000 |
| NS-WF-ISG2000 |
First year subscription for Web Filtering on ISG2000 |
| NS-WF-SSG520 |
First year subscription for Web Filtering on SSG520 |
| NS-WF-SSG550 |
First year subscription for Web Filtering on SSG550 |
| Main Office Content Security |
| NS-SMB-CS-HSC |
First year security subscription for Main Office - includes AV, DI, WF & Anti-Spam on HSC |
| NS-SMB-CS-HSCP |
First year security subscription for Main Office - includes AV, DI, WF & Anti-Spam on HSC Plus |
| NS-SMB-CS-5GT |
First year security subscription for Main Office - includes AV, DI, WF & Anti-Spam on 5GT |
| NS-SMB-CS-5GTP |
First year security subscription for Main Office - includes AV, DI, WF & Anti-Spam on 5GT Plus |
| NS-SMB-CS-5GTE |
First year integrated security subscription for SMB - includes AV, DI, WF & Anti-Spam on 5GTE |
| NS-SMB-CS-SSG520 |
First year integrated security subscription for SMB - includes AV, DI, WF & Anti-Spam on SSG520 |
| NS-SMB-CS-SSG550 |
First year integrated security subscription for SMB - includes AV, DI, WF & Anti-Spam on SSG550 |
| Remote and Branch Office Integrated Content Security |
| NS-RBO-CS-HSC |
1st year security subscription for Remote/Branch office, includes AV, DI & WF on HSC |
| NS-RBO-CS-HSCP |
1st year security subscription for Remote/Branch office, includes AV, DI & WF on HSC Plus |
| NS-RBO-CS-5GT |
1st year security subscription for Remote/Branch office, includes AV, DI & WF on 5GT |
| NS-RBO-CS-5GTP |
1st year security subscription for Remote/Branch office, includes AV, DI & WF on 5GT Plus |
| NS-RBO-CS-5GTE |
1st year security subscription for Remote/Branch office, includes AV, DI & WF on 5GTE |
| NS-RBO-CS-SSG520 |
1st year security subscription for Remote/Branch office, includes AV, DI & WF on SSG520 |
| NS-RBO-CS-SSG550 |
1st year security subscription for Remote/Branch office, includes AV, DI & WF on SSG550 |
| Deep Inspection |
|
| NS-DI-HSC |
First year subscription for Deep Inspection Signature updates on a HSC |
| NS-DI-HSCP |
First year subscription for Deep Inspection Signature updates on a HSC Plus |
| NS-DI-5GT |
First year subscription for Deep Inspection Signature updates on a 5GT |
| NS-DI-5GTE |
First year subscription for Deep Inspection Signature updates on a 5GT Extended |
| NS-DI-5GTP |
First year subscription for Deep Inspection Signature updates on a 5GT Plus |
| NS-DI-5XT |
First year subscription for Deep Inspection Signature updates on a 5XT |
| NS-DI-5XTE |
First year subscription for Deep Inspection Signature updates on a 5XT Elite |
| NS-DI-25 |
First year subscription for Deep Inspection Signature updates on a NS-25 |
| NS-DI-50 |
First year subscription for Deep Inspection Signature updates on a NS-50 |
| NS-DI-204 |
First year subscription for Deep Inspection Signature updates on a NS-204 |
| NS-DI-208 |
First year subscription for Deep Inspection Signature updates on a NS-208 |
| NS-DI-500 |
First year subscription for Deep Inspection Signature updates on a NS-500 |
| NS-DI-5200 |
First year subscription for Deep Inspection Signature updates on a NS-5200 |
| NS-DI-5400 |
First year subscription for Deep Inspection Signature updates on a NS-5400 |
| NS-DI-ISG-1000 |
First year subscription for Deep Inspection Signature updates on a ISG-1000 |
| NS-DI-ISG-2000 |
First year subscription for Deep Inspection Signature updates on a ISG 2000 |
| NS-DI-SSG520 |
First year subscription for Deep Inspection on SSG520 |
| NS-DI-SSG550 |
First year subscription for Deep Inspection on SSG550 |
|