Virtual system supportSupports up to 500 virtual firewalls – each with a
unique set of administrators, policies, VPNs, and
address books.
World-class professional servicesFrom simple lab testing to major network
implementations, Juniper Networks Professional
Services will collaborate with your team to identify
goals, define the deployment process, create or
validate the network design, and manage the
deployment.
flexibility required to protect large enterprise and
carrier environments.
Ensures scalable performance and low latency in
sensitive applications such as VoIP and streaming
media.
Prevents unauthorized access, contains any attacks
that may occur, and facilitates regulatory compliance.
Provides the reliability required for high-speed network
deployments.
Achieve maximum availability and ensure
synchronization for sub-second failover between
interfaces or devices.
Simplifies network integration and helps reduce the
cost of future network upgrades.
Facilitates the deployment of the NetScreen Series as
a combined security and LAN routing device, lowering
operational and capital expenditures.
Reduces the number of physical units and allows
the partitioning of the network into separate
administrative domains.
Transforms the network infrastructure to ensure that it
is secure, flexible, scalable, and reliable.
Product Options
OPTIONOPTION DESCRIP TIONAPPLICABLE PRODU CTS
Integrated IPS (Deep Inspection)Prevents application level attacks from flooding the
network using a combination of stateful signatures
and protocol anomaly detection mechanisms. IPS is
annually licensed.
Web filtering (redirect)Block access to malicious Web sites using a Web
filtering redirect solution such as SurfControl or
Websense technology.
Virtual systemsSupports up to 500 virtual firewalls—each with a
unique set of administrators, policies, VPNs, and
address books.
2
NetScreen-5200 and
NetScreen-5400
NetScreen-5200 and
NetScreen-5400
NetScreen-5200 and
NetScreen-5400
Page 3
NETSCREEN-5200
NETSCREEN-5400
Specifications
NetScreeN-5 200NetScreeN-5 400
Maximum Performance and Capacity
ScreenOS® version testedScreenOS 6.2ScreenOS 6.2
Firewall performance (large packets)
2
Firewall performance (small packets)4 Gbps12 Gbps
Firewall Packets Per Second (64 byte) 6 M PPS18 M PPS
AES256+SHA-1 VPN performance
3DES+SHA-1 VPN performance
Maximum concurrent sessions
New sessions/second
10
2
2
3
Maximum security policies40,00040,000
Maximum users supported UnrestrictedUnrestricted
Network Connectivity
Fixed I/O
Interface expansion slots
LAN interface options
Firewall
Network attack detectionYesYes
Denial of Service (DoS) and Distributed Denial of Service
(DDoS) protection
TCP reassembly for fragmented packet protectionYesYes
Brute force attack mitigationYesYes
SYN cookie protectionYesYes
Zone-based IP spoofingYesYes
Malformed packet protectionYesYes
Unified Threat Management / Content Security
IPS (Deep Inspection firewall)
Protocol anomaly detection
Stateful protocol signatures
IPS/Deep Inspection attack pattern obfuscation
External URL filtering
5
1
10/8 Gbps30/24 Gbps
5/4 Gbps15/12 Gbps
5/4 Gbps15/12 Gbps
1,000,0002,000,000
26,500/22,00026,500/22,000
00
2 (1 x Management, 1 x SPM)4 (1 x Management, 3 x SPM)
8 mini-GBIC (SX, LX or TX), or 2 XFP 10Gig
(SR or LR)
8 mini-GBIC (SX, LX or TX), or 2 XFP 10Gig
(SR or LR)
YesYes
4
YesYes
YesYes
YesYes
YesYes
YesYes
(9)
3
Page 4
Specifications (continued)
NetScreeN-5 200NetScreeN-5 400
VoIP Security
H.323 ALG
SIP ALG
MGCP ALG
SCCP ALG
NAT for VoIP protocols YesYes
IPsec VPN
Concurrent VPN tunnels
Tunnel interfaces
DES (56-bit), 3DES (168-bit) and AES encryptionYesYes
MD-5 and SHA-1 authenticationYesYes
Manual key, IKE, PKI (X.509), IKEv2 with EAPYesYes
Perfect forward secrecy (DH Groups)1,2,51,2,5
Prevent replay attack YesYes
Remote access VPNYesYes
L2TP within IPsecYesYes
IPsec NAT traversalYesYes
Redundant VPN gatewaysYesYes
3
3
User Authentication and Access Control
Built-in (internal) database - user limit
Third-party user authenticationRADIUS, RSA SecurID, and LDAPRADIUS, RSA SecurID, and LDAP
RADIUS AccountingYes – start/stopYes – start/stop
XAUTH VPN authenticationYesYes
Web-based authenticationYesYes
802.1X authenticationYesYes
Unified access control enforcement pointYesYes
3
PKI Support
PKI Certificate requests (PKCS 7 and PKCS 10)YesYes
Operating temperature32° to 105° F (0° to 45° C)32° to 105° F (0° to 45° C)
Non-operating temperature- 4° to 158° F (-20° to 70° C)- 4° to 158° F (-20° to 70° C)
Humidity10% to 90% noncondensing10% to 90% noncondensing
17.5 X 8.6 X 14 in
(44.5 X 21.8 X 35.6 cm)
(1) Performance, capacity and features listed are based upon systems running ScreenOS 6.2 and are the measured maximums under ideal testing conditions unless otherwise noted. Actual results
may vary based on ScreenOS release and by deployment. Please note the firewall/VPN performance data are identical for MGT2/SPM2 and MGT3/SPM3 configurations. For a complete list of
supported ScreenOS versions for NetScreen Series Security Systems, please visit the Juniper Customer Support Center (www.juniper.net/customers/support/).
(2) Listed first, higher performance numbers are achieved with 2XGE, lower numbers with the 8G2 Secure Port Modules.
(3) Shared among all virtual systems.
(4) IPS/Deep Inspection is delivered by annual subscriptions purchased separately from Juniper Networks. Annual subscriptions provide signature updates and associated support.
(5) Redirect Web filtering sends traffic to a secondary server and therefore entails purchasing a separate Web filtering license from either Websense or SurfControl.
(6) Requires purchase of virtual system key. Every virtual system includes one virtual router and two security zones, usable in the virtual or root system.
(7) NAT, PAT, policy based NAT, virtual IP, mapped IP, virtual systems, virtual routers, VLANs, OSPF, BGP, RIPv2, Active/Active HA, and IP address assignment are not available in
layer 2 transparent mode.
(8) Not available with virtual systems.
(9) Two million sessions requires at least two Secure Port Modules (8G2 or 2XGE).
(10) The first numbers are performance achieved with the new MGT3/8G2-G4 modules, and the second numbers represent the performance achieved with the MGT2/8G2 modules.
Juniper Networks Services and Support
Juniper Networks is the leader in performance-enabling services and support, which are designed to accelerate, extend, and optimize
your high-performance network. Our services allow you to bring revenue-generating capabilities online faster so you can realize bigger
productivity gains and faster rollouts of new business models and ventures. At the same time, Juniper Networks ensures operational
excellence by optimizing your network to maintain required levels of performance, reliability, and availability. For more details, please visit
www.juniper.net/us/en/products-services/.
7
Page 8
Ordering Information
MODEL NUMBERDESCRIPTION
NetScreen-5200
NS-5200NS-5200 system, no SPM or MGT modules,
NS-5200-DC NS-5200 system, no SPM or MGT modules,
Note: Add Management and SPM Modules to build complete systems
NetScreen-5400
NS-5400 NS-5400 system, no SPM or MGT modules,
NS-5400-DCNS-5400 system, no SPM or MGT modules,
Note: Add Management and SPM Modules to build complete systems
NetScreen Series – Components needed to build
complete systems
NS-5000-MGT2Management Module 2
NS-5000-2XGE2 x 10GigE Secure Port Module (SPM) – does NOT
NS-5000-8G28 x GigE Secure Port Module 2 (SPM) – includes
NS-5000-8G2-TX8 x GigE Secure Port Module 2 TX (SPM) – includes
NS-5000-MGT3*Management Module 3
NS-5000-2XGE-G4*2 x 10GigE Secure Port Module (SPM) – does NOT
NS-5000-8G2-G4*8 x GigE Secure Port Module (SPM) – includes
NS-5000-8G2-G4-TX*8 x GigE Secure Port Module (SPM) – includes
* The NS-5000-MGT3, NS-5000-2XGE-G4, NS-5000-8G2-G4, and NS-5000-8G2-G4-
TX modules require ScreenOS version 6.1 or higher and CANNOT be intermixed with prior
generation management or SPM modules. Customer who wish to deploy NetScreen Series
systems with the latest Management Module 3 must also deploy the latest G4 SPM modules.
includes fan tray, dual AC power supply, 19”
rack mount, 0 VSYS
includes fan tray, dual DC power supply, 19”
rack mount, 0 VSYS
includes fan tray, 3 x AC power supply, 19”
rack mount, 0 VSYS
includes fan tray, 3 x DC power supply, 19”
rack mount, 0 VSYS
include transceivers
8 x transceivers (SX)
8 x Gig copper transceivers
include transceivers
8 x transceivers (SX)
8 x Gig copper transceivers
MODEL NUMBERDESCRIPTION
NetScreen Series – Virtual System Upgrades
NS-5000-VSYS-5VSYS upgrade 0 to 5
NS-5000-VSYS-25VSYS upgrade 5 to 25
NS-5000-VSYS-50VSYS upgrade 25 to 50
NS-5000-VSYS-100VSYS upgrade 50 to 100
NS-5000-VSYS-250VSYS upgrade 100 to 250
NS-5000-VSYS-500VSYS upgrade 250 to 500
NS-5000-VSYSVSYS upgrade 0 to 500
NetScreen Series – Accessories
NS-SYS-GBIC-MSXSX transceiver (mini-GBIC)
NS-SYS-GBIC-MLXLX transceiver (mini-GBIC)
NS-SYS-GBIC-MXSRXFP 10GigE transceiver Short Range (SR) (300 m)
NS-SYS-GBIC-MXLRXFP 10GigE transceiver Long Range (LR) (10 km)
NetScreen-5200 – Components
NS-5200-CHANetScreen-5200 chassis
NS-5200-PWR-ACNetScreen-5200 AC power supply
NS-5200-PWR-DCNetScreen-5200 DC power supply
NS-5200-FANNetScreen-5200 fan assembly
NetScreen-5400 – Components
NS-5400-CHANetScreen-5400 chassis
NS-5400-PWR-ACNetScreen-5400 AC power supply
NS-5400-PWR-DCNetScreen-5400 DC power supply
NS-5400-FANNetScreen-5400 fan assembly
About Juniper Networks
Juniper Networks, Inc. is the leader in high-performance
networking. Juniper offers a high-performance network
infrastructure that creates a responsive and trusted environment
for accelerating the deployment of services and applications
over a single network. This fuels high-performance businesses.
Additional information can be found at www.juniper.net.
Corporate and Sales Headquarters
Juniper Networks, Inc.
1194 North Mathilda Avenue
Sunnyvale, CA 94089 USA
Phone: 888.JUNIPER (888.586.4737)
or 408.745.2000
Fax: 408.745.2100
www.juniper.net
Copyri ght 2010 Juniper Netw orks, Inc. All r ights reser ved. Juniper N etworks, t he Juniper Net works logo, Jun os,
NetScr een, and Screen OS are registere d trademarks o f Juniper Netw orks, Inc. in th e United States and oth er
countri es. All other trad emarks, se rvice marks , registered m arks, or regis tered serv ice marks are th e property o f
their re spective own ers. Junipe r Networks a ssumes no res ponsibilit y for any inaccurac ies in this docum ent. Juniper
Netwo rks reser ves the right to cha nge, modify, tran sfer, or otherw ise revise thi s publication w ithout notice.
1100007-005-EN Nov 2010
APAC Headquar ters
Juniper Networks (Hong Kong)
26/F, Citypla za One
1111 King’s Road
Taikoo Shing, Hong Kong
Phone: 852. 2332.3636
Fax: 852.2574.7803
Printed o n recycled pape r
8
EMEA Headquarters
Juniper Networks Ireland
Airside Business Park
Swords, County D ublin, Ireland
Phone: 35.31.8903.600
EMEA Sales: 00800.4586.4737
Fax: 35.31.8903.601
To purchase Juniper Networks solutions,
please contact your Juniper Networks
representative at 1-866-298-6428 or
authorized reseller.
Loading...
+ hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.