Juniper SSG5, SSG20 Datasheet

SSG5 AND SSG20 SECURE SERVICES GATEWAYS
DATASHEET
Product Overview
The Juniper Networks SSG5 and SSG20 Secure Services Gateways are purpose-built security appliances that deliver a perfect blend of performance, security, routing and LAN/WAN connectivity for small branch offi ces, fi xed telecommuters and small standalone business deployments. Traffi c fl owing in and out of the branch offi ce or business is protected from worms, spyware, trojans, and malware by a complete set of Unifi ed Threat Management security features that include stateful fi rewall, IPsec VPN, intrusion prevention system (IPS), antivirus (includes anti-spyware, anti-adware, anti-phishing), anti­spam and Web fi ltering.
Product Description
The Juniper Networks® SSG5 and SSG20 Secure Services Gateways are high­performance security platforms for small branch offi ce and standalone businesses that want to stop internal and external attacks, prevent unauthorized access and achieve regulatory compliance. Both the SSG5 and SSG20 deliver 160 Mbps of stateful fi rewall traffi c and 40 Mbps of IPsec VPN traffi c.
Security: Protection against worms, viruses, trojans, spam, and emerging malware is delivered by proven unifi ed threat management (UTM) security features that are backed by best-in-class partners. To address internal security requirements and facilitate regulatory compliance, the SSG5 and SSG20 both support an advanced set of network protection features such as security zones, virtual routers and VLANs that allow administrators to divide the network into distinct secure domains, each with its own unique security policy. Policies protecting each security zone can include access control rules and inspection by any of the supported UTM security features.
REGIONAL OFFICE
Zone A
INTERNET
SSG20
HEADQUARTERS
M7i
NetScreen-5400
Zone C
The SSG20 deployed at a branch offi ce for secure Internet connectivity and site-to-site VPN to
corporate headquarters. Internal wired and wireless resources are protected with unique security
Zone B
policies applied to each security zone.
1
Connectivity and Routing: The SSG5 has seven on-board 10/100
interfaces with optional fixed WAN ports. The SSG20 has five 10/100 interfaces with two I/O expansion slots for additional WAN connectivity. The broad array of I/O options coupled with WAN protocol and encapsulation support in the routing engine make both the SSG5 and the SSG20 a solution that can easily be deployed as a traditional branch office router or as a consolidated security and routing device to reduce CapEx and OpEx. Both the SSG5 and SSG20 support 802.11 a/b/g as a factory configured option supported by a wide array of wireless specific security features.
Access Control Enforcement: The SSG5 and SSG20 can act as enforcement points in a Juniper Networks Unified Access Control deployment with the simple addition of the IC Series UAC appliance. The IC Series functions as a central policy management engine, interacting with the SSG5 or SSG20 to augment or replace the firewall-based access control with a solution that grants/denies access based on more granular criteria that include endpoint state and user identity in order to accommodate the dramatic shifts in attack landscape and user characteristics.
World Class Support: From simple lab testing to major network implementations, Juniper Networks Professional Services will collaborate with your team to identify goals.
Features and Benefits
FEATURE FEATURE DESCRIPTION BENEFIT
High performance Purpose-built platform is assembled from
custom-built hardware, powerful processing and a security-specific operating system.
Delivers performance headroom required to protect against internal and external attacks now and into the future.
Best-in-class UTM security features
Integrated antivirus Annually licensed antivirus engine is based on
Integrated anti-spam Annually licensed anti-spam offering is based on
Integrated Web filtering Annually licensed Web filtering solution is based
Integrated IPS (Deep Inspection) Annually licensed IPS engine. Prevents application-level attacks from flooding
Fixed Interfaces Seven fixed 10/100 interfaces on the SSG5, and five
Network segmentation Security zones, virtual LANs and virtual routers
Interface modularity Two interface expansion slots (SSG20 only)
UTM security features (antivirus, anti-spam, Web filtering, IPS) stop all manner of viruses and malware before they damage the network.
Kaspersky Lab engine.
Sophos technology.
on Websense SurfControl technology.
fixed 10/100 interfaces on the SSG20. The SSG5 is factory configured with either RS232 Serial/AUX or ISDN BRI S/T or V.92 fixed WAN backup. Both models include one console port and one auxiliary port.
allow administrators to deploy security policies to isolate guests, wireless networks and regional servers or databases.
supporting optional ADSL 2+, T1, E1, ISDN BRI S/T, Serial, SFP and v.92 Mini physical interface modules (Mini-PIMs).*
Ensures that the network is protected against all manner of attacks.
Stops viruses, spyware, adware and other malware.
Blocks unwanted email from known spammers and phishers.
Controls/blocks access to malicious Web sites.
the network.
Provides high-speed LAN connectivity, redundant WAN connectivity and flexible management.
Facilitates deployment of internal security to prevent unauthorized access, contain attacks and assist in achieving regulatory compliance.
Delivers combination of LAN and WAN connectivity on top of unmatched security to reduce costs and extend investment protection.
Robust routing engine Proven routing engine supports OSPF, BGP, and
802.11 a/b/g wireless-specific security features
*Serial and SFP Mini-PIMs only supported in ScreenOS 6.0 or greater releases
2
RIP v1/2.
Wireless-specific privacy and authentication features augment the UTM security capabilities to protect wireless traffic.
Enables the deployment of a consolidated security and routing device, thereby lowering operational and capital expenditures.
Provides additional device consolidation opportunities (WLAN access point, security, routing) for small office environment.
Features and Benefi ts (continued)
FEATURE FEATURE DESCRIPTION BENEFIT
Juniper Networks Unifi ed Access Control enforcement point
Interacts with the centralized policy management engine (IC Series) to enforce session-specifi c access control policies using criteria such as user identity, device security state and network location.
Improves security posture in a cost-effective manner by leveraging existing customer network infrastructure components and best-in-class technology.
Management fl exibility Use any one of three mechanisms, command
World-class professional services
line interface (CLI), WebUI or Juniper Networks Network and Security Manager (NSM) to securely deploy, monitor and manage security policies.
From simple lab testing to major network implementations, Juniper Networks Professional Services will collaborate with your team to identify goals, defi ne the deployment process, create or validate the network design and manage the deployment.
Enables management access from any location, eliminating onsite visits thereby improving response time and reducing operational costs.
Transforms the network infrastructure to ensure that it is secure, fl exible, scalable and reliable.
Product Options
OPTION OPTION DESCRIPTION APPLICABLE PRODUCTS
DRAM
Unifi ed Threat Management/Content Security (high memory option required)
I/O options
802.11 a/b/g connectivity
Extended license
The SSG5 and SSG20 are available with either 128 MB or 256 MB of DRAM.
The SSG5 and SSG20 can be confi gured with any combination of the following best-in-class UTM and content security functionality: antivirus (includes anti-spyware, anti-phishing), IPS (Deep Inspection), Web fi ltering and/or anti-spam.
Two interface expansion slots supporting optional ADSL 2+, T1, E1, ISDN BRI S/T, Serial, SFP and v.92 Mini physical interface modules (Mini-PIMs).
The SSG5 and SSG20 can be factory confi gured for
802.11 a/b/g wireless LAN connectivity. Key capacities can be increased (sessions, VPN
tunnels, VLANs) and stateful high availability (HA) support for fi rewall and VPN can be added.
SSG5 and SSG20
High memory SSG5 or SSG20 only
SSG20 only
SSG5 and SSG20
SSG5 and SSG20
SSG5
SSG20
SSG5 Wireless
SSG20 Wireless
3
Specifications
(1)
SSG5 BASE/EXTENDED SSG20 BASE/EXTENDED
Maximum Performance and Capacity
ScreenOS® version tested ScreenOS 6.2 ScreenOS 6.2
Firewall performance (Large packets) 160 Mbps 160 Mbps
Firewall performance (IMIX)
Firewall packets per second (64 byte) 30,000 PPS 30,000 PPS
Advanced Encryption Standard (AES) 256+SHA-1 VPN performance
3DES encryption +SHA-1 VPN performance 40 Mbps 40 Mbps
Maximum concurrent sessions 8,000/16,000 8,000/16,000
New sessions/second 2,800 2,800
Maximum security policies 200 200
Maximum users supported Unrestricted Unrestricted
(3)
(2)
90 Mbps 90 Mbps
40 Mbps 40 Mbps
Network Connectivity
Fixed I/O 7x10/100 5x10/100
Mini-Physical Interface Module (Mini-PIM) slots 0 2
WAN interface options Factory configured: RS232 Serial AUX or ISDN
BRI S/T or V.92
Mini-PIMs: 1xADSL 2+, 1xT1, 1xE1, V.92, ISDN
BRI S/T, 1xSFP, 1xSerial
Firewall
Network attack detection Yes Yes
DoS and DDoS protection Yes Yes
TCP reassembly for fragmented packet protection Yes Yes
Brute force attack mitigation Yes Yes
SYN cookie protection Yes Yes
Zone-based IP spoofing Yes Yes
Malformed packet protection Yes Yes
Unified Threat Management
IPS (Deep Inspection firewall) Yes Yes
Protocol anomaly detection Yes Yes
Stateful protocol signatures Yes Yes
IPS/DI attack pattern obfuscation Yes Yes
Antivirus Yes Yes
Instant message AV Yes Yes
Signature database 200,000+ 200,000+
Protocols scanned POP3, HTTP, SMTP, IMAP, FTP, IM POP3, HTTP, SMTP, IMAP, FTP, IM
Anti-spyware Yes Yes
Anti-adware Yes Yes
Anti-keylogger Yes Yes
Anti-spam Yes Yes
Integrated URL filtering Yes Yes
External URL filtering
(5)
(4)
Yes Yes
VoIP Security
H.323. Application-level gateway (ALG) Yes Yes
SIP ALG Yes Yes
MGCP ALG Yes Yes
SCCP ALG Yes Yes
Network Address Translation (NAT) for VoIP protocols Yes Yes
4
Loading...
+ 8 hidden pages