SSG140 Secure Services Gateway - Chicago Web Hosting

Transcription

DATASHEETSSG140 SECURESERVICES GATEWAYProduct OverviewThe SSG140 Secure Services Gatewayis a purpose-built security appliancethat delivers a perfect blend ofperformance, security, routing andLAN/WAN connectivity for mediumsized branch offices and businessdeployments. Traffic flowing in andout of the branch office or business isprotected from worms, spyware, trojans,and malware by a complete set ofUnified Threat Management securityfeatures that include stateful firewall,IPsec VPN, intrusion prevention system(IPS), antivirus (includes antispyware,antiadware, antiphishing), antispamand Web filtering.Product DescriptionThe Juniper Networks SSG140 Secure Services Gateway is a high-performance securityplatform for branch offices and small/medium sized standalone businesses that want tostop internal and external attacks, prevent unauthorized access, and achieve regulatorycompliance. The SSG140 is a modular platform that delivers more than 350 Mbps ofstateful firewall traffic and 100 Mbps of IPsec VPN traffic.Security: Protection against worms, viruses, trojans, spam, and emerging malware isdelivered by proven unified threat management (UTM) security features that are backedby best-in-class partners. To address internal security requirements and facilitateregulatory compliance, the SSG140 supports an advanced set of network protectionfeatures such as security zones, virtual routers and VLANs that allow administrators todivide the network into distinct, secure domains, each with its own unique security policy.Policies protecting each security zone can include access control rules and inspection byany of the supported UTM security features.Connectivity and Routing: The SSG140 supports ten on-board interfaces (eight 10/100plus two 10/100/1000) complemented by four I/O expansion slots that can houseadditional WAN interfaces (T1, E1, ISDN BRI S/T and Serial), making the SSG140 the mostextensible security platform in its class. This broad array of I/O options coupled with WANprotocol and encapsulation support in its routing engine make the SSG140 a platform thatcan easily be deployed as a traditional branch office router or as a consolidated securityand routing device to reduce CapEx and OpEx.Access Control Enforcement: The SSG140 can act as an enforcement point in a JuniperNetworks Unified Access Control (UAC) deployment with the simple addition of theIC Series UAC appliance. The IC Series functions as a central policy management engine,interacting with the SSG140 to augment or replace the firewall-based access control witha solution that grants/denies access based on more granular criteria that include endpointstate and user identity, in order to accommodate the dramatic shifts in attack landscapeand user characteristics.World Class Support: From simple lab testing to major network implementations,Juniper Networks Professional Services will collaborate with your team to identify goals,define the deployment process, create or validate the network design, and manage thedeployment to its successful conclusion.1

Branch OfficeHeadquartersWWWZONE AInternetSSG140M7iISG2000ZONE BThe SSG140 deployed at a branch offi ce for secure Internet connectivity and site-to-site VPN to corporate headquarters.Internal branch offi ce resources are protected with unique security policies for each security zone.Features and BenefitsFEATUREFEATURE DESCRIPTIONBENEFITHigh performancePurpose-built platform is assembled from custom-builthardware, powerful processing and a security-specificoperating system.Delivers performance headroom required to protectagainst internal and external attacks now and into thefuture.Best-in-class UTM securityfeaturesUTM security features (antivirus, antispam, Web filtering,IPS) stop all manner of viruses and malware before theydamage the network.Ensures that the network is protected against all mannerof attacks.Integrated antivirusAnnually licensed antivirus engine, provided by Juniper, isbased on Kaspersky Lab engine.Stops viruses, spyware, adware and other malware.Integrated antispamAnnually licensed antispam offering, provided by Juniper,is based on Sophos technology.Blocks unwanted email from known spammersand phishers.Integrated Web filteringAnnually licensed Web filtering solution, provided byJuniper, is based on Websense SurfControl technology.Controls/blocks access to malicious Web sites.Integrated IPS (DeepInspection)Annually licensed IPS engine.Prevents application-level attacks from floodingthe network.Fixed InterfacesEight fixed 10/100 interfaces and two 10/100/1000interfaces, one USB port, one console port, and oneauxiliary port.Provides high-speed LAN connectivity, futureconnectivity, and flexible management.Network segmentationBridge groups, security zones, virtual LANs and virtualrouters allow administrators to deploy security policies toisolate guests, wireless networks and regional servers ordatabases.*Powerful capabilities facilitate deploying security forvarious internal, external and DMZ sub-groups on thenetwork, to prevent unauthorized access.Robust routing engineProven routing engine supports OSPF, BGP and RIP v1/2along with Frame Relay, Multilink Frame Relay, PPP,Multilink PPP and HDLC.Enables the deployment of consolidated security androuting device, thereby lowering operational and capitalexpenditures.High interface densityEight 10/100 plus two 10/100/1000 interfaces plus aconsole and an Aux interface for management.Provides unmatched interface density when compared tocompetitive offerings.Interface modularityFour SSG140 interface expansion slots support optionalT1, E1, ISDN BRI S/T, ADSL2 , G.SHDSL and serialphysical interface modules (PIMs), and 10/100/1000 andSFP universal PIMs (uPIMs).**Delivers LAN and WAN connectivity options on topof unmatched security to reduce costs and extendinvestment protection.Management flexibilityUse any one of three mechanisms, CLI, WebUI orJuniper Networks Network and Security Manager (NSM),to securely deploy, monitor and manage security policies.Enables management access from any location,eliminating on-site visits thereby improving responsetime and reducing operational costs.Juniper Networks UnifiedAccess Control enforcementpointInteracts with the centralized policy management engine(IC Series) to enforce session-specific access controlpolicies using criteria such as user identity, device securitystate, and network location.Improves security posture in a cost-effective mannerby leveraging existing customer network infrastructurecomponents and best-in-class technology.World-class professionalservicesFrom simple lab testing to major network implementations,Juniper Networks Professional Services will collaborate withyour team to identify goals, define the deployment process,create or validate the network design, and manage thedeployment.Transforms the network infrastructure to ensure that it issecure, flexible, scalable and reliable.Auto-Connect VPNAutomatically sets up and takes down VPN tunnelsbetween spoke sites in a hub-and-spoke topology.Provides a scalable VPN solution for mesh architectureswith support for latency-sensitive applications such asVoIP and video conferencing.* Bridge groups supported only on uPIMs in ScreenOS 6.0 and greater releases**uPIMs are only supported in ScreenOS 6.0 or greater releases2

Product OptionsOPTIONOPTION DESCRIPTIONAPPLICABLE PRODUCTSDRAMThe SSG140 is available with either 256 MB or512 MB of DRAM.SSG140Unified Threat Management/Content Security (high memoryoption required)The SSG140 can be configured with any combinationof the following best-in-class UTM and contentsecurity functionality: antivirus (includes antispyware,antiphishing), IPS (Deep Inspection), Web filtering,and/or antispam.SSG140 high memory model onlyI/O optionsFour SSG140 interface expansion slots supportoptional T1, E1, ISDN BRI S/T, ADSL2 , G.SHDSLand serial physical interface modules (PIMs), and10/100/1000 and SFP universal PIMs (uPIMs).SSG140Unified Threat Management(3) (continued)SSG140SpecificationsSignature database200,000 Protocols scannedPOP3, HTTP, SMTP, IMAP,FTP, ant message AVYesAntispamYesIntegrated URL filteringYesExternal URL filtering(4)YesMaximum Performance and Capacity(1)VoIP SecurityScreenOS version testedScreenOS 6.2H.323. Application-level gateway (ALG)YesFirewall throughput (large packets)350 MbpsSIP ALGYesFirewall throughput (IMIX)(2)300 MbpsMGCP ALGYesFirewall packets per second (64 byte)90,000 PPSSCCP ALGYesAdvanced Encryption Standard (AES)256 SHA-1 VPN throughput100 MbpsNetwork Address Translation (NAT) for VoIPprotocolsYes3DES encryption SHA-1 VPN throughput100 MbpsIPsec VPNMaximum concurrent sessions48,000Concurrent VPN tunnels500New sessions/second8,000Tunnel interfaces50Maximum security policies1,000YesMaximum users supportedUnrestrictedDES encryption (56-bit), 3DES encryption(168-bit) and AES (256-bit)MD-5 and SHA-1 authenticationYesManual key, Internet Key Exchange (IKE),IKEv2 with EAP public key infrastructure (PKI)(X.509)YesPerfect forward secrecy (DH Groups)1,2,5Prevent replay attackYesRemote access VPNYesLayer 2 Tunneling Protocol (L2TP) within IPsecYesI Psec Network Address Translation (NAT)traversalYesAuto-Connect VPNYesRedundant VPN gatewaysYesNetwork ConnectivityFixed I/O8x10/100, 2x10/100/1000Physical Interface Module (PIM) slots4Modular WAN/LAN interface options (PIMs/uPIMs)2xT1, 2xE1, 2xSerial, 1xISDNBRI S/TSFP, 10/100/1000FirewallNetwork attack detectionYesDoS and DDoS protectionYesTCP reassembly for fragmented packetprotectionYesBrute force attack mitigationYesSYN cookie protectionYesUser Authentication and Access ControlZone-based IP spoofingYesBuilt-in (internal) database user limit250YesThird-party user authenticationRADIUS, RSA SecureID,LDAPRADIUS AccountingYes – start/stopXAUTH VPN authenticationYesWeb-based authenticationYes802.1X authenticationYesMalformed packet protectionUnified Threat Management(3)IPS (Deep Inspection firewall)YesProtocol anomaly detectionYesStateful protocol signaturesYesIPS/DI attack pattern obfuscationAntivirusYesYesUnified Access Control (UAC) enforcement point Yes3

Specifications (continued)IPv6PKI SupportPKI certificate requests (PKCS 7 and PKCS 10)YesDual stack IPv4/IPv6 firewall and VPNYesAutomated certificate enrollment (SCEP)YesYesOnline Certificate Status Protocol (OCSP)YesIPv4 to/from IPv6 translations andencapsulationsVerisign, Entrust, Microsoft,RSA Keon,iPlanet (Netscape)Baltimore, DOD PKISyn-Cookie and Syn-Proxy DoS AttackDetectionYesCertificate Authorities supportedSIP, RTSP, Sun-RPC, and MS-RPC ALG’sYesRIPngYesBGPYesTransparent modeYesNSRPYesDHCPv6 RelayYesSelf signed certificatesYesVirtualizationMaximum number of security zones40Maximum number of virtual routers6Bridge groups*YesMaximum number of VLANs100RoutingBGP instances6BGP peers24BGP routes2,048OSPF instances3OSPF routes2,048RIPv1/v2 instancesMode of OperationLayer 2 (transparent) mode(5)YesLayer 3 (route and/or NAT) modeYesAddress TranslationNetwork Address Translation (NAT)YesPort Address Translation (PAT)YesPolicy-based NAT/PAT (L2 and L3 mode)YesMapped IP (MIP) (L3 mode)1,500Virtual IP (VIP) (L3 mode)1664MIP/VIP Grouping (L3 mode)YesRIP v2 routes2,048IP Address AssignmentStatic routes2,048StaticYesSource-based routingYesYesPolicy-based routingYesEqual-cost multipath (ECMP)YesDynamic Host Configuration Protocol(DHCP),Point-to-Point Protocol over Ethernet(PPPoE) clientInternal DHCP serverYesMulticastYesDHCP relayYesReverse Forwarding Path (RFP)YesI nternet Group Management Protocol (IGMP)(v1, v2)YesIGMP ProxyYesP rotocol Independent Multicast (PIM) singlemodeYesPIM source-specific multicastMulticast inside IPsec tunnelYesYesYes - per policyHigh Availability (HA)YesSession synchronization for firewall and VPNYesSession failover for routing changeYesVRRPYesDevice failure detectionYesYesLink failure detectionYes4Authentication for new HA membersYesYesEncryption of HA trafficYes4YesEncapsulations (continued)*Bridge groups supported only on uPIMs in ScreenOS 6.0 and greater releases4YesDifferentiated Services markingYesYesHDLCYesPriority-bandwidth utilizationConfiguration synchronizationMultilink Point-to-Point Protocol (MLPPP)MLFR max physical interfacesYes - per policyIngress traffic policingYesYesMultilink Frame Relay (MLFR) (FRF 15, FRF 16)Yes - per policyMaximum bandwidthActive/passive - Transparent & L3 modePoint-to-Point Protocol (PPP)Frame relayGuaranteed bandwidthActive/active - L3 modeEncapsulationsMLPPP max physical interfacesTraffic Management Quality of Service (QoS)

Specifications (continued)System ManagementDimensions and PowerWebUI (HTTP and HTTPS)YesCommand line interface (console)YesCommand line interface (telnet)YesCommand line interface (SSH)Yes – v1.5 and v2.0compatibleNetwork and Security Manager (NSM)YesAll management via VPN tunnel on anyinterfaceYesRapid deploymentNoAdministrationDimensions (W x H x D)17.5 x 1.8 x 15 in(44.5 x 4.5 x 38.1 cm)Weight10.2 lb (4.63 kg)Rack mountableYes, 1RUPower supply (AC)100-240 VAC,AC Input line frequency50 Hz or 60 HzAC system currentrating 2 AMaximum thermal output580 BTU/hour (170 W)Noise Level48.8 dBLocal administrator database size20CertificationsExternal administrator database supportRADIUS, RSA SecureID,LDAPSafety certificationsUL, CUL, CSA, CBFCC class B, CE class BRestricted administrative networks6Electromagnetic compatibility (EMC)certificationsRoot Admin, Admin, and Read Only user levelsYesNetwork Equipment Building System (NEBS)NoSoftware upgradesTFTP, WebUI, NSM, SCP,USBMean time between failures (MTBF) (Bellcoremodel)16 yearsConfiguration roll-backYesSecurity CertificationsLogging/MonitoringCommon Criteria: EAL4FutureSystem log (multiple servers)Yes – up to 4 serversFIPS 140-2: Level 2FutureEmail (2 addresses)YesICSA Firewall and VPNYesNetIQ WebTrendsYesOperating EnvironmentSNMP (v2)YesOperating temperature32 to 104 F (0 to 40 C)SNMP full custom MIBYesNon-operating temperatureTracerouteYes-4 to 158 F(-20 to 70 C)VPN tunnel monitorYesHumidity10% to 90% noncondensingExternal FlashAdditional log storageUSB 1.1Event logs and alarmsYesSystem configuration scriptYesScreenOS SoftwareYes(1) Performance, capacity and features listed are based upon systems running ScreenOS 6.2and are the measured maximums under ideal testing conditions unless otherwise noted.Actual results may vary based on ScreenOS release and deployment. For a complete list ofsupported ScreenOS versions for SSG Series gateways, please visit the Juniper CustomerSupport Center (www.juniper.net/customers/support/) and click on ScreenOS SoftwareDownloads.(2) IMIX stands for Internet mix and is more demanding than a single packet size as it representsa traffic mix that is more typical of a customer’s network. The IMIX traffic used is made upof 58.33% 64 byte packets 33.33% 570 byte packets 8.33% 1518 byte packets of UDPtraffic.(3) UTM Security features (IPS/Deep Inspection, antivirus, antispam and Web filtering) aredelivered by annual subscriptions purchased separately from Juniper Networks. Annualsubscriptions provide signature updates and associated support. The high memory option isrequired for UTM Security features.(4) Redirect Web filtering sends traffic from the firewall to a secondary server. The redirectfeature is free, however it does require the purchase of a separate Web filtering license fromeither Websense or SurfControl.(5) NAT, PAT, policy-based NAT, virtual IP, mapped IP, virtual systems, virtual routers, VLANs,OSPF, BGP, RIPv2, active/active HA and IP address assignment are not available in layer 2transparent mode.IPS (Deep Inspection firewall) Signature PacksSignature packs provide the ability to tailor the attack protection to the specific deployment and/or attack type. The following signaturepacks are available for the SSG140:SIGNATURE PACKTARGET DEPLOYMENTDEFENSE TYPETYPE OF ATTACK OBJECTBaseBranch offices, small/mediumbusinessesClient/server and worm protectionRange of signatures and protocolanomaliesClientRemote/branch officesPerimeter defense, compliance for hosts(for example desktops)Attacks in the server-to-client directionServerSmall/medium businessesPerimeter defense, compliance forserver infrastructureAttacks in the client-to-server directionWorm mitigationRemote/branch offices of largeenterprisesMost comprehensive defense againstworm attacksWorms, trojans, backdoor attacks5

Juniper Networks Services and SupportJuniper Networks is the leader in performance-enabling servicesand support, which are designed to accelerate, extend, andMODEL NUMBERDESCRIPTIONUnified Threat Management/Content Security(High Memory Option Required)optimize your high-performance network. Our services allowNS-K-AVS-SSG140Antivirus (antispyware, antiphishing)you to bring revenue-generating capabilities online faster soNS-DI-SSG140IPS (Deep Inspection)you can realize bigger productivity gains and faster rollouts ofNS-SPAM2-SSG140Antispamnew business models and ventures. At the same time, JuniperNS-WF-SSG140Web filteringNetworks ensures operational excellence by optimizing yourNS-RBO-CS-SSG140Remote Office Bundle (AV, IPS, WF)network to maintain required levels of performance, reliability, andNS-SMB2-CS-SSG140Main Office Bundle (AV, IPS, WF, AS)availability. For more details, please visit www.juniper.net/us/en/*uPIMs are only supported in ScreenOS 6.0 or greater releasesproducts-services/.SSG140 Memory Upgrades, Spares and Communications CablesOrdering InformationMODEL NUMBERDESCRIPTIONSSG140SSG-140-SBSSG140 with 256 MB memory, 0 PIM cards, ACpowerSSG-140-SHSSG140 with 512 MB memory, 0 PIM cards, AC powerSSG140 I/O OptionsJX-1BRI-ST-S1-port ISDN BRI S/T PIMJX-2E1-RJ48-S2-port E1 PIM with integrated CSU/DSUJX-2T1-RJ48-S2-port T1 PIM with integrated CSU/DSUJX-2Serial-S2-port Serial PIMJX-1ADSL-A-S1-port ADSL 2/2 Annex A PIMJX-1ADSL-B-S1-port ADSL 2/2 Annex B PIMJX-2SHDSL-S1-port G.SHDSL PIMJXU-6GE-SFP-S6-port SFP Gigabit Ethernet Universal PIM*JXU-1SFP-S1-port SFP 100 Mbps or Gigabit Ethernet UniversalPIM * (SFP sold separately)JXU-8GE-TX-S8-port Gigabit Ethernet 10/100/1000 CopperUniversal PIM*JXU-16GE-TX-S16-port Gigabit Ethernet 10/100/1000 CopperUniversal PIM** uPIMs are only supported in ScreenOS 6.0 or greater releasesSSG-100-MEM-512512 MB DIMM Memory upgradeCBL-JX-PWR-AUPower Cable, AustraliaCBL-JX-PWR-CHPower Cable, ChinaCBL-JX-PWR-EUPower Cable, EuropeCBL-JX-PWR-ITPower Cable, ItalyCBL-JX-PWR-JPPower Cable, JapanCBL-JX-PWR-UKPower Cable, UKCBL-JX-PWR-USPower Cable, USJX-Blank-FP-SBlank I/O plateJX-CBL-EIA530-DTEEIA530 cable (DTE)JX-CBL-RS232-DTERS232 cable (DTE)JX-CBL-RS449-DTERS449 cable (DTE)JX-CBL-V35-DTE35 cable (DTE)JX-CBL-X21-DTEX.21 cable (DTE)Note: The appropriate power cord is included based upon the sales order “Ship To” destinationAbout Juniper NetworksJuniper Networks, Inc. is the leader in high-performancenetworking. Juniper offers a high-performance networkinfrastructure that creates a responsive and trusted environmentfor accelerating the deployment of services and applicationsover a single network. This fuels high-performance businesses.Additional information can be found at www.juniper.net.Corporate and Sales HeadquartersAPAC HeadquartersEMEA HeadquartersTo purchase Juniper Networks solutions,Juniper Networks, Inc.Juniper Networks (Hong Kong)Juniper Networks Irelandplease contact your Juniper Networks1194 North Mathilda Avenue26/F, Cityplaza OneAirside Business ParkSunnyvale, CA 94089 USA1111 King’s RoadSwords, County Dublin, Irelandrepresentative at 1-866-298-6428 orPhone: 888.JUNIPER (888.586.4737)Taikoo Shing, Hong KongPhone: 35.31.8903.600or 408.745.2000Phone: 852.2332.3636EMEA Sales: 00800.4586.4737Fax: 408.745.2100Fax: 852.2574.7803Fax: 35.31.8903.601authorized reseller.www.juniper.netCopyright 2010 Juniper Networks, Inc. All rights reserved. Juniper Networks, the Juniper Networks logo, Junos, NetScreen, andScreenOS are registered trademarks of Juniper Networks, Inc

UTM security features (antivirus, antispam, Web filtering, IPS) stop all manner of viruses and malware before they damage the network. Ensures that the network is protected against all manner of attacks. Integrated antivirus Annually license