Vous êtes sur la page 1sur 6

Secospace USG5300

Secospace USG5300
Secospace USG5300

Product Overview
With the dramatic increase in threats to networks, users are and possesses the industry’s most comprehensive protocol
become ever more concerned by application- and service- library. These unique resources allow Huawei Symantec to
based network security problems. As security threats such offer in-depth analysis of network threats aimed at different
as malicious intrusions, phishing Web sites, Trojan horse protocols, and provides users with technical support to
programs, and P2P applications proliferate, the efficiency of combat a wide range of network security problems.
enterprise networks is reduced and their security threatened. Developed by Huawei Symantec, the USG5300 series is a new-
Huawei Symantec Technologies Co., Ltd. (hereafter referred to generation multi-function firewall. Delivering comprehensive
as Huawei Symantec) is dedicated to providing comprehensive advanced security functions such as VPN, IPS, anti-virus, and
network security solutions for users. Huawei Symantec URL filtering, it provides all-around security protection to
organizes an industry-leading network protocol analysis team safeguard the efficient running of network systems.

Product Family

USG5310/5320/5330/5350/5360

Product Features
Perfect Firewall Functions USG5300 series with a robust, reliable security operating

•• Advanced Architecture and Platform system.

Adopting an advanced multi-core hardware architecture •• Industry-leading Performance

and multi-thread concurrent processing, the USG5300 series Multi-core concurrent processing technology substantially

optimizes the security service processing flow, especially the enhances the USG5300’s per formance allowing it to

processing of header packets. All these features equip the concurrently process dozens of threads. With three industry-

USG5300 series with an industry-leading firewall indicator — leading performance indexes, the USG5300 provides an

the number of new connections per second – enabling it to exceptional performance experience for customers. New

easily deal with mass network traffic. Moreover, the USG5300 connections per second, the key firewall performance indicator,

series separates data decapsulation and in-depth detection, can comfortably reach 150,000, setting a clear lead for the

and concurrently implements multiple types of in-depth industry. Quickly setting up a large number of connections for

detection, considerably promoting the performance of its in- network access, the USG5300 provides high-speed forwarding

depth detection state. With ten years of successful commercial rates and low delay. This performance advantage also enables

application, the mature VRP software platform furnishes the the USG5300 to effectively process burst and attack traffic – fully
Secospace USG5300

meeting customer demand for high-speed bandwidth increase. that can be identified increases. In so doing, the USG5300
•• Super-Capacity VPN series controls the P2P traffic of abundant protocols at Kbps-
As an organization extends its service, the number of branches level speeds. Moreover, the USG5300 series controls different
and employees on business trips increases, imposing more modes of P2P traffic such as single user-based, group-based,
demands for encrypted data transmission. Supporting and global control, effectively safeguarding bandwidth
L2TP, GRE, and IPSec VPN functions, the USG5300 series resources. By helping users plan network traffic, it dramatically
facilitates flexible selection and configuration. Its advanced enhances a network’s application value.
hardware architecture allows for high VPN performance
and 15000 VPN tunnels, freeing users from worries about Leading UTM Functions
the security of encrypted data transmission. The data of •• IPS Intrusion Detection
various network applications, including heavy-traffic video Using Symantec's advanced IPS detection engine, the IPS
and audio applications, can be transmitted at high speed Intrusion Detection function efficiently and accurately scans
in the encrypted tunnel, enabling users to enjoy Gbps-level network packets. Any IPS evasion and deception techniques
encrypted data transmission. are also accurately identified. With advanced software and
Note: The VPN function is optional. Customers can purchase related license hardware platforms, and a rich signature library, the USG5300
to apply this function. series unified security gateway rapidly and accurately identifies
•• Powerful DDoS Defense any application layer attacks mixed in with normal traffic.
Protecting key network services against DDoS attacks is a vital Symantec's global deployment of honeypot systems catches
security problem for organization-level users. With the large the latest attacks, worms, Trojans and other threats, instantly
number of new connections per second, the USG5300 series extracting their signatures and providing timely updates. The
defends against DDoS attacks at speeds of up to millions of USG5300 series unified security gateway offers zero-attack
packets per second, providing effective DDoS defense for defense capability.
users' service systems. Based on its powerful protocol analysis •• Anti-Virus
capability, the USG5300 series accurately identifies and Using Symantec's advanced virus detection engine, an Anti-
controls many DDoS attacks such as SYN, UDP, ICMP, and DNS Virus function efficiently and accurately detects viruses
floods, and CC attacks. It also identifies and defends against hidden in network traffic. Advanced software and hardware
worm-infected traffic. By integrating Huawei Symantec’s platforms, and a rich Accessible Virus library provide the
proprietary ICA, the USG5300 series precisely identifies DDoS USG5300 series with unique antivirus capabilities allowing it to
traffic without affecting users' access, providing genuine identify compression shelling and other techniques to evade
security protection on complicated networks. All these confirm detection.
that the USG5300 series is the industry’s leading DDoS defense Symantec's global distribution network of analysis virus
solution. monitoring, and professional team of the virus, USG5300
•• Accurate P2P Traffic Control series of unified security gateways can obtain the latest virus
P2P traffic is a broadband killer. Disrupting service applications, signatures and the latest anti-virus engines timely. USG5300
it is a key concern for most organizations. In practice, series unified security gateway can keep high efficiency and
controlling P2P traffic is extremely difficult due to protocol precise antivirus ability.
flexibility. Utilizing Huawei Symantec’s powerful network •• URL Filtering
protocol analysis capability, the USG5300 series precisely Using an advanced matching engine, the URL filtering
identifies up to 50 types of P2P traffic. It supports library function greatly shortens URL match times and makes URL
upgrades and with each upgrade, the number of protocols filtering more efficient. A huge URL classification database
Secospace USG5300

and powerful URL classification capabilities allow for accurate been guiding principles in the design of the USG5300 series.
URL filtering. A flexible security policy allows the URL Numerous components have been optimized to reduce power
filtering function to apply to most scenarios. Friendly, easy consumption. Indeed the USG5300 series uses only 25% of
configuration greatly improves the URL filtering function's the power consumed by similar products, greatly reducing
usability. Thanks to all these features, the USG5300 series maintenance costs.
unified security gateway offers powerful functionality together The USG5300 series strictly adheres to the European Union's
with ease of operation and maintenance. "Restriction on the use of Hazardous Substances in Electrical
and Electronic Equipment" (RoHS) code. Constructed of

Eco-friendly Experience pollution-free, environmentally-friendly materials, it will

"High performance and low power consumption" have enhance your green credentials.

Typical Networking

USG2000

Branch
Remote user IPSec VPN
IPSec VPN
Internet VPN tunnel

Fir Key service system


VP ewall
USG2000 URL Anti-v IPS N
filte irus
ring Link aggregation
SOHO
IPSec or L2TP VPN
USG5300

Data center Intranet


Online behavior management

Typical networking diagram of the USG5300


Secospace USG5300

Product Specifications
Model USG5310 USG5320 USG5330 USG5350 USG5360

Firewall Maximum throughput 1.5 Gbps 2 Gbps 4 Gbps 6 Gbps 8 Gbps

IPS Goodput(UDP) 600Mbps 800Mbps 1Gbps 1.3Gbps 1.5Gbps

AV Goodput 60Mbps 80Mbps 100Mbps 130Mbps 150Mbps

URL Filtering Support Support Support Support Support

Connections per second 50,000 60,000 80,000 100,000 150,000

Number of concurrent connections 1,600,000 1,600,000 1,600,000 2,000,000 2,000,000

Maximum VPN throughput 1 Gbps 2 Gbps 4 Gbps 5 Gbps 6 Gbps

Number of VPN tunnels 15,000 15,000 15,000 15,000 15,000

Maximum number of ACL rules 30,000 30,000 30,000 30,000 30,000

Maximum GTP throughput 1.5 Gbps 2 Gbps 4 Gbps 6 Gbps 8 Gbps

Maximum number of GTP tunnels 200,000 200,000 200,000 200,000 200,000

Maximum number of virtual firewalls 100 100 100 100 100

4 GE optical and electrical (mutually exclusive) interfaces


Fixed interface 1 console port
2 USB interfaces

Number of extension slots 2

4×FE (10/100M) interface module


Type of extension modules 2×GE optical and electrical interface module
4×GE interface module

Dimensions (mm) (W×D×H) 436×560×44.2

Weight 10 kg

AC: 100 V to 240 V


Input voltage
DC: -48 V to -60 V

Maximum/Average power 100/75 W

Mean Time Between Failures (MTBF) 37.54 years


Secospace USG5300

Secospace USG5300

The information contained in this document is for reference purpose only, do not constitute the warranty of any kind, experss or implied. It is
subject to change or withdrawal according to specific customer requirements and conditions.
All the trademarks, pictures, and brands mentioned in this document are the property of Huawei Symantec Technologies Co., Ltd or their
respective holders.

Copyright ©2010 Huawei Symantec Technologies Co., Ltd. All rights reserved.

Version No.: M3-110019999-20100426-V-2.0

Vous aimerez peut-être aussi