
|
|
|
NetScreen appliance product line overview
|
NetScreen
Technologies' line of integrated security appliances are purpose-built
Internet security appliances that combine firewall, virtual
private networking (VPN), and traffic management functions.
All NetScreen integrated security appliances feature near-wire-speed
performance, even for 3DES encryption, and very low latency,
allowing them to seamlessly fit into any network. Installing
and managing appliances is easily accomplished using the WebUI,
the command line interface, or NetScreen's central management
solutions.
|
Firewall security |
NetScreen's
appliance provides a scalable security solution, ranging from
protecting broadband telecommuters to large corporate offices
and e-commerce sites. NetScreen's full-featured firewall uses
technology based on stateful inspection, securing against intruders
and denial-of-service attacks. NetScreen's custom designed ASIC
processes the firewall access policies and encryption algorithms
in hardware; providing significantly higher performance than
software solutions of devices that use generic PC derived hardware.
-
ICSA certified stateful-inspection firewall
- Fully
integrated solution with security-optimized hardware, operating
system and firewall
- Specialized
device that only supports security functions and has no
holes from other functions that can be exploited like software
based systems
- Robust
attack prevention including SYN attack, ICMP flood, Port
Scan, and others
- Network
Address Translation (NAT), Port Address Translation (PAT)-hide
internal, non-routable IP addresses
|
Virtual Private Networking (VPN) |
Integrated
into all NetScreen Appliances are full-featured VPN IPSEC
functions.
- ICSA
certified IPSec and VPNC tested-compatible with other IPSec
certified devices
- 3DES
and DES encryption using digital certificates (PKI X.509),
IKE auto-key, or manual key
- SHA-1
and MD5 strong authentication
- Hub
and spoke support to simplify configuration for widely deployed
VPN networks, alleviating the need to configure tunnels
between all remote sites
|
IPSec NAT traversal |
All NetScreen appliances support the ability to connect two NetScreen devices, or a NetScreen device and a compatible remote client, with an IPSec VPN tunnel even when there are intervening devices that perform NAT.
|
Traffic management |
Traffic
management allows a network administrator to allocate bandwidth
utilized by various types of network traffic in real time; ensuring
business-critical traffic is never compromised for web surfing.
-
Manage based on IP Address, user, application, or time of
day
- Set
guaranteed bandwidth and maximum bandwidth
- Prioritize
traffic
|
Secure,
easy-to-use management |
NetScreen's
appliances include multiple management interfaces, allowing
a network administrator to securely manage the devices in a
way that does not disrupt their normal operation. Since VPN
functionality is built in, all management can be encrypted for
truly secure remote management.
- Menu-driven
central site management using NetScreen's Global Manager
or NetScreen-Global PRO
- Browser-based
management with the built in Web UI
- Command
line interface (CLI) accessible via SSH, Telnet, and console
port
- E-mail
alerts, SNMP alarms
- Syslog
or WebTrends ™ for logging, monitoring, and analysis
|
NetScreen-204 and NetScreen-208 0 |
The NetScreen-200 Series includes two products, the NetScreen-204 and the NetScreen-208, differentiated by the number of 10/100 interfaces. Together, they are two of the most versatile security appliances available today, easily integrating into many different environments, including medium and large enterprise offices, e-business sites, data centers, and carrier infrastructures. Complete with either four or eight auto-speed-sensing, auto-polarity correcting 10/100 Base-T Ethernet ports, the NetScreen- 200 Series performs firewall functions at near wire-speed (550 Mbps on the NetScreen-208 and 400 Mbps on the NetScreen-204). Even the most computationally-intense applications, such as 3DES encryption, are performed at speeds greater than 200 Mbps.
|
Multiple interfaces for flexible deployments
|
Supporting either four (NetScreen-204) or eight (NetScreen-208) 10/100 interfaces, the NetScreen-200 Series easily adapts to network requirements, providing advanced levels of security beyond simple inside and outside networks. Using multiple interfaces, networks can be segmented into more pieces, better separating potential threats from valuable resources.
|
Firewall attack protections on every interface
|
All interfaces support firewall denial-of-service and attack prevention, protecting against external and internal attacks. Each interface supports up to 28 attack preventions that are configurable per interface. This provides added flexibility and security for todays networks.
|
VPN tunnels on any interface
|
The NetScreen-200 Series supports the ability to initiate and/or terminate IPSec VPN tunnels on any interface, allowing advanced VPN deployments. One critical application of this feature is in wireless LANs, where encryption can now be used to secure internal communication over wireless networks by terminating VPN tunnels on internal interfaces. Combined with firewall and user authentication services, networks can now be locked down from unwanted access and wireless traffic can be encrypted to ensure privacy.
|
Central point in hub and spoke VPNs
|
The NetScreen-200 Series is ideal at the central site of a hub and spoke VPN network. Instead of configuring VPN tunnels between every remote site, configure one VPN tunnel to the central site, and let the central site route the traffic to the correct remote site. This is more easily achieved with the NetScreen-200 Series due to the high VPN capacity and throughput.
|
High availability (device redundancy)
|
The NetScreen-200 Series supports high availability, maintaining full session synchronization, including IPSec Security Associations (SAs). Since all sessions and IPSec SAs are maintained between both devices, the fail-over from the Master device to the Backup device occurs with near-zero interruption to the network.
|
NetScreen-100 0 |
The
Power of ASICs |
NetScreen's security ASIC processes the firewall access policies
and encryption algorithms in hardware, which is a significantly
faster approach than in software and one that frees the CPU
to manage data flow. This security-accelerating ASIC is tightly
integrated with NetScreen's ScreenOS operating system and
system software to eliminate unnecessary software layers and
security holes found in other security products built on general-purpose
commercial operating systems. By bringing security functionality
to the system level, NetScreen has removed the overhead of
extra platform layers that currently degrade the performance
of other security products, which are typically PC-based or
worksta-tion- based solutions.
|
NetScreen-100 |
The
NetScreen-100 is one of the most versatile security products
available today, easily integrating into many different environments,
including colocation facilities, data centers, multi-tenant
buildings, and medium and large enterprise offices. Complete
with three auto-sensing 10/100 Base-T Ethernet ports, the
NetScreen-100 performs at near wire-speed for even the most
intense applications, such as 3DES encryption.
|
Central point in hub and spoke VPNs |
The
NetScreen-100 is ideal at the central site of a hub and spoke
VPN network. Instead of configuring VPN tunnels between every
remote site, configure one VPN tunnel to the central site,
and let the central site route the traffic to the correct
remote site.
|
High availability |
The
NetScreen-100 supports high availability, maintaining full
session synchronization, including IPSec Security Associations
(SAs). Since all sessions and IPSec SAs are maintained between
both devices, the fail-over from the Master device to the
Slave device occurs with near-zero interruption to the network.
|
High-powered performance |
The
NetScreen-100 offers industry-leading performance, but that
is not the only measure of performance in today's networks.
The NetScreen-100 supports 128,000 concurrent sessions, approximate-ly
20,000 new sessions per second; and since the firewall and
VPN encryption is processed on NetScreen's custom ASIC, the
NetScreen-100 offers very low latency. With support for 1,000
VPN tunnels, the NetScreen-100 can comfortably protect and
connect large VPN networks.
|
Rack,
Computer Room or Office |
Measuring
only 10.8" x 17.5" x 1.875", the NetScreen-100 is rack mountable
and includes rack-mounting brackets. Additionally, the NetScreen-100
offers AC and dual-feed DC power supply options.
|
Content filtering |
All
NetScreen Appliances integrate with the Websense™ content
filtering solution, to block inappropriate content and defer
personal browsing to non-work hours.

Click
here to enlarge image
|
NetScreen-50, 25 0
|
Reliability
and security of appliances |
Not only is it easy to install and manage NetScreen's security
appliances, but they also offer improved reliability and security.
Without the typical reliability issues of disk drives and
other moving parts, appliances are the best long-term solutions
when up-time is important. NetScreen Appliances only require
configuration and management of the firewall, VPN, and traffic
shaping features, alleviating the need for configuring servers
and third-party operating systems. This limits the time required
to install the security device and reduces the number of setup
steps where security holes can form.
|
NetScreen-50
and NetScreen-25 0
|
The NetScreen-50 and NetScreen-25 offer a complete security
solution for small and medium sized business main offices
and branch offices. The NS-50 features four auto-sensing 10/100
Base-T Ethernet ports (Trust, Untrust, DMZ, and one reserved
for future use). The NS-50 is a high performance security
appliance, offering 170 Mbps for firewall and 50 Mbps of 3DES
VPN, to protect your LAN as well as public servers such as
mail, web, and FTP. The NS-25 has the same interfaces and
offers 100 Mbps of firewall and 20 Mbps of 3DES VPN.
|
Full-featured
product with best price to performance in the industry |
Featuring firewall, VPN, and traffic management technology
of NetScreen's ScreenOS, the NS-50 and NS-25 are all-in-one
solutions. The NS-50 supports up to 8,000 concurrent TCP/IP
sessions and 100 VPN tunnels. The NS-25 supports up to 4,000
concurrent TCP/IP sessions and 25 VPN tunnels
|
DHCP
Server |
These appliances can be configured as DHCP servers to assign
IP addresses to the trusted network.
|
NetScreen-5XP 0  |
While at the low end of the NetScreen appliance product line,
the NetScreen-5XP still offers an enterprise-class performance.
Using the same firewall, VPN, and traffic management technology,
the NetScreen-5XP is fully capable of securing a broadband
telecommuter or a small office.
|
PPPoE
and DHCP client |
The NetScreen-5XP's untrusted IP address can be automatically
assigned dynamically using PPPoE and DHCP.
|
Big
performance for a small device |
While only weighing 1 lb., the NetScreen-5XP supports 2,000
concurrent TCP/IP sessions, 10 VPN tunnels, and is available
in 10-user and unrestricted user versions. As with all NetScreen
appliances, the NetScreen-5XP offers near wire-speed performance
over it's two 10Base-T ports.

Click
here to enlarge image
|
Appliance Features  |
Click here
to view Appliance Features
|
|
Specifications: |
Standards supported |
ARP, TCP/IP, UDP, ICMP, HTTP, RADIUS, LDAP, SecureID, IPSec (ESP, AH), MD5, SHA-1, AES, DES, 3DES, L2TP, IKE (ISAKMP), TFTP (client), SNMP, X.509v3, DHCP, PPPoE, SCEP, OCSP |
Certifications |
FCC, UL, CE, CUL, C-Tick, VCCI, BSMI, CSA Environments |
Environment |
Temperature: 40-105 degrees F, 5-40 degrees C,
Humidity: 5-90%, non-condensing
|
MTBF
(Bellcore model) |
NetScreen-5XP: 8.8 years
NetScreen-25: 8.1 years
NetScreen-50: 8.1 years
NetScreen-100: 6.4 years
NetScreen-204: 6.8 years
NetScreen-208: 6.5 years
|
|
|
|
NetScreen product warranty and services |
The
standard hardware warranty is for a period of one year. The
system software has a 90-day warranty that it will meet published
specifications. Optional hardware maintenance and software subscription
services are also available. These services are recommended
to ensure the system is kept updated with the latest software
enhancements and to ensure high availability for end users.
. |
|