DATASHEET 및 보안서비스게이트웨이 제품소개주니퍼네트웍스 SSG300 라인보안서비스게이트웨이 (Secure Service Gateway) 는대규모지역지사와중규모단독기업을위해설계된최적의성능, 보안, 라우팅및 LAN/WAN 연결기능을완벽하게결합한맞춤형보안어플라이언스로이루어져있습니다. Stateful 방화벽, IPSec VPN (Virtual Private Network), IPS (Intrusion Prevention System), 바이러스차단 ( 스파이웨어 / 애드웨어 / 피싱차단포함 ), 스팸차단및웹필터링을포함한포괄적인 제품설명 SSG300 Series는기업이내부및외부공격을막고불법적인액세스를차단하며규제를준수할수있도록돕는 High Performance 보안플랫폼으로구성되어있습니다. 은 500Mbps의 Stateful 방화벽성능과 225Mbps의 IPSec VPN 성능을, 은 400Mbps의 Stateful 방화벽성능과 175Mbps의 IPSec VPN 성능을제공합니다. 이들제품은다음 3개원칙에초점을맞추고있습니다 : 보안 : 동급최강의파트너가뒷받침하는입증된 UTM 보안기능을통해바이러스, 스팸및신종악성코드의공격을차단합니다. SSG300 Series는관리자들이내부의보안요구를해결하고규제를준수하기위해네트워크를각각고유한보안정책을가진별개의보안영역으로나눌수있도록하는보안존 (Security Zone), 가상라우터및 VLAN 등을비롯한일련의고급네트워크보호기능을제공합니다. 각각의보안존을보호하는정책에는지원되는모든 UTM 보안기능을통한검사와접근제어규칙이포함될수있습니다. UTM (Unified Threat Management) 보안기능들을통해지사또는기업에서수행되는트랜잭션을웜, 스파이웨어, 트로이목마및악성코드로부터보호합니다. SSG300 Series는 및 제품군으로구성되어있습니다. 은기업본사에대한안전한인터넷접속및사이트간 VPN 을위해지사에구축되었습니다. 내부지사자원은각보안존 (Security Zone) 에적용되는고유의보안정책을통해보호됩니다. 1
연결및라우팅 : SSG300 Series는 4개의온보드 10/100/1000 인터페이스와추가로 LAN 또는 WAN 인터페이스를장착할수있는 I/O 확장슬롯 (은 3개 I/O 슬롯, 은 5개의 I/O 슬롯제공 ) 을제공한다는점에서유연성이탁월한플랫폼입니다. 또한, 광범위한 I/O 옵션과함께 WAN 프로토콜캡슐화기술을채용했기때문에, 기존의지사라우터나통합보안 / 라우팅장비와마찬가지로손쉽게구축할수있으며, 따라서투자및운영비용을줄일수있습니다. 접근제어정책적용 : Infranet Controller를추가하면 SSG300 Series 플랫폼은주니퍼네트웍스의통합접근제어구축환경에서정책적용지점의역할을할수있습니다. Infranet Controller는방화벽기반접근제어를확장 / 교체하기위해 SSG300 Series와상호작용함으로써중앙정책관리엔진의역할을수행합니다. 또한, 공격상황및사용자속성측면에대한큰폭의변화를수용할수있도록단말장치상태및사용자 ID를포함한보다세분화된기준에따라액세스를허용 / 거부합니다. 뿐만아니라, 주니퍼네트웍스의전문서비스 (Professional Services) 는 IT 팀과의협력을통해목표규명, 구축프로세스정의, 네트워크설계의개발 / 검증및구축시스템관리를수행함으로써성공적으로프로젝트가완료될수있도록합니다. 또한, 간단한랩테스트에서대규모네트워크구현에이르는모든프로젝트에참여하여성공을거둘수있도록돕고있습니다. 기능및이점 기능기능설명이점 고성능 동급최강의 UTM 보안기능 통합바이러스차단 통합스팸차단통합웹필터링통합 IPS (Intrusion Prevention System) (Deep Inspection) 고정인터페이스 네트워크세그먼트분할 인터페이스모듈성 강력한라우팅엔진 주니퍼네트웍스 UAC (Unified Access Control) Enforcement Point 관리의유연성 Auto-Connect VPN 세계정상의전문서비스 맞춤형하드웨어, 강력한프로세싱및보안전용운영체제를통합한맞춤형플랫폼 UTM 보안기능 ( 바이러스 / 스팸차단, 웹필터링, IPS) 으로네트워크에손상을입기전에모든형태의바이러스및악성코드차단 Kaspersky Lab 엔진기반의연간등록제바이러스백신엔진제공 Symantec 기술기반의연간등록제스팸차단제공 SurfControl 기술기반의연간등록제웹필터링솔루션제공주니퍼네트웍스의 Deep Inspection Firewall Signature Pack 을통해연간등록제 IPS 엔진제공모든 SSG300 Series 모델에는기본적으로 4개의고정 10/100/1000 인터페이스, 2개의 USB 포트, 1개의콘솔포트및 1개의 Auxiliary 포트가장착됨관리자는브리지그룹 (bridge group), 보안존, 가상 LAN 및가상라우터를통해게스트, 무선네트워크및지역서버 / 데이터베이스를분리하도록보안정책을구축할수있음 * 3개 () 또는 5개 () 의확장슬롯으로 T1, E1, Serial, ADSL/ADSL2/ADSL2+, G.SHDSL, 10/100/1000 및 SFP 연결옵션지원입증된라우팅엔진으로 OSPF, BGP 및 RIP v1/2와함께 Frame Relay, Multilink Frame Relay, PPP, Multilink PPP 및 HDLC 등지원중앙정책관리엔진 (IC Series) 과연동되어사용자계정, 장비보안상태, 네트워크위치등과같은정보를통해세션별접근제어실행 CLI, WebUI 또는 Juniper Networks Network and Security Manager 메커니즘을이용한보안정책의구축, 모니터링및관리허브앤스포크 (hub-and-spoke) 토폴로지에서스포크사이트간VPN 터널의자동설정 / 해제 간단한랩테스트에서대규모네트워크구현에이르는모든프로젝트에서주니퍼네트웍스의전문서비스는고객의 IT 팀과의협력을통해목표규명, 구축프로세스정의, 네트워크설계의개발 / 검증및구축시스템관리를수행함 현재및미래에내부 / 외부공격을차단하는데필요한성능헤드룸제공모든형태의공격으로부터네트워크보호 바이러스, 스파이웨어, 애드웨어및기타악성코드차단 알려진스팸 / 피싱공격자로부터오는원치않는 e-메일차단악의적웹사이트에대한접근제어 / 차단애플리케이션수준의네트워크플러딩공격차단 고속 LAN 연결, 향후연결옵션및유연한관리기능제공 강력한기능을활용하여인증받지않은액세스를차단하도록네트워크상의다양한내부, 외부및 DMZ 서브그룹에대한정책구축지원비용절감및투자보호강화를위해탁월한보안을바탕으로 LAN 및 WAN 연결통합 보안및라우팅통합장비의구축으로운영및자본비용절감 고객의기존네트워크인프라스트럭처구성요소들과최상급기술을활용하여비용대비효과적으로보안수준강화 모든위치에서관리자가액세스할수있도록하여현장방문의필요성을없앰. 이를통해응답시간단축및운영비용절감실현 VoIP 및화상회의와같이지연시간에민감한애플리케이션을지원하는메시 (mesh) 아키텍처를위한확장형 VPN 솔루션제공네트워크인프라스트럭처혁신을통해탁월한보안성, 유연성, 확장성및안정성보장 * 브리지그룹은 ScreenOS 6.0 이상의 upim 상에서만지원 2
제품옵션 옵션옵션설명해당제품 NEBS (Network Equipment Building System) 호환 DRAM UTM/ 컨텐트보안 ( 대용량메모리옵션필요 ) I/O 옵션 의 NEBS 호환버전지원 모든 SSG300 Series 모델은 1GB DRAM 지원. 및 은 256MB-DRAM 버전도지원라이센싱키가추가된 Juniper SSG300 Series의경우, 바이러스차단 ( 스파이웨어 / 피싱차단포함 ), IPS (Deep Inspection 방화벽 ), 웹필터링및스팸차단등을비롯한동급최강 UTM 및컨텐트보호기능의모든조합으로구성가능 3 개 () 또는 5 개 () 의확장슬롯으로 T1, E1, Serial, ADSL2+, G.SHDSL, 10/100/1000 및 SFP 옵션지원 대용량메모리모델에서만지원 대용량메모리모델에서만지원 사양 Maximum Performance and Capacity (1) ScreenOS version tested Firewall performance (Large packets) Firewall performance (IMIX) (2) Firewall Packets Per Second (64 byte) AES256+SHA-1 VPN performance 3DES+SHA-1 VPN performance Maximum concurrent sessions New sessions/second Maximum security policies Maximum users supported Convertible to Juniper Networks JUNOS Software 8.0 or higher Network Connectivity Fixed I/O Physical Interface Module (PIM) Slots WAN interface options (PIMS) LAN interface options (upims) ScreenOS 6.2 450+Mbps 400Mbps 175,000 PPS 175Mbps 175Mbps 64,000 2,000 Unrestricted 4x10/100/1000 3 Serial, T1, E1, ADSL/ADSL2/ADSL2+, G.SHDSL 8x10/100/1000, 16x10/100/1000, and 6xSFP ScreenOS 6.2 550+Mbps 500Mbps 225,000 PPS 225Mbps 225Mbps 128,000 12,500 2,000 Unrestricted 4x10/100/1000 5 Serial, T1, E1, ADSL/ADSL2/ADSL2+, G.SHDSL 8x10/100/1000, 16x10/100/1000, and 6xSFP 3
사양 ( 계속 ) Firewall Network attack detection DoS and DDoS protection TCP reassembly for fragmented packet protection Brute force attack mitigation SYN cookie protection Zone-based IP spoofing Malformed packet protection Unified Threat Management (3) IPS (Deep Inspection firewall) Protocol anomaly detection Stateful protocol signatures IPS/DI attack pattern obfuscation Antivirus Signature database Protocols scanned Anti-spyware Anti-adware Anti-keylogger Instant message AV Anti-spam Integrated URL filtering External URL filtering (4) VoIP Security H.323 ALG SIP ALG MGCP ALG SCCP ALG NAT for VoIP protocols IPsec VPN Concurrent VPN tunnels Tunnel interfaces DES (56-bit), 3DES (168-bit) and AES (256-bit) MD-5 and SHA-1 authentication Manual key, IKE, IKEv2 with EAP, PKI (X.509) Perfect forward secrecy (DH Groups) Prevent replay attack Remote access VPN L2TP within IPsec IPsec NAT traversal Auto-Connect VPN Redundant VPN gateways User Authentication and Access Control Built-in (internal) database - user limit Third-party user authentication RADIUS Accounting XAUTH VPN authentication Web-based authentication 802.1X authentication Unified Access Control enforcement point 200,000+ POP3, HTTP, SMTP, IMAP, FTP, IM 500 100 1,2,5 500 RADIUS, RSA SecureID, LDAP - start/stop 200,000+ POP3, HTTP, SMTP, IMAP, FTP, IM 500 300 1,2,5 500 RADIUS, RSA SecureID, LDAP - start/stop 4
사양 ( 계속 ) PKI Support PKI Certificate requests (PKCS 7 and PKCS 10) Automated certificate enrollment (SCEP) Online Certificate Status Protocol (OCSP) Certificate Authorities supported Self-signed certificates Virtualization Maximum number of security zones Maximum number of virtual routers Bridge groups* Maximum number of VLANs Routing BGP instances BGP peers BGP routes OSPF instances OSPF routes RIP v1/v2 instances RIP v2 routes Static routes Source-based routing Policy-based routing ECMP Multicast Reverse Path Forwarding (RPF) IGMP (v1, v2) IGMP Proxy PIM SM PIM SSM Multicast inside IPsec tunnel Encapsulations PPP MLPPP MLPP max physical interfaces Frame Relay MLFR (FRF.15, FRF.16) MLFR max physical interfaces HDLC IPv6 Dual stack IPv4/IPv6 firewall and VPN IPv4 to/from IPv6 translations and encapsulations Syn-Cookie and Syn-Proxy DoS Attack Detection SIP, RTSP, Sun-RPC, and MS-RPC ALG s RIPng BGP Transparent mode NSRP DHCPv6 Relay Mode of Operation Layer 2 (transparent) mode (5) Layer 3 (route and/or NAT) mode * 브리지그룹은 ScreenOS 6.0 이상의 upim 상에서만지원 VeriSign, Entrust, Microsoft, RSA Keon, iplanet (Netscape) Baltimore, DoD PKI 40 5 125 8 36 3 128 6 6 VeriSign, Entrust, Microsoft, RSA Keon, iplanet (Netscape) Baltimore, DoD PKI 40 8 125 8 48 3 128 10 10 5
사양 ( 계속 ) Address Transtation Network Address Translation (NAT) Port Address Translation (PAT) Policy-based NAT/PAT (L2 and L3 mode) Mapped IP (L3 mode) Virtual IP (L3 mode) MIP/VIP Grouping (L3 mode) IP Address Assignment Static DHCP, PPPoE client Internal DHCP server DHCP relay Traffic Management Quality of Service (QoS) Guaranteed bandwidth Maximum bandwidth Ingress traffic policing Priority-bandwidth utilization DiffServ marking High Availability (HA) Active/Active - L3 mode Active/Passive - Transparent & L3 mode Configuration synchronization Session synchronization for firewall and VPN VRRP Session failover for routing change Device failure detection Link failure detection Authentication for new HA members Encryption of HA traffic System Management WebUI (HTTP and HTTPS) Command line interface (console) Command line interface (telnet) Command line interface (SSH) Network and Security Manager (NSM) All management via VPN tunnel on any interface Rapid deployment Administration Local administrator database size External administrator database support Restricted administrative networks Root Admin, Admin and Read Only user levels Software upgrades Configuration rollback Logging/Monitoring Syslog (multiple servers) Email (two addresses) NetIQ WebTrends SNMP (v2) SNMP full custom MIB Traceroute VPN tunnel monitor 4,000 32 - per policy - per policy - per policy, v1.5 and v2.0 compatible No 20 RADIUS, RSA SecurID, LDAP 50 TFTP, WebUI, NSM, SCP, USB - up to 4 servers 4,000 32 - per policy - per policy - per policy, v1.5 and v2.0 compatible No 20 RADIUS, RSA SecurID, LDAP 50 TFTP, WebUI, NSM, SCP, USB - up to 4 servers 6
사양 ( 계속 ) External Flash Additional log storage Event logs and alarms System configuration script ScreenOS Software Dimensions and Power Dimensions (W x H x D) Weight Rack mountable Power supply (AC) 100-240 VAC Average power consumption Maximum power consumption Input frequency Maximum current consumption Maximum Inrush current Average heat dissipation Maximum heat dissipation Power supply (DC) Noise level Certifications Safety certifications EMC certifications NEBS MTBF (Bellcore model) Security Certifications Common Criteria : EAL4 FIPS 140-2: Level 2 ICSA Firewall and VPN Operating Environment Operating temperature Non-operating temperature Humidity USB 1.1 17.5 x 1.8 x 15.1 in (44.5 x 4.5 x 38.3 cm) 15.0 lb (no interface modules) 6.8 kg, 1 RU 275 W 80 W (No PIMs) 320 W 47-63 Hz 100-240 VAC, 3.2 A - 1.3 A 100-240 VAC, 42 A - 62 A 273 BTU (No PIMs) 1091 BTU N/A 40.0 db CSA, TUV, CB FCC class A, CE class A, C-Tick, VCCI class A No 7.2 years Future Future 32 to 122 F (0 to 50 C) -4 to 158 F (-20 to 70 C) 10% to 90% noncondensing USB 1.1 17.5 x 2.6 x 15.1 in (44.5 x 6.6 x 38.3 cm) 25.0 lb (no interface modules + one power supply) (11.34 kg), 1.5 RU 300 W 80 W (No PIMs) 350 W 47-63 Hz 100-240 VAC, 3.5 A - 1.5 A 100-240 VAC, 13 A - 75 A 273 BTU (No PIMs) 1195 BTU -48 to -60 VDC, 300 watts 59.2 db CSA, TUV, CB FCC class A, CE class A, C-Tick, VCCI class A Level 3 6.8 years Future Future 32 to 122 F (0 to 50 C) -4 to 158 F (-20 to 70 C) 10% to 90% noncondensing (1) 위의성능, 용량및기능은 ScreenOS 6.2를실행하는시스템을기준으로한것으로, 별도의언급이없는경우이상적인테스트조건에서측정된최대값을뜻합니다. 실제결과는 ScreenOS 버전및구축시스템에따라다를수있습니다. (2) IMIX 란 Internet Mix의약자로서보다일반적인고객네트워크의트래픽혼합구성을나타내기때문에단일패킷크기보다성능요구수준이훨씬높습니다. 사용되는 IMIX 트래픽은 64 바이트패킷 (58.33%) + 570바이트패킷 (33.33%) + 1518바이트패킷 (8.33%) 의 UDP 트래픽으로이루어집니다. (3) UTM 보안기능 (IPS/Deep Inspection, 바이러스 / 스팸차단및웹필터링 ) 은주니퍼네트웍스에서별도로구입한연간회원제서비스를통해제공됩니다. 연간회원제서비스는패턴업데이트및관련지원서비스를제공합니다. UTM 보안기능의경우, 대용량옵션이필요합니다. (4) 리다이렉트웹필터링은방화벽에서보조서버로트래픽을전송합니다. 이러한리다이렉트기능은무료로제공되지만, Websense 또는 SurfControl로부터별도의웹필터링라이센스를구입해야합니다. (5) NAT, PAT, 정책기반 NAT, 가상 IP, 매핑된 IP, 가상시스템, 가상라우터, VLAN, OSPF, BGP, RIPv2, Active/Active HA 및 IP 주소할당은 Layer 2 Transparent 모드에서는지원되지않습니다. Performance-Enabling 서비스및지원 주니퍼는하이퍼포먼스네트워킹의가치를가속, 확장, 최적화시키는 Performance -Enabling 서비스및지원을제공합니다. 이러한서비스를통해매출과직결되는역량들을신속하게제공함으로써생산성을향상시키고, 새로운비즈니스모델을지원하며, 시장확대와고객만족증대를실현시킵니다. 동시에주니퍼는뛰어난운영효율성을통해성능, 안정성, 가용성, 확장성요구를만족시키고운영비용을절감시키며 IT 위험요소들을제거합니다. 7
c 주문정보 Model Number SSG-320M-SB SSG-320M-SH SSG-350M-SB SSG-350M-SH SSG-350M-SB-TAA SSG-350M-SH-TAA SSG-350M-SB-DC- N-TAA SSG-350M-SH-DC- N-TAA Description, ScreenOS, base memory (256 MB), HW security, AC power supply, ScreenOS, base memory (1 GB), HW security, AC power supply, ScreenOS, base memory (256 MB), HW security, AC power supply, ScreenOS, base memory (1 GB), HW security, AC power supply gateway, ScreenOS, base memory (256 MB), 5 PIM slots, HW Crypto, AC power supply, TAA, 19 rack mount gateway, ScreenOS, base memory (1 GB), 5 PIM slots, HW Crypto, AC power supply, TAA, 19 rack mount gateway, ScreenOS, base memory (256 MB), 5 PIM slots, HW Crypto, DC power supply, fan filter, NEBS, TAA, 19 rack mount gateway, ScreenOS, base memory (1 GB), 5 PIM slots, HW Crypto, DC power supply, fan filter, NEBS, TAA, 19 rack mount SSG300 Line I/O Options JX-2T1-RJ48-S 2-port T1 PIM with integrated CSU/DSU JX-2E1-RJ48-S 2-port E1 PIM with integrated CSU/DSU JX-2Serial-S 2-port Synchronous Serial PIM JX-1ADSL-A-S 1-port ADSL 2/2+ Annex A PIM JX-1ADSL-B-S 1-port ADSL 2/2+ Annex B PIM JX-2SHDSL-S 2-port 2-wire or 1-port 4-wire G.SHDSL PIM JX-1BRI-ST-S 1-port ISDN BRI S/T PIM JXU-6GE-SFP-S 6-port SFP Gigabit Ethernet Universal PIM2 JXU-8GE-TX-S 8-port Gigabit Ethernet 10/100/1000 Copper Universal PIM2 JXU-16GE-TX-S 16-port Gigabit Ethernet 10/100/1000 Copper Universal PIM2 Small form factor pluggable 1000BASE-LX JX-SFP-1GE-LX Gigabit Ethernet Optical Transceiver Module Small form factor pluggable 1000BASE-SX JX-SFP-1GE-SX Gigabit Ethernet Optical Transceiver Module Model Number Description Unified Threat Management/Content Security (High Memory Option Required) NS-K-AVS-SSG350 NS-K-AVS-SSG320 NS-DI-SSG350 NS-DI-SSG320 NS-WF-SSG350 NS-WF-SSG320 NS-SPAM-SSG350 NS-SPAM-SSG320 NS-RBO-CS-SSG350 NS-RBO-CS-SSG320 NS-SMB-CS-SSG350 NS-SMB-CS-SSG320 주니퍼네트웍스에대하여 Antivirus (includes anti-spyware, anti-phishing) IPS (Deep Inspection) Web filtering Anti-spam SSG300 Line Memory Upgrades, Spares and Communications Cables CBL-JX-PWR-AU CBL-JX-PWR-CH CBL-JX-PWR-EU CBL-JX-PWR-IT CBL-JX-PWR-JP CBL-JX-PWR-UK CBL-JX-PWR-US SSG-300-MEM-1GB SSG-350-FLTR JX-CBL-EIA530-DTE JX-CBL-RS232-DTE JX-CBL-RS449-DTE JX-CBL-V35-DTE JX-CBL-X21-DT JX-Blank-FP-S Remote Office Bundle (includes AV, DI, WF) Main Office Bundle (includes AV, DI, WF, AS) Power cable, Australia Power cable, China Power cable, Europe Power cable, Italy Power cable, Japan Power cable, UK Power cable, USA 1 Gigabyte memory upgrade for the SSG300 line Replacement air filter for SSG300 line EIA530 cable (DTE) RS232 cable (DTE) RS449 cable (DTE) V.35 cable (DTE) X.21 cable (DTE) Blank I/O plate 주니퍼네트웍스는하이퍼포먼스네트워킹을지향하는네트워크업계선도적인업체입니다. 주니퍼는단일네트워크상에서서비스와애플리케이션운용을가속화시킬수있는신뢰성있는네트워크환경구축을위해하이퍼포먼스네트워크인프라를제공하는데주력하고있습니다. 이러한하이퍼포먼스네트워크는곧고객에게하이퍼포먼스비즈니스가가능하게하는원동력이되고있습니다. 추가정보는 www.juniper.net/kr 에서확인할수있습니다. 한국주니퍼네트웍스 ( 주 ) 서울시강남구역삼 1 동 736-1 캐피탈타워 19 층 TEL : 02)3483-3400 FAX : 02)3483-3488 www.juniper.net/kr Corporate And Sales Headquarters Juniper Networks, Inc. 1194 North Mathilda Avenue Sunnyvale, CA 94089 USA Phone: 888.JUNIPER (888.586.4737) or 408.745.2000 Fax: 408.745.2100 APAC Headquarters Juniper Networks (Hong Kong) 26/F, Cityplaza One 1111 King s Road Taikoo Shing, Hong Kong Phone: 852.2332.3636 Fax: 852.2574.7803 EMEA Headquarters Juniper Networks Ireland Airside Business Park Swords, County Dublin, Ireland Phone: 35.31.8903.600 Fax: 35.31.8903.601 2009 주니퍼네트웍스사. 모든권리보유. 주니퍼네트웍스, 주니퍼 네트웍스로고, NetScreen 및 ScreenOS는미국과다른나라에서주니퍼네트웍스의등록상표입니다. JUNOS와 JUNOSe는주니퍼네트웍스의상표입니다. 다른모든상표, 서비스마크, 등록상표또는등록서비스마크는해당소유권자의자산일수있습니다. 주니퍼네트웍스는본자료의오류에대해그어떠한책임도지지않습니다. 주니퍼네트웍스는사전통보없이본자료를변경, 수정, 교체또는정정할수있는권한을보유하고있습니다. 주니퍼네트웍스솔루션의구매를원하시면주니퍼네트웍스영업담당자 02-3483-3400 또는공인리셀러에게문의해주십시오. 1000203-003-KR June 2009 Printed on recycled paper. 8