3
Datasheet Page 1 Juniper Networks NetScreen-25/50 The Juniper Networks NetScreen-25 and NetScreen-50 offer a complete security solution for enterprise branch and remote ofces as well as small and medium size companies. Featuring four auto-sensing 10/100 Ethernet ports, the NetScreen-25 and NetScreen-50 provide solutions for perimeter security with multiple DMZ s, VPNs for wireless LAN security, or protection of internal networks. The NetScreen-25 has the same number of Ethernet interfaces and offers 100 Mbps of rewall and 20 Mbps of 3DES or AES VPN performance, with support for 32,000 concurrent sessions and 125 VPN tunnels. The NetScreen-50 is a high performance security appliance, offering 170 Mbps of rewall and 45 Mbps of 3DES or AES VPN performance, with support for 64,000 concurrent sessions and 500 VPN tunnels.  Juniper Networks Juniper Networks NetScreen-25 1)  NetScreen-50 1) Maximum Performance and Capacity (1)  ScreenOS version support ScreenOS 5.4 ScreenOS 5.4 Firewall performance 100 Mbps 170 Mbps 3DES+SHA-1 performance 20 Mbps 45 Mbps Concurrent sessions 32,000 64,000 New sessions/second 4,000 5,000 Policies 500 1,000 Interfaces 4 10/1 00 Base-T 4 10/1 00 Base-T Mode of Operation  Layer 2 mode (transparent mode )(2)  Yes Yes  Layer 3 mode (route and/or NA T mode) Yes Yes  NA T (Network Address Translation) Yes Yes  PAT (Port Address Translation) Yes Yes  Policy-based NAT Yes Yes  Virtual IP 2 2  Mapped IP 500 500  MIP/VIP Grouping Yes Yes  Users supported Unrestricted Unrestricted Firewall  Number of network attacks detected 31 31  Network attack detect ion Yes Yes  DoS and DDoS protecti ons Yes Yes  TCP reassemb ly for fragment ed packet protect ion Yes Yes  Malformed packet protect ions Yes Yes  IPS (Deep Inspection FW) Yes Yes  Protocol anomaly Yes Yes  Statefu l protocol signat ures Yes Yes  Content Inspect ion Yes Yes  Embedded antivirus No No  Embedded Anti-S pam Yes Yes  Malicious Web ltering up to 48 URLs up to 48 URLs  Externa l Web lteri ng (Websense or SurfCont rol) Yes Yes  Integrat ed Web lteri ng Yes Yes  Brute force attack mitigation Yes Yes  Deep Inspection (DI) attack pattern obfuscation Yes Yes  Zone-based IP spoong Yes Yes VPN  Concurrent VPN tunnels 125 500  Tun nel interfaces 25 50  DES (56-bit), 3DES (168-bit) and AES encryption Yes Yes  Manual Key, IKE, PKI (X.509) Yes Yes  Perfect forward secrecy (DH Groups) 1,2,5 1,2,5  Prevent replay attack Yes Yes  Remote access VPN Yes Yes  L2TP within IPSec Yes Yes  Dead Peer Detecti on Yes Yes  IPSec NA T Traversal Yes Yes  Redundant VPN gateways Yes Yes  VPN tunnel monitor Yes Yes  Juniper Networks Juniper Networks NetScreen-25 1)  NetScreen-50 1) Firewall and VPN User Authentication  Built-in (internal) database - user limit up to 250 Up to 250  3rd Party user authentication RADIUS, RSA RADIUS, RSA SecurID, and LDAP SecurID, and LDAP  XAUTH VPN authent icati on Yes Yes  Web-based authent icati on Yes Yes PKI Support  PKI Certic ate requests (PKCS 7 and PKCS 10) Yes Yes  Automated certicate enrollment (SCEP) Yes Yes  Online Certicate Status Protocol (OCSP) Yes Yes  Self Signed Certicates Yes Yes  Certicate Authorities Supported  Verisign Yes Yes  Entrust Yes Yes  Microsof t Yes Yes  RSA Keon Yes Yes  iPlanet (Netscape) Yes Yes  Baltimo re Yes Yes  DOD PKI Yes Yes Logging/Monitoring  Syslog (multiple servers) External, up to External, up to 4 servers 4 servers  E-mail (2 addresse s) Yes Yes  NetIQ WebT rends Externa l External  SNMP (v1, v2) Yes Yes  Standard and custom MIB Yes Yes  Traceroute Yes Yes  At sessio n start and end Yes Yes Virtualization  Custom security zones 4 4  Virtual routers (VRs) 3 3  VLANs supported 16 16 Routing  OSPF/BGP Dynamic routing 3 instances each 3 instances each  RIPv1/v2 Dynamic routing 3 instances 3 instances  Static routes 2.048 2,048  Source Based Routing, Source Interface Based Routing Yes Yes  Equal cost multi-path routing Yes Yes High Availability (HA)  HA mode HA Lite Active/P assive  Firewall/VP N session synchronization No Yes  Redundant Interfa ces Yes Yes  Conguration synchronization Yes Yes  Device failure detect ion Yes Yes  Link failure detecti on Yes Yes  Authentica tion for new HA members Yes Yes  Encrypt ion of HA trafc Yes Yes VoIP H.323 ALG Yes Yes  SCCP ALG Yes Yes  SIP ALG Yes Yes  MGCP ALG Yes Yes  NAT for H.323/SI P/SCCP/MGCP Yes Yes

Juniper Netscreen 25 50

Embed Size (px)

DESCRIPTION

Juniper Networks NetScreen-25/50

Citation preview

  • DatasheetPage

    Juniper Networks NetScreen-25/50The Juniper Networks NetScreen-25 and NetScreen-50 offer a complete security solution for enterprise branch and remote offices as well as small and medium size companies. Featuring four auto-sensing 10/100 Ethernet ports, the NetScreen-25 and NetScreen-50 provide solutions for perimeter security with multiple DMZs, VPNs for wireless LAN security, or protection of internal networks. The NetScreen-25 has the same number of Ethernet interfaces and offers 100 Mbps of firewall and 20 Mbps of 3DES or AES VPN performance, with support for 32,000 concurrent sessions and 125 VPN tunnels. The NetScreen-50 is a high performance security appliance, offering 170 Mbps of firewall and 45 Mbps of 3DES or AES VPN performance, with support for 64,000 concurrent sessions and 500 VPN tunnels.

    JuniperNetworks JuniperNetworks NetScreen-251) NetScreen-501)

    MaximumPerformanceandCapacity(1)

    ScreenOSversionsupport ScreenOS5.4 ScreenOS5.4 Firewallperformance 100Mbps 170Mbps 3DES+SHA-1performance 20Mbps 45Mbps Concurrentsessions 32,000 64,000 Newsessions/second 4,000 5,000 Policies 500 1,000 Interfaces 410/100Base-T 410/100Base-T

    ModeofOperation Layer2mode(transparentmode)(2) Yes Yes Layer3mode(routeand/orNATmode) Yes Yes NAT(NetworkAddressTranslation) Yes Yes PAT(PortAddressTranslation) Yes Yes Policy-basedNAT Yes Yes VirtualIP 2 2 MappedIP 500 500 MIP/VIPGrouping Yes Yes Userssupported Unrestricted Unrestricted

    Firewall Numberofnetworkattacksdetected 31 31 Networkattackdetection Yes Yes DoSandDDoSprotections Yes Yes TCPreassemblyforfragmentedpacketprotection Yes Yes Malformedpacketprotections Yes Yes IPS(DeepInspectionFW) Yes Yes Protocolanomaly Yes Yes Statefulprotocolsignatures Yes Yes ContentInspection Yes Yes Embeddedantivirus No No EmbeddedAnti-Spam Yes Yes MaliciousWebfiltering upto48URLs upto48URLs ExternalWebfiltering(WebsenseorSurfControl) Yes Yes IntegratedWebfiltering Yes Yes Bruteforceattackmitigation Yes Yes DeepInspection(DI)attackpatternobfuscation Yes Yes Zone-basedIPspoofing Yes Yes

    VPN ConcurrentVPNtunnels 125 500 Tunnelinterfaces 25 50 DES(56-bit),3DES(168-bit)andAESencryption Yes Yes ManualKey,IKE,PKI(X.509) Yes Yes Perfectforwardsecrecy(DHGroups) 1,2,5 1,2,5 Preventreplayattack Yes Yes RemoteaccessVPN Yes Yes L2TPwithinIPSec Yes Yes DeadPeerDetection Yes Yes IPSecNATTraversal Yes Yes RedundantVPNgateways Yes Yes VPNtunnelmonitor Yes Yes

    JuniperNetworks JuniperNetworks NetScreen-251) NetScreen-501)

    FirewallandVPNUserAuthentication Built-in(internal)database-userlimit upto250 Upto250 3rdPartyuserauthentication RADIUS,RSA RADIUS,RSA SecurID,andLDAP SecurID,andLDAP XAUTHVPNauthentication Yes Yes Web-basedauthentication Yes Yes

    PKISupport PKICertificaterequests(PKCS7andPKCS10) Yes Yes Automatedcertificateenrollment(SCEP) Yes Yes OnlineCertificateStatusProtocol(OCSP) Yes Yes SelfSignedCertificates Yes Yes CertificateAuthoritiesSupported Verisign Yes Yes Entrust Yes Yes Microsoft Yes Yes RSAKeon Yes Yes iPlanet(Netscape) Yes Yes Baltimore Yes Yes DODPKI Yes Yes

    Logging/Monitoring Syslog(multipleservers) External,upto External,upto 4servers 4servers E-mail(2addresses) Yes Yes NetIQWebTrends External External SNMP(v1,v2) Yes Yes StandardandcustomMIB Yes Yes Traceroute Yes Yes Atsessionstartandend Yes Yes

    Virtualization Customsecurityzones 4 4 Virtualrouters(VRs) 3 3 VLANssupported 16 16

    Routing OSPF/BGPDynamicrouting 3instanceseach 3instanceseach RIPv1/v2Dynamicrouting 3instances 3instances Staticroutes 2.048 2,048 SourceBasedRouting,SourceInterfaceBasedRouting Yes Yes Equalcostmulti-pathrouting Yes Yes

    HighAvailability(HA) HAmode HALite Active/Passive Firewall/VPNsessionsynchronization No Yes RedundantInterfaces Yes Yes Configurationsynchronization Yes Yes Devicefailuredetection Yes Yes Linkfailuredetection Yes Yes AuthenticationfornewHAmembers Yes Yes EncryptionofHAtraffic Yes Yes

    VoIP H.323ALG Yes Yes SCCPALG Yes Yes SIPALG Yes Yes MGCPALG Yes Yes NATforH.323/SIP/SCCP/MGCP Yes Yes

  • Copyright 2006, Juniper Networks, Inc. All rights reserved. Juniper Networks and the Juniper Networks logo are registered trademarks of Juniper Networks, Inc. in the United States and other countries. All other trademarks, service marks, registered trademarks, or registered service marks in this document are the property of Juniper Networks or their respective owners. All specifications are subject to change without notice. Juniper Networks assumes no responsibility for any inaccuracies in this document or for any obligation to update information in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice.

    CORPORATE HEADQUARTERS

    AND SALES HEADQUARTERS

    FOR NORTH AND SOUTH AMERICA

    Juniper Networks, Inc.

    94 North Mathilda Avenue

    Sunnyvale, CA 94089 USA

    Phone: 888-JUNIPER (888-586-4737)

    or 408-745-2000

    Fax: 408-745-200

    www.juniper.net

    EAST COAST OFFICE

    Juniper Networks, Inc.

    0 Technology Park Drive

    Westford, MA 0886-346 USA

    Phone: 978-589-5800

    Fax: 978-589-0800

    ASIA PACIFIC REGIONAL

    SALES HEADQUARTERS

    Juniper Networks (Hong Kong) Ltd.

    Suite 2507-, Asia Pacific Finance Tower

    Citibank Plaza, 3 Garden Road

    Central, Hong Kong

    Phone: 852-2332-3636

    Fax: 852-2574-7803

    EUROPE, MIDDLE EAST, AFRICA

    REGIONAL SALES HEADQUARTERS

    Juniper Networks (UK) Limited

    Juniper House

    Guildford Road

    Leatherhead

    Surrey, KT22 9JH, U. K.

    Phone: 44(0)-372-385500

    Fax: 44(0)-372-38550

    Page 2

    0003-00 Sept 2006

    JuniperNetworks JuniperNetworks NetScreen-251) NetScreen-501)

    IPAddressAssignment Static Yes Yes DHCP,PPPoEclient Yes Yes InternalDHCPserver Yes Yes DHCPRelay Yes Yes

    SystemManagement WebUI(HTTPandHTTPS) Yes Yes CommandLineInterface(console) Yes Yes CommandLineInterface(telnet) Yes Yes CommandLineInterface(SSH) Yes,v1.5and Yes,v1.5and v2.0compatible v2.0compatible NetScreen-SecurityManager Yes Yes AllmanagementviaVPNtunnelonanyinterface Yes Yes SNMPFullCustomMIB Yes Yes Rapiddeployment Yes Yes

    Administration Localadministratorsdatabase 20 20 Externaladministratordatabase RADIUS/LDAP/ RADIUS/LDAP/ SecurID SecurID Restrictedadministrativenetworks 6 6 RootAdmin,Admin,andReadOnlyuserlevels Yes Yes Softwareupgrades TFTP/ TFTP/ WebUI/SCP/NSM WebUI/SCP/NSM ConfigurationRoll-back Yes Yes

    TrafficManagement Guaranteedbandwidth Yes Yes Maximumbandwidth Yes Yes IngressTrafficPolicing Yes Yes Priority-bandwidthutilization Yes Yes DiffServstamp Yes Yes

    ExternalFlash CompactFlash Supports96,128or Supports96,128or 512MBIndustrial 512MBIndustrial GradeSanDisk GradeSanDisk Eventlogsandalarms Yes Yes Systemconfigscript Yes Yes ScreenOSsoftware Yes Yes

    DimensionsandPower Dimensions(H/W/L) 1.73/17.5/10.8inches 1.73/17.5/10.8inches Weight 8lbs. 8lbs. Rackmountable 19standard,23 19standard,23 optional optional PowerSupply(AC) 90to264VAC,45watts 90to264VAC,45watts PowerSupply(DC) -36to-72VDC,50watts -36to-72VDC,50watts

    CertificationsSafetyCertifications UL,CUL,CSA,CBEMCCertifications FCCclassA,BSMIClassA,CEclassA,C-Tick,VCCIclassA

    Environment Operationaltemperature:23to122F,-5to50C Non-operationaltemperature:-4to158F,-20to70C Humidity:10to90%non-condensing

    MTBF(Bellcoremodel) NetScreen-25:8.1years,NetScreen-50:8.1years

    SecurityCertifications(Advancedmodelsonly) CommonCriteria:EAL4andEAL4+

    Licensing Options:TheNetScreen-25andNetScreen-50arebothavailablewithtwolicens-ingoptionstoprovidetwodifferentlevelsoffunctionalityandcapacity.Advanced Models:TheAdvancedsoftwarelicenseprovidesallofthefeaturesandcapaci-tieslistedwithinthisspecsheet.Baseline Models: TheBaselinesoftwarelicenseprovidesanentry-levelsolutionforcus-tomerenvironmentswherefeaturessuchasDeepInspection,OSPFandBGPdynamicrouting,advancedHighAvailabilty,andfullcapacityarenotcriticalrequirements.Thefol-lowingtableshowsthefeaturesandcapacitiesthataredifferentthantheAdvancedmodels:

    NetScreen-25 Baseline NetScreen-50 Baseline

    Sessions 24,000 48,000Site-to-sitetunnels 50 150RemoteAccessTunnels Sharedw/site-to-site Sharedw/site-to-siteDeepInspectionFirewall N/A N/AVLANs 0 0OSPF/BGP N/A N/AHighAvailability(HA) HALite* HALite* NetScreenSecurityManager Supported Supported

    *HALiteprovidesconfigurationsynchronizationonly(doesnotprovidesessionortunnelsynchronization)

    Ordering Information Product Part Number

    JuniperNetworksNetScreen-50w/ACpowersupplyNetScreen-50 USpowercord NS-050-001NetScreen-50f* USpowercord NS-050-101NetScreen-50 UKpowercord NS-050-003NetScreen-50f* UKpowercord NS-050-103NetScreen-50 Europeanpowercord NS-050-005NetScreen-50f* Europeanpowercord NS-050-105NetScreen-50 Japanesepowercord NS-050-007NetScreen-50f* Japanesepowercord NS-050-107*fproductsdonotincludeVPNfunctionality(internationalonly)

    JuniperNetworksNetScreen-50w/DCpowersupplyNetScreen-50 w/DCpowersupplyDCpower NS-050-001-DC

    JuniperNetworksNetScreen-25w/ACpowersupplyNetScreen-25 USpowercord NS-025-001NetScreen-25 UKpowercord NS-025-003NetScreen-25 Europeanpowercord NS-025-005NetScreen-25 Japanesepowercord NS-025-007

    BaselineProductsNetScreen-50Baseline USpowercord NS-050B-001NetScreen-50Baseline UKpowercord NS-050B-003NetScreen-50Baseline Europeanpowercord NS-050B-005NetScreen-50Baseline Japanesepowercord NS-050B-007NetScreen-50BaselinetoAdvancedUpgrade NS-050-UPG-ANetScreen-25Baseline USpowercord NS-025B-001NetScreen-25Baseline UKpowercord NS-025B-003NetScreen-25Baseline Europeanpowercord NS-025B-005NetScreen-25Baseline Japanesepowercord NS-025B-007NetScreen-25BaselinetoAdvancedUpgrade NS-025-UPG-A

    (1)Performance,capacityandfeatureslistedarebaseduponsystemsrunningScreenOS5.4andarethemeasuredmaximumsunderidealtestingconditionsunlessotherwisenoted.ActualresultsmayvarybasedonScreenOSreleaseandbydeployment.

    (2)ThefollowingfeaturesarenotsupportedinLayer2(transparentmode):NAT,PAT,policybasedNAT,virtualIP,mappedIP,VLANs,OSPF,BGP,RIPv2,Active/ActiveHA,andIPaddressassignment.