Catalog excerpts
DATASHEET SSG320M AND SSG350M SECURE SERVICES GATEWAYS Product Overview The Juniper Networks SSG300 line consists of purpose-built security appliances that deliver the ideal blend of performance, security, routing, and LAN/WAN connectivity for large, regional branch offices and medium-size, standalone businesses. Traffic flowing in and out of a regional office or business is protected from worms, spyware, trojans, and malware by a complete set of Unified Threat Management security features, including stateful firewall, IPsec VPN, intrusion prevention system (IPS), antivirus (includes antispyware, antiadware, antiphishing), antispam, and Web filtering. The SSG300 line comprises the SSG350M and the SSG320M Secure Services Gateways. Product Description The Juniper Networks® SSG300 line of secure services gateways comprises highperformance security platforms that help businesses stop internal and external attacks, prevent unauthorized access, and achieve regulatory compliance. The Juniper Networks SSG350M Secure Services Gateway provides 500 Mbps of stateful firewall performance and 225 Mbps of IPsec VPN performance, while the Juniper Networks SSG320M Secure Services Gateway provides 400 Mbps of stateful firewall performance and 175 Mbps of IPsec VPN performance. These products focus on three key disciplines: Security: Protection against worms, viruses, trojans, spam, and emerging malware is delivered by proven Unified Threat Management (UTM) security features that are backed by best-in-class partners. To address internal security requirements and facilitate regulatory compliance, the SSG300 line supports an advanced set of network protection features such as security zones, virtual routers, and VLANs that allow administrators to divide the network into distinct, secure domains, each with their own unique security policy. Policies protecting each security zone can include access control rules and inspection by any of the supported UTM security features. Regional Office Headquarters Zone A M7i SSG350M Zone C Internet NetScreen-5400 Zone B The SSG350M deployed at a branch office for secure Internet connectivity and site-to-site VPN to corporate headquarters. Internal branch office resources are protected with unique security policies applied to each security zone. 1
Open the catalog to page 1Connectivity and Routing: The SSG300 line provides four onboard 10/100/1000 interfaces complemented by I/O expansion slots that can house a mix of LAN or WAN interfaces, making the SSG300 line an extremely flexible platform. The broad array of I/O options coupled with WAN protocol and encapsulation support makes the SSG300 line of gateways easily deployable as traditional branch office routers or as consolidated security and routing devices, which can help reduce CapEx and OpEx. Access Control Enforcement: The SSG300 line of gateways can act as enforcement points in a Juniper Networks...
Open the catalog to page 2Product Options Network Equipment Building Systems (NEBS) compliance Option Description Applicable Products UTM/Content Security (high memory option required) All models in the SSG300 line are available with available in 256 MB-DRAM versions. With the addition of licensing keys, the SSG300 line can be configured with any combination of the following best-in-class UTM and content security functionality: antivirus (includes antispyware, antiphishing), IPS (Deep Inspection firewall), Web filtering and/or antispam. SSG350M high-memory model only SSG320M high-memory model only Three (SSG320M) or...
Open the catalog to page 3Specifications (continued) SSG320M SSG350M Firewall Network attack detection Yes Yes DoS and DDoS protection Yes Yes TCP reassembly for fragmented packet protection Yes Yes Brute force attack mitigation Yes Yes SYN cookie protection Yes Yes Zone-based IP spoofing Yes Yes Malformed packet protection Yes Yes IPS (Deep Inspection firewall) Yes Yes Protocol anomaly detection Yes Yes Stateful protocol signatures Yes Yes IPS/DI attack pattern obfuscation Yes Yes Yes Yes Signature database 200,000+ 200,000+ Protocols scanned POP3, HTTP, SMTP, IMAP, FTP, IM POP3, HTTP, SMTP, IMAP, FTP, IM...
Open the catalog to page 4Specifications (continued) SSG320M SSG350M PKI Support PKI Certificate requests (PKCS 7 and PKCS 10) Yes Yes Automated certificate enrollment (SCEP) Yes Yes Online Certificate Status Protocol (OCSP) Yes Yes Certificate Authorities supported VeriSign, Entrust, Microsoft, RSA Keon, iPlanet (Netscape) Baltimore, DoD PKI VeriSign, Entrust, Microsoft, RSA Keon, iPlanet (Netscape) Baltimore, DoD PKI Self-signed certificates Yes Yes Maximum number of security zones 40 40 Maximum number of virtual routers 8 8 Bridge groups* Yes Yes Maximum number of VLANs 125 125 BGP instances 8 8 BGP peers 36 48...
Open the catalog to page 5Specifications (continued) SSG320M SSG350M Address Translation Network Address Translation (NAT) Yes Yes Port Address Translation (PAT) Yes Yes Policy-based NAT/PAT (L2 and L3 mode) Yes Yes Mapped IP (L3 mode) 4,000 4,000 Virtual IP (L3 mode) 32 32 MIP/VIP Grouping (L3 mode) Yes Yes Static Yes Yes DHCP, PPPoE client Yes Yes Internal DHCP server Yes Yes DHCP relay Yes Yes IP Address Assignment Traffic Management Quality of Service (QoS) Guaranteed bandwidth Yes - per policy Yes - per policy Maximum bandwidth Yes - per policy Yes - per policy Ingress traffic policing Yes Yes...
Open the catalog to page 6Specifications (continued) SSG320M SSG350M External Flash Additional log storage USB 1.1 USB 1.1 Event logs and alarms Yes Yes System configuration script Yes Yes ScreenOS Software Yes Yes Dimensions (W x H x D) 17.5 x 1.8 x 15.1 in (44.5 x 4.5 x 38.3 cm) 17.5 x 2.6 x 15.1 in (44.5 x 6.6 x 38.3 cm) Weight 15.0 lb (no interface modules) 6.8 kg 25.0 lb (no interface modules + one power supply) (11.34 kg) Rack mountable Yes, 1 RU Yes, 1.5 RU Power supply (AC) 100-240 VAC 275 W 300 W Average power consumption 80 W (No PIMs) 80 W (No PIMs) Maximum power consumption 320 W 350 W Input frequency...
Open the catalog to page 7Ordering Information Model Number Description Model Number SSG320M SSG-320M-SB SSG320M, ScreenOS, base memory (256 MB), HW security, AC power supply SSG-320M-SH SSG320M, ScreenOS, base memory (1 GB), HW security, AC power supply SSG350M Description Unified Threat Management/Content Security (High Memory Option Required) NS-K-AVS-SSG350 NS-K-AVS-SSG320 Antivirus (includes antispyware, antiphishing) NS-DI-SSG350 NS-DI-SSG320 IPS (Deep Inspection) SSG-350M-SB SSG350M, ScreenOS, base memory (256 MB), HW security, AC power supply NS-WF-SSG350 NS-WF-SSG320 Web filtering SSG-350M-SH SSG350M,...
Open the catalog to page 8All Juniper Networks catalogs and technical brochures
-
EX2300 ETHERNET SWITCH
12 Pages
-
QFX5200 SWITCH
13 Pages
-
QFX5210 SWITCH
9 Pages
-
EX9250 Ethernet Switch
12 Pages
-
EX9200 Ethernet Switch
15 Pages
-
EX4650 Ethernet Switch
11 Pages
-
EX4600 ETHERNET SWITCH
14 Pages
-
EX4300 LINE OF ETHERNET SWITCHES
15 Pages
-
EX3400 ETHERNET SWITCH
11 Pages
-
AP550
2 Pages
-
AP250
2 Pages
-
AP150W
2 Pages
-
AP245X
2 Pages
-
PTX1000
4 Pages
-
SRX300
6 Pages
-
SRX1500
4 Pages
-
SRX4000
5 Pages
-
JSA7500
8 Pages
-
ISG Series
11 Pages
-
vSRX
6 Pages
-
ACX500
7 Pages
-
LN1000 Mobile Secure Router
6 Pages
-
JSA Series Secure Analytics
12 Pages
-
EX4550 Ethernet Switch
12 Pages
-
EX4300 Ethernet Switch
12 Pages
-
WLA Series Antenna Matrix
2 Pages
-
QFX3100 QFabric Director
4 Pages
-
EX Series Ethernet Switches
20 Pages
-
QFX3500 Switch
12 Pages
-
QFX3600 Switch
12 Pages
-
QFabric System
12 Pages
-
QFX5100 Ethernet Switch
12 Pages
-
Unified Access Control
12 Pages
-
DDoS Secure
4 Pages
-
LN2600 Rugged Secure Router
6 Pages
-
1100018
6 Pages
-
1000195
6 Pages
-
1000300
4 Pages
-
backgrounder
4 Pages
-
VXA Series
4 Pages
-
SRX1400 Services Gateway
8 Pages
-
Security Services Gateways
8 Pages
-
T Series Core Routers
8 Pages
-
JCS1200 Control System
6 Pages
-
J Series Services Routers
16 Pages
-
BX7000 Multi-Access Gateway
4 Pages