1. Catalogs
  2. Juniper Networks
  3. SSG5 and SSG20 Secure Services Gateways
video corpo

SSG5 and SSG20 Secure Services Gateways

SSG5 and SSG20 Secure Services Gateways
1 / 12 PagesView full catalog

SSG5 and SSG20 Secure Services Gateways

Product catalog summary
Product Description: The Juniper Networks SSG5 and SSG20 Secure Services Gateways are designed for small branch offices and standalone businesses. They provide protection against internal and external threats, unauthorized access, and ensure regulatory compliance with 160 Mbps of stateful firewall traffic and 40 Mbps of IPsec VPN traffic.
Security Features: These gateways offer protection against worms, viruses, trojans, spam, and emerging malware through unified threat management (UTM) features. They support security zones, virtual routers, and VLANs to create secure network domains with unique security policies.
Product Overview: The SSG5 and SSG20 combine performance, security, routing, and LAN/WAN connectivity. They utilize UTM features like stateful firewall, IPsec VPN, intrusion prevention system (IPS), antivirus, antispam, and web filtering to protect against various threats.
Connectivity and Routing: The SSG5 has seven 10/100 interfaces, while the SSG20 has five, with additional WAN connectivity options. Both support 802.11 a/b/g wireless connectivity and can function as traditional routers or consolidated security devices.
Access Control: These devices enforce access control policies based on user identity and endpoint state, enhancing security posture.
Features and Benefits: Key features include high performance, best-in-class UTM security, integrated antivirus and antispam, network segmentation, interface modularity, robust routing engine, and wireless-specific security features.
Product Options: Options include different DRAM capacities, UTM/content security configurations, I/O options, wireless connectivity, and extended licenses for increased capacities.
Specifications: Both models support various security and routing features, including firewall performance, VPN capabilities, user authentication, PKI support, virtualization, and IPv6. They offer high availability, system management, and logging/monitoring capabilities.
Dimensions and Power: The SSG5 measures 8.8 x 1.6 x 5.6 inches and weighs 2.1 lbs, while the SSG20 measures 11.6 x 1.8 x 7.4 inches and weighs 3.3 lbs. Both are rack-mountable and have a power supply of 100-240 VAC.
Certifications: Both models have safety and EMC certifications and a mean time between failures (MTBF) of 40.5 years for non-wireless and 22.8 years for wireless configurations.
Specifications and Standards: Compliance with standards such as Common Criteria EAL4, FIPS 140-2 Level 2, and ICSA Firewall and VPN ensures the product meets specific security and operational benchmarks.
Operating Environment: The operating temperature range is 32° to 104° F (0° to 40° C), with non-operating temperatures from -4° to 149° F (-20° to 65° C). Humidity levels are supported from 10% to 90% non-condensing.
Wireless Radio Specifications: Wireless models support dual radio 802.11a and 802.11b/g standards with a maximum transmit power of up to 200 mW. They can configure up to 16 SSIDs, with 4 active at any time. Features like Atheros SuperG and eXtended Range (XR) are included.
Wireless Security: Security protocols supported include WPA, WPA2 (AES or TKIP), IPsec VPN, and WEP. Authentication methods include PSK, EAP-PEAP, EAP-TLS, and EAP-TTLS over 802.1x. MAC access controls and client isolation are also available.
Antenna Options: Diversity antennas are included, with optional directional and omni-directional antennas available.
Performance and Features: Performance metrics are based on systems running ScreenOS 6.3. UTM Security features require annual subscriptions for updates and support. NAT, PAT, and other features are not available in layer 2 transparent mode.
IPS Signature Packs: Signature packs are tailored for specific deployments and attack types, including base, client, server, and worm mitigation packs.
Firewall Extended Licenses: Extended licenses increase session, VPN tunnel, VLAN, and VoIP call capacities and add high availability support.
Ordering Information: Various models of SSG5 and SSG20 are available with different memory configurations and backup interfaces. Accessories and upgrades include memory modules, rack mount kits, and antennas.
Juniper Networks Services: Juniper Networks offers services to optimize network performance, reduce costs, and minimize risks. More information is available on their website.
Contact Information: Contact details for Juniper Networks' headquarters in the USA, EMEA, and APAC regions are provided for further inquiries and purchases.
See more

Catalog excerpts

SSG5 and SSG20 Secure Services Gateways-1

DATASHEET SSG5 AND SSG20 SECURE SERVICES GATEWAYS Product Overview The Juniper Networks SSG5 and SSG20 Secure Services Gateways are purpose-built security appliances that deliver a perfect blend of performance, security, routing and LAN/WAN connectivity for small branch offices, fixed telecommuters and small standalone business deployments. Traffic flowing in and out of the branch office or business is protected from worms, spyware, trojans, and malware by a complete set of Unified Threat Management security features that include stateful firewall, IPsec VPN, intrusion prevention system (IPS), antivirus (includes antispyware, anti-adware, antiphishing), antispam and Web filtering. Product Description The Juniper Networks® SSG5 and SSG20 Secure Services Gateways are high-performance security platforms for small branch office and standalone businesses that want to stop internal and external attacks, prevent unauthorized access and achieve regulatory compliance. Both the SSG5 and SSG20 deliver 160 Mbps of stateful firewall traffic and 40 Mbps of IPsec VPN traffic. Security: Protection against worms, viruses, trojans, spam, and emerging malware is delivered by proven unified threat management (UTM) security features that are backed by best-in-class partners. To address internal security requirements and facilitate regulatory compliance, the SSG5 and SSG20 both support an advanced set of network protection features such as security zones, virtual routers and VLANs that allow administrators to divide the network into distinct secure domains, each with its own unique security policy. Policies protecting each security zone can include access control rules and inspection by any of the supported UTM security features. Regional Office Headquarters Zone A M7i Internet SSG20 Zone C NetScreen-5400 Zone B The SSG20 deployed at a branch office for secure Internet connectivity and site-to-site VPN to corporate headquarters. Internal wired and wireless resources are protected with unique security policies applied to each security zone. 1

 Open the catalog to page 1
SSG5 and SSG20 Secure Services Gateways-2

Connectivity and Routing: The SSG5 has seven on-board 10/100 interfaces with optional fixed WAN ports. The SSG20 has five 10/100 interfaces with two I/O expansion slots for additional WAN connectivity. The broad array of I/O options coupled with WAN protocol and encapsulation support in the routing engine make both the SSG5 and the SSG20 a solution that can easily be deployed as a traditional branch office router or as a consolidated security and routing device to reduce CapEx and OpEx. Both the SSG5 and SSG20 support 802.11 a/b/g as a factory configured option supported by a wide array of wireless...

 Open the catalog to page 2
SSG5 and SSG20 Secure Services Gateways-3

Features and Benefits (continued) Feature Feature Description Benefit Juniper Networks Unified Access Control enforcement point Interacts with the centralized policy management engine (IC Series) to enforce session-specific access control policies using criteria such as user identity, device security state and network location. Improves security posture in a cost-effective manner by leveraging existing customer network infrastructure components and best-in-class technology. Management flexibility Use any one of three mechanisms, command line interface (CLI), WebUI or Juniper Networks Network...

 Open the catalog to page 3
SSG5 and SSG20 Secure Services Gateways-4

ScreenOS version tested ScreenOS 6.3 Firewall performance (Large packets) 160 Mbps Firewall performance (IMIX)(3) 90 Mbps Firewall packets per second (64 byte) 30,000 PPS Advanced Encryption Standard (AES) 256+SHA-l VPN 40 Mbps 3DES encryption +SHA-1 VPN performance 40 Mbps Maximum concurrent sessions 8,000/16,000 Maximum security policies 200 Maximum users supported Unrestricted Network Connectivity Mini-Physical Interface Module (Mini-PIM) slots Factory configured: RS232 Serial AUX or ISDN Mini-PIMs: lxADSL 2+, lxTl, lxEl, V.92, ISDN Network attack detection TCP reassembly for fragmented packet...

 Open the catalog to page 4
SSG5 and SSG20 Secure Services Gateways-5

Specifications (continued) SSG5 Base/Extended SSG20 Base/Extended Auto-Connect VPN Yes Yes Concurrent VPN tunnels 25/40 25/40 Tunnel interfaces 10 10 DES encryption (56-bit), 3DES encryption (168-bit) and Advanced Encryption Standard (AES) (256-bit) Yes Yes MD-5 and SHA-1 authentication Yes Yes Manual key, Internet Key Exchange (IKE), IKEv2 with EAP public key infrastructure (PKI) (X.509) Yes Yes Perfect forward secrecy (DH Groups) 1,2,5 1,2,5 Prevent replay attack Yes Yes Remote access VPN Yes Yes Layer2 Tunneling Protocol (L2TP) within IPsec Yes Yes IPsec Network Address Translation (NAT) traversal...

 Open the catalog to page 5
SSG5 and SSG20 Secure Services Gateways-6

Specifications (continued) Routing (continued) Reverse Path Forwarding (RPF) Yes Yes Internet Group Management Protocol (IGMP) (vl,v2) Yes Yes Multicast inside IPsec tunnel Yes Yes ICMP Router Discovery Protocol (IRDP) Yes Yes Multilink Point-to-Point Protocol (MLPPP) N/A Yes Multilink Frame Relay (MLFR) (FRF 15, FRF 16) Yes Yes Dual stack IPv4/IPv6 firewall and VPN Yes Yes IPv4 to/from IPv6 translations and encapsulations Yes Yes Syn-Cookie and Syn-Proxy DoS Attack Detection Yes Yes SIP, RTSP, Sun-RPC, and MS-RPC ALG's Yes Yes Layer 3 (route and/or NAT) mode Yes Yes Address Translation Network...

 Open the catalog to page 6
SSG5 and SSG20 Secure Services Gateways-7

Specifications (continued) SSG5 Base/Extended SSG20 Base/Extended Active/Active - L3 mode Yes Yes Active/Passive -Transparent & L3 mode Yes Yes Configuration synchronization Yes Yes Session synchronization for firewall and VPN Yes Yes Session failover for routing change Yes Yes VRRP Yes Yes Device failure detection Yes Yes Link failure detection Yes Yes Authentication for new HA members Yes Yes Encryption of HA traffic Yes Yes WebUI (HTTP and HTTPS) Yes Yes Command line interface (console) Yes Yes Command line interface (telnet) Yes Yes Command line interface (SSH) Yes v1.5 and v2.0 compatible...

 Open the catalog to page 7
SSG5 and SSG20 Secure Services Gateways-8

Specifications (continued) SSG5 Base/Extended SSG20 Base/Extended Dimensions and Power Dimensions (W x H x D) 8.8 x 1.6 x 5.6 in (22.2 x 4.1 x 14.3 cm) 11.6 x 1.8 x 7.4 in (29.5 x 4.5 x 18.7 cm) Weight 2.1 lb (0.95 kg) 3.3 lb (1.5 kg) Rack mountable Yes Yes Power supply (AC) 100-240 VAC 100-240 VAC Maximum thermal output 122.8 BTU/Hour 122.8 BTU/Hour Safety certifications CSA, CB CSA, CB EMC certifications FCC class B, CE class B, A-Tick, VCCI class B FCC class B, CE class B, A-Tick, VCCI class B Non-wireless 40.5 years 35.8 years Wireless 22.8 years 28.9 years Common Criteria: EAL4 Yes Yes FIPS...

 Open the catalog to page 8

Archived catalogs

  1. QFX3500 Switch

    12  Pages

  2. QFX3600 Switch

    12  Pages

  3. QFabric System

    12  Pages

  4. DDoS Secure

    4  Pages

  5. 1100018

    6  Pages

  6. 1000195

    6  Pages

  7. 1000300

    4  Pages

  8. backgrounder

    4  Pages

  9. VXA Series

    4  Pages

  10. JSA7500

    8  Pages

  11. AP150W

    2  Pages

  12. AP245X

    2  Pages

  13. AP250

    2  Pages

  14. AP550

    2  Pages

*Prices are pre-tax. They exclude delivery charges and customs duties and do not include additional charges for installation or activation options. Prices are indicative only and may vary by country, with changes to the cost of raw materials and exchange rates.