huawei usg6000 series next-generation firewall datasheet (1)

Upload: rabih-r-bou-orm

Post on 02-Jun-2018

581 views

Category:

Documents


15 download

TRANSCRIPT

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    1/20

    HUAWEI Secospace USG6000

    Next-Generation Firewall Datasheet

    Huawei Technologies Co., Ltd.

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    2/20

    2014-8-26 Huawei Confidential Page 2 of 20

    Copyright Huawei Technologies Co., Ltd. 2012. All rights reserved.

    No part of this document may be reproduced or transmitted in any form or by any means without prior written

    consent of Huawei Technologies Co., Ltd.

    Trademarks and Permissions

    and other Huawei trademarks are trademarks of Huawei Technologies Co., Ltd.

    All other trademarks and trade names mentioned in this document are the property of their respective holders.

    Notes:

    The purchased products, services, and features are stipulated by the contract made between Huawei TechnologiesCo., Ltd. and the customer. All or part of the products, services, and features described in this document may not be

    within the purchase scope or the usage scope. Unless otherwise specified in the contract, all statements, information,

    and recommendations in this document are provided "AS IS" without warranties, guarantees or representations of any

    kind, either express or implied.

    The information in this document is subject to change due to version upgrade or other reasons. Every effort has been

    made in the preparation of this document to ensure accuracy of the contents, but all statements, information, and

    recommendations in this document do not constitute a warranty of any kind, express or implied.

    Huawei Technologies Co., Ltd.

    Address: Huawei Industrial Base Bantian, Longgang Shenzhen 518129, People's Republic of

    China

    Website: http://www.huawei.com

    Tel: 4008302118

    http://www.huawei.com/http://www.huawei.com/http://www.huawei.com/
  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    3/20

    2014-8-26 Huawei Confidential Page 3 of 20

    With the popularity of mobile working using smartphones and tablets, mobile apps, Web2.0,

    and social networking become integral parts of enterprise operation. These changes in IT

    environments greatly improve the communication efficiency for enterprises, but blurs

    network borders and makes information security more challenging. Traditional security

    gateway implements security control only based on IP addresses and ports, and cannot cope

    with the ever-increasing application layer and web threats.

    Against this background, Huawei launches the Secospace USG6000 series next-generation

    firewall to address these challenges. With the awareness of applications, content, time, users,

    attacks, and locations, the USG6000 series clearly maps the network environment to service

    environment and provides application- and user-based security management and QoS

    management functions. Based on application identification, the USG6000 series provides

    powerful IPS, AV, and data leak prevention capabilities to efficiently and comprehensively

    secure enterprise information.

    Application protection is the core of the next-generation security. Configuring and managing

    application protection require more administrators with higher skills, increasing maintenance

    costs. However, the USG6000 series eliminates such concerns by using the industry-leading

    SmartPolicy technology to automatically generates security policies based on the service

    awareness result, making next-generation security simple, consistent, and cost-effective.

    Product Appearance

    Secospace USG6000 series next-generation firewall

    Features and Highlights

    Granular Application Access Control

    In the Web2.0 era, social networking and IM applications are widely used for communication

    and information sharing on enterprise networks. Massive applications are used, and most of

    them use the same protocol (HTTP) and the same port. Traditional firewalls are aware of IP

    addresses and ports, but not of user information, service environment, and application-layer

    information. However, awareness is the basis of access control and security protection.

    Firewalls require comprehensive context awareness to effectively take actions and protect

    information security.

    Huawei USG6000 series next-generation firewall analyzes intranet service traffic from six

    dimensions, including application, content, time, user, attack, and location and implements

    comprehensive network protection.

    Application: Identifies 6000+ mobile and web applications using technologies, such

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    4/20

    2014-8-26 Huawei Confidential Page 4 of 20

    as feature identification, port identification, correlation identification, and behavior

    identification. Application awareness, coupled with antivirus scanning, can

    recognize traffic of different applications and detect the viruses, Trojan horses, and

    malware hidden in applications.

    User: Supports eight user authentication methods, including RADIUS, LDAP, and

    AD authentication to associate traffic IP addresses and ports with users for per-user

    traffic control.

    Threat: Provides over 3000 signatures for attack identification. The USG6000 series

    defends against web application attacks, such as cross-site scripting and SQL

    injection attacks, identifies and defends against more than 10 types of DDoS attacks,

    including SYN flood and UDP flood attacks, and identifies more than 5,000,000

    viruses. With cloud-based URL filtering enabled, the USG6000 series provides over

    85,000,000 predefined URLs to block malicious websites.

    Content: Identifies and filters the files and content to be transferred. The USG6000

    series not only reassembles and filters over 20 types of files, including Word, Excel,PPT, PDF, and RAR, and identifies more than 60 types of file name extensions to

    prevent data leaks and virus attacks even when the file name extensions are

    intentionally modified.

    Time: Records the time when traffic anomalies or security events occur to provide

    evidence for audit.

    Location: Identifies the location where the traffic is initiated to implement

    differentiated traffic control in different regions. The USG6000 series supports

    location customization based on IP addresses.

    Based on the ACTUAL-awareness system, the USG6000 series next-generation firewall

    accurately identifies threats hidden in applications and implements granular access control and

    network protection.

    Easy Security Management

    Traditional security gateways and most next-generation firewalls can only passively execute

    policies configured by administrators. However, in the real world, attacks are usually a step

    ahead of network administrators. Therefore, completely relying on administrators cannot

    protect network security in the long run. However, Huawei USG6000 series next-generation

    firewall can proactively discover network risks and dynamically generate protection and

    optimizing advises, like a security consultant. Proactive functions of security appliances are

    better than completely relying on administrators in the long run.

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    5/20

    2014-8-26 Huawei Confidential Page 5 of 20

    Compared with the traditional security gateways, the next-generation firewall features

    granular application control and in-depth application protection. Compared with traditional

    firewalls, using 5-tuple-based policies on the next-generation firewall does not improve

    network security. Next-generation firewalls has more powerful functions. However,

    configuring and managing these functions require more administrators with higher skills,

    which means a higher operation cost.

    The USG6000 series resolves this issue using the SmartPolicy technology. After automatictraffic pattern learning, the USG6000 automatically generates security policies using the

    predefined knowledge base. Enterprise administrators need only a confirmation before the

    firewall applies the policies to the network. The SmartPolicy function decreases the TCO by

    30% using the following functions:

    Dynamically discover security risks and automatically generate defense policies.

    Discover invalid and redundant policies to remove them.

    Discover incorrect policies, such as the policy in which the source and destination

    zones are any, but the action is permit.

    Excellent Performance

    Nowadays, hackers are launching organized attacks for illegal gains. Therefore, in-depth

    application protection, such as application-layer access control and intrusion prevention,

    becomes a must for network protection. However, the throughput of UTM devices is poor

    when application-layer protection is enabled.

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    6/20

    2014-8-26 Huawei Confidential Page 6 of 20

    In contrast, the USG6000 series uses the Intelligent Awareness Engine (IAE) to implement

    Layer-7 protection and still deliver a throughput of a Layer-4 gateway. The traditional threat

    detection engine implements per-packet inspection and is easy to evade. The IAE analyzes and

    processes multiple services concurrently. The hardware acceleration module conducts core

    application analysis and signature matching, concurrently processing each security services,

    and updates the security status. This structure ensures the minimum compromise of the overall

    performance with multiple security services enabled. In terms of hardware, the USG6000

    series uses the dedicated multi-core platform for parallel processing. In addition, it uses the

    hardware acceleration technology and the content security acceleration chip on the CPU to

    function with the IAE for a higher detection efficiency. The combination of the intelligent

    awareness engine and the elastic hardware structure enable the USG6000 series to deliver

    10-Gigabit level threat prevention performance, meeting the security protection requirements

    of large enterprise data centers.

    Prevention of Unknown Threats

    Unknown threats refer to the threats whose signatures are not yet extracted. These threatsattack networks mainly through email and web access. Unknown attacks may occur when a

    user downloads a malicious email attachment, clicks a malicious URL link in an email

    message, executes a malicious script, or downloads a malicious file. However, the security

    devices cannot detect such attacks because they have no signatures to match them.

    To address this issue, Huawei USG6000 series next-generation firewall uses the Power

    Fortress Cloud detection system to detect unknown threats, and prevent Advanced Persistent

    Threat (APT) attacks. This system simulates suspicious samples collected around the world in

    the cloud sandbox and virtualization system to analyze these samples, including behavior

    analysis and service awareness, to detect viruses, 0-day attacks, phishing websites, botnets,

    and malicious websites. If any threat is found in a sample, the system further identifies the

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    7/20

    2014-8-26 Huawei Confidential Page 7 of 20

    threat by IP address, domain name, file, URL, location, spam, user IP, and history. Then the

    system updates the global reputation detection and query system in the cloud. With 7 x 24

    pushing service of the Power Fortress Cloud-U cloud center for security knowledge base

    updates, the USG6000 series can obtain the latest threat detection and prevention capability to

    effective defend against unknown threats.

    Typical Application Scenarios

    Enterprise Intranet Management and Isolation

    Security challenges:

    1.

    Isolation of service departments or areas and mutual access management

    2.

    Accurate user identification and access permission control

    3. Identification of PCs, tablets, and mobile applications and unified network

    behavior management

    4. Prevention of confidential data leaks through social networking websites,

    instant messaging, and Internet storage applications

    Solution:

    1.

    Deploy next-generation firewalls at internal network boarders.2.

    Configure firewall policies to implement user-based access control on PC users.

    3. Implement user- and application-based policy control on mobile users for

    refined permission management and logging

    4.

    Implement content filtering and auditing on email transfer, IM, and file transfer

    to monitor social networking applications and prevent data leaks.

    Internet Border Protection

    Security challenges:

    1.

    Anonymous access or access with forged identities from the Internet

    2. Large-scale and organized DDoS attacks, paralyzing the service platform

    3.

    Confidential data leaks through social networking websites, instant messaging,

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    8/20

    2014-8-26 Huawei Confidential Page 8 of 20

    and Internet storage applications

    4.

    Employees' access to malicious websites, bringing threats to the intranet

    5.

    Employees' access to non-work-related websites, affecting productivity

    Solution:

    1.

    Deploy a next-generation firewall at the Internet egress to implement access

    control and prevent unauthorized access.

    2.

    Enable intrusion prevention and provide 10-Gigabit level application-layer

    protection.

    3.

    Enable anti-DDoS to clean massive traffic and ensure service qualities.

    4. Implement content filtering and auditing on email transfer, IM, and file transfer

    to monitor social networking applications and prevent data leaks.

    5.

    Implement user-, application-, and time-based QoS management to

    preferentially guarantee the service qualities for mission-critical personnel and

    services.

    6.

    Use URL categories and application blocking to prevent Trojan horse websitesand non-work-related websites and monitor the accessible websites and

    available network applications.

    Data Center Isolation

    Security challenges:

    1.

    In the virtualization-based cloud computing environment, each virtual system

    must be independently protected to provide services for multiple tenants or

    provide different services for one tenant.

    2. The big and centralized data faces unprecedented privacy challenges from

    hackers.

    3.

    Data centers must provide reliable services in real time. However, DoS attacks

    occur frequently.

    Solution:

    1.

    Deploy a USG series next-generation firewall which virtualizes all security

    services and system resources to provide exceptional experiences for each

    virtual system.

    2. Enable the 10-Gigabit level intrusion prevention function to effectively block

    attacks and provide differentiated defense functions in different virtual systems.

    3.

    Enable anti-DDoS to remove DDoS traffic and protect data centers.

    Enterprise Branch Interconnection (VPN Remote Interconnection)Security challenges:

    1.

    The sensitive data exchanged between headquarters and branch offices faces

    the risk of in-transit interception and tampering.

    2. Intranet access from mobile devices is insecure.

    Solution:

    1.

    Deploy a USG series next-generation firewall which provides five VPN access

    methods and over 10 encryption algorithms to establish a reliable, controllable,

    and manageable tunnel for secure data transfer on the Internet.

    2. Provide SSL VPN across multiple platforms (including Windows, IOS, Android,

    Blackberry, and Symbian).

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    9/20

    2014-8-26 Huawei Confidential Page 9 of 20

    Specifications

    Model USG6310 USG6320 USG6330 USG6350 USG6360 USG6370 USG6380 USG6390

    Firewall

    throughput 1 Gbit/s 2 Gbit/s 1 Gbit/s 2 Gbit/s 3 Gbit/s 4 Gbit/s 6 Gbit/s 8 Gbit/s

    IPS

    throughput300Mbit/s 400Mbit/s 500Mbit/s 550Mbit/s 580Mbit/s 2Gbit/s 2Gbit/s 2Gbit/s

    IPS+AV

    throughput300Mbit/s 400Mbit/s 500Mbit/s 550Mbit/s 560Mbit/s 1.4Gbit/s 1.6Gbit/s 1.8Gbit/s

    Concurrent

    sessions300,000 500,000 1,500,000 2,000,000 3,000,000 4,000,000 4,000,000 4,000,000

    New sessions

    per second10,000 20,000 30,000 30,000 30,000 60,000 70,000 80,000

    VPN

    Throughput

    (IPSec,

    3DES)

    300Mbit/s 400Mbit/s 400Mbit/s 400Mbit/s 400Mbit/s 3Gbit/s 3Gbit/s 3Gbit/s

    Virtual

    firewalls 20 2050 50 50 100 100 100

    Fixed port 8GE 4GE+2Combo 8GE+4SFP

    Expansion

    Slots- 2 x WSIC

    Interface

    module -

    2 x 10GE (SFP+)+8 x GE (RJ45), 8 x GE (RJ45), 8 x GE (SFP), 4 x GE

    (RJ45) BYPASS

    HeightDesktop(Can be

    installed in rack) 1U

    Dimensions

    (H x W x D)300*220*44.5 442*421*43.6

    Weight (full

    configuration)1.7kg 10 kg

    HDD - Optional. Supports single 300 GB hard disks ( hot swappable).

    Redundant

    power supply Adepter Optional

    AC power

    supply 100 V to 240 V

    DC power

    supply -

    Maximum

    power 60W 170W

    Operating

    environment:

    (Temperature/

    Temperature: 0to

    40

    Humidity: 10% to 90%

    Temperature: 0to 40/5to 40(with optional HDD)

    Humidity: 10% to 90%

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    10/20

    2014-8-26 Huawei Confidential Page 10 of 20

    Humidity)

    Non-operating

    environment

    Temperature: -40to 70

    Humidity: 5% to 95%

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    11/20

    2014-8-26 Huawei Confidential Page 11 of 20

    Model USG6620 USG6630 USG6650 USG6660 USG6670 USG6680

    Firewall

    throughput

    12 Gbit/s 16 Gbit/s 20 Gbit/s 25 Gbit/s 35 Gbit/s 40 Gbit/s

    IPS throughput 5.8Gbit/s 5.8Gbit/s 8.8Gbit/s 8.8Gbit/s 8.8Gbit/s 15Gbit/s

    IPS+AV

    throughput5Gbit/s 5Gbit/s 8Gbit/s 8Gbit/s 8Gbit/s 13Gbit/s

    Concurrent

    sessions6,000,000 6,000,000 8,000,000

    10,000,00

    010,000,000 12,000,000

    New sessions per

    second200,000 250,000 300,000 350,000 400,000 400,000

    VPN Throughput

    (IPSec, 3DES)12 Gbit/s 12 Gbit/s 15 Gbit/s 18 Gbit/s 18Gbit/s 18 Gbit/s

    Virtual firewalls 200 200 500 500 500 1,000

    Fixed port 8GE+4SFP 2 x 10GE+8GE+8SFP 4 x 10GE+16GE+8SFP

    Expansion Slots 2 x WSIC 6 x WSIC 5 x WSIC 2 x WSIC

    Interface module

    WSIC:

    2 x 10GE (SFP+)+8 x GE (RJ45), 8 x GE (RJ45), 8 x GE (SFP) ,4 x GE (RJ45)

    BYPASS

    Height 1U 3 U

    Dimensions (H x

    W x D)442mmx 421mm x43.6mm 130.5 mm x 442 mm x 415 mm

    Weight (full

    configuration)10 kg 24 kg

    HDDOptional. Supports single 300 GB

    hard disks ( hot swappable).

    Optional. Supports 300 GB hard disks (RAID1 and

    hot swappable).

    Redundant power

    supplyOptional Standard configuration

    AC power supply 100 V to 240 V 100 V to 240 V

    DC power supply - - 48 V to60 V

    Maximum power 170W 350 W

    Operating

    environment

    Temperature: 0to 40/5to 40(with optional HDD)

    Humidity: 10% to 90%

    Non-operating

    environment

    Temperature: -40to 70

    Humidity: 5% to 95%

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    12/20

    2014-8-26 Huawei Confidential Page 12 of 20

    Functions

    Functions

    Context awareness

    ACTUAL (Application, Content, Time, User, Attack, Location)based

    awareness capabilities

    Eight authentication methods (local, RADIUS, HWTACACS, SecureID,

    AD, CA, LDAP, and Endpoint Security)

    Application security

    Fine-grained identification of over 6000 application protocols,

    application-specific action, and online update of protocol databases

    Combination of application identification and virus scanning to recognize

    the viruses (more than 5 millions), Trojan horses, and malware hidden in

    applications

    Combination of application identification and content detection to identify

    file types and sensitive information to prevent information leaks

    Intrusion prevention

    Provides over 3500 signatures for attack identification.

    Provides protocol identification to defend against abnormal protocol

    behaviors.

    Supports user-defined IPS signatures.

    Web security

    Cloud-based URL filtering with a URL category database that contains over

    85 million URLs in over 80 categories

    Defense against web application attacks, such as cross-site scripting and

    SQL injection attacks

    HTTP/HTTPS/FTP-based content awareness to defend against web viruses

    URL blacklist and whitelist and keyword filtering

    Email security

    Real-time anti-spam to detect and filter out phishing emails

    Local whitelist and blacklist, remote real-time blacklist, content filtering,

    keyword filtering, and mail filtering by attachment type, size, and quantity

    Virus scanning and notification for POP3/SMTP/IMAP email attachments

    Data security

    Data leak prevention based on content awareness

    File reassembly and data filtering for more than 30 file types (including

    Word, Excel, PPT, and PDF), and file blocking for more than 120 file types

    Security virtualizationVirtualization of security features, forwarding statistics, users, management

    operations, views, and resources (such as bandwidths and sessions)

    Network security

    Defense against more than 10 types of DDoS attacks, such as the SYN flood

    and UDP flood attacks

    VPN technologies: IPSec VPN, SSL VPN, L2TP VPN, MPLS VPN, and

    GRE

    RoutingIPv4: static routing, RIP, OSPF, BGP, and IS -IS

    IPv6: RIPng, OSPFv3, BGP4+, IPv6 IS-IS, IPv6 RD, and ACL6

    Working mode and

    availability

    Transparent, routing, or hybrid working mode and high availability (HA),

    including the Active/Active and Active/Standby mode

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    13/20

    2014-8-26 Huawei Confidential Page 13 of 20

    Intelligent management

    Evaluates the network risks based on the passed traffic and intelligently

    generates policies based on the evaluation to automatically optimize security

    policies. Supports policy matching ratio analysis and the detection of

    conflict and redundant policies to remove them, simplifying policy

    management.

    Provides a global configuration view and integrated policy management. The

    configurations can be completed in one page.

    Provides visualized and multi-dimensional report display by user,

    application, content, time, traffic, threat, and URL.

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    14/20

    2014-8-26 Huawei Confidential Page 14 of 20

    Ordering Guide

    Model Description

    Main Equipment

    USG6310-ACUSG6310 AC Host(8GE(RJ45),2GB Memory),with HW General Security Platform

    Software

    USG6310-BDL-ACUSG6310 AC Host(8GE(RJ45),2GB Memory, with IPS-AV-URL Function Group

    Update Service Subscribe 12 Months),with HW General Security Platform Software

    USG6320-ACUSG6320 Standard Configuration 8*GE(RJ45) Desk Host(2G Memory,1 external

    power adapter),with HW General Security Platform Software

    USG6320-BDL-ACUSG6320 AC Host(8GE(RJ45),2GB Memory,with IPS -AV-URL Function Group

    Update Service Subscribe 12 Months),with HW General Security Platform Software

    USG6330-ACUSG6330 AC Host(4GE(RJ45)+2GE Combo,4GB Memory,1 AC Power),with HW

    General Security Platform Software

    USG6330-BDL-AC

    USG6330 AC Host(4GE(RJ45)+2GE Combo,4GB Memory,1 AC Power,with

    IPS-AV-URL Function Group Update Service Subscribe 12 Months),with HW General

    Security Platform Software

    USG6350-ACUSG6350 AC Host(4GE(RJ45)+2GE Combo,4GB Memory,1 AC Power),with HW

    General Security Platform Software

    USG6350-BDL-AC

    USG6350 AC Host(4GE(RJ45)+2GE Combo,4GB Memory,1 AC Power,with

    IPS-AV-URL Function Group Update Service Subscribe 12 Months),with HW General

    Security Platform Software

    USG6360-ACUSG6360 AC Host(4GE(RJ45)+2GE Combo,4GB Memory,1 AC Power),with HW

    General Security Platform Software

    USG6360-BDL-AC

    USG6360 AC Host(4GE(RJ45)+2GE Combo,4GB Memory,1 AC Power,with

    IPS-AV-URL Function Group Update Service Subscribe 12 Months),with HW General

    Security Platform Software

    USG6370-ACUSG6370 AC Host(8GE(RJ45)+4GE(SFP),4G Memory,1 AC Power),with HW

    General Security Platform Software

    USG6370-BDL-AC

    USG6370 AC Host(8GE(RJ45)+4GE(SFP),4G Memory,1 AC Power,with

    IPS-AV-URL Function Group Update Service Subscribe 12 Months),with HW General

    Security Platform Software

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    15/20

    2014-8-26 Huawei Confidential Page 15 of 20

    USG6380-ACUSG6380 AC Host(8GE(RJ45)+4GE(SFP),4GB Memory,1 AC Power),with HW

    General Security Platform Software

    USG6380-BDL-AC

    USG6380 AC Host(8GE(RJ45)+4GE(SFP),4GB Memory,1 AC Power,with

    IPS-AV-URL Function Group Update Service Subscribe 12 Months),with HW General

    Security Platform Software

    USG6390-ACUSG6390 AC Host(8GE(RJ45)+4GE(SFP),4GB Memory,1 AC Power),with HW

    General Security Platform Software

    USG6390-BDL-AC

    USG6390 AC Host(8GE(RJ45)+4GE(SFP),4G Memory,1 AC Power,with

    IPS-AV-URL Function Group Update Service Subscribe 12 Months),with HW General

    Security Platform Software

    USG6620-ACUSG6620 AC Host(8GE(RJ45)+4GE(SFP),8GB Memory,1 AC Power),with HW

    General Security Platform Software

    USG6620-BDL-AC

    USG6620 AC Host(8GE(RJ45)+4GE(SFP),8GB Memory,1 AC Power,with

    IPS-AV-URL Function Group Update Service Subscribe 12 Months),with HW General

    Security Platform Software

    USG6630-ACUSG6630 AC Host(8GE(RJ45)+4GE(SFP),8GB Memory,1 AC Power),with HW

    General Security Platform Software

    USG6630-BDL-AC

    USG6630 AC Host(8GE(RJ45)+4GE(SFP),8GB Memory,1 AC Power,with

    IPS-AV-URL Function Group Update Service Subscribe 12 Months),with HW General

    Security Platform Software

    USG6650-ACUSG6650 AC Host(8GE(RJ45)+8GE (SFP)+2*10GE(SFP+),16G Memory,2 AC

    Power),with HW General Security Platform Software

    USG6650-BDL-AC

    USG6650 AC Host(8GE(RJ45)+8GE (SFP)+2*10GE(SFP+),16G Memory,2 AC

    Power,with IPS-AV-URL Function Group Update Service Subscribe 12 Months),with

    HW General Security Platform Software

    USG6660-ACUSG6660 AC Host(8GE(RJ45)+8GE(SFP)+2*10GE(SFP+),16G Memory,2 AC

    Power),with HW General Security Platform Software

    USG6660-BDL-AC

    USG6660 AC Host(8GE(RJ45)+8GE(SFP)+2*10GE(SFP+),16G Memory,2 AC

    Power,with IPS-AV-URL Function Group Update Service Subscribe 12 Months),with

    HW General Security Platform Software

    USG6660-DCUSG6660 DC Host(8GE(RJ45)+8GE(SFP)+2*10GE(SFP+),16G Memory,2 DC

    Power),with HW General Security Platform Software

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    16/20

    2014-8-26 Huawei Confidential Page 16 of 20

    USG6670-ACUSG6670 AC Host(16GE(RJ45)+8GE(SFP)+4*10GE(SFP),16G Memory,2 AC

    Power),with HW General Security Platform Software

    USG6670-BDL-AC

    USG6670 AC Host(16GE(RJ45)+8GE(SFP)+4*10GE(SFP),16G Memory,2 AC

    Power,with IPS-AV-URL Function Group Update Service Subscribe 12 Months),with

    HW General Security Platform Software

    USG6670-DCUSG6670 DC Host(16GE(RJ45)+8GE(SFP)+4*10GE(SFP),16G Memory,2 DC

    Power),with HW General Security Platform Software

    USG6680-ACUSG6680 AC Host(16GE(RJ45)+8GE(SFP)+4*10GE(SFP+),16G Memory,2 AC

    Power),with HW General Security Platform Software

    USG6680-BDL-AC

    USG6680 AC Host(16GE(RJ45)+8GE(SFP)+4*10GE(SFP+),16G Memory,2 AC

    Power,with IPS-AV-URL Function Group Update Service Subscribe 12 Months),with

    HW General Security Platform Software

    USG6680-DCUSG6680 DC Host(16GE(RJ45)+8GE(SFP)+4*10GE(SFP+),16G Memory,2 DC

    Power),with HW General Security Platform Software

    Business Module Group

    WSIC-8GE 8GE Electric Ports Interface Card,with HW General Security Platform Software

    WSIC-4GEBYPASS 4GE Electric Ports Bypass Card,with HW General Security Platform Software

    WSIC-8GEF 8GE Optical Ports WSIC Interface Card,with HW General Security Platform Software

    WSIC-2XG8GE2*10GE Optical Ports+8GE Electric Ports Interface Card,with HW General Security

    Platform Software

    Hard disk Group

    SM-HDD-SAS300G-A 300GB 10K RPM SAS HHD unit for USG6600

    SM-HDD-SAS300G-B 300GB 10K RPM SAS HHD unit for USG6300

    Option Power Group

    Power-AC-B The AC power extension module-25degC-60degC-90V-290V-12V/14.2A

    Optical Transmitter Module Collection

    OSX040N01 Optical Transceiver,SFP+,10G,Single-mode Module(1550nm,40km,LC)

    OSU015N00 Optical Transceiver,eSFP,2.5G,Single-mode Module(1310nm,15km,LC)

    SFP-GE-LX-SM1310 Optical Transceiver,eSFP,GE,Single-mode Module(1310nm,10km,LC)

    eSFP-GE-SX-MM850 Optical Transceiver,eSFP,GE,Multi-mode Module(850nm,0.5km,LC)

    S-SFP-GE-LH40-SM1310 Optical Transceiver,eSFP,GE,Single-mode Module(1310nm,40km,LC)

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    17/20

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    18/20

    2014-8-26 Huawei Confidential Page 18 of 20

    LIC-SSL-200-USG6000Quantity of SSL VPN Concurrent Users(200 Users),with HW General Security

    Platform Software

    LIC-SSL-500-USG6000Quantity of SSL VPN Concurrent Users(500 Users),with HW General Security

    Platform Software

    LIC-SSL-1000-USG6000Quantity of SSL VPN Concurrent Users(1000 Users),with HW General Security

    Platform Software

    LIC-SSL-2000-USG6000Quantity of SSL VPN Concurrent Users(2000 Users),with HW General Security

    Platform Software

    LIC-SSL-5000-USG6000Quantity of SSL VPN Concurrent Users(5000 Users),with HW General Security

    Platform Software

    NGFW License

    USG6600 License

    LIC-IPS-12-USG6600 IPS Update Service Subscribe 12 Months,With HW General Security PlatformSoftware

    LIC-IPS-36-USG6600IPS Update Service Subscribe 36 Months,With HW General Security Platform

    Software

    LIC-URL-12-USG6600URL Filtering Update Service Subscribe 12 Months,With HW General

    Security Platform Software

    LIC-URL-36-USG6600URL Filtering Update Service Subscribe 36 Months,With HW General

    Security Platform Software

    LIC-AV-12-USG6600Anti-Virus Update Service Subscribe 12 Months,With HW General Security

    Platform Software

    LIC-AV-36-USG6600Anti-Virus Update Service Subscribe 36 Months,With HW General Security

    Platform Software

    LIC-IPSAVURL-12-USG6600IPS-AV-URL Function Group Subscribe 12 Months,With HW General Security

    Platform Software

    LIC-IPSAVURL-36-USG6600IPS-AV-URL Function Group Subscribe 36 Months,With HW General Security

    Platform Software

    USG6310/20 License

    LIC-IPS-12-USG6300-01IPS Update Service Subscribe 12 Months,With HW General Security Platform

    Software(Applies to USG6310/20)

    LIC-IPS-36-USG6300-01IPS Update Service Subscribe 36 Months,With HW General Security Platform

    Software(Applies to USG6310/20)

    LIC-URL-12-USG6300-01URL Filtering Update Service Subscribe 12 Months,With HW General

    Security Platform Software(Applies to USG6310/20)

    LIC-URL-36-USG6300-01URL Filtering Update Service Subscribe 36 Months,With HW General

    Security Platform Software(Applies to USG6310/20)

    LIC-AV-12-USG6300-01Anti-Virus Update Service Subscribe 12 Months,With HW General Security

    Platform Software(Applies to USG6310/20)

    LIC-AV-36-USG6300-01Anti-Virus Update Service Subscribe 36 Months,With HW General Security

    Platform Software(Applies to USG6310/20)

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    19/20

    2014-8-26 Huawei Confidential Page 19 of 20

    LIC-IPSAVURL-12-USG6300-01IPS-AV-URL Function Group Subscribe 12 Months,With HW General Security

    Platform Software(Applies to USG6310/20)

    LIC-IPSAVURL-36-USG6300-01IPS-AV-URL Function Group Subscribe 36 Months,With HW General Security

    Platform Software(Applies to USG6310/20)

    USG6330/50/60 License

    LIC-IPS-12-USG6300-02IPS Update Service Subscribe 12 Months,With HW General Security Platform

    Software(Applies to USG6330/50/60)

    LIC-IPS-36-USG6300-02IPS Update Service Subscribe 36 Months,With HW General Security Platform

    Software(Applies to USG6330/50/60)

    LIC-URL-12-USG6300-02URL Filtering Update Service Subscribe 12 Months,With HW General

    Security Platform Software(Applies to USG6330/50/60)

    LIC-URL-36-USG6300-02URL Filtering Update Service Subscribe 36 Months,With HW General

    Security Platform Software(Applies to USG6330/50/60)

    LIC-AV-12-USG6300-02Anti-Virus Update Service Subscribe 12 Months,With HW General Security

    Platform Software(Applies to USG6330/50/60)

    LIC-AV-36-USG6300-02Anti-Virus Update Service Subscribe 36 Months,With HW General Security

    Platform Software(Applies to USG6330/50/60)

    LIC-IPSAVURL-12-USG6300-02IPS-AV-URL Function Group Subscribe 12 Months,With HW General Security

    Platform Software(Applies to USG6330/50/60)

    LIC-IPSAVURL-36-USG6300-02IPS-AV-URL Function Group Subscribe 36 Months,With HW General Security

    Platform Software(Applies to USG6330/50/60)

    USG6370/80 License

    LIC-IPS-12-USG6300-03IPS Update Service Subscribe 12 Months,With HW General Security Platform

    Software(Applies to USG6370/80)

    LIC-IPS-36-USG6300-03IPS Update Service Subscribe 36 Months,With HW General Security Platform

    Software(Applies to USG6370/80)

    LIC-URL-12-USG6300-03URL Filtering Update Service Subscribe 12 Months,With HW General

    Security Platform Software(Applies to USG6370/80)

    LIC-URL-36-USG6300-03URL Filtering Update Service Subscribe 36 Months,With HW General

    Security Platform Software(Applies to USG6370/80)

    LIC-AV-12-USG6300-03Anti-Virus Update Service Subscribe 12 Months,With HW General Security

    Platform Software(Applies to USG6370/80)

    LIC-AV-36-USG6300-03Anti-Virus Update Service Subscribe 36 Months,With HW General Security

    Platform Software(Applies to USG6370/80)

    LIC-IPSAVURL-12-USG6300-03IPS-AV-URL Function Group Subscribe 12 Months,With HW General Security

    Platform Software(Applies to USG6370/80)

    LIC-IPSAVURL-36-USG6300-03IPS-AV-URL Function Group Subscribe 36 Months,With HW General Security

    Platform Software(Applies to USG6370/80)

    USG6390 License

    LIC-IPS-12-USG6300-04IPS Update Service Subscribe 12 Months,With HW General Security Platform

    Software(Applies to USG6390)

  • 8/10/2019 HUAWEI USG6000 Series Next-Generation Firewall Datasheet (1)

    20/20

    2014-8-26 Huawei Confidential Page 20 of 20

    LIC-IPS-36-USG6300-04IPS Update Service Subscribe 36 Months,With HW General Security Platform

    Software(Applies to USG6390)

    LIC-URL-12-USG6300-04URL Filtering Update Service Subscribe 12 Months,With HW General

    Security Platform Software(Applies to USG6390)

    LIC-URL-36-USG6300-04URL Filtering Update Service Subscribe 36 Months,With HW General

    Security Platform Software(Applies to USG6390)

    LIC-AV-12-USG6300-04Anti-Virus Update Service Subscribe 12 Months,With HW General Security

    Platform Software(Applies to USG6390)

    LIC-AV-36-USG6300-04Anti-Virus Update Service Subscribe 36 Months,With HW General Security

    Platform Software(Applies to USG6390)

    LIC-IPSAVURL-12-USG6300-04IPS-AV-URL Function Group Subscribe 12 Months,With HW General Security

    Platform Software(Applies to USG6390)

    LIC-IPSAVURL-36-USG6300-04IPS-AV-URL Function Group Subscribe 36 Months,With HW General Security

    Platform Software(Applies to USG6390)

    Basic License

    LIC-CONTENT Content Filtering Function

    About This Publication

    This publication is for reference only and shall not constitute any commitments or guarantees.

    All trademarks, pictures, logos, and brands mentioned in this document are the property of

    Huawei Technologies Co., Ltd. or a third party.

    Copyright Huawei Technologies Co., Ltd. All rights reserved.