Você está na página 1de 4

Hillstone M/G Series

Next-Generation Firewall

Hillstone M/G Series next-generation firewalls provide visibility and control of web-based application traffic regardless of port, protocol or IP
address. Policies can be defined that guarantee bandwidth to mission-critical applications while restricting or blocking inappropriate or malicious
applications. Administrators can control access to applications (and application features) based on users and/or user-groups regardless of IP
address, location or device. Hillstone M/G Series firewalls incorporate comprehensive network security and advanced firewall features. They
provide superior price performance, better energy efficiency, and a smaller size compared to competing products.

Product Highlights
Granular Application Control

Visibility and Control

Hillstone M/G Series firewalls provide granular


application control. Administrators can build policies
that allow specific users or user-groups to access
selected applications. (Allow Marketing to access
Facebook). It is even possible to limit access to certain
features within an application. (Allow Marketing to
access MSN IM but Not file sharing). Policies can also be
defined that block or limit access to applications. For
example, certain games may be blocked during work
hours but allowed after work hours. Alternatively, some
applications may be allowed during work hours but
with limited bandwidth.

Hillstone M/G Series provides visibility and control of


network traffic. An intuitive user interface displays all
applications traversing the network along with
application categories and bandwidth. An administrator
can quickly choose an application and see all the users
who are accessing that application along with
bandwidth consumption. If a particular user is of interest
the administrator can see all the applications that user is
using - now and in the past. Inappropriate applications
can be blocked or limited by bandwidth or time of day.
Multiple reports show top applications, top users, top
URLs, top URL categories, top threats, etc.

Proactive Threat Protection


Hillstone M/G Series firewalls provide real-time
protection for application and network attacks including
viruses, spyware, worms, botnets, ARP spoofing,
DoS/DDoS, Trojans, buffer overflows, and SQL
injections. It incorporates a unified malware detection
engine that shares packet details with multiple security
defenses (IPS, URL filtering, and Anti-Virus), which
significantly reduces latency.
www.hillstonenet.com

Product Specification

Specification

FW Throughput

SG-6000-M8860

SG-6000-M7260

SG-6000-G5150

40Gbps

16/20Gbps

8/10Gbps

25Gbps

9/12Gbps

4Gbps

10 million sessions

5/6 million sessions

3/4 million sessions

AV Throughput (2)

4 Gbps

1.5/2Gbps

800Mbps

IPS Throughput (3)

7 Gbps

2/3Gbps

2.5Gbps

(Standard/Maximum)
IPSec Throughput(1)
Maximum Concurrent Sessions
(Standard/Maximum)

New Sessions/s
( Standard/Maximum)
Maximum SSL VPN Users

400,000 sessions per second(4)

150,000/200,000 sessions per


second(4)

120,000 sessions per second(5)

10,000

10,000

6,000

1 x Console Port, 1 x AUX Port,

1 x Console Port, 1 x AUX Port,

1 x Console Port, 1 x AUX Port,

1 x USB Port, 1 x HA, 1 x MGT

1 x USB Port, 1 x HA, 1 x MGT

1 x USB 2.0 Port

4 x GE, 4x SFP

4 x GE, 4x SFP

4 x GE, 8 x SFP

4 x Generic Slot

4 x Generic Slot

4 x Generic Slot

IOC-8GE-MIOC-8SFP-M

IOC-8GE, IOC-8SFP, IOC-4GE-B,

IOC-4GE-B-MIOC-2XFP-Lite-M

IOC-2XFP, Storage Extension Slot

1 x 450W Redundancy 1 + 1

1 x 450W Redundancy 1 + 1

1 x 450W Redundancy 1 + 1

AC 100-240V 50/60Hz

AC 100-240V 50/60Hz

AC 100-240V 50/60Hz

DC -40 ~ -60V

DC -40 ~ -60V

DC -40~-60V

2U 17.3 20.5 3.5 in

2U 17.3 20.5 3.5 in

2U 17.3 x 20.5 x 3.5 in

(44052088 mm)

(44052088)

(440 x 520 x 88mm)

Weight

27.1 lb (12.3KG)

27.1 lb (12.3KG)

37.0 lb (16.8kg)

Temperature

32-104 F (0-40)

32-104 F (0-40)

32-104 F (0-40)

Relative Humidity

10-95% (no dew)

10-95%(no dew)

10-95%( no dew)

Management Ports
Fixed I/O Ports
Available Slots for Extension
Modules

IOC-8GE-M, IOC-8SFP-M,
Expansion Module Option

IOC-4GE-B-M, IOC-2XFP-Lite-M
(only for Slot-2/4), IOC-4XFP

Maximum Power Consumption


Power Supply

Dimension (WDH, mm)

www.hillstonenet.com

Specification

FW Throughput
(Standard/Maximum)
IPSec Throughput(1)
Maximum Concurrent Sessions
(Standard/Maximum)

SG-6000-G2120

SG-6000-M3108

SG-6000-M3100

SG-6000-M1600

4Gbps

1/2Gbps

1 Gbps

500Mbps

1.5Gbps

500Mbps

500 Mbps

200Mbps

600,000 / 1 million

400,000 / 1 million

sessions

sessions

1/2 million sessions

200,000 sessions

AV Throughput (2)

350Mbps

70Mbps

70 Mbps

50 Mbps

IPS Throughput (3)

800Mbps

200Mbps

200 Mbps

150 Mbps

New Sessions/s

45,000 sessions per

12,000 sessions per

10,000 sessions per

4,000 sessions per

( Standard/Maximum)

second(5)

second(5)

second(5)

second(5)

Maximum SSL VPN Users

2,000

500

500

128

1 x Console Port, 1 x AUX

1 x Console Port,

1 x Console Port,

1 x Console Port,

Port, 1 x USB 2.0 Port

1 x USB 2.0 Port

1 x USB 2.0 Port

1 x USB 2.0 Port

4 x GE, 4 x SFP

8 x GE, 2 x GE/SFP

8 x GE

5 x GE

2 x Generic Slot

1 x SD Slot

NA

NA

SDHC Card

NA

NA

1 x 45W, dual power

1 x 45W, dual power

supply available

supply available

Management Ports
Fixed I/O Ports
Available Slots for Extension
Modules

IOC-8GE, IOC-8SFP,
Expansion Module Option

IOC-4GE-B, Storage
Extension Slot

Maximum Power Consumption

150W Redundancy 1 + 1
AC 100-240V 50/60Hz

AC 100-240V 50/60Hz

DC -40~-60V

DC -40~-60V

1U 17.2 x 14.4 x 1.7 in


(436 366 44 mm)

Weight

Power Supply

1 x 15W

AC 100-240V 50/60Hz

AC 100-240V 50/60Hz

1U 17.4 x 9.5 x 1.7 in

1U 17.4 x 9.5 x 1.7 in

Desktop 11.8 x 6.5 x 1.7

(442 x 241 x 44 mm)

(442 x 241 x 44 mm)

in(300 x 165 x 44mm)

19.8 lb (9 kg)

12.5 lb (5.7kg)

12.3 lb (5.6kg)

4.07 lb (1.85 kg)

Temperature

32-104 F (0-40oC)

32-104 F(0-40)

32-104 F(0-40)

32-104 F ( 0-40)

Relative Humidity

10-95%(no dew)

10-95%(no dew)

10-95% (no dew)

10-95% (no dew)

Dimension (WDH, mm)

Unless specified otherwise, all performance, capacity and function


functionality
ion
are based on StoneOS 5.0R3. Results
ts may
m va
vvary based on StoneOS version and
deployment.
NOTES:(1) IPSec throughput data is obtained under
AES256+SHA-1
and 1400-byte
packet;
un
Preshare Key AES256+SH
+SHA-1 configuration an
byte packet
p et ssize
ize pack
k t; (2)) AV throughput
ut da
data
taa is
obtained under HTTP traffic with file attachment;
obtained
bi-direction HTTP
traffic
detection
with alll IPS rrules being
turned
nt; (3) IPS
PS throughput data is obtain
tained under bi-direct
TP traff
ffic det
et ction w
ein tur
r
on; (4) New Sessions/s is obtained under HTTP traffic; (5
(5) New Sessions/s is obtained un
close traffic
under TCP no clo
f

www.hillstonenet.com
w.hillsto
o

Product Specification
M8860 Options:
Specification IOC-8GE-M

IOC-8SFP-M

IOC-4GE-B-M

IOC-2XFP-Lite-M

IOC-4XFP

Name

8GE Extension Module

8SFP Extension Module

4GE Bypass Extension Module

2XFP Extension Module

4XFP Extension Module

I/O Ports

8 x GE

8 x SFP, SFP module not

4 x GE Bypass (2 pair bypass

2 x XFP, XFP module

4 x XFP, XFP module not

included

ports)

not included

included

U(Occupy 1 generic slots)

1 U(Occupy 2 generic slots)

2.0 lb (0.9kg)

2.0 lb (0.9kg)

Dimension

U (Occupy 1 generic slots) U (Occupy 1 generic slots) U(Occupy 1 generic slots)

Weight

1.8 lb (0.8kg)

2.0 lb (0.9kg)

1.8 lb (0.8kg)

M7260 Options:
Specification

IOC-8GE-M

IOC-8SFP-M

IOC-4GE-B-M

IOC-2XFP-Lite-M

Name

8GE Extension Module

8SFP Extension Module

4GE Bypass Extension Module

2XFP Extension Module

I/O Ports

8 x GE

8 x SFP, SFP module not

4 x GE Bypass (2 pair bypass

2 x XFP, XFP module

included

ports)

not included

Dimension

U (Occupy 1 generic slots)

U (Occupy 1 generic slots)

U(Occupy 1 generic slots)

U(Occupy 1 generic slots)

Weight

1.8 lb (0.8kg)

2.0 lb (0.9kg)

1.8 lb (0.8kg)

2.0 lb (0.9kg)

Stone OS Core Features


Networking Features

VPN

Centralized Mgt

Dynamic routing(OSPF,
BGP,RIPv2)
Policy based routing
Route controlled by application
IPv6
Tap mode connect to SPAN
port
L2/L3 switching & routing
Virtual wire (Layer 1) transparent
in-line deployment

PnP VPN
SSL VPN (optional USB-key)
L2TP
L2TP over IPSec VPN

Centralized deployment and


management
Unified policy mgt.
Performance and traffic monitoring

High Availability

Zone-Base Architecture

Active/passive
Configuration and session
synchronization

All interfaces assigned to security


zones for policy enforcement

Virtual Firewalls

Over 1.3 million AV signatures


Over 3500 IPS signatures
Over 20 million domain names
DoS/DDos DNS Query Flood
SYN Flood
ARP spoofing
Malformed packets

QoS Traffic Shaping


Max/guaranteed and priority
By user, group, app, IP address,
time, and more
By Class of Service (CoS) and app
priority (compatible with DiffServ
tag)

Multiple virtual firewalls in a single


device Load Balancing
By Source IP
Vy Destination IP
By Session
By Bandwidth/Latency

U.S. Oce

www.hillstonenet.com

Threat Detection

292 Gibraltar Drive Suite 105,


Sunnyvale, CA 94089
Phone: 1-408-508-6750
Email: inquiry@hillstonenet.com

China Oce

Building D, Tongfang Plaza, 6F


No.1 Wangzhuang Road
Haidian, Beijing 100083
Phone: +86-10-8236-6000
Email: inquiry@hillstonenet.com

Você também pode gostar