 |
 |
 |
 |
The Juniper Networks Integrated Security Gateway 1000 is purpose-built security solution that leverage a fourth generation security ASIC, the GigaScreen, along with high speed microprocessors to deliver unmatched firewall and VPN performance. The Juniper Networks ISG 1000 is ideally suited for securing enterprise, carrier and data center environments where advanced applications such as VoIP and streaming media dictate consistent, scalable performance. Integrating best-in-class Deep Inspection firewall, VPN and DoS solutions, the ISG 1000 enable secure, reliable connectivity along with network and application-level protection for critical, high traffic network segments.
The ISG 2000 is a fully integrated FW/VPN/IDP system with multi-gigabit performance, a modular architecture, and rich virtualization capabilities. The base FW/VPN system allows for up to four I/O modules and three security modules for IDP integration.
The ISG Series can be upgraded to support integrated Intrusion Detection and Prevention (IDP) to provide robust network and application layer protection against current and emerging threats. Leveraging the same software as found on Juniper Networks IDP platforms, but integrated into ScreenOS, the ISG Series provides a combination of best in class firewall, VPN, and IDP in a single solution. Plus, with dedicated processing modules called security modules, dedicated processing is provided to ensure multi-gigabit firewall, VPN, and IDP. With unmatched security processing power and network segmentation features, the ISG Series can be deployed to protect perimeter deployments as well as internal networks.
Key features and benefits of the ISG 1000 and ISG 2000 include the following:
- Linear gigabit firewall and IPSec VPN throughput for all packet sizes to protect applications of all types including those that require low latency yet scalable small packet performance such as VoIP and streaming media
- Combination of GigaScreen3 ASIC and high performance CPUs deliver parallel processing for application level protection, network level protection and management to ensure multi-gigabit firewall, VPN, and IDP performance
- Optional integrated IDP upgrade protects critical high speed networks against the penetration and proliferation of existing and emerging application level threats such as worms, Trojans, Spyware and malware
- Scalability to meet future requirements, ensuring organizations' ability to leverage their investment and reduce their total cost of ownership
- Comprehensive high-availability solution for sub-second failover between interfaces or devices
- Full mesh configurations to allow for redundant physical paths in the network, thereby providing maximum resiliency and uptime
- Virtual System support to allow partitioning into multiple security domains, each with a unique set of administrators, policies, firewall/VPNs, and address books
- Interface flexibility for varying network-connectivity requirements and future growth requirements
- Virtual Router support to map internal, private, or overlapped IP addresses to a new IP address, providing an alternate route to the final destination and concealing it from public view
- Customizable security zones to increase interface density without additional hardware expenditures, lower policy-creation costs, contain unauthorized users and attacks, and simplify management of firewall/VPNs
- Transparent mode to enable the device to function as a Layer 2 IP security bridge, providing firewall, VPN, and DoS protections, with minimal change to the existing network
- Management through graphical Web UI, CLI, or Juniper Networks NetScreen-Security Manager central management system
- Policy-based management to allow centralized, end-to-end life-cycle management
|
| Interfaces/Ports |
4 x RJ-45 10/100/1000Base-T |
|
| Data Transfer Rate |
10Mbps Ethernet
100Mbps Fast Ethernet
1Gbps Gigabit Ethernet |
| Performance |
1 Gbps Firewall Performance Maximum
1 Gbps 3DES Performance Maximum |
| Virtualization |
250000 Concurrent Sessions Maximum
20000 New Sessions/second Maximum
10000 Policies Maximum
2000 Concurrent VPN tunnels
512 Tunnel Interfaces
20 Security Zones Default
3 Virtual Routers Default
250 VLANs Supported |
| Stateful Packet Filtering |
NAT |
| Firewall Protections |
Network Attack Detection
Distributed Denial of Service (DDoS)
Denial of Service (DoS)
TCP Reassembly for Fragmented Packet Protection
Malformed Packet Attacks
Deep Inspection Firewall
Stateful Protocol Signatures
External Web Filtering (SurfControl)
Replay Attack Prevention
VPN Authentication |
| Encryption |
DES (56-bit)
3DES (168-bit)
AES |
| Authentication |
MD5
SHA-1 |
| VPN Support |
Manual Key, IKE, PKI (X.509)
Perfect forward secrecy (DH Groups): 1,2,5
Remote access VPN
Redundant VPN gateway
Firewall and VPN User Authentication:
Built-in (internal) database user limit: 5000
3rd Party user authentication: RADIUS, RSA SecurID, and LDAP
XAUTH VPN authentication
Web-based authentication
|
| Licenses |
Unlimited Users License |
| Upgradeability |
Maximum number of Virtual Systems: 0 default, Upgradeable to 50
Maximum number of security zones: Upgradeable to 40
Maximum number of virtual routers: Upgradeable to 13
Software upgrades: TFTP/WebUI/NSM |
|
| Expansion Slots |
4 x mini-GBIC |
|
| Protocols |
HTTP
TCP/IP
FTP
SMTP
POP3
IMAP
DNS
L2TP
IPSec
Telnet
SSH
HTTPS
SNMP
SNMP v2
OSPF
BGP
RIP v1.0
RIP v2.0
H.323
SIP
SCEP
OCSP |
| Management |
WebUI (HTTP and HTTPS)
Command Line Interface (console)
Command Line Interface (SSH): v1.5 and v2.0 compatible
Command Line Interface (telnet)
System Management:
NetScreen-Security Manager
All management via VPN tunnel on any interface
SNMP full custom MIB
Logging/Monitoring:
Syslog (multiple servers): External, up to 4 servers
E-mail: 2 addresses
NetIQ WebTrends: External
SNMP v2
Traceroute
VPN tunnel monitor
Administration:
Local administrators database: 20
External administrator database RADIUS/LDAP/SecurID
Restricted administrative networks: 6
Root Admin, Admin, and Read Only user levels
Configuration Roll-back
Traffic Management:
Maximum bandwidth: Per physical interface only
DiffServ stamp: Per policy
|
|
| Input Voltage |
-36 V DC to -72 V DC |
| Power Consumption |
250 W |
|
| Temperature |
0 °C (32 °F) to 50 °C (122 °F) Operating
-20 °C (-4 °F) to 70 °C (158 °F) Non-operating |
| Humidity |
10 to 90% Non-condensing |
|
| Form Factor |
19" Rack-mountable |
| Dimensions |
5.25" Height x 17.5" Width x 17.258" Depth |
| Weight |
30 lb |
|
| Additional Information |
Two I/O modules for interface expansion
Two security modules for IDP integration
Rack mountable: 23" optional
MTBF (Bellcore model): 7.6 years
Mode of Operation:
Layer 2 mode (transparent mode)
Layer 3 mode (route and/or NAT mode)
Policy-based NAT
Mapped IP: 4096
Virtual IP: 8
Routing:
OSPF/BGP dynamic routing: Up to 8 instances each
RIP v1, RIP v2 dynamic routing: Up to 12 instances supported
BGP dynamic routing: 64 instances, 128 peers
Static routes: 10000
Source-based routing
ECMP flow based routing
High Availability:
Active/Active
Active/Passive
Redundant interfaces
Configuration synchronization
Session synchronization for firewall and VPN
Session failover for routing change
Device failure detection
Link failure detection
Authentication for new HA members
Encryption of HA traffic
IP Address Assignment:
Static
DHCP client
Internal DHCP server
DHCP relay
Certificate Authorities Supported:
Verisign
Entrust
Microsoft
RSA Keon
iPlanet (Netscape)
Baltimore
DOD PKI
External Flash:
CompactFlash: Supports 128 or 512 MB Industrial-Grade SanDisk
System config script
|
| Certifications & Standards |
Safety Certifications:
UL
CUL
CSA
CB
EMC Certifications:
FCC class A
CE class A
C-Tick
VCCI class A
IEEE:
IEEE 802.3
IEEE 802.3u
IEEE 802.3ab
IEEE 802.1Q
|
|
|
 |
 |
 |
 |
|
 |

|