 |
 |
 |
 |
- Purpose-built, high-performance integrated security gateways designed to deliver scalable network and application security for large enterprise, carrier and data center networks
- Enables secure, reliable connectivity and network and application-level protection for the network gateway
- Delivers linear firewall and IPSec VPN performance, for all packet sizes, at gigabit levels to support applications that require low latency and small packet throughput
The Juniper Networks Integrated Security Gateways (ISG) are purpose-built, security solutions that leverage a fourth generation security ASIC, the GigaScreen3, along with high-speed microprocessors to deliver unmatched firewall and VPN performance. The Juniper Networks ISG 1000 and ISG 2000 are ideally suited for securing enterprise, carrier and data center environments where advanced applications such as VoIP and streaming media dictate consistent, scalable performance. Integrating best-in-class Deep Inspection firewall, VPN and DoS solutions, the ISG 1000 and ISG 2000 enable secure, reliable connectivity along with network and application-level protection for critical, high-traffic network segments.
- ISG 1000: The ISG 1000 is a fully integrated FW/VPN/IDP system with gigabit performance, a modular architecture, and rich virtualization capabilities. The base FW/VPN system comes with four fixed 10/100/1000 interfaces and two additional I/O modules for interface expansion.
The ISG Series can be upgraded to support integrated Intrusion Detection and Prevention (IDP) to provide robust network and application layer protection against current and emerging threats. Leveraging the same software as found on Juniper Networks IDP platforms, but integrated into ScreenOS, the ISG Series provides a combination of best in class firewall, VPN, and IDP in a single solution. Plus, with dedicated processing modules called security modules, dedicated processing is provided to ensure multi-gigabit firewall, VPN, and IDP. With unmatched security processing power and network segmentation features, the ISG Series can be deployed to protect perimeter deployments as well as internal networks.
Key features and benefits of the ISG 1000 and ISG 2000 include the following:
- Linear gigabit firewall and IPSec VPN throughput for all packet sizes to protect applications of all types including those that require low latency yet scalable small packet performance such as VoIP and streaming media
- Combination of GigaScreen3 ASIC and high performance CPUs deliver parallel processing for application level protection, network level protection and management to ensure multi-gigabit firewall, VPN, and IDP performance
- Optional integrated IDP upgrade protects critical high speed networks against the penetration and proliferation of existing and emerging application level threats such as worms, Trojans, Spyware and malware
- Scalability to meet future requirements, ensuring organizations' ability to leverage their investment and reduce their total cost of ownership
- Comprehensive high-availability solution for sub-second failover between interfaces or devices
- Full mesh configurations to allow for redundant physical paths in the network, thereby providing maximum resiliency and uptime
- Virtual System support to allow partitioning into multiple security domains, each with a unique set of administrators, policies, firewall/VPNs, and address books
- Interface flexibility for varying network-connectivity requirements and future growth requirements
- Virtual Router support to map internal, private, or overlapped IP addresses to a new IP address, providing an alternate route to the final destination and concealing it from public view
- Customizable security zones to increase interface density without additional hardware expenditures, lower policy-creation costs, contain unauthorized users and attacks, and simplify management of firewall/VPNs
- Transparent mode to enable the device to function as a Layer 2 IP security bridge, providing firewall, VPN, and DoS protections, with minimal change to the existing network
- Management through graphical Web UI, CLI, or Juniper Networks NetScreen-Security Manager central management system
- Policy-based management to allow centralized, end-to-end life-cycle management
Integrated IDP
The Juniper Networks Integrated Security Gateway (ISG) Series with IDP tightly integrates the same software found on Juniper Networks' IDP platform into ScreenOS to provide unmatched application level protection against worms, Trojans, Spyware, and malware. The ISG Series delivers gigabit plus IDP performance through a combination of a fourth generation security ASIC, the GigaScreen3, high-speed microprocessors and pluggable security modules each with their own processing and memory.
- ISG 1000: The ISG 1000 with IDP uses up to two security modules to deliver up to 1Gbps of IDP throughput to deliver application level protection. The ISG 1000 comes with four fixed 10/100/1000 interfaces and two additional I/O modules for interface expansion.
The ISG Series with IDP provides the throughput and networking features that are required to protect high speed perimeter and internal network deployments where advanced applications such as VoIP and streaming media dictate network and application level protection with consistent, scalable performance. A stateful inspection firewall, along with an IPSec VPN and robust networking capabilities complement the integrated IDP functionality to deliver secure, reliable connectivity for critical, high-traffic network segments. The ISG Series with IDP includes the following features:
- Application level protection: Unmatched security processing power and network segmentation features allow the ISG Series to protect critical high-speed networks against the penetration and proliferation of existing and emerging application level threats such as worms, Trojans, Spyware, and malware. With multiple attack detection mechanisms including stateful signatures and protocol anomaly, IDP performs in-depth analysis of application protocol, context and state to deliver Zero Day coverage against existing and emerging threats.
- Network friendly: To simplify network deployments, the IDP functionality is seamlessly integrated with ScreenOS and takes full advantage of proven networking features such as dynamic routing, including OSPF, BGP, and RIP; multiple routing domains via virtual routers; and NAT/Route/Transparent deployment options. Seamless ScreenOS integration also means that IDP attack protection can be deployed across Virtual Systems and Security Zones to stop attacks from penetrating or proliferating throughout the network.
- Policy-based management:Using granular, rule-by-rule flexibility provided by NetScreen-Security Manager, administrators can deploy IDP inline or inline-tap mode on a per rule, per protocol basis. Role based administration allows a security team to delegate management authority to appropriate personnel, allowing one team to manage only the IDP component while others can manage firewall, VPN or other tasks. Attack and incident investigation as well as auditing and reporting for compliance purposes are managed easily and quickly with the NetScreen-Security Manager's intuitive graphical user interface.
| Interfaces/Ports |
4 x RJ-45 10/100/1000Base-T |
|
| Data Transfer Rate |
10Mbps Ethernet
100Mbps Fast Ethernet
1Gbps Gigabit Ethernet |
| Performance |
1 Gbps Firewall Performance Maximum
1 Gbps 3DES Performance Maximum |
| Virtualization |
250000 Concurrent Sessions Maximum
20000 New Sessions/second Maximum
10000 Policies Maximum
2000 Concurrent VPN tunnels
512 Tunnel Interfaces Maximum
20 Security Zones Default
3 Virtual Routers Default
250 VLANs Supported |
| Stateful Packet Filtering |
NAT
PAT
IPSec NAT-Traversal |
| Firewall Protections |
Network Attack Detection
Denial of Service (DoS)
Distributed Denial of Service (DDoS)
TCP Reassembly for Fragmented Packet Protection
Malformed Packet Attacks
Deep Inspection Firewall
Stateful Protocol Signatures
External Web Filtering (SurfControl)
Replay Attack Prevention
VPN Authentication |
| VPN Support |
MD-5 and SHA-1 authentication
Manual Key, IKE, PKI (X.509)
Perfect forward secrecy (DH Groups): 1,2,5
Remote access VPN
Redundant VPN gateways
Encryption:
DES (56-bit)
3DES (168-bit)
AES
|
| Licenses |
Unlimited Users License |
| Upgradeability |
Maximum number of Virtual Systems: 0 default, Upgradeable to 50
Maximum number of security zones: Upgradeable to 40
Maximum number of virtual routers: Upgradeable to 13
Software upgrades: TFTP/WebUI/NSM |
|
| Expansion Slots |
4 x mini-GBIC |
|
| Protocols |
HTTP
TCP/IP
FTP
SMTP
POP3
IMAP
DNS
L2TP
IPSec
Telnet
SSH
HTTPS
SNMP
SNMP v2
OSPF
BGP
RIP v1.0
RIP v2.0
H.323
SIP
SCEP
OCSP |
| Management |
WebUI (HTTP and HTTPS)
Command Line Interface (console)
Command Line Interface (SSH): v1.5 and v2.0 compatible
Command Line Interface (telnet)
System Management:
NetScreen-Security Manager
All management via VPN tunnel on any interface
SNMP full custom MIB
Logging/Monitoring:
Syslog (multiple servers): External, up to 4 servers
E-mail: 2 addresses
NetIQ WebTrends: External
SNMP v2
Traceroute
VPN tunnel monitor
Administration:
Local administrators database: 20
External administrator database RADIUS/LDAP/SecurID
Restricted administrative networks: 6
Root Admin, Admin, and Read Only user levels
Configuration Roll-back
Traffic Management:
Maximum bandwidth: Per physical interface only
DiffServ stamp: Per policy
|
|
| Input Voltage |
100 V AC to 240 V AC |
| Power Consumption |
250 W |
|
| Temperature |
0 °C (32 °F) to 50 °C (122 °F) Operating
-20 °C (-4 °F) to 70 °C (158 °F) Non-operating |
| Humidity |
10 to 90% Non-condensing |
|
| Form Factor |
19" Rack-mountable |
| Dimensions |
5.25" Height x 17.5" Width x 17.258" Depth |
| Weight |
30 lb |
|
| Additional Information |
Two I/O modules for interface expansion
Two security modules for IDP integration
Rack mountable: 23" optional
MTBF (Bellcore model): 7.6 years
Mode of Operation:
Layer 2 mode (transparent mode)
Layer 3 mode (route and/or NAT mode)
Policy-based NAT
Mapped IP: 4096
Virtual IP: 8
Firewall and VPN User Authentication:
Built-in (internal) database user limit: 5000
3rd Party user authentication: RADIUS, RSA SecurID, and LDAP
XAUTH VPN authentication
Web-based authentication
Routing:
OSPF/BGP dynamic routing: Up to 8 instances each
RIPv1, RIPv2 dynamic routing: Up to 12 instances supported
BGP dynamic routing: 64 instances, 128 peers
Static routes: 10000
Source-based routing
ECMP flow based routing
High Availability:
Active/Active
Active/Passive
Redundant interfaces
Configuration synchronization
Session synchronization for firewall and VPN
Session failover for routing change
Device failure detection
Link failure detection
Authentication for new HA members
Encryption of HA traffic
IP Address Assignment:
Static
DHCP client
Internal DHCP server
DHCP relay
Certi cate Authorities Supported:
Verisign
Entrust
Microsoft
RSA Keon
iPlanet (Netscape)
Baltimore
DOD PKI
External Flash:
CompactFlash: Supports 128 or 512 MB Industrial-Grade SanDisk
System config script
|
| Certifications & Standards |
Safety Certifications:
UL
CUL
CSA
CB
EMC Certifications:
FCC class A
CE class A
C-Tick
VCCI class A
IEEE:
IEEE 802.3
IEEE 802.3u
IEEE 802.3ab
|
|
|
 |
 |
 |
 |
|
 |

|