|

|
SSG Series Appliances |
| Juniper Networks Secure Services Gateway 550M
with 1GB DRAM, 1 AC Power Supply |
#SSG-550M-SH
List Price: $10,500.00
Our Price: $8,085.00 |
|
| Juniper Networks Secure Services Gateway 550M
with 1GB DRAM, 1 DC Power Supply |
#SSG-550M-SH-DC
List Price: $12,500.00
Our Price: $9,625.00 |
|
More pricing below,
click here
SSG550M Overview:
The Juniper Networks SSG550M is a purpose-built,
modular security platform that delivers 1+ Gbps of firewall
traffic and 500 Mbps of IPsec VPN for large branch offices,
regional offices, and enterprises.
The Juniper Networks SSG500 line consists of purpose-built
security appliances that deliver the perfect blend of
performance, security, routing and LAN/WAN connectivity
for large, regional branch offices and medium-sized,
standalone businesses. Traffic flowing in and out of
the regional office or business is protected from worms,
spyware, trojans and malware by a complete set of unified
threat management security features including stateful
firewall, IPsec VPN, IPS, antivirus (includes anti-spyware,
anti-adware, anti-phishing), anti-spam and Web filtering.
The SSG500 line comprises the SSG550/SSG550M and the
SSG520/SSG520M Secure Services Gateways.
The Juniper Networks SSG500 line of secure services
gateways consists of high-performance security platforms
for regional branch office and medium-sized, standalone
businesses that want to stop internal and external attacks,
prevent unauthorized access and achieve regulatory compliance.
The Juniper Networks SSG550/SSG550M Secure Services
Gateway provides 1+ Gbps of stateful firewall performance
and 500 Mbps of IPsec VPN performance, while the Juniper
Networks SSG520/SSG520M Secure Services Gateway provides
650 Mbps of stateful firewall performance and 300 Mbps
of IPsec VPN performance.
These products focus on three key disciplines:
Security: Protection against worms, viruses,
trojans, spam and emerging malware is delivered by proven
unified threat management (UTM) security features that
are backed by best-in-class partners. To address internal
security requirements and facilitate regulatory compliance,
the SSG500 line supports an advanced set of network
protection features such as security zones, virtual
routers and VLANs that allow administrators to divide
the network into distinct, secure domains, each with
their own unique security policy. Policies protecting
each security zone can include access control rules
and inspection by any of the supported UTM security
features.

The SSG550 deployed at a branch
office for secure Internet connectivity and site-to-site
VPN to corporate headquarters. Internal branch office
resources are protected with unique security policies
applied to each security zone.
Connectivity and Routing: The SSG500 line
provides four onboard 10/100/1000 interfaces complemented
by six I/O expansion slots that can house a mix of LAN
or WAN interfaces, making the SSG500 line an extremely
flexible platform. The broad array of I/O options coupled
with WAN protocol and encapsulation support makes SSG500
line gateways easily deployable as traditional branch
office routers or as consolidated security and routing
devices to reduce CAPEX and OPEX.
Access Control Enforcement: The SSG500 line
gateways can act as enforcement points in a Juniper
Networks Unified Access Control deployment with the
simple addition of the IC Series UAC appliance. The
IC Series appliance functions as a central policy management
engine by interacting with the SSG500 line to augment
or replace the firewall-based access control with a
solution that grants/denies access based on more granular
criteria, including endpoint state and user identity
in order to accommodate the dramatic shifts in attack
landscape and user characteristics.
World-Class Support: From simple lab testing
to major network implementations, Juniper Networks Professional
Services will collaborate with your team to identify
goals, define the deployment process, create or validate
the network design and manage the deployment to its
successful conclusion.

Features & Benefits:
|
Features |
Features Description |
Benefits |
|
High performance |
Purpose-built platform is assembled from
custom-built hardware, powerful processing
and a security-specific operating system. |
Delivers performance headroom required to
protect against internal and external attacks
now and into the future. |
|
Best-in-class UTM security features |
UTM security features (antivirus, anti-spam,
Web filtering, IPS) stop all manner of viruses
and malware before they damage the network. |
Ensures that the network is protected against
all manner of attacks. |
|
Integrated antivirus |
Annually licensed antivirus engine is based
on Kaspersky Lab engine. |
Stops viruses, spyware, adware and other
malware. |
|
Integrated anti-spam |
Annually licensed anti-spam offering is
based on Symantec technology. |
Blocks unwanted email from known spammers
and phishers. |
|
Integrated Web filtering |
Annually licensed Web filtering solution
is based on Websense SurfControl technology. |
Controls/blocks access to malicious Web
sites. |
|
Integrated IPS (Deep Inspection) |
Annually licensed IPS engine is available
with Juniper Networks Deep Inspection Firewall
Signature Packs. |
Prevents application-level attacks from
flooding the network. |
|
Fixed Interfaces |
Four fixed 10/100/1000 interfaces, two USB
ports, one console port and one auxiliary
port are standard on all SSG500 line models. |
Provides high-speed LAN connectivity, future
connectivity, and flexible management. |
|
Network segmentation |
Bridge groups, security zones, virtual LANs
and virtual routers allow administrators
to deploy security policies to isolate guests,
wireless networks and regional servers or
databases.* |
Powerful capabilities facilitate deploying
security for various internal, external
and DMZ sub-groups on the network, to prevent
unauthorized access. |
|
Interface modularity |
Six interface expansion slots support optional
T1, E1, Serial, ADSL/ADSL2/ADSL2+, G.SHDSL,
DS3, E3, 10/100/1000, 10/100 and SFP connectivity. |
Delivers LAN and WAN connectivity options
on top of unmatched security to reduce costs
and extend investment protection. |
|
Robust routing engine |
Proven routing engine supports OSPF, BGP
and RIP v1/2 along with Frame Relay, Multilink
Frame Relay, PPP, Multilink PPP and HDLC. |
Enables the deployment of consolidated security
and routing device, thereby lowering operational
and capital expenditures. |
|
Juniper Network Unified Access Control
enforcement point |
Interacts with the centralized policy management
engine (IC Series) to enforce session-specific
access control policies using criteria such
as user identity, device security state,
and network location. |
Improves security posture in a cost-effective
manner by leveraging existing customer network
infrastructure components and best-in-class
technology. |
|
Management flexibility |
Use any one of three mechanisms, command
line interface (CLI), WebUI or Juniper Networks
Network and Security Manager (NSM) to securely
deploy, monitor and manage security policies. |
Enables management access from any location,
eliminating onsite visits thereby improving
response time and reducing operational costs. |
|
Auto-Connect VPN |
Automatically sets up and takes down VPN
tunnels between spoke sites in a hub-and-spoke
topology. |
Provides a scalable VPN solution for mesh
architectures with support for latency-sensitive
applications such as VoIP and video conferencing. |
|
World-class professional services |
From simple lab testing to major network
implementations, Juniper Networks Professional
Services will collaborate with your team
to identify goals, define the deployment
process, create or validate the network
design and manage the deployment. |
Transforms the network infrastructure to
ensure that it is secure, flexible, scalable
and reliable. |
* Bridge groups supported
only on uPIMs in ScreenOS 6.0 and greater releases
Product Options:
|
Option |
Option Description |
Applicable Products |
|
Single or redundant AC or DC power supplies |
All models in the SSG500 line are available
with either AC or DC power supplies. The
SSG520 and SSG520M offer a single power
supply. The SSG550 and SSG550M are available
with optional redundant power supplies. |
SSG550/SSG550M
SSG520/SSG520M |
|
Network Equipment Building Systems (NEBS)
compliance |
NEBS-compliant versions of the SSG520M and
the SSG550M are available. |
SSG520M and SSG550M |
|
DRAM |
All models in the SSG500 line are available
with 1 GB of DRAM. The SSG520 and SSG550
are also available in 512 MB-DRAM versions. |
SSG550/SSG550M
SSG520/SSG520M |
|
Unified Threat Management / Content Security
(high memory option required) |
The SSG500 line can be configured with any
combination of the following best-in-class
UTM and content security functionality:
antivirus (includes anti-spyware, anti-phishing),
IPS (Deep Inspection), Web filtering and/or
anti-spam. |
SSG550 (high-memory model only)/SSG550M
SSG520 (high-memory model only)/SSG520M |
|
I/O options |
Six interface expansion slots support optional
T1, E1, Serial, DS3, 10/100/1000, 10/100
and SFP connectivity. |
SSG550/SSG550M
SSG520/SSG520M |
Technical Specifications:


|
Model: |
SSG520M |
SSG550M |
 |

|
|
Dimensions and Power |
|
Size (W x H x D) |
17.5 x 3.5 x 21.5 in
(44.5 x 8.9 x 54.6 cm) |
17.5 x 3.5 x 21.5 in
(44.5 x 8.9 x 54.6 cm) |
|
Weight |
23.0 lb (no interface modules)
10.43 kg |
25.0 lb (no interface modules + one power
supply) 11.34 kg |
|
Rack mountable |
Yes, 2RU |
Yes, 2RU |
|
Power supply (AC) |
100 to 240 VAC, 350 watts |
100 to 240 VAC, 420 watts |
|
Power supply (DC) |
-48 to -60 VDC, 420 watts |
-48 to -60 VDC, 420 watts |
|
Redundant power supply (hot swappable) |
No |
Yes |
|
Maximum thermal output |
1,070 BTU/Hour (W) |
1,145 BTU/Hour (W) |
|
Certifications |
|
Safety Certifications |
UL, CUL, CSA, CB |
UL, CUL, CSA, CB |
|
Electromagnetic compatibility (EMC) Certifications |
FCC class A, CE class A, C-Tick, VCCI class
B |
FCC class A, CE class A, C-Tick, VCCI class
B |
|
Network Equipment Building System (NEBS) |
Level 3 (SSG520M only) |
Level 3 |
|
Mean time between failures (MTBF) |
12 years |
12 years |
|
Security Certification |
|
Common Criteria: EAL4 |
Yes (SSG520M) |
Yes (SSG550M) |
|
FIPS 140-2: Level 2 |
Yes (SSG520M) |
Yes (SSG550M) |
|
ICSA Firewall and VPN |
Yes |
Yes |
|
Environment |
|
Operating Temperature |
32° to 122° F (0° to 50° C) |
32° to 122° F (0° to 50° C) |
|
Non-Operating Temperature |
-4° to 158° F (-20° to 70° C) |
-4° to 158° F (-20° to 70° C) |
|
Humidity |
10% to 90% noncondensing |
10% to 90% noncondensing |
|
Model: |
SSG520M |
SSG550M |
 |

|
|
Maximum Performance and Capacity(1) |
|
ScreenOS version tested |
ScreenOS 6.2 |
ScreenOS 6.2 |
|
Firewall performance (Large packets) |
650+ Mbps |
1+ Gbps |
|
Firewall performance (IMIX)(2) |
600 Mbps |
1 Gbps |
|
Firewall packets per second (64 byte) |
300,000 PPS |
600,000 PPS |
|
Advanced Encryption Standard (AES) 256+SHA-1
VPN performance |
300 Mbps |
500 Mbps |
|
3DES encryption +SHA-1 VPN performance |
300 Mbps |
500 Mbps |
|
Maximum concurrent sessions |
128,000 |
256,000 |
|
New sessions/second |
10,000 |
15,000 |
|
Maximum security policies |
4,000 |
4,000 |
|
Maximum users supported |
Unrestricted |
Unrestricted |
|
Convertible to Juniper Networks JUNOS
Software 8.0 or higher |
Yes |
Yes |
|
Network Connectivity |
|
Fixed I/O |
4 x 10/100/1000 |
4 x 10/100/1000 |
|
Physical Interface Module (PIM) slots |
6 (2 ePIM/uPIM/PIM + 4 uPIM/PIM) |
6 (4 ePIM/uPIM/PIM + 2 uPIM/PIM) |
|
WAN Interface options (PIMs) |
Serial, T1, E1, DS3, E3, ADSL/ADSL2/ADSL2+,
G.SHDSL |
Serial, T1, E1, DS3, E3, ADSL/ADSL2/ADSL2+,
G.SHDSL |
|
LAN Interface options (ePIMs and uPIMs) |
10/100, 10/100/1000, and SFP |
10/100, 10/100/1000, and SFP |
|
Firewall |
|
Network attack detection |
Yes |
Yes |
|
DoS and DDoS protection |
Yes |
Yes |
|
TCP reassembly for fragmented packet
protection |
Yes |
Yes |
|
Brute force attack mitigation |
Yes |
Yes |
|
SYN cookie protection |
Yes |
Yes |
|
Zone-based IP spoofing |
Yes |
Yes |
|
Malformed packet protection |
Yes |
Yes |
|
Unified Threat Management(3) |
|
IPS (Deep Inspection firewall) |
Yes |
Yes |
|
Protocol anomaly detection |
Yes |
Yes |
|
Stateful protocol signatures |
Yes |
Yes |
|
IPS/DI attack pattern obfuscation |
Yes |
Yes |
|
Antivirus |
Yes |
Yes |
|
Signature database |
200,000+ |
200,000+ |
|
Protocols scanned |
POP3, HTTP, SMTP, IMAP, FTP, IM |
POP3, HTTP, SMTP, IMAP, FTP, IM |
|
Anti-spyware |
Yes |
Yes |
|
Anti-adware |
Yes |
Yes |
|
Anti-keylogger |
Yes |
Yes |
|
Instant message AV |
Yes |
Yes |
|
Anti-spam |
Yes |
Yes |
|
Integrated URL filtering |
Yes |
Yes |
|
External filtering(4) |
Yes |
Yes |
|
VoIP Security |
|
H.323. Application-level gateway (ALG) |
Yes |
Yes |
|
SIP ALG |
Yes |
Yes |
|
MGCP ALG |
Yes |
Yes |
|
SCCP ALG |
Yes |
Yes |
|
Network Address Translation (NAT) for
VoIP protocols |
Yes |
Yes |
|
IPsec VPN |
|
Concurrent VPN tunnels |
500 |
1,000 |
|
Tunnel interfaces |
100 |
300 |
|
DES encryption (56-bit), 3DES encryption
(168-bit) and Advanced Encryption Standard
(AES) (256-bit) |
Yes |
Yes |
|
MD-5 and SHA-1 authentication |
Yes |
Yes |
|
Manual key, Internet Key Exchange (IKE),
IKEv2 with EAP public key infrastructure
(PKI) (X.509) |
Yes |
Yes |
|
Perfect forward secrecy (DH Groups) |
1,2,5 |
1,2,5 |
|
Prevent replay attack |
Yes |
Yes |
|
Remote access VPN |
Yes |
Yes |
|
Layer2 Tunneling Protocol (L2TP) within
IPsec |
Yes |
Yes |
|
IPsec Network Address Translation (NAT)
traversal |
Yes |
Yes |
|
Auto-Connect VPN |
Yes |
Yes |
|
Redundant VPN gateways |
Yes |
Yes |
|
User Authentication and Access Control |
|
Built-in (internal) database - user limit |
500 |
1,500 |
|
Third-party user authentication |
RADIUS, RSA SecureID, LDAP |
RADIUS, RSA SecureID, LDAP |
|
RADIUS Accounting |
Yes - start/stop |
Yes - start/stop |
|
XAUTH VPN authentication |
Yes |
Yes |
|
Web-based authentication |
Yes |
Yes |
|
802.1X authentication |
Yes |
Yes |
|
Unified Access Control (UAC) enforcement
point |
Yes |
Yes |
|
PKI Support |
|
PKI Certificate requests (PKCS 7 and
PKCS 10) |
Yes |
Yes |
|
Automated certificate enrollment (SCEP) |
Yes |
Yes |
|
Online Status Protocol (OCSP) |
Yes |
Yes |
|
Certificate Authorities supported |
VeriSign, Entrust, Microsoft, RSA Keon,
iPlanet (Netscape) Baltimore, DoD PKI |
VeriSign, Entrust, Microsoft, RSA Keon,
iPlanet (Netscape) Baltimore, DoD PKI |
|
Self-signed certificates |
Yes |
Yes |
|
Virtualization |
|
Maximum number of security zones |
60 |
60 |
|
Maximum number of virtual routers |
11 |
16 |
|
Bridge groups* |
Yes |
Yes |
|
Maximum number of VLANs |
125 |
150 |
|
Routing |
|
BGP instances |
10 |
15 |
|
BGP peers |
64 |
128 |
|
BGP routes |
250,000 |
250,000 |
|
OSPF instances |
3 |
8 |
|
OSPF routes |
250,000 |
250,000 |
|
RIP v1/v2 instances |
128 |
256 |
|
RIP v2 routes |
250,000 |
250,000 |
|
Static routes |
250,000 |
250,000 |
|
Source-based routing |
Yes |
Yes |
|
Policy-based routing |
Yes |
Yes |
|
Equal-cost multipath (ECMP) |
Yes |
Yes |
|
Multicast |
Yes |
Yes |
|
Reverse Path Forwarding (RPF) |
Yes |
Yes |
|
Internet Group Management Protocol (IGMP)
(v1,v2) |
Yes |
Yes |
|
IGMP Proxy |
Yes |
Yes |
|
PIM single mode |
Yes |
Yes |
|
PIM source-specific multicast |
Yes |
Yes |
|
Multicast inside IPsec tunnel |
Yes |
Yes |
|
Encapsulations |
|
Point-to-Point Protocol (PPP) |
Yes |
Yes |
|
Multilink Point-to-Point Protocol (MLPPP) |
Yes |
Yes |
|
MLPPP max physical interfaces |
12 |
12 |
|
Frame Relay |
Yes |
Yes |
|
Multilink Frame (MLFR) (FRF 15, FRF 16) |
Yes |
Yes |
|
MLFR max physical interfaces |
12 |
12 |
|
HDLC |
Yes |
Yes |
|
IPv6 |
|
Dual stack IPv4/IPv6 firewall and VPN |
Yes |
Yes |
|
IPv4 to/from IPv6 translations and encapsulations |
Yes |
Yes |
|
Syn-Cookie and Syn-Proxy DoS Attack Detection |
Yes |
Yes |
|
SIP, RTSP, Sun-RPC, and MS-RPC ALG’s |
Yes |
Yes |
|
RIPng |
Yes |
Yes |
|
BGP |
Yes |
Yes |
|
Transparent mode |
Yes |
Yes |
|
NSRP |
Yes |
Yes |
|
DHCPv6 Relay |
Yes |
Yes |
|
Mode of Operation |
|
Layer 2 (transparent) mode(5) |
Yes |
Yes |
|
Layer 3 (route and/or NAT) mode |
Yes |
Yes |
|
Address Translation |
|
Network Address Translation (NAT) |
Yes |
Yes |
|
Port Translation (PAT) |
Yes |
Yes |
|
Policy-based NAT/PAT (L2 and L3 mode) |
Yes |
Yes |
|
Mapped IP (MIP) (L3 mode) |
6,000 |
6,000 |
|
Virtual IP (VIP) (L3 mode) |
32 |
64 |
|
MIP/VIP Grouping (L3 mode) |
Yes |
Yes |
|
IP Address Assignment |
|
Static |
Yes |
Yes |
|
DHCP, PPPoE client |
Yes |
Yes |
|
Internal DHCP server |
Yes |
Yes |
|
DHCP relay |
Yes |
Yes |
|
Traffic Management Quality of Service
(QoS) |
|
Guaranteed bandwidth |
Yes - per policy |
Yes - per policy |
|
Maximum bandwidth |
Yes - per policy |
Yes - per policy |
|
Ingress traffic policing |
Yes |
Yes |
|
Priority-bandwidth utilization |
Yes |
Yes |
|
Differv marking |
Yes - per policy |
Yes - per policy |
|
High Availability (HA)(7) |
|
Active/Active - L3 mode |
Yes |
Yes |
|
Active/Passive -Transparent & mode |
Yes |
Yes |
|
Configuration synchronization |
Yes |
Yes |
|
VRRP |
Yes |
Yes |
|
Session synchronization for firewall
and VPN |
Yes |
Yes |
|
Session failover for routing change |
Yes |
Yes |
|
Device failure detection |
Yes |
Yes |
|
Link failure detection |
Yes |
Yes |
|
Authentication for new HA members |
Yes |
Yes |
|
Encryption of HA traffic |
Yes |
Yes |
|
System Management |
|
WebUI (HTTP and HTTPS) |
Yes |
Yes |
|
Command line interface (console) |
Yes |
Yes |
|
Command line interface (telnet) |
Yes |
Yes |
|
Command line interface (SSH) |
Yes v1.5 and v2.0 compatible |
Yes v1.5 and v2.0 compatible |
|
Network and Security Manager (NSM) |
Yes |
Yes |
|
All management via VPN tunnel on any
interface |
Yes |
Yes |
|
Rapid deployment |
No |
No |
|
Administration |
|
Local administrator database size |
20 |
20 |
|
External administrator database support |
RADIUS, RSA SecurID, LDAP |
RADIUS, RSA SecurID, LDAP |
|
Restricted administrative networks |
6 |
6 |
|
Root Admin, Admin and Read Only user
levels |
Yes |
Yes |
|
Software upgrades |
TFTP, WebUL, NSM, SCP, USB |
TFTP, WebUL, NSM, SCP, USB |
|
Configuration rollback |
Yes |
Yes |
|
Logging/Monitoring |
|
Syslog (multiple servers) |
Yes - up to 4 servers |
Yes - up to 4 servers |
|
Email (two addresses) |
Yes |
Yes |
|
NetIQ WebTrends |
Yes |
Yes |
|
SNMP (v2) |
Yes |
Yes |
|
SNMP full custom MIB |
Yes |
Yes |
|
Traceroute |
Yes |
Yes |
|
VPN tunnel monitor |
Yes |
Yes |
|
External Flash |
|
Additional log storage |
USB 1.1 |
USB 1.1 |
|
Event logs and alarms |
Yes |
Yes |
|
System configuration script |
Yes |
Yes |
|
ScreenOS Software |
Yes |
Yes |
*Bridge groups supported
only on uPIMs in ScreenOS 6.0 and greater releases
(1) Performance, capacity and features listed are based
upon systems running ScreenOS 6.2 and are the measured
maximums under ideal testing conditions unless otherwise
noted. Actual results may vary based on ScreenOS release
and deployment. For a complete list of supported ScreenOS
versions for SSG Series gateways, please visit the Juniper
Customer Support Center (www.juniper.net/customers/support/)
and click on ScreenOS Software Downloads.
(2) IMIX stands for Internet mix and is more demanding
than a single packet size as it represents a traffic
mix that is more typical of a customer’s network. The
IMIX traffic used is made up of 58.33% 64 byte packets
+ 33.33% 570 byte packets + 8.33% 1518 byte packets
of UDP traffic.
(3) UTM Security features (IPS/Deep Inspection, antivirus,
anti-spam and Web filtering) are delivered by annual
subscriptions purchased separately from Juniper Networks.
Annual subscriptions provide signature updates and associated
support. The high memory option is required for UTM
Security features.
(4) Redirect Web filtering sends traffic from the firewall
to a secondary server. The redirect feature is free,
however it does require the purchase of a separate Web
filtering license from either Websense or SurfControl.
(5) NAT, PAT, policy-based NAT, virtual IP, mapped IP,
virtual systems, virtual routers, VLANs, OSPF, BGP,
RIPv2, active/active HA and IP address assignment are
not available in layer 2 transparent mode.
SSG Series Comparison Matrix:
|
Model: |
SSG5 Wired / Wireless |
SSG20 Wired / Wireless |
SSG140 |
SSG320M |
SSG350M |
SSG520M |
SSG550M |
 |
 |
 |
 |
 |
 |
 |
|
Interfaces |
7 10/100 with Factory Configured V.92 or
ISDN BRI S/T or RS232 Serial/AUX. Optional
802.11a/b/g |
5 10/100 + 2 I/O slots supporting T1, E1,
V.92, ISDN BRI S/T, SFP, Serial, or ADSL2+,
Optional 802.11a/b/g |
8 10/100 + 2 10/100/1000 + 4 I/O slots supporting
T1, E1, ISDN BRI S/T, Serial, ADSL2+, G.SHDSL,
10/100/1000, SFP |
4 10/100/1000 and 3 I/O slots supporting
Serial, T1, E1, ADSL, ADSL2, ADSL2+, G.SHDSL |
4 10/100/1000 and 5 I/O slots supporting
Serial, T1, E1, ADSL, ADSL2, ADSL2+, G.SHDSL |
4 10/100/1000 and 6 I/O slots, supporting
SFP, FE, Serial, T1, E1, DS3, E3, ADSL2+,
G.SHDSL, 10/100/1000 |
4 10/100/1000 and 6 I/O slots, supporting
SFP, FE, Serial, T1, E1, DS3, E3, ADSL2+,
G.SHDSL, 10/100/1000 |
|
Max Throughput |
160 Mb firewall 40 Mb 3DES VPN |
160 Mb firewall 40 Mb 3DES VPN |
350+ Mb firewall 100 Mb 3DES VPN |
450+ Mb firewall 175 Mb 3DES VPN 175,000
packets per second |
550+ Mb firewall 225 Mb 3DES VPN 225,000
packets per second |
650+ Mb firewall 300 Mb 3DES VPN 300,000
packets per second |
1+ Gb firewall 500 Mb 3DES VPN 600,000 packets
per second |
|
Max Sessions |
8,000/1,600 |
8,000/1,600 |
48,000 |
64,000 |
128,000 |
128,000 |
256,000 |
|
Max VPN Tunnels |
25/40 |
25/40 |
500 |
500 |
500 |
500 |
1,000 |
|
Max Policies |
200 |
200 |
1,000 |
2,000 |
2,000 |
4,000 |
4,000 |
|
Virtual Systems |
N/A |
N/A |
N/A |
N/A |
N/A |
N/A |
N/A |
|
Virtual LANs |
10/50 |
10/50 |
100 |
125 |
125 |
125 |
150 |
|
Security Zones |
8 |
8 |
40 |
40 |
40 |
60 |
60 |
|
Virtual Routers |
3 |
3 |
6 |
5 |
8 |
11 |
16 |
|
High Availability |
Dial Backup, A/P, A/A |
Dial Backup, A/P, A/A |
A/P, A/A |
A/P, A/A |
A/P, A/A |
A/P, A/A |
A/P, A/A |
|
Routing |
OSPF, BGP, RIPv1/v2, along with Frame Relay,
Multilink Frame Relay, PPP, HDLC |
OSPF, BGP, RIPv1/v2, along with Frame Relay,
Multilink Frame Relay, PPP, Multilink PPP,
HDLC |
OSPF, BGP, RIPv1/v2, along with Frame Relay,
Multilink Frame Relay, PPP, Multilink PPP,
HDLC |
OSPF, BGP, RIPv1/v2, along with Frame Relay,
Multilink Frame Relay, PPP, Multilink PPP,
HDLC |
OSPF, BGP, RIPv1/v2, along with Frame Relay,
Multilink Frame Relay, PPP, Multilink PPP,
HDLC |
OSPF, BGP, RIPv1/v2, along with Frame Relay,
Multilink Frame Relay, PPP, Multilink PPP,
HDLC |
OSPF, BGP, RIPv1/v2, along with Frame Relay,
Multilink Frame Relay, PPP, Multilink PPP,
HDLC |
|
Deep Inspection/IPS |
Yes/No |
Yes/No |
Yes/No |
Yes/No |
Yes/No |
Yes/No |
Yes/No |
|
Integrated Antivirus |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Integrated Anti-Spam |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Web Filtering
(Integrated/ External) |
Yes/Yes |
Yes/Yes |
Yes/Yes |
Yes/Yes |
Yes/Yes |
Yes/Yes |
Yes/Yes |
|
SSG Series Appliances |
| Juniper Networks Secure Services Gateway 550M
with 1GB DRAM, 1 AC Power Supply |
#SSG-550M-SH
List Price: $10,500.00
Our Price: $8,085.00 |
|
| Juniper Networks Secure Services Gateway 550M
with 1GB DRAM, 1 DC Power Supply |
#SSG-550M-SH-DC
List Price: $12,500.00
Our Price: $9,625.00 |
|
|
First Year Subscriptions Main Office Content Security |
One Year Security Subscription for SMB on SSG550
or SSG550M
- Includes Antivirus, Web
Filtering, Antispam and IDP |
#NS-SMB-CS-SSG550
List Price: $6,160.00 |
|
Two Year Security Subscription for SMB on SSG550
or SSG550M
- Includes Antivirus, Web
Filtering, Antispam and IDP |
#NS-SMB-CS-SSG550-2
List Price: $9,856.00 |
|
Three Year Security Subscription for SMB on SSG550
or SSG550M
- Includes Antivirus, Web
Filtering, Antispam and IDP |
#NS-SMB-CS-SSG550-3
List Price: $14,168.00 |
|
|
Renewal Subscriptions Main Office Content Security |
One Year Renewal Security Subscription for SMB
on SSG550 or SSG550M
- Includes Antivirus, Web
Filtering, Antispam and IDP |
#NS-SMB-CS-SSG550-R
List Price: $6,160.00 |
|
Two Year Renewal Subscription for SMB on SSG550
or SSG550M
- Includes Antivirus, Web
Filtering, Antispam and IDP |
#NS-SMB-CS-SSG550-2-R
List Price: $9,856.00 |
|
Three Year Renewal Subscription for SMB on SSG550
or SSG550M
- Includes Antivirus, Web
Filtering, Antispam and IDP |
#NS-SMB-CS-SSG550-3-R
List Price: $14,168.00 |
|
|
First Year Subscriptions Remote and Branch Office
Integrated Content Security |
One Year Security Subscription for Remote Branch
Office on SSG550 or SSG550M
- Includes Antivirus, Web
Filtering, and Deep Inspection |
#NS-RBO-CS-SSG550
List Price: $4,875.00 |
|
Two Year Security Subscription for Remote Branch
Office on SSG550 or SSG550M
- Includes Antivirus, Web
Filtering, and Deep Inspection |
#NS-RBO-CS-SSG550-2
List Price: $7,800.00 |
|
Three Year Security Subscription for Remote Branch
Office on SSG550 or SSG550M
- Includes Antivirus, Web
Filtering, and Deep Inspection |
#NS-RBO-CS-SSG550-3
List Price: $11,213.00 |
|
|
Renewal Subscriptions Remote and Branch Office Integrated
Content Security |
One Year Renewal Security Subscription for Remote
Branch Office on SSG550 or SSG550M
- Includes Antivirus, Web
Filtering, and Deep Inspection |
#NS-RBO-CS-SSG550-R
List Price: $4,875.00 |
|
Two Year Renewal Security Subscription for Remote
Branch Office on SSG550 or SSG550M
- Includes Antivirus, Web
Filtering, and Deep Inspection |
#NS-RBO-CS-SSG550-2-R
List Price: $7,800.00 |
|
Three Year Renewal Security Subscription for
Remote Branch Office on SSG550 or SSG550M
- Includes Antivirus, Web
Filtering, and Deep Inspection |
#NS-RBO-CS-SSG550-3-R
List Price: $11,213.00 |
|
|
Use our
Quote Form to request
additional subscription pricing
|
|
SSG Interface Modules |
| SSG 550M ScreenOS to J6350 JUNOS-ES Conversion
Kit |
#SSG-550M-J-CONV-S
List Price: $200.00 |
|
1-Port ADSL2+ Annex A PIM - Supporting ADSL/ADSL2/ADSL2+
Annex A
Note: Requires ScreenOS
6.0 or later. |
#JX-1ADSL-A-S
List Price: $750.00 |
|
1-Port ADSL2+ Annex B PIM - Supporting ADSL/ADSL2/ADSL2+
Annex B
Note: Requires ScreenOS
6.0 or later. |
#JX-1ADSL-B-S
List Price: $750.00 |
|
| 1xDS3 PIM |
#JX-1DS3-S
List Price: $8,500.00 |
|
| 1 Port E3 PIM |
#JX-1E3-S
List Price: $8,500.00 |
|
| 2 Port E1 PIM with integrated CSU/DSU |
#JX-2E1-RJ48-S
List Price: $1,000.00 |
|
2 Port 2-wire or 1 Port 4-wire G.SDHSL PIM
Note: Requires ScreenOS
6.0 or later. |
#JX-2T1-RJ48-S
List Price: $950.00 |
|
| 2 Port T1 PIM with integrated CSU/DSU - Spare |
#JXM-1SERIAL-S
List Price: $1,000.00 |
|
1 Port Fiber Gigabit Ethernet Enhanced PIM
(SFP sold separately) |
#JXE-1GE-SFP-S
List Price: $1,500.00 |
|
| 1 Port Gigabit Ethernet 10/100/1000 Copper Enhanced
PIM |
#JXE-1GE-TX-S
List Price: $1,500.00 |
|
| 4 Port Fast Ethernet Enhanced PIM |
#JXE-4FE-TX-S
List Price: $1,200.00 |
|
SFP 100BASE-FX Optical Transceiver, LC connector
Note: This will work in
the 1-port SFP UPIM, not the 6-port SFP and not 1xSFP
EPIM |
#JX-SFP-1FE-FX
List Price: $250.00 |
|
| SFP 1000Base-LX Gigabit Optical Tranceiver SFP
Module |
#JX-SFP-1GE-LX
List Price: $995.00 |
|
| SFP 1000Base-SX Gigabit Optical Tranceiver Module |
#JX-SFP-1GE-SX
List Price: $500.00 |
|
| SFP 1000BASE-T Gigabit Copper Transceiver SFP
Module |
#JX-SFP-1GE-T
List Price: $400.00 |
|
| 16 Port Gigabit Ethernet 10/100/1000 Copper Double-height
Universal PIM |
#JXU-16GE-TX-S
List Price: $3,000.00 |
|
1 port Small Form-Factor pluggable (SFP) Universal
Physical Interface Module.
100M and 1000M SFP speeds
supported. (SFP Tranceiver purchased separately) |
#JXU-1SFP-S
List Price: $1,500.00 |
|
6 Port SFP Gigabit Ethernet Universal PIM
Note: SFPs sold separately.
Supports 1000M SFPs only |
#JXU-6GE-SFP-S
List Price: $3,000.00 |
|
| 8 Port Gigabit Ethernet 10/100/1000 Copper Universal
PIM |
#JXU-8GE-TX-S
List Price: $1,800.00 |
|
|
Accessories |
1 Gigabyte RAM Memory Upgrade for the SSG500
series, SSG300 series
Note: This 1GB memory is
required to run Anti-Virus or Deep Inspection Services |
#SSG-500-MEM-1GB
List Price: $2,000.00 |
|
|