| |
 |
 |
 |
 |
 |
| Feature List |
iPolicy
2000
Series |
iPolicy
3000 Series |
iPolicy
4000 Series |
iPolicy
5000 Series |
|
PERFORMANCE: (1) |
2100 |
2200 |
3300 |
4400 |
4600 |
4800 |
5200 |
5400 |
Throughput with FW, IDS/IPS
and URL Filtering |
|
|
|
|
|
|
|
|
-UDP
Traffic |
Up to 140 Mbps |
Up to 200 Mbps |
Up to 350 Mbps |
Up to 600 Mbps |
Up to 1.2 Gbps |
Up to 1.8
Gbps |
Up to 2.5
Gbps |
Up to 6
Gbps |
-HTTP
Traffic |
Up to 100 Mbps |
Up to 100 Mbps |
Up to 320 Mbps |
Up to 600 Mbps |
Up to 900 Mbps |
Up to 900 Mbps |
Up to 1.5 Gbps |
Up to 2.8 Gbps |
| Concurrent Sessions |
100,000 |
100,000 |
200,000 |
300,000 |
400,000 |
500,000 |
1 Million |
1
Million |
| New Sessions/Second |
1,000 |
2,000 |
4,000 |
10,000 |
10,000 |
10,000 |
25,000 |
30,000 |
| Security Domains (2) |
10 |
10 |
10 |
25 |
50 |
100 |
100 |
250 |
| Policies |
100K |
100K |
150K |
200K |
200K |
200K |
250K |
250K |
| INTERFACES: |
|
|
|
|
|
|
|
|
| 10/100 Ethernet Ports (Copper) |
3 |
3 |
2 |
No |
No |
No |
No |
No |
| Gigabit Ethernet Ports (Copper or Fiber) |
No |
No |
4 Copper |
6 Copper or 6 Fiber Opt. |
6 Copper or 6 Fiber Opt |
6 Copper or 6 Fiber Opt |
4 Fiber |
4
Fiber |
| DMZ Support |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Dedicated Management Port |
Shared |
Shared |
1FE Copper |
1GE Copper |
1GE Copper |
1GE
Copper |
1GE Copper |
1GE
Copper |
| High Availability Port |
Shared |
Shared |
1FE Copper |
1GE Copper |
1GE Copper |
1GE
Copper |
1GE Copper |
1GE
Copper |
| DEPLOYMENT MODE: |
|
|
|
|
|
|
|
|
| Gateway |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Transparent |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| SPAN |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Security Virtualization |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| FIREWALL: |
|
|
|
|
|
|
|
|
| L3-7 Stateful Inspection |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Application Transaction |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Application Parameter |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Bidirection & Inter-domain |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| NAT, PAT |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Gateway/Transparent Mode |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| VLAN (802.1Q) |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Overlapping RFC1918 IP Address Support |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| User Authentication |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
-Internal
Database |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
-Radius |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
-LDAP |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
-NTLM |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Zone based rules |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Support for DHCP Relay |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Time of Day Policies |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| IDS/IPS: |
|
|
|
|
|
|
|
|
| In-Line Bidirectional IDS/IPS |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Tap Mode IDS |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| IPS
Simulation Mode |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Number of Attack Signatures |
2500+ |
2500+ |
2500+ |
2500+ |
2500+ |
2500+ |
2500+ |
2500+ |
| Attack Categories |
31 |
31 |
31 |
31 |
31 |
31 |
31 |
31 |
| Worm Protection |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Spyware Protection |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Protocol/Traffic Anomaly |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Web/CGI Attacks |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| OS based Attacks |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Custom Signatures |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Custom Categories |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| DoS/DDoS Attack Prevention |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Traffic Normalization |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Disruption-free Signature Updates |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Real Time Attack Prevention |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
-Malicious
Packet Drop |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
-Attack
Connection Reset/Drop |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
-Dynamic
Firewall Hardening |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
-Bandwidth
Control |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
-Connection
Rate Control |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Support IP De-fragmentation
and Re-assembly |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Detect Session Anomaly |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Detect Attack Evasion |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Packet Logging |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| URL FILTERING: |
|
|
|
|
|
|
|
|
Inline Deployment Without
Requiring Proxy |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Web URLs (Millions) |
19+ |
19+ |
19+ |
19+ |
19+ |
19+ |
19+ |
19+ |
| Web Pages (Billions) |
2 |
2 |
2 |
2 |
2 |
2 |
2 |
2 |
| Predefined Categories |
54 |
54 |
54 |
54 |
54 |
54 |
54 |
54 |
| Custom Categories |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| IP Address Based Blocking |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Black List/White List |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Spyware Protection |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Keyword Search Blocking |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Mobile Code Filtering |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| URL
Redirection for notification |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| MANAGEMENT: |
|
|
|
|
|
|
|
|
| Configuration Wizard |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Interactive Network Topology Map |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| IPS Configuration Summary Dashboard |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Secure Management Communication |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| In-band & Out-of-band Management |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Local/Remote Console Interface |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Command Line Interface |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Centralized Management GUI |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Role-based Management |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Hierarchical
Management |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Real Time Monitoring Console |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Syslog Support |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Comprehensive Reporting |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| 3rd Party Reporting Support |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Software/Policy Update/ Upgrade Management |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Software/Policy Rollback Management |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| HIGH AVAILABILITY: |
|
|
|
|
|
|
|
|
| Full mesh Active-Active |
No |
No |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Master-Slave |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Stateful Failover |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Fail Open (3) |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Redundant Power Supply |
No |
No |
No |
Option |
Option |
Option |
Standard |
Standard |
| ENVIRONMENTAL CONDITIONS: |
|
|
|
|
|
|
|
|
| Operating Temperatures |
10°C to 35°C |
10°C to 35°C |
10°C to 35°C |
10°C to 35°C |
10°C to 35°C |
10°C to 35°C |
0°C to 40°C |
0°C
to 40°C |
| Storage Temperatures |
-40°C to +70°C |
-40°C to +70°C |
-40°C to +70°C |
-40°C to +70°C |
-40°C to +70°C |
-40°C to +70°C |
-25°C to +70°C |
-25°C
to +70°C |
| Relative Humidity (non-condensing) |
10%
to 90% |
10%
to 90% |
10%
to 90% |
Up to 95% |
Up to 95% |
Up to 95% |
20% to 85% |
20%
to 85% |
| POWER: |
|
|
|
|
|
|
|
|
| AC Input Voltage |
100 to 240 VAC |
100 to 240 VAC |
100 to 240 VAC |
100 to 155 VAC (5.2A) 200 to 240 VAC (2.6A) |
100 to 155 VAC (5.2A) 200 to 240 VAC (2.6A) |
100 to 155 VAC (5.2A) 200 to 240 VAC (2.6A) |
100
to 155 VAC (8A) 200
to 240 VAC (4A) |
100
to 155 VAC (8A) 200 to
240 VAC (4A) |
| Frequency |
50/60
Hz |
50/60
Hz |
50/60
Hz |
50/60
Hz |
5/60
Hz |
50/60
Hz |
50/60
Hz |
|
| Power Dissipation |
150W |
150W |
250W |
500W |
500W |
500W |
450W |
|
| CERTIFICATIONS: |
|
|
|
|
|
|
|
|
| UL |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| CE |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| FCC Class A |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| DIMENSIONS: |
|
|
|
|
|
|
|
|
| WxDxH (inch) |
16.8 x9 x1.72 |
16.8 x9 x1.72 |
16.8 x20 x1.72 |
17.5 x25 x3.5 |
17.5 x25 x3.5 |
17.5 x25 x3.5 |
17.5
x23 x3.5 |
17.5
x23 x3.5 |
| Weight |
9 lbs |
9 lbs |
15 lbs |
37.5 lbs |
37.5 lbs |
37.5 lbs |
40 lbs |
40
lbs |
| Rack Mountable (19 inch) |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| |
|
|
|
|
|
|
|
|
Notes: (1) Performance figures listed are based upon measured maximums under ideal
test conditions. Actual throughput may vary based upon network traffic and deployment.
(2) Upgrade license required; includes 1 SD license with base configuration. (3)
IPF-3300 has built-in fail-open support. Other platforms support fail-open via external
fail-open kit. |
| |