Huawei USG2100/2200 UTM Firewalls

The USG2100/2200 series is Huawei's unified security gateway developed to meet the network security needs of various organizations including the small enterprises, branch offices, operating nodes, and SOHOs. Based on industry-leading software and hardware architectures, the USG2110 series offers user-based security policies which integrate the professional security technologies including IPS, anti-virus (AV), URL filtering, application control, and anti-spam (AS). This series supports IPv6 protection and related transition technology, and provides powerful, scalable, and sustainable security capabilities for customers.

USG2210-W UTM firewall

Characteristic

Multi-Core Hardware for Exceptional Performance

Uses the advanced multi-core hardware and All-Flow multi-thread processing technology to ensure fast data processing and improved user experience.

Employs the stable VSP software platform and next generation high efficiency engine to implement one-time packet check for all security modules, greatly improving the throughput and concurrent detection performance and ensuring service availability and efficiency for customers.

Provides professional bypass cards to protect networks from breakdown.

 

Simple Configuration and Management

Provides user/application/content-based security policies of fine granularity to ensure accurate protection.

Provides unified security policies in all series, and supports centralized and simplified configuration of all security modules.

Provides a profession Web-based configuration wizard and visible management software for centralized policy management and easy operation.

 

Professional and Comprehensive Protection

Basic security defense: supports high availability, NAT, VPN, identity authentication, load balancing, bandwidth management, anti-DDoS, and IPv6.

Complete UTM function: supports IPS, anti-virus (5 million viruses), AS, URL filtering (65 million URLs), and application control (1000+ applications), effectively ensuring bandwidth for mission-critical services and improving employees productivity.

Virtualization: virtualizes the firewall and UTM functions, supports refined management of security policies for each virtual zone follows the trend of cloud, and smoothly transfers to the next generation network.

 

Choice of Wired or Wireless Access

Supports multiple Internet access modes by means of FE, GE, E1/CE1, serial, ADSL2+, G.SHDSL, and 3G (WCDMA,TD-CDMA and CDMA2000).

Supports 802.11a/b/g/n WLAN to maximize your return on investment (ROI).

Supports 10 expansion slots and up to 26 GE ports (with a single card supporting a maximum of 20 GE ports) to meet your needs for network expansion and seamless upgrade.

 

All in One, Low TCO

Integrates a range of functions such as routing, switching, wireless access (Wi-Fi and 3G), and data security, accelerating the deployment and decreasing the maintenance complexity and the TCO.

 

Specification

Model USG2110-F/FW USG2110-AW USG2110-AGW-W/-C USG2160/-W USG2230 USG2260
Performance
Firewall 180 Mbps 200 Mbit/s 900 Mbit/s 2Gbit/s
VPN 40 Mbps 50 Mbit/s 300 Mbit/s 500 Mbit/s
Recommended number of users 50 50-200 200-500 500-800
Expansion and I/O
Fixed port 2 x FE WAN+8 x FE LAN 1 x FE WAN+1ADSL
+8 x FE LAN+WI-FI
1 x FE WAN
+1ADSL
+8 x FE LAN+WI-FI+3G
1 x FE WAN
+8 x FE LAN*
2 x GE (combo) 2 x GE (combo)
Expansion slot Not supported 2 x MIC 4 x MIC+2 x FIC 4 x MIC+2 x FIC
Interface module type USB expansion: WCDMA 3G, CDMA2000 3G, TD-SCDMA 3G MIC: 1 x FE (RJ45), 5 x FE (RJ45), 1 x E1, 1 x CE1, 1 x Wi-Fi**, 1 x SA, 2 x SA, 1 x ADSL2+, 4 x G.SHDSL.bis, 2 x G.SHDSL.bis, 1 x G.SHDSL.bis, 3G-WCDMA, 3G-CDMA2000, 3G-TD-SCDMA
DMIC: 8 x FE (RJ45)+2 x GE (RJ45)
FIC: 2 x E1, 2 x CE1, 4 x E1, 4 x CE1, 8 x E1, 8 x CE1, 2 x FE (RJ45)+2 x FE (combo), 1 x GE (RJ45), 4 x GE (RJ45), bypass
DFIC: X86, 18 x FE (RJ45)+2 x GE (SFP), 16 x GE (RJ45)+4 x GE (SFP)
USB expansion: WCDMA 3G, CDMA2000 3G, TD-SCDMA 3G
Routing Features
IPv4 802.1Q, static routing, WCMP, policy-based routing, RIP, OSFPv1/v2, BGP4, IS-IS, DHCP, and link aggregation
IPv6 Static routing, policy-based routing, RIPng, OSPFv3, BGP4+, and IS-ISv6
Multicast IGMP V1/2/3, PIM-DM, PIM-SM, and MSDP
Security Features
VPN types IPSec VPN, SSL VPN, MPLS VPN, L2TP VPN, and GRE VPN
User authentication Local Web, LDAP, AD, and RADIUS
Basic security defense Application/user-based access control, NAT, application/user-based bandwidth control, anti-DDoS, firewall/VPN high availability, and load balancing
UTM Signature-based IPS, AV, AS, URL filtering, application control, keywords/search engine filtering, user-defined signature, manual/automatic/local signature update
Dimensions, Power Supply, and Operating Environment
Dimensions (H x W x D) mm 280 mm x 190 mm x 35 mm 420 mm x 255 mm x 43.6 mm 442 mm x 414 mm x 43.6mm 442 mm x 414 mm x 43.6 mm
Weight (standard configuration) < 4.4 lbs (2 kg) 11 lbs (5 kg) 11.9 lbs (5.4 kg) 11.9 lbs (5.4 kg)
AC power supply 100 V to 240 V
Power 18 W 35W 100 W 100 W

Feature
IPS Defends system vulnerabilities, defends against unauthorized download, spoofing software, and spyware/adware, and provides protocol identification.
AV Supports file identification and filtering, efficient virus scanning, and can detects more than 7,000,000 viruses.
AS Supports local whitelist, local blacklist, remote real-time blacklist, content filtering, keyword filtering, and mail filtering based on the types, sizes, and numbers of attachments.
URL Filtering Identifies more than 85 million URLs (blacklist/whitelist filtering, remote category filtering, user-defined category filtering, search engine keyword filtering, malicious URL filtering, and phishing site filtering).
Application Control Identifies and manages over 1200 application protocols covering all mainstream applications, such as QQ, NetEase PoPo, AliTalk, PPStream, PPLive, Thunder, eMule, StongHuaShun, DaZhiHui, MSN, GoogleTalk, Youtube, Facebook, BitTorrent, and Skype.
VPN IPSec VPN、SSL VPN、MPLS VPN、GRE VPN、L2TP VPN
Anti-DDoS Defends against various DoS and DDoS attacks, such as SYN flood, ICMP flood, and UDP flood attacks.
Routing IPv4:Static、RIP、OSPF、BGP、IS-IS
IPv6:RIPng、OSPFv3、BGP4+、IPv6 IS-IS、IPv6RD、ACL6
Deployment and Reliability Supports transparent, routing, and composite deployment modes, and active/active and active/standby backup modes.

 

Huawei USG2100/2200

The USG9500 Data Center Firewall is the world’s fastest and provides services for large data centers, cloud computing environments, and enterprise campus networks. Integrated switching, routing, and security make upgrades smooth, virtualization easy, and its TB-level processing capability comes in a compact unit with carrier-grade reliability.

Its multiple core network processor and distributed architecture integrates security and virtualization while continual database updates optimize protection.

Competitive products include Cisco ASA5510, ASA5520, ASA5540 Fortinet FortiGate 20C, FortiGate40C, FortiGate60,FotiWiFi60, FortiGate80