Juniper Networks SSG 140: Portfolio Description
Juniper Networks SSG 140: Portfolio Description
Juniper Networks SSG 140: Portfolio Description
Juniper Networks
Front
SSG 140
Portfolio Description
Back The SSG 140 is a high-performance security platform for branch offices and small/
medium sized standalone businesses that want to stop internal and external attacks,
The Juniper Networks Secure Services Gateway prevent unauthorized access, and achieve regulatory compliance. The SSG 140 is a
modular platform that delivers more than 350 Mbps of stateful firewall traffic and 100
140 (SSG 140) is a purpose-built security Mbps of IPSec VPN traffic.
appliance that delivers a perfect blend of Security: Protection against viruses, SPAM, and emerging malware is delivered by
proven Unified Threat Management (UTM) security features that are backed by best-
performance, security, routing and LAN/WAN in-class partners. To address internal security requirements and facilitate regulatory
compliance, the SSG 140 supports an advanced set of network protection features such
connectivity for medium sized branch offices
as security zones, virtual routers and VLANs that allow administrators to divide the
and business deployments. Traffic flowing in and network into distinct, secure domains, each with its own unique security policy. Policies
protecting each security zone can include access control rules and inspection by any of
out of the branch office or business is protected the supported UTM security features.
from worms, spyware, trojans, and malware by Connectivity and Routing: The SSG 140 supports ten on-board interfaces (8 10/100
plus 2 10/100/1000) complemented by four I/O expansion slots that can house
a complete set of Unified Threat Management
additional WAN interfaces (T1, E1, ISDN BRI S/T and Serial), making the SSG 140 the
(UTM) security features that include stateful most extensible security platform in its class. This broad array of I/O options coupled
with WAN protocol and encapsulation support in its routing engine make the SSG 140
firewall, IPSecurity (IPSec) virtual private network a platform that can easily be deployed as a traditional branch office router or as a
consolidated security and routing device to reduce CAPEX and OPEX.
(VPN), Intrusion Prevention System (IPS),
Access Control Enforcement: The SSG 140 can act as an enforcement point in a
antivirus (includes anti-spyware, anti-adware, Juniper Networks Unified Access Control deployment with the simple addition of the
anti-phishing), anti-spam and Web Filtering. Infranet Controller. The Infranet Controller functions as a central policy management
engine, interacting with the SSG 140 to augment or replace the firewall-based access
control with a solution that grants/denies access based on more granular criteria that
include endpoint state and user identity, in order to accommodate the dramatic shifts
in attack landscape and user characteristics.
World Class Support: From simple lab testing to major network implementations,
Juniper Networks Professional Services will collaborate with your team to identify goals,
define the deployment process, create or validate the network design, and manage the
deployment to its successful conclusion.
Zone A WWW
HQ
Product Options
Option Option Description Applicable Products
DRAM The SSG 140 is available with either 256 MB or SSG 140
512 MB of DRAM.
Unified Threat Management/ The SSG 140 can be configured with any combination SSG 140 high memory model only
Content Security (high memory of the following best-in-class UTM and content security
option required) functionality: Antivirus (includes anti-spyware, anti-
phishing), IPS (Deep Inspection), Web filtering, and/or
anti-spam.
I/O options Four SSG 140 interface expansion slots support SSG 140
optional T1, E1, ISDN BRI S/T, ADSL2+, G.SHDSL
and serial physical interface modules (PIMs), and
10/100/1000 and SFP universal PIMs (uPIMs).
* Bridge groups supported only on uPIMs in ScreenOS 6.0 and greater releases
**uPIMs are only supported in ScreenOS 6.0 or greater releases
3
Specifications
Juniper Networks SSG 140 IPSec VPN (cont’d)
Perfect forward secrecy (DH Groups) 1,2,5
Maximum Performance and Capacity(1) Prevent replay attack Yes
Minimum ScreenOS version support ScreenOS 5.4 Remote access VPN Yes
Firewall throughput (large packets) 350+ Mbps Layer 2 Tunneling Protocol (L2TP) within IPSec Yes
Firewall throughput (IMIX)(2) 300 Mbps IPSec Network Address Translation (NAT) traversal Yes
Firewall packets per second (64 byte) 100,000 PPS Auto-Connect VPN Yes
Advanced Encryption Standard (AES)256+SHA-1 VPN throughput 100 Mbps Redundant VPN gateways Yes
3DES encryption +SHA-1 VPN throughput 100 Mbps
User Authentication and Access Control
Maximum concurrent sessions 32,000
Built-in (internal) database user limit 250
New sessions/second 8,000
Third-party user authentication RADIUS, RSA SecureID, LDAP
Maximum security policies 500
RADIUS Accounting Yes – start/stop
Maximum users supported Unrestricted
XAUTH VPN authentication Yes
Network Connectivity Web-based authentication Yes
Fixed I/O 8x10/100, 2x10/100/1000 802.1X authentication Yes
Physical Interface Module (PIM) slots 4 Unified Access Control (UAC) enforcement point Yes
Modular WAN/LAN interface options (PIMs/uPIMs) 2xT1, 2xE1, 2xSerial, 1xISDN BRI S/T PKI Support
SFP, 10/100/1000
PKI certificate requests (PKCS 7 and PKCS 10) Yes
Firewall Automated certificate enrollment (SCEP) Yes
Network attack detection Yes Online Certificate Status Protocol (OCSP) Yes
DoS and DDoS protection Yes Certificate Authorities supported Verisign, Entrust, Microsoft, RSA Keon,
TCP reassembly for fragmented packet protection Yes iPlanet (Netscape) Baltimore, DOD PKI
Brute force attack mitigation Yes Self signed certificates Yes
SYN cookie protection Yes Virtualization
Zone-based IP spoofing Yes
Maximum number of security zones 40
Malformed packet protection Yes
Maximum number of virtual routers 3
Unified Threat Management(3) Bridge groups* Yes
Maximum number of VLANs 100
IPS (Deep Inspection firewall) Yes
Protocol anomaly detection Yes Routing
Stateful protocol signatures Yes
BGP instances 2
IPS/DI attack pattern obfuscation Yes BGP peers 4
Antivirus Yes BGP routes 2,048
Signature database 200,000+ OSPF instances 2
Protocols scanned POP3, HTTP, SMTP, IMAP, FTP, IM OSPF routes 2,048
Anti-spyware Yes RIPv1/v2 instances 2
Anti-adware Yes RIP v2 routes 2,048
Anti-keylogger Yes Static routes 2,048
Instant message AV Yes Source-based routing Yes
Anti-spam Yes Policy-based routing Yes
Integrated URL filtering Yes Equal-cost multipath (ECMP) Yes
External URL filtering(4) Yes Multicast Yes
Reverse Forwarding Path (RFP) Yes
Voice over IP (VoIP) Security
Internet Group Management Protocol (IGMP) (v1, v2) Yes
H.323. Application-level gateway (ALG) Yes IGMP Proxy Yes
SIP ALG Yes Protocol Independent Multicast (PIM) single mode Yes
MGCP ALG Yes PIM source-specific multicast Yes
SCCP ALG Yes Multicast inside IPSec tunnel Yes
Network Address Translation (NAT) for VoIP protocols Yes
Encapsulations
IPSec VPN
Point-to-Point Protocol (PPP) Yes
Concurrent VPN tunnels 125 Multilink Point-to-Point Protocol (MLPPP) Yes
Tunnel interfaces 50 MLPPP max physical interfaces 8
DES encryption (56-bit), 3DES encryption (168-bit) and AES (256-bit) Yes Frame relay Yes
MD-5 and SHA-1 authentication Yes Multilink Frame Relay (MLFR) (FRF 15, FRF 16) Yes
Manual key, Internet Key Exchange (IKE), public key infrastructure MLFR max physical interfaces 8
(PKI) (X.509) Yes HDLC Yes
*Bridge groups supported only on uPIMs in ScreenOS 6.0 and greater releases
4
CORPORATE HEADQUARTERS EUROPE, MIDDLE EAST, AFRICA EAST COAST OFFICE ASIA PACIFIC REGIONAL SALES HEADQUARTERS
AND SALES HEADQUARTERS FOR REGIONAL SALES HEADQUARTERS Juniper Networks, Inc. Juniper Networks (Hong Kong) Ltd.
NORTH AND SOUTH AMERICA Juniper Networks (UK) Limited 10 Technology Park Drive 26/F, Cityplaza One
Juniper Networks, Inc. Building 1 Westford, MA 01886-3146 USA 1111 King’s Road
1194 North Mathilda Avenue Aviator Park Phone: 978.589.5800 Taikoo Shing, Hong Kong
Sunnyvale, CA 94089 USA Station Road Fax: 978.589.0800 Phone: 852.2332.3636
Phone: 888.JUNIPER (888.586.4737) Addlestone Fax: 852.2574.7803
or 408.745.2000 Surrey, KT15 2PG, U.K.
Fax: 408.745.2100 Phone: 44.(0).1372.385500
www.juniper.net Fax: 44.(0).1372.385501
Copyright 2007 Juniper Networks, Inc. All rights reserved. Juniper Networks, the Juniper
Networks logo, NetScreen, and ScreenOS are registered trademarks of Juniper Networks, Inc.
in the United States and other countries. JUNOS and JUNOSe are trademarks of Juniper To purchase Juniper Networks solutions, please
Networks, Inc. All other trademarks, service marks, registered trademarks, or registered service
marks are the property of their respective owners. Juniper Networks assumes no responsibility contact your Juniper Networks sales representative
for any inaccuracies in this document. Juniper Networks reserves the right to change, modify,
transfer, or otherwise revise this publication without notice.
at 1-866-298-6428 or authorized reseller.
100181-005 Nov 2007