HUAWEI USG9500 @nettrain
HUAWEI USG9500 @nettrain
The USG9500 is a new-generation, terabit-level, all-in-one DC firewall from Huawei for cloud
service providers, large-scale DCs, and large-scale enterprise campus networks.
The USG9500 provides terabit-level processing performance and 99.999% reliability. It
integrates multiple security features such as Network Address Translation (NAT), Virtual Private
Network (VPN), Intrusion Protection System (IPS), virtualization, and Service Awareness (SA)
to help enterprises construct cloud computing–oriented DCs under border security protection
and reduce the equipment room investment and Total Cost of Ownership (TCO) per Mbit/s.
Highlights
Most accurate access control – ACTUAL-based comprehensive protection
The core function of both traditional firewalls and NGFWs is access control. However, access control is
based on port and IP address on traditional firewalls. In contrast, the USG9500 provides a more fine-
grained access control:
• Comprehensive protection: Provides integrated control and protection based on application,
content, time, user, attack, and location (ACTUAL). The application-layer protection and
application identification are combined. For example, the USG9500 can identify Oracle-specific
traffic and implement intrusion prevention accordingly to increase efficiency and reduce false
positives.
• Based on application: Accurately identifies over 6000 applications (including mobile and web
applications) and their services, and then implements access control and service acceleration
accordingly. For example, the USG9500 can identify the voice and data services of an instant
messaging application and apply different control policies to the services.
• Based on user: Supports eight user authentication methods, including RADIUS, LDAP, and AD
authentication, synchronization of user information from an existing user authentication system,
user-based access control, and QoS management.
• Based on location: Uses IP address geolocation to identify from where application and attack
traffic originates, promptly detects network anomalies, and implements differentiated user-defined
access control for traffic from different locations.
Most advanced network processor + multi-core CPU + distributed architecture – allowing linear
increase of performance to break the performance bottleneck
The USG9500 uses a hardware platform that is often used in core routers to provide modularized
components. Each LPU has two network processors (NPs) to provide line rate forwarding. The SPU
uses multi-core CPUs and a multi-threaded architecture, and each CPU has an application acceleration
engine. These hardware advantages, combined with Huawei's optimized concurrent processing
technology, increase CPU capacity to ensure the high speed parallel processing of multiple services,
such as NAT and VPN. LPUs and SPUs function separately. The overall performance increases linearly
with the number of SPUs so that customers can easily scale up the performance at a low cost.
With the revolutionary system architecture, the USG9500 is the industry's highest-performance
security gateway in terms of throughput and concurrent connections. The dedicated traffic distribution
technology allows for linear performance growth with the number of SPUs. The USG9500 delivers a
maximum of 1.92 Tbps large-packet throughput, 2.56 billion concurrent connections, and 4095 virtual
firewalls to meet the performance demand of high-end customers, such as television and broadcast
companies, government agencies, energy companies, and education organizations.
Most stable and reliable security gateway – full redundancy to ensure service continuity
Network security is important for the normal operation of enterprises. To ensure the service continuity
on high-speed networks, the USG9500 supports active/standby and active/active redundancy, port
aggregation, VPN redundancy, and SPU load balancing. The USG9500 also supports dual-MPU active/
Customer Requirements
Upgrading data centers to cloud data centers will increase the volume of remote access traffic that a
cloud data center handles. Separate security planes are therefore required for different services and
tenants; however, deploying traditional security devices at the egress of data centers will complicate
internal traffic policing and management and expose data centers to malicious access and attacks.
As a result, the functions and performance of traditional security devices at the egress of data centers
cannot meet new requirements and have become a bottleneck of data centers.
Solution
As shown in the preceding figure, two USG9500 firewalls are deployed at the ingress of a large IDC/
VDC/enterprise network. Virtual systems can be created on the firewalls for different tenants. The
bandwidth and number of available sessions of virtual systems can be configured as needed. The
virtual systems are isolated from each other, and the external network is isolated from the internal
network. Adding SPUs to the USG9500 increases the volume of traffic it can handle, which is more
cost-effective than purchasing new devices in terms of per Gigabit power consumption, and also
facilitates smooth capacity expansion. The service awareness and log analysis reports provide visibility
into network security and forensic evidence. IPS and anti-DDoS boards can be added to block viruses
from external networks. To ensure availability and implement millisecond-level switchover, two devices
are deployed in active/active or active/standby mode.
USG9500 USG9500
USG9500 USG9500
Intranet Intranet
Hardware
Product Appearance
The USG9500 series comprises the USG9520, USG9560, and USG9580.
By using dedicated multi-core chips and a distributed hardware platform, the USG9500 provides
industry-leading service processing and expansion capabilities. Moreover, all key components are
redundant to ensure service continuity on high-speed networks, providing a level of availability that is
normally seen in core routers. The distributed technology uses line-rate intelligent traffic distribution
for data forwarding. All data flows are equally distributed to service processing units (SPUs) to prevent
performance bottlenecks. Therefore, the service processing capability increases linearly with service
modules, supporting the long-term development of customer networks.
SPU
The SPUs of the USG9500 process all services. The motherboard of each SPU can hold expansion
cards that house multi-core CPUs, which together with the software modules allow the SPUs to
process all services on the USG9500. To ensure service continuity, the USG9500 provides SPU
redundancy and a heartbeat detection mechanism between the SPU and LPU If one SPU fails, all
functions are switched to other SPUs without interrupting service transmission.
Available Mapping
Board Mapping FPIC
slot Chassis
LPUF-240 • FW-20X1G-RJ45
• E8KE-X-101-24XGE-SFP
• E8KE-X-101-5X10GE-SFP+
USG9560
2 • FW-6X10G-SFP+
USG9580
• FW-12X10G-SFP+
• FW-1X100G-CFP
• FW-3X40G-QSFP+
LPUF-120 • FW-20X1G-RJ45
• E8KE-X-101-24XGE-SFP
• E8KE-X-101-5X10GE-SFP+ USG9520
2 • FW-6X10G-SFP+ USG9560
• FW-12X10G-SFP+ USG9580
• FW-1X100G-CFP
• FW-3X40G-QSFP+
Specifications
System Performance and Capacity
Firewall Throughput
49Mpps 392Mpps 784Mpps
(Packets Per Second)
Virtual Firewalls
10/4,095 10/4,095 10/4,095
(Default/Maximum)
URL Filtering: URLs Can access a database of over 120 million URLs in the cloud
Automated Threat Feed and IPS Yes, an industry-leading security center from Huawei
Signature Updates (http://sec.huawei.com/sec/web/index.do)
Open APIs for integration with third-party products through RESTCONF and
NETCONF interfaces
Third-Party and Open-Source
Other third-party management software based on SNMP, SSH, and syslog
Ecosystem
Collaboration with third-party tools, such as FireMon
Collaboration with Anti-APT solution
1. Performance is tested under ideal conditions based on RFC 2544 and RFC 3511. The actual result may vary with deployment
environments.
Note: This content is applicable only to regions outside mainland China. Huawei reserves the right to interpret this content.
USG9520 USG9560&USG9580
Firewall Throughput
24.5Mpps 49Mpps 24.5Mpps 49Mpps
(Packets Per Second)
New Sessions/Second
800,000 1,600,000 800,000 1,600,000
(HTTP1.1)1
1. Performance is tested under ideal conditions based on RFC 2544 and RFC 3511. The actual result may vary with deployment
environments.
2. SA performances are measured using 100 KB of HTTP files.
3. SSL VPN throughput is measured using TLS v1.2 with AES128-SHA.
1. Antivirus, IPS, and SA performances are measured using 100 KB of HTTP files.
2. Throughput is measured with the Enterprise Traffic Model.
3. SSL inspection throughput is measured with IPS-enabled and HTTPS traffic using TLS v1.2 with AES256-SHA.
Note: This content is applicable only to regions outside mainland China. Huawei reserves the right to interpret this content.
Hardware Specifications
175 × 442 × 650 (4U, DC) 620 × 442 × 650 1420 × 442 × 650
Dimensions (H × W × D) mm
220 × 442 × 650 (5U, AC) (14U) (32U)
Empty: 15 kg (DC)
Full configuration: 30.7 kg
Empty: 43.2 kg Empty: 94.4 kg
(DC)
Weight (Full Configuration) Full configuration: Full configuration:
Empty: 25 kg (AC)
112.9 kg 233.9 kg
Full configuration: 40.7 kg
(AC)
Expansion Slot 3 8 16
Console Ports 2 2 2
Management Ports 2 2 2
Security Features
Note: Not all versions support all listed features. Contact your Huawei representative for details.
Certifications
Certifications
Certifications
Regulatory Compliance Products comply with CE markings per directives 2014/30/EU and 2014/35/EU.
• UL 60950-1
• CSA-C22.2 No. 60950-1
Safety
• EN 60950-1
• IEC 60950-1
• EN 55022 Class A
• ETSI EN 300 386
• IEC 61000-3-2/EN 61000-3-2
• IEC 61000-3-3/EN 61000-3-3
EMC: Emissions
• FCC CFR47 Part 15 Subpart B Class A
• ICES-003 Class A
• VCCI V-3 Class A
• CNS 13438 Class A
• EN 55024
EMC: Immunity • ETSI EN 300 386
• CNS 13438 Class A
Ordering Guide
Host
USG9500 SPUs
USG9500 LPUs
Note: This table lists only some parts of the USG9500. For more information, please contact your Huawei representative.
GENERAL DISCLAIMER
The information in this document may contain predictive statement including, without limitation, statements regarding the future
financial and operating results, future product portfolios, new technologies, etc. There are a number of factors that could cause
actual results and developments to differ materially from those expressed or implied in the predictive statements. Therefore,
such information is provided for reference purpose only and constitutes neither an offer nor an acceptance. Huawei may change
the information at any time without notice.
Copyright © 2019 HUAWEI TECHNOLOGIES CO., LTD. All Rights Reserved.