HP 5820 VPN Firewall Module-C04140074
HP 5820 VPN Firewall Module-C04140074
HP 5820 VPN Firewall Module-C04140074
Overview
Models
HP 5820 VPN Firewall Module JD255A
Key features
Industry-Leading Performance, 6.5G FW throughput
Comprehensive Security Protection
Rich VPN Functions, IPSec/GRE/L2TP
Advanced Virtual Firewall
Low Running Cost
Product overview
Built on the latest state-of-art, multi-core CPU platform,this module enables advanced network protection at multi-Gigabit speeds. It
combines built-in protection against denial of service (DoS) and hacking attacks with VPN support, zonal and virtual stateful packet
inspection firewall, application bandwidth management, IP unicast/multicast routing, and e-mail attachment filtering. Running on the
Comware®OS that powers all HP A Series enterprise switching and routing platforms also ensures a rich networking feature set that
facilitates application integration and lowers an enterprise network's total cost of ownership.This module safeguards network from
attacks and misuse, while at the same time delivering policy-based, multisite connectivity for mission-critical applications such as
VoIP, video and collaboration tools. High-availability features ensure traffic flow even in the event of network or internal device error,
or loss of power to the primary device.
High Performance:
Performance 6.5 Gbps throughput secures traffic without compromising network performance.Support for 1.8 million
concurrent connections and 50,000 new connections per second enables high-volume networks to remain secure under peak
traffic
Application Specific Packet Filter (ASPF): Dynamically determines whether to forward or drop a packet by checking its
application layer protocol information (such as FTP, HTTP, SMTP, RTSP and other application layer protocols based on
TCP/UDP) and monitoring the connection-based application layer protocol status.
Virtualization:
Virtualization Multi-core architecture enables both multiple zones and multiple separate firewall instances to be created on
the same device. Support for 256 security zones, 256 virtual firewalls and 4,094 virtual LANs (VLANs) offers robust protection
to all corners of your network. Centralized deployment of a single device offering multiple virtual firewalls lowers total cost of
ownership through streamlined training, simplified deployment and management and reduced power consumption
Zone-based access policies:
policies logically groups virtual LANs (VLANs) into zones that share common security policies; allows
both unicast and multicast policy settings by zones instead of by individual VLANs
Application-level gateway (ALG): deep packet inspection in the firewall discovers the IP address and service port information
embedded in the application data; the firewall then dynamically opens appropriate connections for specific applications
NAT:
NAT Fully support of NAT applications including many-to-one, many-to-many, static NAT, dual translation, easy IP and DNS
mapping. It supports NAT traversal with multiple protocols, and delivers NAT ALG functions such as DNS, FTP, H.323, and
NBT
IPsec:
IPsec provides secure tunneling over an untrusted network such as the Internet or a wireless network; offers data
confidentiality, authenticity, and integrity between two endpoints of the network
Management
Layer 3 routing
Static IP routing:
routing provides manually configured routing; includes ECMP capability
Routing Information Protocol (RIP): provides RIPv1 and RIPv2 routing
OSPF:
OSPF includes host-based ECMP to provide link redundancy/scalable bandwidth and NSSA
Border Gateway Protocol 4 (BGP-4): Exterior Gateway Protocol (EGP) with path vector protocol uses TCP for enhanced
reliability for the route discovery process, reduces bandwidth consumption by advertising only incremental updates, and
supports extensive policies for increased flexibility, as well as scales to very large networks
Dual IP stack:
stack maintains separate stacks for IPv4 and IPv6 to ease transition from an IPv4-only network to an IPv6-only
network design
Policy routing:
routing allows custom filters for increased performance and security; supports ACLs, IP prefix, AS paths, community
lists, and aggregate policies
Layer 3 IPv6 routing:
routing provides routing of IPv6 at media speed; supports static routes, RIPng, OSPFv3, BGP+,policy route and
PIM-SM/DM
Security
Refer to the HP website at: www.hp.com/networking/services for details on the service-level descriptions
© Copyright 2011 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without
notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such
products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for
technical or editorial errors or omissions contained herein.