0% found this document useful (0 votes)
17 views17 pages

Firewall

The HUAWEI HiSecEngine USG6000F series AI firewalls are designed to enhance network security amidst increasing digital threats by utilizing advanced hardware and software architectures for intelligent defense, improved performance, and simplified operations. These firewalls offer features such as application identification, intrusion prevention, and antivirus capabilities, while also supporting various network functionalities like VPN and intelligent traffic steering. Additionally, they can be centrally managed for efficient security operations and integrate with Huawei's Qiankun Security Cloud for automated threat analysis and handling.

Uploaded by

Júlia Gouveia
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
17 views17 pages

Firewall

The HUAWEI HiSecEngine USG6000F series AI firewalls are designed to enhance network security amidst increasing digital threats by utilizing advanced hardware and software architectures for intelligent defense, improved performance, and simplified operations. These firewalls offer features such as application identification, intrusion prevention, and antivirus capabilities, while also supporting various network functionalities like VPN and intelligent traffic steering. Additionally, they can be centrally managed for efficient security operations and integrate with Huawei's Qiankun Security Cloud for automated threat analysis and handling.

Uploaded by

Júlia Gouveia
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 17

HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

HUAWEI HiSecEngine USG6600F&USG6700F


Series AI Firewalls
1 Overview
As digitalization is sweeping the world, extensive connections, explosive growth of data, and
booming intelligent applications are profoundly changing the way we live and work.
Enterprise services are going digital and moving to the cloud, which promotes the
transformation of enterprise networks while bringing greater challenges to network security.
As threats increase, unknown threats are ever-changing and highly covert. As users'
requirements for security services increase, performance and latency become bottlenecks. With
mass numbers of security policies and logs, threat handling and O&M are extremely time-
consuming. As the "first gate" on network borders, firewalls are the first choice for enterprise
security protection. However, traditional firewalls can only analyze and block threats based on
signatures and therefore are unable to effectively handle unknown threats. In addition, the
effectiveness of threats depends on the professional experience of O&M personnel. The single-
point, reactive, and in-event defense method cannot effectively defend against unknown
threat attacks, let alone threats hidden in encrypted traffic.

With new hardware and software architectures, Huawei HiSecEngine USG6000F series are
next-generation AI firewalls that feature intelligent defense, outstanding performance, and
simplified O&M, effectively addressing the preceding challenges. The USG6000F series uses
intelligence technologies to enable border defense to accurately block known and unknown
threats. Equipped with multiple built-in security-dedicated acceleration engines, the USG6000F
series firewalls support enhanced forwarding, content security detection, and IPsec service
processing acceleration. The security O&M platform implements unified management and
O&M of multiple types of security products, such as firewalls, anti-DDoS devices, reducing
security O&M OPEX.

2 Product Highlights

Excellent performance
By leveraging fresh-new hardware and software architectures, HiSecEngine USG6000F series
AI firewalls dynamically allocate resources to service modules through the adaptive security
engine (ASE), maximizing resource utilization and improving overall service performance. For
core services, the HiSecEngine USG6000F series also supports network processor (NP), pattern
matching, and encryption/decryption engines. These engines greatly improve short-packet
forwarding, reduce the forwarding latency, and enhance application identification, intrusion
prevention detection, and IPsec service performance.

2024-06-06 Page 1 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Intelligent defense
HiSecEngine USG6000F series AI firewalls provide content security functions, such as
application identification, IPS, antivirus, and URL filtering to protect intranet servers and users
against threats.

Traditional IPS signatures are manually produced through analysis, resulting in low
productivity. Also, the accuracy of the signatures depends heavily on expert experience.
Huawei innovatively enables the IPS signature production on the intelligent cloud by adopting
intelligence technologies and utilizing expert experience. Such an intelligent mode helps
increase the signature productivity by 30 times compared with manual production, reduce
errors caused by manual analysis, and continuously improve the accuracy of intrusion
detection.

The built-in antivirus content-based detection engine (CDE) powered by intelligence


technologies can detect unknown threats and provide in-depth data analysis. With these
capabilities, the CDE-boosted firewall is able to gain insight into threat activities and quickly
detect malicious files, effectively improving the threat detection rate.

NGFW USG supports to detect and defend malware spreading and network attacks, like
Worm, Virus, Trojan-horse, Spyware, etc. malware spreading and botnet, DoS/DDoS, SQL
injection, cross site attack,ransomware,etc.

2024-06-06 Page 2 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Simplified O&M
The HiSecEngine USG6000F series provides a brand-new web UI, which intuitively visualizes
threats as well as displays key information such as device status, alarms, traffic, and threat
events. With multi-dimensional data drilling, the web UI offers optimal user experience,
enhanced usability, and simplified O&M.

The HiSecEngine USG6000F series firewalls can be centrally managed by the security
management platform SecoManager, implementing a shift from single-point defense to
collaborative network protection. The SecoManager provides policy tuning and intelligent
O&M capabilities. It can also manage security products, such as anti-DDoS devices to quickly
eliminate network threats and improve security handling effectiveness.

The HiSecEngine USG6000F series NGFW can also be managed by NCE-Campus, and NCE-
Campus can also support to manage switch, AR, POL device at the same time, even third
party devices.

A wide range of network features


Huawei HiSecEngine USG6000F series also provides various network features such as VPN,
IPv6, and intelligent traffic steering.
⚫ Provides various VPN features such as IPsec VPN and SSL VPN, and supports multiple
encryption algorithms, such as DES, 3DES, AES, and SHA, ensuring secure and reliable
data transmission.

2024-06-06 Page 3 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

⚫ Provides secure and rich IPv6 network switchover, policy control, security protection, and
service visualization capabilities, helping government, media, carrier, Internet, and finance
sectors implement IPv6 reconstruction.
⚫ Provides dynamic and static intelligent traffic steering based on multi-egress links, selects
the outbound interface based on the specified link bandwidth, weight, or priority,
forwards traffic to each link based on the specified traffic steering mode, and dynamically
tunes the link selection result in real time to maximize the usage of link resources and
improve user experience.

Collaboration with Huawei Qiankun Security Cloud Service


⚫ Most threats and attacks come from network traffic. Firewalls are deployed at the egress
of the local network to interwork with Huawei Qiankun security cloud service to
implement automatic threat analysis and handling. This ensures the interconnection
between the intranet and extranet, effectively intercepts traffic attacks, and automatically
handles external attack sources. Protects enterprise network resources.

⚫ By associating with Huawei Qiankun security cloud service, the firewall can obtain
security services such as border protection and response on demand. Lightweight

2024-06-06 Page 4 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

deployment and unified cloud O&M effectively reduce hardware stacking and greatly
reduce enterprise security investment and O&M difficulties.

3 Deployment

Small data center border protection


⚫ Firewalls are deployed at egresses of data centers, and functions and system resources
can be virtualized. The firewall has multiple types of interfaces, such as 100G,40G, 10G,
and 1G interfaces. Services can be flexibly expanded without extra interface cards.
⚫ The intrusion prevention capability effectively blocks a variety of malicious attacks and
delivers differentiated defense based on virtual environment requirements to guarantee
data security.
⚫ VPN tunnels can be set up between firewalls and mobile workers and between firewalls
and branch offices for secure and low-cost remote access and mobile working.

Enterprise border protection


⚫ Firewalls are deployed at the network border. The built-in traffic probe can extract packets
of encrypted traffic to monitor threats in encrypted traffic in real time.
⚫ The policy control and data filtering functions of the firewalls are used to monitor social
network applications to prevent data breach and protect enterprise networks.

4 Product Appearance
Figure 4-1 HiSecEngine USG6615F/USG6625F

Figure 4-2 HiSecEngine USG6635F/USG6655F/USG6685F

2024-06-06 Page 5 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Figure 4-3 HiSecEngine USG6710F/USG6715F

Figure 4-4 HiSecEngine USG6725F

5 Software Features

Feature Description

Integrated Integrates firewall, VPN, intrusion prevention, antivirus, bandwidth


protection management, Anti-DDoS, URL filtering; provides a global configuration
view; manages policies in a unified manner.

Application Identifies over 6000 applications and supports the access control
identification granularity down to application functions; combines application
and control identification with intrusion detection, antivirus, and data filtering,
improving detection performance and accuracy.

Intrusion Obtains the latest threat information in a timely manner for accurate
prevention and detection and defense against vulnerability-based attacks. Supports
web protection coverage of tens of thousands of Common Vulnerabilities and Exposures
(CVE). Detects malicious traffic, such as vulnerability attack traffic, web
attack traffic (such as SQL injection and cross-site scripting attacks),

2024-06-06 Page 6 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Feature Description
botnets ,remote control, and Trojan horses, and supports brute-force
attack detection. Supports 22,000+ IPS signatures, and supports user-
defined signatures. The default IPS blocking rate is up to 85%. Supports
brute-force cracking detection based on user behaviors, and user-defined
statistical periods.

Anti-botnet Supports detecting Botnet traffic by using the intrusion prevention


function.

Antivirus Supports intelligent, heuristic antivirus engine that can detect hundreds
of millions of virus variants. Supports intelligent, heuristic antivirus
engine that can detect hundreds of millions of virus variants. Supports
virus detection for files using protocols such as
HTTP/FTP/SMTP/POP3/IMAP4/NFS/SMB. Detects Trojan horses, worms,
spyware, vulnerability exploit programs, adware, hacker tools, rootkits,
backdoors, grayware, botnet programs, ransomware, phishing software,
mining software, and web shell programs. Supports virus detection for
various file types, such as Office documents, executable files
(Windows/Linux/MacOS), script files, Flash files, PDF files, RTF files, web
pages, and images. Supports attack evidence collection. Supports virus
detection for a maximum of 100 layers of compressed files, including tar,
gzip, zip, rar, and 7z files.

Bandwidth Manages per-user and per-IP bandwidth based on service application


management identification, ensuring the network experience of key services and users.
The management and control can be implemented by limiting the
maximum bandwidth, guaranteeing the minimum bandwidth, and
changing the application forwarding priority.

URL filtering Provides a URL category database with over 500 million URLs and
accelerates access to specific categories of websites, improving access
experience of high-priority websites.
Supports DNS filtering, in which accessed web pages are filtered based
on domain names.
Supports the anti-phishing URL filter.

Supports management and control of 27 industrial control application


protocols, such as Modbus, DNP3, IEC 60870-5-104, IEC 61850, OPC, S7,
Industrial CIP, and PROFINET; supports intrusion detection and blocking for more
control security than 100 industrial control systems: SCADA/Engineering/MES/HMI/PLC
signature detection and blocking to reduce intrusion risks of known
vulnerabilities.

Intelligent Supports service-specific PBR and intelligent uplink selection based on


uplink selection multiple load balancing algorithms (for example, based on bandwidth
ratio and link health status) in multi-egress scenarios.

VPN encryption Supports multiple highly available VPN features, such as IPsec VPN, SSL

2024-06-06 Page 7 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Feature Description
VPN and GRE.

Detects and defends against threats in SSL-encrypted traffic using


SSL-encrypted
application-layer protection methods, such as intrusion prevention,
traffic detection
antivirus, data filtering, and URL filtering.

Replaces servers to implement SSL encryption and decryption, effectively


SSL offloading
reducing server loads and implementing HTTP traffic load balancing.

Anti-DDoS Defends against over 20 types of single-packet attacks and over 10 types
of DDoS attacks, such as SYN flood, UDP flood, ICMP flood, HTTP flood,
HTTPS flood, DNS flood, and SIP flood.

Security Supports virtualization of multiple types of security services, including


virtualization firewall, intrusion prevention, antivirus, and VPN. Users can separately
conduct personal management on the same physical device.

Security policy Manages and controls traffic based on VLAN IDs, quintuples, security
management zones, regions, applications, URL categories, and time ranges, and
implements integrated content security detection.
Provides predefined common-scenario defense templates to facilitate
security policy deployment.
Provides security policy management solutions in partnership with
Firemon and AlgoSec to reduce O&M costs and potential faults.

Routing Supports multiple types of routing protocols and features, such as RIP,
OSPF, BGP, IS-IS, RIPng, OSPFv3, BGP4+, and IPv6 IS-IS.

IS-IS for SRv6、 SRv6 TE Policy、 SRv6 SRH compressing


SRv6 BGP、 SRv6 BE、 SRv6 BE SBFD、 SRv6 TI-LFA FRR、 SRv6
SRv6
intermediate node protection、 SRv6 Anti-Micro-Ring、 SRv6 OAM、
EVPN L3VPN

Built-in secure SD-WAN solution to build low-cost, business-grade


Internet links
ZTP one-click deployment (email), zero skill requirements, and device
provisioning in minutes
FEC is supported. No artifact or frame freezing occurs when the video
packet loss rate reaches 30%. Link selection based on link quality and
Secure SD-WAN
real-time link switchover ensure the experience of key applications.
Multi-link routing and dual-CPE flexible networking ensure that site
services are not interrupted. End-to-end IPSec encryption, secure and
reliable devices, and secure service transmission.
The USG6600F series can be a spoke or a hub,USG6700F series doesn’t
support SD-WAN

2024-06-06 Page 8 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Feature Description

Supports IPv6, L4/L7 server load balancing, and multiple session


persistence methods based on source IP addresses and HTTP cookies;
Server load supports SSL offloading and encryption; supports combination of services
balancing and security policies for effective service security enhancement; supports
health check based on multiple protocols, such as TCP, RADIUS, DNS,
and HTTP, to detect server status changes in a timely manner.

IP multicast Supports IPv4 Layer 3 multicast protocols, such as IGMP, MSDP, PIM, and
provides point-to-multipoint services to reduce bandwidth consumption.

Deployment Supports transparent, routing, and hybrid working modes and high
and reliability availability (HA), including the Active/Active and Active/Standby modes.

Supports IPv6, L4/L7 server load balancing, and multiple session


persistence methods based on source IP addresses and HTTP cookies;
Server load supports SSL offloading and encryption; supports combination of services
balancing and security policies for effective service security enhancement; supports
health check based on multiple protocols, such as TCP, RADIUS, DNS,
and HTTP, to detect server status changes in a timely manner.

Asset Provides asset-based threat visualization, which supports associating IPS


management and Antivirus threat logs with user assets and displaying asset risk
assessment results.

PPPoE Functions as a PPPoE client to provide Internet access services, including


user authentication and authorization and dynamic IP address allocation.

Behavior and Audits and traces the sources of the accessed content based on users
content

User Supports multiple user authentication methods, including local, RADIUS,


authentication HWTACACS, AD, and LDAP. The firewall supports built-in Portal and
Portal redirection functions,It can synchronize the users that go online
from the RADIUS server or Agile Controller (NCE-Campus) to the device.

6 Specifications
System Performance and Capacity

Model USG6615F USG6625F USG6635F USG6655F

IPv4Firewall Throughput1 15/15/15 25/25/25 35/35/35 Gbps 50/50/40 Gbps


(1518/512/64-byte, UDP) Gbps Gbps

IPv6 Firewall
15/15/15 25 /25 /25
Throughput1 35/35/25 Gbps 50/50/25 Gbps
Gbps Gbps
(1518/512/84-byte, UDP)

2024-06-06 Page 9 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Model USG6615F USG6625F USG6635F USG6655F

Firewall Latency (64-byte,


18µs 18 µs 18 µs 18 µs
UDP)

Firewall Latency (64-byte,


7 us 7 us 7 us 7 us
UDP) 8

Secure SD-WAN
Throughput(1400 15 Gbps 25 Gbps 35 Gbps 50 Gbps
byte,UDP) 9

Secure SD-WAN
Throughput(512 byte,UDP) 15 Gbps 25 Gbps 25 Gbps 25 Gbps
9

Concurrent Sessions
10,000,000 10,000,000 20,000,000 20,000,000
(HTTP1.1)1

New Sessions/Second
250,000 250,000 500,000 500,000
(HTTP1.1)1

FW + SA* Throughput2 12Gbps 12Gbps 18Gbps 25Gbps

NGFW Throughput3
10Gbps 10Gbps 12Gbps 18Gbps
(HTTP 100K)

NGFW Throughput
4.6Gbps 5Gbps 8Gbps 8Gbps
(Enterprise Mix)4

Threat Protection
Throughput (Enterprise 4Gbps 4Gbps 7Gbps 7Gbps
Mix)5

IPsec VPN Throughput1


(AES-256 + SHA256, 1420- 15Gbps 25Gbps 30Gbps 30Gbps
byte)

Maximum IPsec VPN


15,000 15,000 20,000 20,000
Tunnels

SSL Inspection
2.5 Gbps 2.5 Gbps 4 Gbps 4 Gbps
Throughput7

SSL VPN Throughput 6


1 Gbps 1.5 Gbps 3 Gbps 3 Gbps

Concurrent SSL VPN Users


100/4000 100/8000 100/10000 100/10000
*(Default/Maximum)

Security Policies
50,000 50,000 100,000 100,000
(Maximum)

Virtual Firewalls 1000 1000 1000 1000

2024-06-06 Page 10 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Model USG6615F USG6625F USG6635F USG6655F

URL Filtering: Categories More than 130

URL Filtering: URLs A database of over 500 million URLs in the cloud

Automated IPS Signature Yes, an industry-leading security center from Huawei


Updates (http://sec.huawei.com/sec/web/index.do)

Third-Party and Open- Open API for integration with third-party products, providing
Source Ecosystem NETCONF interfaces
Other third-party management software based on SNMP,
SSH, and Syslog

VLANs (Maximum) 4094

VLANIF Interfaces 4094


(Maximum)

Model USG6685F USG6710F USG6715F USG6725F

IPv4Firewall Throughput1 80/80/40 100/100/60 160/160/80 240/240/120


(1518/512/64-byte, UDP) Gbps Gbps Gbps Gbps

IPv6 Firewall
80/80/25 100/100/45 160/160/50 240/240/75
Throughput1
Gbps Gbps Gbps Gbps
(1518/512/84-byte, UDP)

Firewall Latency (64-byte,


18 µs 35 µs 35 µs 35 µs
UDP)

Firewall Latency (64-byte,


7 us 7 us 7 us 7 us
UDP) 8

Secure SD-WAN
Throughput(1400 50 Gbps / / /
byte,UDP) 9

Secure SD-WAN
Throughput(512 byte,UDP) 25 Gbps / / /
9

Concurrent Sessions
25,000,000 30,000,000 50,000,000 75,000,000
(HTTP1.1)1

New Sessions/Second
750,000 1,000,000 1,500,000 2,250,000
(HTTP1.1)1

FW + SA* Throughput2 25Gbps 45Gbps 50Gbps 75Gbps

NGFW Throughput3 18Gbps 40Gbps 50Gbps 75Gbps

2024-06-06 Page 11 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Model USG6685F USG6710F USG6715F USG6725F

NGFW Throughput
8Gbps 16Gbps 17Gbps 26Gbps
(Enterprise Mix)4

Threat Protection
Throughput (Enterprise 7Gbps 14Gbps 14Gbps 21Gbps
Mix)5

IPsec VPN Throughput1 65(Up to


(AES-256 + SHA256, 1420- 30 Gbps 40 Gbps 45 Gbps
byte) 100)Gbps

Maximum IPsec VPN


20000 40000 40000 60000
Tunnels

SSL Inspection
4 Gbps 8 Gbps 8 Gbps 12 Gbps
Throughput7

SSL VPN Throughput 6 5 Gbps 10 Gbps 10 Gbps 12 Gbps

Concurrent SSL VPN Users


100/10000 100/20000 100/20000 100/30000
*(Default/Maximum)

Security Policies
100,000 100,000 100,000 100,000
(Maximum)

Virtual Firewalls 1000 1000 1000 1000

URL Filtering: Categories More than 130

URL Filtering: URLs A database of over 500 million URLs in the cloud

Automated IPS Signature Yes, an industry-leading security center from Huawei


Updates (http://sec.huawei.com/sec/web/index.do)

Third-Party and Open- Open API for integration with third-party products, providing
Source Ecosystem NETCONF interfaces
Other third-party management software based on SNMP,
SSH, and Syslog

VLANs (Maximum) 4094

VLANIF Interfaces 4094


(Maximum)

1. Performance is tested under ideal conditions based on RFC2544, 3511. The actual result
may vary with deployment environments.
2. SA performances are measured using 100 KB HTTP files.
3. NGFW throughput is measured with Firewall, SA, and IPS enabled; the performance is
measured using 100 KB HTTP files.

2024-06-06 Page 12 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

4. NGFW throughput is measured with Firewall, SA, and IPS enabled; the performance is
measured using the Enterprise Mix Traffic Model.
5. The threat protection throughput is measured with Firewall, SA, IPS, and AV enabled; the
performance is measured using the Enterprise Mix Traffic Model.
6. SSL VPN throughput is measured using TLS v1.2 with AES128-SHA.
7. SSL inspection throughput is measured with IPS-enabled and HTTPS traffic using TLS v1.2
with TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256.
8. The data test condition is the interface pair mode.
9. The SD-WAN tunnel is packed with GRE over IPSec.

*SA: indicates service awareness.

7 Hardware Specifications

Model USG6615F USG6625F USG6635F USG6655F

Form Factor/Height 1U

Dimensions (H x W x D) mm 43.6 x 442 x 420

Fixed Interface 8*GE COMBO + 4*GE RJ45 + 8*GE COMBO + 4*GE RJ45
4*GE SFP + 6*10GE SFP+ + 10*10GE SFP+

USB Port 1 x USB 3.0

Weight 6.3 kg 7.3 kg

External Storage Optional, SATA (1 x 2.5 inch) supported,


240GB/480GB/960GB/1920GB, hot-swappable

Power Supply(AC) 100 V to 240 V

Maximum power 222 W 242 W


consumption of the machine

Power Supplies Optional dual AC power Dual AC power supply


supplies

Operating Environment Temperature: 0°C to 45°C


(Temperature/Humidity) Humidity: 5% to 95%, non-condensing

Non-operating Environment Temperature: –40°C to +70°C


Humidity: 5% to 95%, non-condensing

Model USG6685F USG6710F USG6715F USG6725F

Form Factor/Height 1U

2024-06-06 Page 13 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Model USG6685F USG6710F USG6715F USG6725F

Dimensions (H x W x D) 43.6 x 442 x 420


mm

Fixed Interface 8*GE COMBO + 2*100GE(QSFP28) + 4*100GE(QSFP2


4*GE(RJ45)+ 2*40G(QSFP+)+ 8) +
10*10GE(SFP+) 8*25(ZSFP+) + 16*25GE(ZSFP+)
20*10GE(SFP+)1 + 8*10GE(SFP+)2

USB Port 1 x USB 3.0

Weight 7.3 kg 10.26 kg 10.6 kg

External Storage Optional, SATA (1 x 2.5 inch) supported,


240GB/480GB/960GB /1920GB

Power Supply 100 V to 240 V

Maximum power 242 W 391 W 445 W


consumption of the
machine

Power Supplies Dual AC power supplies

Operating Environment Temperature: 0°C to 45°C


(Temperature/Humidity) Humidity: 5% to 95%, non-condensing

Non-operating Temperature: –40°C to +70°C


Environment Humidity: 5% to 95%, non-condensing

1. Some 100GE interfaces and 25GE interfaces of USG6710F and USG6715F are mutually
exclusive.
2. Some 100GE interfaces and 25GE interfaces of USG6715F are mutually exclusive.

8 Ordering Information
Note:

1、The ordering information of USG6625F/USG6635F/USG6655F/USG6685F is the same of 2、


USG6615F
2、The ordering information of USG6710F/USG6715F is the same as USG6725F

3、The model USG6615F support Qiankun Security Cloud Service

Product Model Description

USG6615F USG6615F-AC USG6615F AC Host (8*GE COMBO + 4*GE RJ45


+ 4*GE SFP + 6*10GE SFP+, 1 AC power supply)

USG6725F USG6725F-AC USG6725F AC Host (4*QSFP28 + 16*ZSFP+ +

2024-06-06 Page 14 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Product Model Description


8*SFP+,,2 AC power supplies)

Function License

Virtual LIC-USG6KF-VSYS-10 Quantity of Virtual Firewall (10 Vsys)


Firewall
LIC-USG6KF-VSYS-20 Quantity of Virtual Firewall (20 Vsys)

LIC-USG6KF-VSYS-50 Quantity of Virtual Firewall (50 Vsys)

LIC-USG6KF-VSYS-100 Quantity of Virtual Firewall (100 Vsys)

LIC-USG6KF-VSYS-200 Quantity of Virtual Firewall (200 Vsys)

LIC-USG6KF-VSYS-500 Quantity of Virtual Firewall (500 Vsys)

LIC-USG6KF-VSYS-1000 Quantity of Virtual Firewall (1000 Vsys)

SSL VPN LIC-USG6KF-SSLVPN-100 Quantity of SSL VPN Concurrent Users (100


Users)

LIC-USG6KF-SSLVPN-200 Quantity of SSL VPN Concurrent Users (200


Users)

LIC-USG6KF-SSLVPN-500 Quantity of SSL VPN Concurrent Users (500


Users)

LIC-USG6KF-SSLVPN-1000 Quantity of SSL VPN Concurrent Users (1000


Users)

LIC-USG6KF-SSLVPN-2000 Quantity of SSL VPN Concurrent Users (2000


Users)

LIC-USG6KF-SSLVPN-5000 Quantity of SSL VPN Concurrent Users (5000


Users)

NGFW License

IPS Update LIC-USG6615F-IPS-1Y IPS Update Service Subscribe Per Year (Applies
Service to USG6615F)

LIC-USG6725F-IPS-1Y IPS Update Service Subscribe Per Year (Applies


to USG6725F)

URL LIC-USG6615F-URL-1Y URL Update Service Subscribe Per Year


Filtering (Applies to USG6615F)
Update
Service LIC-USG6725F-URL-1Y URL Update Service Subscribe Per Year
(Applies to USG6725F)

Antivirus LIC-USG6615F-AV-1Y AV Update Service Subscribe Per Year (Applies


Update to USG6615F)

2024-06-06 Page 15 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Product Model Description


Service LIC-USG6725F-AV-1Y AV Update Service Subscribe Per Year (Applies
to USG6725F)

Threat LIC-USG6615F-TP -1Y-OVS Threat Protection Subscription Per Year


Protection (Applies to USG6615F Overseas)
Bundle (IPS,
AV, URL) LIC-USG6725F-TP-1Y-OVS Threat Protection Subscription Per Year
(Applies to USG6725F Overseas)

Industrial Industrial Control Security Service Subscribe


LIC-USG6615F-ICS-1Y
Control Per Year (Applies to USG6615F)
Security
Service Industrial Control Security Service Subscribe
LIC-USG6725F-ICS-1Y
Per Year (Applies to USG6725F)

IPv6+ IPv6+ Feature (includes SRv6,channel


N1-AD-USG6600F-IPv6+-LIC
subinterface, iFit) (Applies to USG6600F)

IPv6+ Feature (includes SRv6,channel


N1-AD-USG6700F-IPv6+-LIC
subinterface, iFit) (Applies to USG6700F)

Enhanced
Enhanced anti-DDoS function (applies to US
DDoS LIC-USG6000F-AntiDDoS
G6000F)
defense

N1 License

USG6615F N1-USG6615F-F-Lic N1-USG6615F Foundation, Per Device

N1-USG6615F-F-SnS1Y N1-USG6615F Foundation, SnS, Per Device, Per


Year

N1-USG6615F-A-Lic N1-USG6615F Advanced, Per Device

N1-USG6615F-A-SnS1Y N1-USG6615F Advanced, SnS, Per Device, Per


Year

USG6725F N1-USG6725F-F-Lic N1-USG6725F Foundation, Per Device

N1-USG6725F-F-SnS1Y N1-USG6725F Foundation, SnS, Per Device, Per


Year

N1-USG6725F-A-Lic N1-USG6725F Advanced, Per Device

N1-USG6725F-A-SnS1Y N1-USG6725F Advanced, SnS, Per Device, Per


Year

QianKun Cloud Deployment License

USG6615F Cloud Deployment Model Foundation, Per


N1-C-USG6615F-F-Lic Device,Per Year

LIC-USG6615F-BA-1Y Border Protection and Response - Threat

2024-06-06 Page 16 of 17
HUAWEI HiSecEngine USG6000F Series AI Firewalls (Fixed-Configuration)

Product Model Description


automatic blocking (Applies to USG6615F), Per
Device, Per Year

Threat Protection Database Upgrade Service


LIC-USG6615F-TPU-1Y (Applies to USG6510F-D), Per Device, Per Year

QianKun OP mode

USG6615F Threat Protection Database Upgrade Service


LIC-USG6615F-TPU-1Y (Applies to USG6510F-D), Per Device, Per Year

N1 SASE Branch Interconnection license

USG6615F N1 SASE Branch Interconnection Standard


N1-USG6615F-S-S-Lic
Package(Package for USG6615F)

N1 SASE Branch Interconnection Standard


N1-USG6615F-S-S-S1Y Package(Package for USG6615F),Per Device,1
Year

Some parts of this table list the sales strategies in different regions. For more information, please contact
your Huawei representative.

2024-06-06 Page 17 of 17

You might also like