Specifications

B-71 SECURITY IPS Firewalls
IPS Firewalls
Model DFL-210 DFL-800 DFL-1600 DFL-2500
Port Interface
Ethernet WAN Port 1 2 -
EthernetDMZPort
(User-Configurable)
1 1 -
Ethernet LAN Port 4 7 -
User-Configurable
Gigabit Port
- 6 8
DB-9 RS-232 Console 1
System
Performance
Firewall Throughput 80Mbps 150Mpbs 320Mbps 600Mbps
VPN Throughput 25Mbps 45Mbps 120Mbps 300Mbps
IPS Throughput 20Mbps 40Mbps 150Mbps 400Mbps
Anti-Virus Throughput 10Mbps** 20Mbps** -
Concurrent Sessions 10,000** 20,000** 400,000 1,000,000
New Sessions
(per second)
2,000 4,000 10,000 15,000
Policies 500 1,000 2,500 4,000
Firewall System
Transparent Mode; Network Address Translation (NAT), Port Address Translation (PAT);
DynamicRoutingProtocol:OpenShortestPathFirst(OSPF)(NotapplicableforDFL-210);
H.323NATTraversal;Time-ScheduledPolicies;ApplicationLayerGateway(ALG);
ProactiveNetworkSecurity:ZoneDefense(NotapplicableonDFL-210)
Networking DHCPServer/Client;DHCPRelay;Policy-basedRouting;IPMulticast:IGMPv3
Virtual LAN (VLAN) 8 16 128 1,024
Virtual Private Network (VPN)
Encryption Methods: DES/3DES/AES/Twofish/Browfish/CAST-128; IPSec NAT Traversal;
Dedicated VPN Tunnels: 100 (DFL-210), 200** (DFL-800), 1,200 (DFL-1600), 2,500 (DFL-2500);
Point-to-PointTunnelingProtocol(PPTP)/Layer2TunnelingProtocol(L2TP)Server;HubandSpoke
System Management
RS-232ConsoleInterface;Web-basedUserInterface:HTTP,HTTPS;
CommandLine/SecureShell(SSH);FirmwareUpgrade;CongurationBackup/Restoration
User Authentication
Built-in Database; Remote Authentication Dial In User Service (RADIUS);
LightweightDirectoryAccessProtocol(LDAP):MicrosoftAD2003/2008OpenLDAP2.2.26;
MicrosoftInternetAuthenticationService(IAS);XAUTHforIPSecAuthentication
Logging and Monitoring
InternalLog;ExternalLog:SyslogServer;E-MailNotication;EventLogandAlarm;
Simple Network Management Protocol (SNMP) v1/v2c, SNMP Traps
Traffic Load Balancing
OutboundLoadBalancing;
ServerLoadBalancing(NotapplicableforDFL-210);TrafcRedirectatFail-Over;
OutboundLoadBalanceAlgorithms:Round-Robin,Weight-basedRound-Robin,
Destination-based, Spill-over
Bandwidth Management
Policy-basedTrafcShaping;GuaranteedBandwidth;MaximumBandwidth;
Priority Bandwidth; Dynamic Bandwidth Balancing
HighAvailability(HA)
WANFail-Over(DFL-210:WhenDMZPortisConguredasWANPort);
Active/Passive Modes (Not applicable on DFL-210/800);
Device Failure Detection (Not applicable on DFL-210/800);
Link Failure Detection (Not applicable on DFL-210/800);
Firmware / Virtual Private Network (VPN) Session Synchronization (Not applicable on DFL-210/800)
IntrusionDetection&PreventionSystem
(IDP/IPS)
Automatic Pattern Update; Denial of Service (DoS), Distributed DoS (DDoS) Update;
Attack Alarm via Email; Advanced IDP/IPS Subscription;
IP Blacklist by Threshold or IPS/IDP (Not applicable on DFL-210)
Content Filtering
HTTPType:URLBlacklist/Whitelist;ScriptType:Java,Cookie,ActiveX,VB;
EmailType:EmailBlacklist/Whitelist;ExternalDatabaseContentFiltering**(AvailableonDFL-210/800only)
Anti-Virus**
(Applicable on DFL-210 / DFL-800 only)
Real Time AV Scanning; Unlimited File Size; Scans VLAN Tunnels; Support Compressed Files;
Signature Licensor: Kaspersky; Automatic Pattern Update
Physical&
Environmental
Dimension(WxDxH)
Desktop;
235x162x36mm
11-inch Desktop;
1UHeight;
280x214x44mm
19-inch Rack-Mount;
1UHeight;
440x254x44mm
19-inch Rack-Mount;
1UHeight;
440x454x44mm
Power Input ExternalPowerAdapter Internal Universal Power Supply
OperatingTemperature 0to40°C
Storage Temperature -20to70°C
OperatingHumidity 5% to 95% Non-Condensing
Mean Time Before Failure
(MTBF)
186,614hours 140,532hours 71,965hours 101,819 hours
Certification
EMI-EMC Compliance FCC Class A; CE Class A; C-Tick; VCCI
Safety Compliance UL; LVD (EN60950-1) LVD (EN60950-1)
** Available in Firmware 2.26.00 and above; Performance based on Firmware 2.26.00 and above
B-73