Datasheet
6
SSG320M SSG350M
Address Translation
Network Address Translation (NAT) Yes Yes
Port Address Translation (PAT) Yes Yes
Policy-based NAT/PAT (L2 and L3 mode) Yes Yes
Mapped IP (L3 mode) 4,000 4,000
Virtual IP (L3 mode) 32 32
MIP/VIP Grouping (L3 mode) Yes Yes
IP Address Assignment
Static Yes Yes
DHCP, PPPoE client Yes Yes
Internal DHCP server Yes Yes
DHCP relay Yes Yes
Trac Management Quality of Service (QoS)
Guaranteed bandwidth Yes - per policy Yes - per policy
Maximum bandwidth Yes - per policy Yes - per policy
Ingress trac policing Yes Yes
Priority-bandwidth utilization Yes Yes
DiServ marking Yes - per policy Yes - per policy
High Availability (HA)
Active/Active - L3 mode Yes Yes
Active/Passive - Transparent & L3 mode Yes Yes
Configuration synchronization Yes Yes
Session synchronization for firewall and VPN Yes Yes
VRRP Yes Yes
Session failover for routing change Yes Yes
Device failure detection Yes Yes
Link failure detection Yes Yes
Authentication for new HA members Yes Yes
Encryption of HA trac Yes Yes
System Management
WebUI (HTTP and HTTPS) Yes Yes
Command line interface (console) Yes Yes
Command line interface (telnet) Yes Yes
Command line interface (SSH) Yes v1.5 and v2.0 compatible Yes v1.5 and v2.0 compatible
Network and Security Manager (NSM) Yes Yes
All management via VPN tunnel on any interface Yes Yes
Rapid deployment No No
Administration
Local administrator database size 20 20
External administrator database support RADIUS, RSA SecurID, LDAP RADIUS, RSA SecureID, LDAP
Restricted administrative networks 50 50
Root Admin, Admin and Read Only user levels Yes Yes
Soware upgrades TFTP, WebUI, NSM, SCP, USB TFTP, WebUI, NSM, SCP, USB
Configuration rollback Yes Yes
Logging/Monitoring
Syslog (multiple servers) Yes - up to 4 servers Yes - up to 4 servers
Email (two addresses) Yes Yes
NetIQ WebTrends Yes Yes
SNMP (v2) Yes Yes
SNMP full custom MIB Yes Yes
Traceroute Yes Yes
VPN tunnel monitor Yes Yes
Specifications (continued)