Interfaces | 8x GbE(configurable) |
USB ports | 2 |
Console port | Yes (DB9) |
Rack-mountable | yes |
SPI firewall throughput(Mbps) *2 | 5,000 |
VPN throughput (Mbps) *3 | 650 |
IDP throughput (Mbps) *4 | 900 |
AV throughput (Mbps) *4 | 550 |
UTM throughput (AV and IDP) *4 | 550 |
Max. TCP concurrent sessions *5 | 500,000 |
Max. concurrent IPsec VPN tunnels *6 | 300 |
Concurrent SSL VPN user no. (default/max.) *7 | 50/150 |
VLAN interface | 64 |
Concurrent devices logins (default/max.) *7*8 | 500 / 800 |
Managed AP number (default/max.) *7 | 2/34 |
Recommend max. AP in 1 AP Group | 20 |
Anti-virus (AV) *7 | yes |
Intrusion detection and prevention (IDP) & Application Patrol *7 | yes |
Anti-spam *7 | yes |
Content filtering (CF 2.0) *7*9 | yes |
SecuReporter Premium *7 | yes |
VPN | IKEv2, IPSec, SSL, L2TP/IPSec |
SSL (HTTPS) inspection | yes |
2-Factor Authentication | yes |
EZ Mode | - |
Hotspot Management *7 | yes |
Ticket printer support *10 / Support Q'ty (max.) | Yes (SP350E) / 10 |
Microsoft Azure | yes |
Amazon VPC | yes |
Facebook WiFi | yes |
Device HA Pro | yes |
Link Aggregation (LAG) | yes |
Power input | 100 - 240V AC, 50/60 Hz, 1.3 A max. |
Max. power consumption (watts) | 58.5 |
Heat dissipation (BTU/hr) | 199.61 |
Item | Dimensions (WxDxH)(mm/in.) 430 x 250 x 44/16.93 x 9.84 x 1.73 Weight (kg/lb.) 3.3/7.28 |
Packing | Dimensions (WxDxH)(mm/in.) 519 x 392 x 163/20.43 x 15.43 x 6.42 Weight (kg/lb.) 4.8/10.58 |
Included accessories | Power cord Rack mounting kit |
Operating | Temperature 0°C to 40°C (32°F to 104°F) Humidity 10% to 90%(non-condensing) |
Storage | Temperature -30°C to 70°C (-22°F to 158°F) Humidity 10% to 90%(non-condensing) |
MTBF (hr) | 560,811.5 |
EMC | FCC Part 15 (Class A) CE EMC (Class A) C-Tick (Class A) BSMI |
Safety | LVD (EN60950-1), BSMI |
Features: | |
Firewall | ICSA-certified firewall (certification in progress) Routing and transparent (bridge) modes Stateful packet inspection User-aware policy enforcement SIP/H.323 NAT traversal ALG support for customized ports Protocol anomaly detection and protection Traffic anomaly detection and protection Flooding detection and protection DoS/DDoS protection |
IPv6 Support | IPv6 Ready gold logo (certification in progress) Dual stack IPv4 tunneling (6rd and 6to4 transition tunnel) IPv6 addressing DNS DHCPv6 Bridge VLAN PPPoE Static routing Policy routing Session control Firewall and ADP IPSec VPN Intrusion Detection and Prevention (IDP) Application intelligence and optimization Content filtering Anti-virus, anti-malware Anti-spam |
IPSec VPN | ICSA-certified IPSec VPN (certification in progress) Encryption: AES (256-bit), 3DES and DES Authentication: SHA-2 (512-bit), SHA-1 and MD5 Key management: manual key, IKEv1 and IKEv2 with EAP Perfect forward secrecy (DH groups) support 1, 2, 5 IPSec NAT traversal Dead peer detection and relay detection PKI (X.509) certificate support VPN concentrator Simple wizard support VPN auto-reconnection VPN High Availability (HA): load-balancing and failover L2TP over IPSec GRE and GRE over IPSec NAT over IPSec Zyxel VPN client provisioning |
SSL VPN | Supports Windows and Mac OS X Supports full tunnel mode Supports 2-step authentication Customizable user portal |
Intrusion Detection and Prevention (IDP) | Routing and transparent (bridge) mode Signature-based and behavior-based scanning Automatic signature updates Customizable protection profile Customized signatures supported |
Application Intelligence and Optimization | Granular control over the most important applications Identifies and controls over 3,000 applications and behaviors Supports over 15 application categories Application bandwidth management Supports user authentication Real-time statistics and reports |
Anti-Virus | Supports Kaspersky anti-virus signatures Identifies and blocks over 650,000 viruses Stream-based anti-virus engine HTTP, FTP, SMTP, POP3 and IMAP4 protocol support Automatic signature updates No file size limitation |
Anti-Spam | Transparent mail interception via SMTP and POP3 protocols Configurable POP3 and SMTP ports Sender-based IP reputation filter Recurrent Pattern Detection (RPD) technology Zero-hour virus outbreak protection X-Header support Blacklist and whitelist support Supports DNSBL checking Spam tag support Statistics report |
Content Filtering | Social media filtering Malicious Website filtering URL blocking and keyword blocking Blacklist and whitelist support Blocks java applets, cookies and ActiveX Dynamic, cloud-based URL filtering database Unlimited user license support Customizable warning messages and redirection URL |
Unified Security Policy | Unified policy management interface Supported UTM features: anti-virus, antispam, IDP, content filtering, application intelligence, firewall (ACL) 3-tier configuration: object-based, profilebased, policy-based Policy criteria: zone, source and destination IP address , user, time |
WLAN Management | Zyxel AP Controller (APC) 1.0 compliant Client RSSI threshold to prevent sticky clients IEEE 802.1x authentication Captive portal Web authentication Customizable captive portal page RADIUS authentication Wi-Fi Multimedia (WMM) wireless QoS CAPWAP discovery protocol |
Mobile Broadband | WAN connection failover via 3G and 4G* USB modems Auto fallback when primary WAN recovers* 4G USB modem support available in future firmware upgrades |
Networking | Routing mode, bridge mode and hybrid mode Ethernet and PPPoE NAT and PAT VLAN tagging (802.1Q) Virtual interface (alias interface) Policy-based routing (user-aware) Policy-based NAT (SNAT) Dynamic routing (RIPv1/v2 and OSPF ) DHCP client/server/relay Dynamic DNS support WAN trunk for more than 2 ports Per host session limit Guaranteed bandwidth Maximum bandwidth Priority-bandwidth utilization Bandwidth limit per user Bandwidth limit per IP |
Authentication | Local user database Microsoft Windows Active Directory integration External LDAP/RADIUS user database XAUTH, IKEv2 with EAP VPN authentication Web-based authentication Forced user authentication (transparent authentication) IP-MAC address binding SSO (Single Sign-On) support (Download SSO Agent) |
System Management | Role-based administration Multiple administrator logins Multi-lingual Web GUI (HTTPS and HTTP) Command line interface (console, Web console, SSH and TELNET) SNMP v2c (MIB-II) System configuration rollback Firmware upgrade via FTP, FTP-TLS and Web GUI Dual firmware images |
Logging/Monitoring | Comprehensive local logging Syslog (to up to 4 servers) Email alerts (to up to 2 servers) Real-time traffic monitoring Built-in daily report Advanced reporting with Vantage Report |