| Firewall / IPSec VPN
Juniper Networks NetScreen-500 / NetScreen-500
GPRS
-
Purpose-built, high-performance, integrated
security system for medium to large enterprises and carriers
-
Virtual System support for logical partitioning
of the system into separate firewall and/or VPN domains
-
GPRS support to provide mobile operators
with a purpose-built, high-performance, security solution for
protecting GPRS data networks
Overview:
The Juniper Networks NetScreen-500 system is a purpose-built, integrated
security system that provides a flexible, high-performance solution
for medium and large enterprise central sites and service providers.
The NetScreen-500 network security system integrates firewall, DoS,
VPN, and traffic-management functionality in a low-profile, modular
chassis. It provides high levels of total throughput for firewall
and VPN plus support for virtual systems and security zones. Its
flexible and resilient hardware architecture incorporates modular
physical interfaces, redundant power supplies, fans, and high-availability
interfaces. The NetScreen-500 system is well suited to match the
peak load and strong deterrence requirements of the most demanding
environments.
The Juniper Networks NetScreen-500 GPRS system
combines the hardware-accelerated firewall, VPN, and traffic management
capabilities of the NetScreen-500 with enhanced features designed
to provide mobile operators with a purpose-built, high-performance,
and scalable security solution for protecting GPRS data networks.
The NetScreen-500 GPRS solution secures roaming connections using
a combination of Stateful inspection, traffic rate limiting, traffic
sanity checks, traffic logging, and traffic accounting. These features
allow mobile operators to protect their network infrastructure from
Denial of Service (DoS) attacks and subscriber hijacking attacks.
The NetScreen-500 GPRS features can also be used to control roaming
partner network access, in addition to controlling which external
networks subscribers may access (through APN filtering). GTP Releases
1997 and 1999 are both fully supported, including charging gateway
traffic. The NetScreen-500 GPRS system provides secure, scalable
Internet and corporate intranet connectivity from a mobile operator's
network.
Features & Benefits:
- Integrated security system with security-optimized hardware,
operating system, and applications, providing a higher level
of security than software-based solutions
- Comprehensive, high-availability solution for sub-second
failover between interfaces or devices
- Full mesh configurations to allow for redundant physical
paths in the network, thereby providing maximum resiliency and
uptime
- Virtual System support to allow partitioning into multiple
security domains, each with a unique set of administrators,
policies, VPNs, and address books
- Interface flexibility for varying network-connectivity requirements
and future growth requirements
- Virtual Router support to map internal, private, or overlapped
IP addresses to a new IP address, providing an alternate route
to the final destination and concealing it from public view
- Customizable security zones to increase interface density
without additional hardware expenditures, lower policy-creation
costs, contain unauthorized users and attacks, and simplify
management of VPNs
- Redundant VPN gateways for an additional level of redundancy
in a VPN network, by allowing backup tunnel definitions in the
event of a lost VPN connection
- Firewall attack protection on every interface, for a secure
internal as well as external network
- Transparent mode to allow the device to function as a Layer
2 IP security bridge, providing firewall, VPN, and DoS protections,
but with minimal change to the existing network
- Management through graphical Web UI, CLI, or the NetScreen-Security
Manager central management system
- Policy-based management for centralized, end-to-end life-cycle
management
Specific Features
and Benefits of the NetScreen-500 GPRS:
- Policy-based GTP enforcement for all GPRS features
- Support for GTP Releases 1997 and 1999
- Full support at all GPRS interfaces
- Ability to combine multiple interfaces in single device (Gn,
Gp, Ga, Gi)
- Malicious attack prevention, such as overbilling prevention
- Support for IPSec, L2TP, and 802.1q VLANs to logically separate
the connections from the mobile operator's network to the external
networks, and enable the application of security policies
Back to Juniper Networks Firewall |