YOUR SOLUTIONSFrom application development and management, eVision Systems offers comprehensive, innovative solutions that create real bottom-line value.
|
|
SonicWALL® NSA 5000 is a next generation Unified Threat Management firewall, utilizing a breakthrough multi-core hardware design and 6 Gigabit Ethernet interfaces to deliver real-time internal and external network protection without compromising network performance for campus networks and distributed environments. The NSA 5000 combines high-speed intrusion prevention, file & content inspection and powerful application firewall capabilities with an extensive array of advanced networking, high availability and configuration flexibility features to meet the needs of the most demanding networked environments.
Appliance Features
|
Model Comparison |
| Appliance: |
NSA 3500 |
NSA 4500 |
NSA 5000 |
|
Firewall |
|
SonicOS Version |
SonicOS Enhanced 5.0 (or higher) |
|
Stateful Throughput1 |
1
Gbps |
1.5
Gbps |
1.8
Gbps |
|
GAV Performance1 |
310
Mbps |
500
Mbps |
680
Mbps |
|
IPS Performance1 |
220
Mbps |
410
Mbps |
500
Mbps |
|
UTM Performance Throughput1 |
170
Mbps |
300
Mbps |
350
Mbps |
|
IMIX Peformance1 |
170
Mbps |
300
Mbps |
350
Mbps |
|
Maximum Connections |
128,000 |
450,000 |
600,000 |
|
New Connections/Sec |
5,000 |
7,500 |
8,500 |
|
Nodes Supported |
Unrestricted |
|
Denial of Service Attack Prevention |
22 classes of DoS, DDoS and scanning attacks |
|
VPN |
|
3DES/AES Throughput1 |
625
Mbps |
845
Mbps |
1.1
Gbps |
|
Site-to-Site VPN Tunnels |
800 |
1,500 |
2,500 |
|
Bundled Global VPN Client Licenses for Remote Access |
250 |
500 |
1,000 |
|
Encryption/Authentication |
DES, 3DES, AES (128, 192, 256-bit), MD5, SHA-1 |
|
Key Exchange |
IKE, IKEv2, Manual Key, PKI (X.509) |
|
L2TP/IPSec |
Yes |
|
Certificate Support |
Verisign, Thawte, Baltimore, RSA Keon, Entrust, and
Microsoft CA for SonicWALL-to-SonicWALL VPN |
|
Dead Peer Detection |
Yes |
|
IPSec NAT Traversal |
Yes, NAT_Tv00 and v03 |
|
Redundant VPN Gateway |
Yes |
|
Global VPN Client Platforms Supported |
Microsoft® Windows 2000, Windows XP, Microsoft® Vista
32-bit |
|
Deep Packet Inspection Security Services |
|
Deep Packet Inspection Signature Service |
Comprehensive signature database. Peer- to-peer and
instant messaging control and signature updates through
Distributed Enforcement Architecture |
|
Content Filtering Service (CFS) Premium Edition |
HTTP URL, HTTPS IP, keyword and content scanning ActiveX,
Java Applet, and Cookie blocking |
|
Gateway-enforced Client Anti-Virus and Anti-Spyware |
HTTP/S, SMTP, POP3, IMAP and FTP, Enforced McAfee™ Clients
E-mail attachment blocking |
|
Application Firewall |
Provides application level enforcement and bandwidth
control, regulate Web traffic, e-mail, e-mail attaches
and file transfers, scan and restrict documents and
files for key words and phrase |
|
Networking |
|
IP Address Assignment |
Static, (DHCP, PPPoE, L2TP and PPTP client), Internal
DHCP server, DHCP relay |
|
NAT Modes |
1:1, 1:many, many:1, many:many, flexible NAT (overlapping
IPs), PAT, transparent mode |
|
VLAN Interfaces (802.1q) |
128 |
256 |
512 |
|
Routing |
OSPF, RIPv1/v2, static routes, policy-based routing,
Multicast |
|
QoS |
Bandwidth priority. maximum bandwidth, guaranteed bandwidth,
DSCP marking, 802.1p |
|
IPv6 |
IPv6 Ready |
|
Authentication |
XAUTH/RADIUS, Active Directory, SSO, LDAP, internal
user database |
|
User Database |
500
Users |
1,000
Users |
1,500
Users |
|
VoIP |
Full H.323v1-5, SIP, gatekeeper support, outbound bandwidth
management, VoIP over WLAN, deep inspection security,
full interoperability with most VoIP gateway and communications
devices |
|
System |
|
Zone Security |
Yes |
|
Schedules |
Yes |
|
Object-based/Group-based Management |
Yes |
|
DDNS |
Yes |
|
Management and Monitoring |
Web GUI (HTTP, HTTPS), Command Line (SSH, Console),
SNMP v2: Global management with SonicWALL GMS |
|
Logging and Reporting |
ViewPoint®, Local Log, Syslog |
|
High Availability |
Active/Passive with State Sync |
|
Load Balancing |
Yes, (Outgoing with percent-based, round robin and spill-over)
(Incoming with round robin, random distribution, sticky
IP, block remap and symmetrical remap) |
|
Standards |
TCP/IP, UDP, ICMP, HTTP, HTTPS, IPSec, ISAKMP/IKE, SNMP,
DHCP, PPPoE, L2TP, PPTP, RADIUS |
|
Wireless Standards |
802.11 a/b/g, WEP, WPA, TKIP, 802.1x, EAP-PEAP, EAP-TTLS |
|
Hardware |
|
Interfaces |
(6) 10/100/1000 Copper Gigabit Ports, 1 Console Interface,
2 USB (future Use) |
|
Memory (RAM) |
512
MB |
512
MB |
1
GB |
|
Flash Memory |
512
MB Compact Flash |
512
MB Compact Flash |
16
MB, 512 MB Compact Flash |
|
Power Supply |
Single 180W ATX Power Supply |
|
Fans |
2 Fans |
|
Power Input |
100-240Vac, 60-50Hz |
|
Max Power Consumption |
64
W |
66
W |
66
W |
|
Total Heat Dissipation |
219
BTU |
225
BTU |
225
BTU |
|
Certifications Pending |
ICSA IPSec VPN 1.0d, ICSA Firewall 4.1, FIPS 140-2 Level
2, EAL-4+ |
|
Form Factor |
1U rack-mountable |
|
Dimensions |
17 x 16.75 x 1.75 in/43.18 x 42.54 x 4.44 cm |
|
Weight: |
11.30 lbs
5.14 kg |
|
WEEE Weight: |
11.30 lbs
5.14 kg |
|
Major Regulatory |
FCC Class A, CES Class A, CE, C-Tick, VCCI, Compliance
MIC, UL, cUL, TUV/GS, CB, NOM, RoHS, WEEE |
|
Environment |
40-105° F, 5-40° C Humidity 10-90% non-condensing |
|
Humidity |
10-90% non-condensing |
Notes:
1
Testing Methodologies: Maximum performance based on RFC
2544 (for firewall). Actual performance may vary depending
on network conditions and activated services. VPN throughput
UDP traffic at 1418 byte packet size adhering to RFC 2544.
UTM performance is based on HTTP tests run on the Spirent
Avalanche/Reflector.
|