STT | Tính năng | Watchguard Firebox M4600 |
1 | THROUGHPUT | |
| Firewall | 60 Gbps |
| VPN | 10 Gbps |
| AV | 12 Gbps |
| IPS | 18 Gbps |
| UTM | 11 Gbps |
2 | CAPACITY | |
| Interfaces 10/100/1000 | 8 x 1 Gb and 4 x 10 Gb |
| I/O interfaces | 1 serial/2 USB |
| Concurrent connections (bi-directional) | 12.7 million |
| New connections per second | 240,000 |
| VLANs | Unrestricted |
| Authenticated users limit | Unrestricted |
3 | VPN TUNNELS | |
| Branch Office VPN | Unrestricted |
| Mobile VPN IPSec | Unrestricted |
| Mobile VPN SSL/L2TP | Unrestricted |
4 | SECURITY FEATURES | |
| Firewall | Stateful packet inspection, deep packet inspection, proxy firewall |
| Application proxies | HTTP, HTTPS, FTP, DNS, TCP/UDP, POP3, POP3S, SMTP, IMAPS, Explicit Proxy |
| Threat protection | DoS attacks, fragmented & malformed packets, blended threats & more |
| VoIP | H.323, SIP, call setup and session security |
| Filtering options | Browser Safe Search, YouTube for Schools, Google for Business |
5 | VPN & AUTHETICATION | |
| Encryption | DES, 3DES, AES 128-, 192-, 256-bit |
| IPSec | SHA-2, IKEv1/v2 , IKE pre-shared key, 3rd party cert, Suite B |
| Single sign-on | Windows, macOS, mobile operating systems, RADIUS, SAML 2.0 |
| Authentication | RADIUS, LDAP, Windows Active Directory, VASCO, RSA SecurID, internal database, SAML 2.0, SMS Passcode |
6 | MANAGEMENT | |
| Logging and notifications | WatchGuard, Syslog, SNMP v2/v3 |
| User interfaces | Centralized console (WSM), Web UI, scriptable CLI |
| Reporting | WatchGuard Dimension includes over 100 pre-defined reports, executive summary and visibility tools |
7 | CERTIFICATIONS | |
| Security | CC EAL4+ Pending: ICSA Firewall, ICSA IPSec VPN, FIPS 140-2 |
| Safety | NRTL/C, CB |
| Network | IPv6 Ready Gold (routing) |
| Hazardous substance control | WEEE, RoHS, REACH |
8 | NETWORKING | |
| Routing | Static, Dynamic (BGP, OSPF, RIP), SD-WAN Dynamic Path Selection, VPN |
| High Availability | Active/passive, active/active with load balancing |
| QoS | 8 priority queues, DiffServ, modified strict queuing |
| IP address assignment | Static, DHCP (server, client, relay), PPPoE, DynDNS |
| NAT | Static, dynamic, 1:1, IPSec traversal, policy-based, Virtual IP for server load balancing |
| Link aggregation | 802.3ad dynamic, static, active/backup |
| Other features | Port Independence, Multi-WAN failover and load balancing, server load balancing, transparent/drop-in mode, USB modem as a dedicated interface |