fwx120 specifications firewall fwx120 - hls...

2
P. O. Box 1, Hamamatsu, Japan For details, please contact: Product Information http://www.yamaha.com/products/en/network/ 2016.3 FWX120 Specifications Related Products VPN Concentrator Router RTX5000 Gigabit VPN Router RTX810 Smart L2 Switch SWX2200-24G Smart L2 Switch SWX2200-8G (*1) L2MS (Layer2 Management Service) is a function for managing Yamaha network devices in the Layer 2 level. WAN LAN LAN switching function microSD slot USB port Console port Flash ROM RAM Status LED Operating temperature Operating humidity Regulatory compliance Power supply input range Maximum power consumption Dimensions (excluding cables and connectors) Weight (excluding accessories) Body material Accessories Throughput IPsec throughput IPv4 routing protocol IPv6 routing protocol WAN protocol IPsec VPN L2TP over IPsec Firewall sessions Security Firewall function (Static IPv4/IPv6 filtering) Firewall function (Dynamic IPv4/IPv6 filtering) Firewall performance (large packets) Firewall performance (IMIX) Firewall performance PPS (64 bytes) Number of new sessions/second Certification Availability Line backup Load balancing QoS (Control system) QoS function (Classification system) SNMP Statistics/management function LAN management Web GUI Command line Configuration file transfer Firmware version up Logging Lua script Customized GUI 1 port (10BASE-T/100BASE-TX/1000BASE-T, Straight/Cross auto-distinction) *Labeled as “LAN2” on the rear panel of the unit. 4 port switching hub (10BASE-T/100BASE-TX/1000BASE-T, Straight/Cross auto-distinction) *Labeled as “LAN1” on the rear panel of the unit. Port separation, LAN segmentation (Port base VLAN), Port mirroring 1 (Up to 32GB) 1 (USB2.0 Type-A, Feed current: Max. 500 mA, Available with USB flash drive/USB 3G modem) 1 (D-sub 9 pin, DTE fixed, 9,600bit/s) 16MB 256MB Front: 6 (POWER, STATUS, LAN1, LAN2, microSD, USB), Back: 10 (LINK×5, SPEED×5) 0 to 50 degree Celsius 15 to 80% RH (no condensation) Safety: IEC 60950-1, EN 60950-1, EMC: EN 55022 Class A, EN 55024 AC100 to 240 V (50/60 Hz), 0.23 A (max) 11W (23 VA), 0.23 A, 39.6 kJ/h 220 (W) × 42.6 (H) × 160.5 (D) mm 870 g Plastic case, no fan Up to 1.0Gbit/s Up to 200Mbit/s RIP, RIP2, OSPF, BGP4 RIPng PPPoE (Up to 5 sessions) IKEv1, IKEv2, concurrent sessions: up to 50, encryption: AES-256/128, Triple-DES, DES, hash: SHA-256, SHA-1,MD5 Available for smartphones NAT/NAPT: Up to 32,000 sessions, SPI: Up to 32,000 sessions Max. 1.0Gbit/s 300Mbit/s 100Kpps 600 * When using the firewall (Filter + NAT) RADIUS, PAP/CHAP, MS-CHAP/MS-CHAPv2 VRRP Wired-wired, wired-mobile, L2 keepalive, ICMP keepalive, IPsec keepalive Available IP address, protocol, port number, ToS field v1, v2c, v3 L2MS controller (SWX2200 Series) (*1), VLAN batch setting, snapshot function, LAN cable duplexing Available SSH, TELNET, Serial console SFTP, TFTP HTTP, SFTP, TFTP, external memory Available Available All Combined in a Single Unit. Stress-free Management. License-free Security. Faster WAN. LAN cable (3 m, RJ-45, straight) (x1), User’s Manual, CD-ROM (x1) (“User’s Manual”, “Operation Manual”, and “Command Reference” are included in it.) Static filtering, Dynamic filtering, IDS, URL filtering (internal database reference), DHCP device certification, filter setting verification, password strength check, Winny filtering (Winny Version2 compliant), Share filtering (Share ver.1.0 EX2 compliant), MAC address filtering Supported via input blocking filter (IP addresses, ports, protocols (Established, with TCP flag), sources/destinations; Up to 128 filters can be specified on the LAN side/WAN side) Supported via policy filters (Can be defined freely with IP addresses, protocols, services (ports), or sources/destinations; Up to 265 filters can be specified) Applied to IN/OUT on the LAN side/WAN side, IP header, IP option header, 31 types of unauthorized access can be detected in categories such as ICMP/UDP/TCP/FTP, unauthorized access email notification function Syslog, internal: up to 3,000 lines (non-volatile), output to external memory (microSD/USB memory, with/without encryption), logging at power-off (power-off logging function) , reboot logging function Graphical representation of the statistics information (CPU usage, memory usage, traffic, fast path flow, NAT entries, routes, policy filter sessions, and QoS queue throughput); Export of statistics information to microSD/USB memory; Dashboard function (system information, resource information, interface information, traffic information, provider connection status, VPN connection status, NAT sessions, fast path flows, policy filter sessions, unauthorized access detection history, and SYSLOG) Coloring (ToS), ToS -> CoS conversion Priority queuing, bandwidth control (Dynamic Traffic Control), Dynamic Class Control, VPN QoS, bandwidth detection function, load notification function Firewall function (IDS: IPv4 unauthorized access detection) QoS function (Coordination with the QoS function on the network side) Firewall FWX120 Indonesia HLS Telecom (PT Halilintar Lintas Semesta) Ruko Orion Mangga Dua no. 22 JL Raya Mangga Dua Jakarta Pusat - 10730, Indonesia Tel: +62 (21) 612-6833 Fax: +62 (21) 601-5983 Email: [email protected] http://www.hls-telecom.com Malaysia Yamaha Music (Malaysia) Sdn. Bhd. No.8 Jalan Perbandaran, Kelana Jaya, 47301 Petaling Jaya, Selangor, Malaysia Tel: +60 (3) 7803-0900 Fax: +60 (3) 7803-0611 http://my.yamaha.com/ Thailand EASY NET CO.,LTD 204 M.1 Suksawad Rd., Lampfapha, Prasamutjdee, Samutparkarn, 10290, Thailand Tel: +66 (0) 2-8152540 Fax: +66 (0) 2-8153765 Email: [email protected] http://www.easynetwork.co.th

Upload: lynhi

Post on 28-Mar-2019

219 views

Category:

Documents


0 download

TRANSCRIPT

P. O. Box 1, Hamamatsu, Japan

For details, please contact:

Product Information

http://www.yamaha.com/products/en/network/

2016.3FWX120 Specifications

Related Products

VPN Concentrator RouterRTX5000

Gigabit VPN RouterRTX810

Smart L2 SwitchSWX2200-24G

Smart L2 SwitchSWX2200-8G

(*1) L2MS (Layer2 Management Service) is a function for managing Yamaha network devices in the Layer 2 level.

WAN

LAN

LAN switching function

microSD slot

USB port

Console port

Flash ROM

RAM

Status LED

Operating temperature

Operating humidity

Regulatory compliance

Power supply input range

Maximum power consumption

Dimensions (excluding cables and connectors)

Weight (excluding accessories)

Body material

Accessories

Throughput

IPsec throughput

IPv4 routing protocol

IPv6 routing protocol

WAN protocol

IPsec VPN

L2TP over IPsec

Firewall sessions

Security

Firewall function (Static IPv4/IPv6 filtering)

Firewall function (Dynamic IPv4/IPv6 filtering)

Firewall performance (large packets)

Firewall performance (IMIX)

Firewall performance PPS (64 bytes)

Number of new sessions/second

Certification

Availability

Line backup

Load balancing

QoS (Control system)

QoS function (Classification system)

SNMP

Statistics/management function

LAN management

Web GUI

Command line

Configuration file transfer

Firmware version up

Logging

Lua script

Customized GUI

1 port (10BASE-T/100BASE-TX/1000BASE-T, Straight/Cross auto-distinction) *Labeled as “LAN2” on the rear panel of the unit.

4 port switching hub (10BASE-T/100BASE-TX/1000BASE-T, Straight/Cross auto-distinction) *Labeled as “LAN1” on the rear panel of the unit.

Port separation, LAN segmentation (Port base VLAN), Port mirroring

1 (Up to 32GB)

1 (USB2.0 Type-A, Feed current: Max. 500 mA, Available with USB flash drive/USB 3G modem)

1 (D-sub 9 pin, DTE fixed, 9,600bit/s)

16MB

256MB

Front: 6 (POWER, STATUS, LAN1, LAN2, microSD, USB), Back: 10 (LINK×5, SPEED×5)

0 to 50 degree Celsius

15 to 80% RH (no condensation)

Safety: IEC 60950-1, EN 60950-1, EMC: EN 55022 Class A, EN 55024

AC100 to 240 V (50/60 Hz), 0.23 A (max)

11W (23 VA), 0.23 A, 39.6 kJ/h

220 (W) × 42.6 (H) × 160.5 (D) mm

870 g

Plastic case, no fan

Up to 1.0Gbit/s

Up to 200Mbit/s

RIP, RIP2, OSPF, BGP4

RIPng

PPPoE (Up to 5 sessions)

IKEv1, IKEv2, concurrent sessions: up to 50, encryption: AES-256/128, Triple-DES, DES, hash: SHA-256, SHA-1,MD5

Available for smartphones

NAT/NAPT: Up to 32,000 sessions, SPI: Up to 32,000 sessions

Max. 1.0Gbit/s

300Mbit/s

100Kpps

600 * When using the firewall (Filter + NAT)

RADIUS, PAP/CHAP, MS-CHAP/MS-CHAPv2

VRRP

Wired-wired, wired-mobile, L2 keepalive, ICMP keepalive, IPsec keepalive

Available

IP address, protocol, port number, ToS field

v1, v2c, v3

L2MS controller (SWX2200 Series) (*1), VLAN batch setting, snapshot function, LAN cable duplexing

Available

SSH, TELNET, Serial console

SFTP, TFTP

HTTP, SFTP, TFTP, external memory

Available

Available

All Combined in a Single Unit.Stress-free Management.License-free Security.Faster WAN.

LAN cable (3 m, RJ-45, straight) (x1), User’s Manual, CD-ROM (x1) (“User’s Manual”, “Operation Manual”, and “Command Reference” are included in it.)

Static filtering, Dynamic filtering, IDS, URL filtering (internal database reference), DHCP device certification, filter setting verification, password strength check, Winny filtering (Winny Version2 compliant), Share filtering (Share ver.1.0 EX2 compliant), MAC address filtering

Supported via input blocking filter (IP addresses, ports, protocols (Established, with TCP flag), sources/destinations; Up to 128 filters can be specified on the LAN side/WAN side)

Supported via policy filters (Can be defined freely with IP addresses, protocols, services (ports), or sources/destinations; Up to 265 filters can be specified)

Applied to IN/OUT on the LAN side/WAN side, IP header, IP option header, 31 types of unauthorized access can be detected in categories such as ICMP/UDP/TCP/FTP, unauthorized access email notification function

Syslog, internal: up to 3,000 lines (non-volatile), output to external memory (microSD/USB memory, with/without encryption), logging at power-off (power-off logging function) , reboot logging function

Graphical representation of the statistics information (CPU usage, memory usage, traffic, fast path flow, NAT entries, routes, policy filter sessions, and QoS queue throughput); Export of statistics information to microSD/USB memory; Dashboard function (system information, resource information, interface information, traffic information, provider connection status, VPN connection status, NAT sessions, fast path flows, policy filter sessions, unauthorized access detection history, and SYSLOG)

Coloring (ToS), ToS -> CoS conversion

Priority queuing, bandwidth control (Dynamic Traffic Control), Dynamic Class Control, VPN QoS, bandwidth detection function, load notification function

Firewall function (IDS: IPv4 unauthorized access detection)

QoS function (Coordination with the QoS function on the network side)

Firewall

FWX120

Indonesia

HLS Telecom(PT Halilintar Lintas Semesta)

Ruko Orion Mangga Dua no. 22 JL RayaMangga Dua Jakarta Pusat - 10730,IndonesiaTel: +62 (21) 612-6833Fax: +62 (21) 601-5983Email: [email protected]://www.hls-telecom.com

Malaysia

Yamaha Music (Malaysia) Sdn.Bhd.

No.8 Jalan Perbandaran, Kelana Jaya,47301 Petaling Jaya, Selangor, MalaysiaTel: +60 (3) 7803-0900Fax: +60 (3) 7803-0611http://my.yamaha.com/

Thailand

EASY NET CO.,LTD

204 M.1 Suksawad Rd., Lampfapha,Prasamutjdee, Samutparkarn, 10290,ThailandTel: +66 (0) 2-8152540Fax: +66 (0) 2-8153765Email: [email protected]://www.easynetwork.co.th

Speed up WAN for high-speed Internet!

Carefully selected security functions are all provided

license-free!

SecureEasy

WAN load balancingSupports binding of up to five WAN lines (including mobile lines using the “USB mobile function”) to achieve high-speed access equivalent to a stable high-capacity line.

WAN line visualizationMonitors the time periods when the line speed becomes slow and utilizes the WAN line more efficiently by prioritizing each protocol using “QoS”.

Web access restriction/unauthorized access detection (IDS)Provides a carefully selected range of license-free firewall functions required for small and medium-sized companies.

Security adviceDiagnoses, monitors and reports the security conditions before and during the operation.

LAN visualizationDetects all changes in the LAN network.

Access log saving/transferringAllows the user to save all communication logs to an external memory and/or transfer them to the Syslog server.

VPN using IPsec and L2TP/IPsecAllows the user to perform remote checks/configurations for quick problem isolation and resolution.

Control functions of the “SWX2200 Series” Yamaha Smart L2 switchesEnables a single FWX120 unit to control up to 32 Yamaha switches to unify the management of the entire network.

External memory functionAllows the user to configure a device simply by inserting an external memory containing the configuration information, dramatically reducing the device replacement time in case of failure.

User access managementAllows visualization of the Web sites accessed from each terminal, enabling monitoring of employees to prevent them from accessing non-work-related Web site during work hours.

Dashboard

LAN2

VLAN1

WAN

LAN

IT staff being forced to look after the corporate network security as well

The boss wants us to improve the security and reduce cost at the same time.There are so many security solutions out there and license fees are quite hefty... We have no idea which one to choose! What will we do when a problem occurs?!

FWX120 provides all the necessary security functions for SME license-free! The on-site IT staff can quickly isolate and resolve security problems on their own.

A managing director facing in-house network issues

Managing in-house network so labor intensive!A network problem occurred after one of the employees allegedly accessed a suspicious Web site! While the network is down, we will suffer financial loss including “personnel costs”, “infrastructure depreciation costs” and “license fees for cloud services, etc.”... And worst of all, we are at risk of losing customer trust because they can’t reach us!But we cannot afford subscribing to expensive services or hiring additional IT staff!

FWX120 can help reduce the operations management load for the entire network.

FWX120

Can be installed asa transparenttype firewall

InternetInternet

InternetInternet

No change requiredExistingbroadbandrouterSpeedy

Speedy Secure EasyStress-free

LAN management and operation!

FWX120

Melancholy of an IT staff

Enhance the communication environment with FWX120! The mobile function can also be used for line backup.

Monday morning always starts with a board meeting via teleconference. After the meeting, I always receive complaints about unstable connections from disgruntled participants.Subscribing to a stable, high-speed line or installing a dedicated load balancing device is really expensive and will never be approved...

Unfairness Personnel costVirus Reduces the operations

management load

* URL filtering (internal database reference)

Much cost...

Save cost

License free

Many licenses...

Dashboard

Administrator

Multiple WAN for load-balance and failover

WAN load balancing

Saving moneyVLAN2

ISP2 ISP1

InternetInternetInternetInternet

InternetInternet

InternetInternet InternetInternet

InternetInternet

Looking for solutions?

High-speed WAN connectionUSE CASE

01

License-free security USE CASE

02

Easy LAN managementUSE CASE

03

IDS license VPN license

URL filter license*

Cheap line

MON SUN

InternetInternet

Binding

Cheap line

MON SUN

Slow & unstableFast & stable

Annuallicense

fee

FWX120Firewall

Shows various statistic information by gadget

Mobile network

Security OK

FWX120 Overview