Datasheet
Page 2
SSG 550/SSG 550M SSG 520/SSG520M
Maximum Performance and Capacity
(1)
ScreenOS version support ScreenOS 5.4 ScreenOS 5.4
Firewall performance (Large packets) 1+ Gbps 650+ Mbps
Firewall performance
(2)
(IMIX) 1 Gbps 600 Mbps
3DES+SHA-1 performance 500 Mbps 300 Mbps
FW packets per second (64 byte) 600,000 300,000
Concurrent sessions 128,000 64,000
New sessions/second 15,000 10,000
Policies 4,000 1,000
Users supported Unrestricted Unrestricted
Upgradeable to JUNOS 8.0 SSG 550M Only SSG 520M Only
Network Connectivity
Fixed I/O 4x 10/100/1000 4x 10/100/1000
Physical Interface Module (PIM) Slots 6 6
Enhanced PIM Slots 4 2
WAN interface options Serial, T1, E1, DS3
LAN interface options SFP, FE, 10/100/1000
Mode of Operation
Layer 2 (transparent mode)
(3)
Yes Yes
Layer 3 (route and/or NAT mode) Yes Yes
Address Translation
Network Address Translation (NAT) Yes Yes
Port Address Translation (PAT) Yes Yes
Policy-based NAT/PAT Yes Yes
Mapped IP 6,000 1,500
Virtual IP 64 32
Firewall
Network attack detection Yes Yes
DoS and DDoS protection Yes Yes
TCP reassembly for fragmented
packet protection Yes Yes
Malformed packet protection Yes Yes
Unified Threat Management / Content Security
(4)
IPS (Deep Inspection FW) Yes Yes
Protocol anomaly detection Yes Yes
Stateful protocol signatures Yes Yes
Antivirus Yes Yes
Signature database 100,000+
Protocols scanned POP3, SMTP, HTTP, IMAP, FTP
Anti-Phishing Yes Yes
Anti-Spyware Yes Yes
Anti-Adware Yes Yes
Anti-Keylogger Yes Yes
Anti-Spam Yes Yes
Integrated URL filtering Yes Yes
Extern
al URL filtering
(5)
Yes Yes
VoIP Security
H.323. ALG Yes Yes
SIP ALG Yes Yes
SCCP ALG Yes Yes
MGCP ALG Yes Yes
NAT for SIP/H.323/MGCP/SCCP Yes Yes
VPN
Concurrent VPN tunnels 1,000 500
Tunnel interfaces 300 100
DES (56-bit), 3DES (168-bit)
and AES encryption Yes Yes
MD-5 and SHA-1 authentication Yes Yes
Manual key, IKE, PKI (X.509) Yes Yes
Perfect forward secrecy (DH Groups) Yes Yes
Prevent replay attack Yes Yes
Remote access VPN Yes Yes
L2TP within IPSec Yes Yes
IPSec NAT traversal Yes Yes
Redundant VPN gateways Yes Yes
SSG 550/SSG 550M SSG 520/SSG520M
Firewall and VPN User Authentication
Built-in (internal) database – user limit 1,500 1,500
3rd Party user authentication RADIUS, RSA SecurID, 802.1X and LDAP
XAUTH VPN authentication Yes Yes
Web-based authentication Yes Yes
Routing
BGP 15 instances supported 9 instances supported
OSPF 8 instances supported 3 instances supported
RIPv1/v2 256 instances supported 128 instances supported
Dynamic routing Yes Yes
Static routes Yes Yes
Source-based routing Yes Yes
ECMP Yes Yes
Routes 20,000 10,000
Multicast Yes Yes
Reverse Forwarding Path (RFP) Yes Yes
IGMP (v1, v2) Yes Yes
IGMP Proxy Yes Yes
PIM SM Yes Yes
PIM SSM Yes Yes
Mcast inside IPSec Tunnel Yes Yes
Encapsulations
PPP Yes Yes
MLPPP Yes Yes
MLPPP max physical interfaces 12 12
Frame Relay Yes Yes
MLFR (FRF 15, FRF 16) Yes Yes
MLFR max physical interfaces 12 12
HDLC Yes Yes
Traffic Management (QoS)
Guaranteed bandwidth Yes Yes
Maximum bandwidth Yes, per physical interface Yes, per physical interface
Ingress Traffic Policing Yes Yes
Priority-bandwidth utilization Yes Yes
DiffServ stamp Yes, per policy Yes, per policy
System Management
WebUI (HTTP and HTTPS) Yes Yes
Command Line Interface (console) Yes Yes
Command Line Interface (telnet) Yes Yes
Command Line Interface (SSH) Yes, v1.5 and v2.0 compatible
NetScreen-Security Manager Yes Yes
All management via VPN tunnel
on any interface Yes Yes
SNMP full custom MIB Yes Yes
Rapid deployment No No
Logging and Monitoring
Syslog (multiple servers) External, up to 4 servers
E-mail (2 addresses) Yes Yes
NetIQ WebTrends External External
SNMP (v2) Yes Yes
Traceroute Yes Yes
VPN tunnel monitor Yes Yes
Juniper Networks Secure Services Gateway 500 Series