ZyXEL - Leading provider of complete broadband access solutions.ZyXEL ZyWALL USG 50 Unified Security Gateway

ZyWALL Unified Security Gateway Series

ZyXEL ZyWALL USG 50 Unified Security Gateway

ZyXEL Products
ZyXEL ZyWALL USG 50
ZyXEL ZyWALL USG 50
-Unified Security Gateway w/5 VPN Tunnels, SSL VPN, 6 Gigabit Ports, High Availability
#ZWUSG50
Our Price: $265.00
ZyXEL ZyWALL USG 50 Total Security
-Unified Security Gateway w/5 VPN Tunnels, SSL VPN, 6 Gigabit Ports, High Availability w/ 1 Year CF, AV and IDP
#ZWUSG50TS
Our Price: $476.00

More pricing below, click here

ZyXEL ZyWALL USG 50 Overview:

ZyWALL Unified Security Gateway Series

The ZyWALL USG (Unified Security Gateway) Series is the “third generation” ZyWALL featuring an all-new platform. It provides greater performance protection, as well as a deep packet inspection security solution for small businesses to enterprises alike. It embodies a Stateful Packet Inspection (SPI) firewall, Anti-Virus, Intrusion Detection and Prevention (IDP), Content Filtering, Anti-Spam, and VPN (IPSec/SSL/L2TP) in one box. This multilayered security safeguards your organization’s customer and company records, intellectual property, and critical resources from external and internal threats.

  • All-new platform: “3rd” generation ZyWALL
  • USG clean-traffic architecture
  • New generation UTM solution (except USG 20/20W)
  • Robust hybrid VPN (IPSec and SSL)
  • Application firewall (except USG 20/20W)
  • Granular control over social networking applications
  • Non-stop Internet access with multiple WAN and 3G backups
  • ICSA firewall, IPSec certification
  • Comprehensive report system
  • Anti-Spam service
  • ZyXEL Security Distribution Network (ZSDN)

Benefits:

Secure connectivity:

Given the prevalence and importance of information technology (IT) systems today and the nature and scale of both the opportunities and risks associated with significant deployments of new networking technologies, organizations are forced to evaluate solutions to build up a safer infrastructure to secure online transactions, in which involve exchange of valuable information. The infrastructure should be tailored to meet operation requirements for expanding remote sites as well as mobile teleworkers.

Proactive protection:

Malicious virus, worm, exploits could cripple corporate networks and halt business transactions. In addition to severe financial loss, you also risk leakage of confidential information.

As mass-mailing software companies mushroom on the Internet, your network is bombarded with massive amounts of junk mails (spam). Without intelligent detection and proactive blocking, users have to go through the tedious and time-consuming task of sieving through the overflowing mailbox, and such scenario leads to serious productivity loss.

Policy compliance:

With numerous file-sharing (P2P) and Instant Messaging (IM) applications, it is easier for company employees to share files and chat online during work hours. Rapid file sharing not only compromises network safety with the sharing of questionable files containing malicious viruses, but may also violate copyright issues and create legal hassles.

Network resilience:

ISP links broken, hardware and software failure on the gateway, dead VPN tunnels — these are severe challenges IT staff face when designing the network infrastructure. In short, we need to take fault tolerance on the network path into consideration when build up a highly available network infrastructure for non-stop operations.

Manageability:

With Vantage CNM (Centralized Network Management), users can achieve the follow objects:

  • Easy VPN management and diagnostic capability
  • Complete security policies and UTM management
  • Low TCO of massive deployment and device maintenance
  • Active monitoring, alerting and comprehensive graphic reports

The solution provides an efficient centralized management system for enterprises of any size to reduce operational costs regardless of the number of branch offices or remote locations.

Cost-effectiveness:

With the adoption of ZyXEL’s USG device, the follow costs can be saved:

  • Device hardware maintenance fee: ZyXEL provides a one more year hardware warranty out of factory.
  • Free software upgrade: now ZyXEL provides free software upgrade for you to enjoy complete protection without additional expense.

Application Diagram:

ZyWALL USG clean-traffic architecture:

The ZyWALL USG’s clean-traffic architecture protects against network risks such as viruses, worms, Trojan Horses, spyware, phishing attacks and other emerging Internet threats. With the clean-traffic architecture, enterprises users are assured to have clean and secure network environments.

ZyWALL USG clean-traffic architecture

Endpoint security:

With the new Endpoint Security feature (EPS), administrators can easily identify “bad” users, i.e. where no AV software has been installed. By enforcing installation of the Anti-Virus software, the ZyWALL mitigates the threat of virus outbreaks and thus the loss of money and employee productivity. The EPS supports NortonTM KasperskyTM and TrendMicroTM AV client software, among others. Additionally, personal firewall software such as Kaspersky Internet Security 2009/2010, Windows Firewall and TrendMicro PC-Cillin/Internet Security 2010 are also supported with the new EPS feature.

Endpoint security

New generation UTM solution:

The ZyWALL USG Series deploys hardwareacceleration technology in one box. Powered by high-performance SecuASIC technology and a hardware-based encryption accelerator, the ZyWALL USG Series delivers industry-leading performance and multilayer threat protection for small businesses and enterprises. The ZyWALL USG Series provides integrated Unified Threat Management security features such as Anti- Virus (include Kaspersky Anti-Virus & ZyXEL Anti-Virus), IDP, Anti-Spam, Content Filtering and Firewall, VPN. All ZyWALL USG Series products support the Gigabit Ethernet.

New generation UTM solution

High performance:

ZyXEL USG Series is built with a powerful Integrated High Performance Security architecture, a performance proven architecture for gigabit fiber. It provides real-time inspection to prevent network from threats without sacrificing performance. Company network is not only flawlessly secured but also greatly enhanced on performance to improve operational productivity and efficiency when applications such as file-loading, emailing, and information searches are processed at higher speed. Take USG 50 as an example, USG 50 delivers excellent performance to meet small business.

High performance

Robust hybrid VPN (IPSec and SSL):

The ZyWALL USG Series can provide secure access between remote locations and corporate resources through the Internet for organizations of any size. Using IPSec VPN, companies can secure connections to branch offices, partners and headquarters. Road warriors and telecommuters can use SSL or L2TP VPN to safely access the company network without having to install VPN software. The Series provides a flexible and easy way to enable mobile employees, vendors and partners to confidently access your network resource for better efficiency.

Robust hybrid VPN (IPSec and SSL)

Granular control over social networking applications:

Social networking applications such as Facebook, Twitter, and Youtube have become an Internet phenomenon to connect people quickly and to share information. Without flexible management, social networking applications will eat up business productivity. ZyWALL USG ensures that the Internet is not abused to prevent bandwidth to be wasted or human resource policy violations. ZyWALL USG provides granular control over social networking applications.

Granular control over social networking applications

Application firewall:

More and more network applications bring malicious software into your office. This kind of unwanted software, especially IM/P2P applications, may cause bandwidth waste or even system damage. Using the application patrol and bandwidth management features, you can have full control over traffic blocking or rate limit settings.

Application firewall

Non-stop Internet access with multiple WAN and 3G backups:

The ZyWALL USG not only supports multiple WAN ports but also 3G through USB or PCMCIA cards. This feature enables “active-active” load sharing or “activepassive” failover configuration to deliver highly reliable network connectivity.

Non-stop Internet access with multiple WAN and 3G backups

High availability:

High availability is essential in enterprise networks. It ensures a system or component can be continuously operational for a desirably long length of time. The ZyWALL USG Series provide high availability feature as:

  • Multiple WAN ports and configure load balancing between these ports.
  • An auxiliary (backup) Internet connection as known as out of band Management.
  • A backup ZyWALL in the event the master ZyWALL fails (device HA).

To minimize the impact of single-point failures, the ZyWALL USG Series supports device HA (High Availability) to assure network availability.

High availability

Anti-Spam service:

ZyXEL’s Anti-Spam service eliminates spam, phishing, virus and malware threats through a unified security architecture without dropping legitimate messages. With ZyXEL’s Anti-Spam service, enterprises can save time and resources dealing with unwanted email to reduce operational costs.

Anti-Spam service

Comprehensive reporting system:

The ZyWALL USG Series has a built-in reporting system that offers a comprehensive set of realtime and historical reports including firewall, virus and intrusion attacks, bandwidth usage, Web site usage and user activities. Furthermore, with Vantage Report (VRPT), a Web-based reporting system, administrators can easily collect traffic data and analyze a distributed network for their organizations to become more aware of suspicious activities and to ensure better business productivity.

Comprehensive reporting system

ZyXEL Security Distribution Network (ZSDN) ensures rapid response to new threats:

ZSDN Provides Up-to-Date Protection

  • The myZyXEL.com Web site delivers a convenient, centralized way to register all ZyWALL units and Security Services.
  • The ZyXEL Security Update Servers operates 24x7 to automatically deliver updated signature databases to ZyWALL units around the world.
  • The mySecurityZone portal provides comprehensive, searchable information regarding viruses and system vulnerabilities, and it provides a wealth of information resources that keep customers up-to-date on the latest vulnerabilities and countermeasures.

ZyXEL Security Distribution Network (ZSDN) ensures rapid response to new threats

Specifications:

ZyWALL USG 50 Front

ZyWALL USG 50 Rear

Features:
  • Unified Security Gateway for SME (1~10 PC Users)
  • All Gigabit Ethernet interface hardware design
  • High-performance multi-layer threat protection
  • Hybrid VPN (IPSec and SSL) secures connection
  • 3G USB dongle as the backup WAN
Firewall:
  • ICSA-certified firewall
  • Routing and transparent (bridge) mode
  • Zone-based access control list
  • Stateful packet inspection
  • NAT, PAT
  • Policy base NAT
  • VLAN tagging
  • User-aware policy enforcement
  • SIP/H.323 NAT traversal
  • ALG supports custom ports
Virtual Private Network (VPN):
  • ICSA-certified IPSec VPN
  • PPTP, IPSec
  • Algorithm: AES/3DES/DES
  • Authentication: SHA-1/MD5
  • Key management: Manual key/IKE
  • Perfect forward secrecy: (DH group) supprt 1, 2, 5
  • IPSec NAT traversal
  • Dead peer detection/relay detection
  • PKI (X.509) certificate support
  • Centralize VPN Support
  • Simple wizard support
  • Auto reconnect VPN
  • VPN HA (redundant remote VPN gateways)

SSL VPN:

  • Clientless Secure Remote Access (Reverse Proxy Mode)
  • Support reverse proxy mode and full tunnel mode
  • Unified Policy Enforcement
  • Supports Two Factor Authentication
  • Customizable User Portal

Anti-Spam:

  • Zone to zone protection
  • Transparently intercept mail via SMTP/POP3 protocols
  • Blacklist/whitelist support
  • Support DNSBL checking
  • Spam tag support
  • Statistics report

Anti-Virus:

  • Support Kaspersky and ZyXEL Anti-Virus
  • Stream-based Anti-Virus engine
  • Zone base AV protection
  • HTTP/FTP/SMTP/POP3/IMAP4 protocal support
  • Automatic signature updates
  • No file size limitation
  • Blacklist/whitelist support
Intrusion Detection and Prevention (IDP):
  • Routing and transparent (bridge) mode
  • Zone-based IDP inspection
  • Customizable protection profile
  • Protect over 2000 attack
  • Automatic signature updates
  • Custom signatures
  • Protocol anomaly detection and protection
  • Traffic anomaly detection and protection
  • Flooding detection and protection
  • DoS/DDoS protection
Content Filtering:
  • Social networking control
  • Web security - ZyXEL safe browsering
  • URL blocking, keyword blocking
  • Profile base setting
  • Exempt list (blacklist and whitelist)
  • Blocks java applet, cookies and active X
  • Dynamic URL filtering database (powered by BlueCoat)
  • Unlimited user licenses support
  • Customize warning messages and redirect URL
Networking:
  • Routing mode/bridge mode/mixed mode
  • Layer 2 port grouping
  • Ethernet/PPPoE
  • Tagged VLAN (802.1Q)
  • Virtual interface (alias interface)
  • Policy-based routing (user-aware)
  • Policy-based NAT (SNAT)
  • Dynamic routing(RIP v1/v2, OSPF)
  • DHCP client/server/relay
  • Dynamic DNS support
  • WAN Trunk more than 2 port
  • Dynamic DNS support
  • Per host session limit
  • Guaranteed bandwidth
  • Maximum bandwidth
  • Priority-bandwidth utilization
Authentication:
  • Local user database
  • Microsoft Windows active directory integrate
  • External LDAP/RADIUS user database
  • Xauth over RADIUS for IPSec VPN
  • Forced user authentication (transparent authentication)
  • IP/MAC address binding
System Management:
  • Role-based administration
  • Multiple administrator login
  • Multi-Lingual Web GUI (HTTPS/HTTP)
  • Object-based configuration
  • Command line interface (console/web console/SSH/TELNET)
  • SNMP v2c (MIB-II)
  • System configuration rollback
  • Firmware upgrade via FTP/FTP-TLS/Web GUI
Application Patrol:
  • Application, IM/P2P, stream base media, VoIP granular access control
  • Detail access control of IM (Chat, file transfer, video)
  • Application and IM/P2P bandwidth control
  • User authentication support
  • IM/P2P signature auto update
  • Support more than 15 catalogs IM and P2P
  • Real-Time statistical reports
  • Maximum/guaranteed bandwidth
Logging/Monitoring:
  • Comprehensive local logging
  • Syslog (send to up to 4 servers)
  • E-mail alert (send to up to 2 servers)
  • Real-Time traffic monitoring
  • Built-in daily report
  • Advanced reporting (Vantage Report)
  • Centralized Network Management (Vantage CNM) manageable
System Capacity & Performance:
  • SPI Firewall Throughput*1: 100 Mbps
  • VPN Throughput (3DES)*2: 50 Mbps
  • Unlimited User Licenses
  • Max. Sessions*3: 10,000
  • New Session Rate: 1.000
  • Max. Concurrent IPSec VPN Tunnels: 5
  • Max. Concurrent SSL VPN Users: 5
  • Included SSL VPN Users: 2
  • Customizable Zone

Hardware Specifications:

  • 10/100/1000 Interfaces (Copper): 4 x LAN/DMZ, 1 x WAN
  • USB ports: 2

Physical Specifications:

  • Dimensions: 243 (W) x 167.10 (D) x 35.5 (H) mm
  • Weight: 1.2 kg
Power Requirement:
  • Input Voltage: 100 - 240 V AC, 50 - 60 Hz, 1.2 A
  • Power Rating: 17 W Max
Environmental Specifications:
  • Operating temperature: 0ºC to 40ºC
  • Storage temperature: 0ºC to 40ºC
  • Operating humidity: 20% to 95% (non-condensing)

Note:
*1: Testing Methodologies: Maximum performance based on RFC 2544 (UDP packets, 1,518 bytes). Actual performance may vary depending on network conditions and activated services.
*2: VPN (AES) throughput measured using UDP traffic with 1,424 bytes packet size, based on RFC 2544.
*3: Max sessions measured using industry standard Ixia IxLoad test tool.

Model Comparison:

Model Name ZyWALL USG 20W ZyWALL USG 20 ZyWALL USG 50
  ZyWALL USG 20W ZyWALL USG 20 ZyWALL USG 50
Features • Unified Security Gateway for SB (1~5 PC Users)
• All Gigabit Ethernet interface hardware design
• High-performance multi-layer threat protection
• Hybrid VPN (IPSec, SSL) secures connection
• 3G USB dongle as the backup WAN
• 802.11b/g/n wireless AP
• Unified Security Gateway for SB (1~5 PC Users)
• All Gigabit Ethernet interface hardware design
• High-performance multi-layer threat protection
• Hybrid VPN (IPSec, SSL) secures connection
• 3G USB dongle as the backup WAN
• Unified Security Gateway for SB (1~10 PC Users)
• All Gigabit Ethernet interface hardware design
• High-performance multi-layer threat protection
• Hybrid VPN (IPSec, SSL) secures connection
• Multi WAN ports for multiple ISP links and load balancing
Hardware Specifications
10/100/1000 Interfaces (Copper) 4 x LAN/DMZ, 1 x WAN 4 x LAN/DMZ, 1 x WAN 4 x LAN/DMZ, 2 x WAN
Dual Personality GbE (SFP/RJ45) - - -
USB Ports 1 1 2
SEM Slot (Security Extension Module) - - -
Card Slot - - -
802.11b/g/n Yes - -
2x2 Antenna Yes - -
System Capacity & Performance
SPI Firewall Throughput*1, Mbps 100 100 100
VPN Throughput (3DES)*2, Mbps 30 30 50
UTM Throughput (AV+IDP)*3, Mbps - - 15
WiFi Throughput, Mbps 60 - -
Unlimited User Licenses Yes Yes Yes
Max. Sessions*6 6,000 6,000 10,000
New Session Rate 900 900 1,000
Max. Concurrent IPSec VPN Tunnels 2 2 5
Max. Concurrent SSL VPN Users 1 1 5
Included SSL VPN Users 1 1 2
Customizable Zone Yes Yes Yes
Power Requirement
Input Voltage 100 - 240 V AC, 50 - 60 Hz, 1.2 A 100 - 240 V AC, 50 - 60 Hz, 1.2 A 100 - 240 V AC, 50 - 60 Hz, 1.2 A
Power Rating 16 W Max 15 W Max 17 W Max
Environmental Specifications
Operating Temperature 0°C to 40°C
Storage Temperature 0°C to 40°C
Operating Humidity 20% to 95% (non-condensing)
Physical Specifications
Dimensions, (W) x (D) x (H) mm 216 x 140 x 33 216 x 140 x 33 242 x 167 x 35.5
Weight, kg 0.42 0.38 1.2

Note:
*1: Testing Methodologies: Maximum performance based on RFC 2544 (UDP packets, 1,518 bytes). Actual performance may vary depending on network conditions and activated services.
*2: VPN (AES) throughput measured using UDP traffic with 1,424 bytes packet size, based on RFC 2544.
*3: UTM (AV+IDP) throughput measured using industry standard Ixia IxLoad test tool against HTTP protocol with 1,460 bytes packet size. Testing done with multiple flows.
*4: With SEM-DUAL/SEM-VPN module
*5: With SEM-DUAL module
*6: Max sessions measured using industry standard Ixia IxLoad test tool.

Documentation:

PDF File
Download the ZyXEL ZyWALL USG 50 Datasheet (PDF).

 

ZyXEL Products
ZyXEL ZyWALL USG 50
ZyXEL ZyWALL USG 50
-Unified Security Gateway w/5 VPN Tunnels, SSL VPN, 6 Gigabit Ports, High Availability
#ZWUSG50
Our Price: $265.00
ZyXEL ZyWALL USG 50 Total Security
-Unified Security Gateway w/5 VPN Tunnels, SSL VPN, 6 Gigabit Ports, High Availability w/ 1 Year CF, AV and IDP
#ZWUSG50TS
Our Price: $476.00
ZyXEL ZyWALL USG 50 Subscriptions
ZyWALL USG50 iCard Total Security Service, 1 Year
- Includes Content Filtering, Anti-Virus and IDP Services
#ICTS1YUSG50
Our Price: $231.00
ZyWALL USG50 iCard Content Filtering, 1 Year #ICCF1YUSG50
Our Price: $93.00
ZyWALL USG50 iCard Anti-Virus, 1 Year #ICAV1YUSG50
Our Price: $83.00
ZyWALL USG50 iCard IDP, 1 Year #ICID1YUSG50
Our Price: $63.00
ZyWALL USG50 iCard SSL Upgrade 2-5 Users
- SSL License Upgrade from 2 to 5 Users
#SSL2TO5USG50
Our Price: $63.00
VPN IPSec VPN Client
ZyWALL IPSec VPN Client
- Vista Supported VPN Client - 1 Client
#ZYWALLVPN
List Price: $64.99
Our Price: $47.00
ZyWALL IPSec VPN Client
- Vista Supported VPN Client - 5 Clients
#ZYWALLVPN5
List Price: $249.99
Our Price: $188.00