H3C SecPath F100-C-A1/A2/A3/A5 desktop firewall is a next-generation high-performance firewall product launched by H3C Technology Co., Ltd. (hereinafter referred to as H3C) with the advent of the Web 2.0 era and the current technology trend of deep integration of security and networking, targeting small and medium-sized enterprises, campus network Internet exports, and WAN branch markets.
H3C SecPath F100-C-A1/A2/A3/A5 desktop firewall supports multi-dimensional integrated security protection, which can carry out integrated security access control such as IPS, AV, DLP and other traffic from multiple dimensions such as user, application, time, and pentagram, which can effectively ensure network security. It supports a variety of VPN
| Model | Official Firewall Throughput | Concurrent Connections | New Connections Per Second (CPS) | Official Recommended Concurrent Users |
|---|---|---|---|---|
| F100-C-A1 | 800Mbps | 600,000 | 10,000 | 120 Users |
| F100-C-A2 | 800Mbps | 600,000 | 10,000 | 120 Users |
| F100-C-A3 | 700Mbps | 1,000,000 | 24,000 | 50-70 Users |
| F100-C-A5 | 700Mbps | 1,000,000 | 24,000 | 70-120 Users |
|
project |
F100-C-A1 |
F100-C-A2 |
F100-C-A3 |
F100-C-A5 |
|
interface |
5*GE+2*SFP+1*Console |
10*GE+2*SFP+1*Console |
8*GE+1*Console |
8*GE+1*Console |
|
storage media |
Support up to 500G TF card |
Not supported |
||
|
Ambient temperature |
Operation: 0~45°C Non-working: -40~70°C |
|||
|
Operating mode |
Routing mode, transparent mode, promiscuous mode |
|||
|
AAA services |
Portal Certification, RADIUS Certification, HWTACACS Certification, PKI/CA (X.509 Format) Certification, Domain authentication, CHAP verification, PAP verification |
|||
|
Firewall |
Support security zone division It can protect against various malicious attacks such as Land, Smurf, Fraggle, Ping of Death, Tear Drop, IP Spoofing, ARP Sharding, ARP Active Reverse Query, TCP Packet Flag Bit Illegal Oversized ICMP Packets, Address Scanning, Port Scanning, SYN Flood, UPD Flood, ICMP Flood, DNS Flood, and so on Basic and extended access control lists Access control lists based on time periods User-based, application-based access control lists ASPF application layer packet filtering Static and dynamic blacklist capabilities MAC and IP binding function MAC-based access control list Support 802.1q VLAN transmission |
|||
|
Virus protection |
Detection based on viral characteristics Supports manual and automatic upgrades of virus databases Message flow processing mode Support HTTP, FTP, SMTP, POP3 protocols Supported virus types: Backdoor, Email-Worm, IM-Worm, P2P-Worm, Trojan, AdWare, Virus, etc Support for virus logs and reports |
|||
|
Deep intrusion defense |
It supports defense against common attacks such as hacker attacks, worms/viruses, Trojans, malicious code, spyware/adware, DoS/DDoS, and more Supports defense against attacks such as buffer overflow, SQL injection, and IDS/IPS escape Support the classification and classification of attack feature databases (classification according to attack type and target machine system) (high, medium, low, and prompt levels) Support for manual and automatic upgrades of attack signature libraries (TFTP and HTTP) Support P2P/IM recognition and control of BT and other P2P/IM |
|||
|
Mail/web/app layer filtering |
Mail filtering SMTP email address filtering Message header filtering Email content filtering Email attachment filtering Web filtering HTTP URL filtering HTTP content filtering Apply layer filtering Java Blocking ActiveX Blocking SQL injection attack prevention |
|||
|
NAT |
Supports mapping multiple internal addresses to the same public network address Supports mapping multiple internal addresses to multiple public addresses You can map internal addresses to public network addresses one by one Support simultaneous conversion of source and destination addresses External web hosts are supported to access internal servers Supports direct mapping of internal addresses to public IP addresses of APIs DNS mapping is supported Configurable valid time to support address translation Supports a variety of NAT ALGs, including DNS, FTP, H.323, ILS, MSN, NBT, PPTP, SIP, etc |
|||
|
VPN |
L2TP VPN,IPSec VPN,GRE VPN,SSL VPN |
|||
|
IPv6 |
IPv6-based stateful firewall and attack prevention IPv6 protocols: IPv6 forwarding, ICMPv6, PMTU, Ping6, DNS6, TraceRT6, Telnet6, DHCPv6 Client, DHCPv6 Relay, etc IPv6 routes: RIPng, OSPFv3, BGP4+, static routes, policy routes, PIM-SM, PIM-DM, etc IPv6 security: NAT-PT, IPv6 Tunnel, IPv6 Packet Filter, Radius, IPv6 Inter-Domain Policy, IPv6 Connection Limit, etc |
|||
|
Easy maintenance |
Supports command-line configuration management Supports remote configuration management via web Support H3C SSM Security Management Center for device management SNMPv3 is supported and is compatible with SNMP v1 and v2 Intelligent security policies |
|||
|
Environmental protection and certification |
Support European strict RoHS environmental protection certification |
|||