H3C SecPath F1000-900-AI Series Next-Generation Firewall
The H3C SecPath F1000-900-AI Series represents a high-performance multi-gigabit and ultra-10-gigabit firewall VPN integrated gateway solution designed for enterprise security. As network attacks become increasingly sophisticated and frequent, this AI-powered NGFW provides comprehensive protection against evolving cyber threats.
Product Overview
This enterprise-grade security gateway integrates advanced firewall capabilities with VPN, IPS, DDoS protection, and threat intelligence. The series offers rich interface expansion capabilities and supports large-capacity hard drives for enhanced audit functions and application acceleration features like web buffering.
Technical Specifications
| Model |
Interfaces |
Expansion Slots |
Storage Media |
| F1000-905-AI |
1 CON port, 1 RJ45 management port, 2 USB ports, 8 Gigabit Ethernet ports |
N/A |
N/A |
| F1000-910-AI |
1 CON port, 1 RJ45 management port, 2 USB ports, 8 Gigabit Ethernet ports, 2 Gigabit Combo |
1 |
1*(480G SSD/500G HDD) |
| F1000-920/930/950/960/970-AI |
1 CON port, 1 RJ45 management port, 2 USB ports, 15 Gigabit Ethernet ports, 8 Gigabit Ethernet optical ports |
1 |
1*(480G SSD/500G HDD/1T HDD) |
| F1000-980/990-AI |
1 CON port, 1 RJ45 management port, 2 USB ports, 15 Gigabit Ethernet ports, 8 Gigabit Ethernet optical ports, 2 Gigabit Ethernet optical ports |
2 |
2*(480G SSD/500G HDD/1T HDD) |
Environmental Specifications: Operating Temperature: 0~45°C, Non-operating: -40~70°C
Operating Modes: Routing mode, transparent mode, promiscuous mode
Core Security Features
Firewall Protection
- SOP virtual firewall technology with complete hardware resource virtualization
- Safe zone division and comprehensive attack protection
- Defense against Land, Smurf, Fraggle, Ping of Death, Tear Drop, IP Spoofing attacks
- Protection against ARP Sharding, ARP Active Reverse Query, TCP Packet Flag Bit violations
- Detection and prevention of Oversized ICMP Packets, Address Scanning, Port Scanning
- Mitigation of SYN Flood, UDP Flood, ICMP Flood, DNS Flood DDoS attacks
- Basic and extended access control lists with time-based policies
- User-based and application-based access control lists
- ASPF application layer packet filtering
- Static and dynamic blacklist capabilities
- MAC and IP binding with MAC-based access control
- Support for 802.1q VLAN transmission
Virus Protection
- Detection based on viral characteristics with manual and automatic database updates
- Message flow processing mode for HTTP, FTP, SMTP, POP3 protocols
- Protection against Backdoor, Email-Worm, IM-Worm, P2P-Worm, Trojan, AdWare, Virus types
- Comprehensive virus logs and reporting capabilities
Deep Intrusion Defense
- Defense against hacker attacks, worms/viruses, Trojans, malicious code, spyware/adware
- Protection against DoS/DDoS, buffer overflow, SQL injection, IDS/IPS escape attacks
- Classification and categorization of attack feature databases by type and severity
- Manual and automatic signature library upgrades via TFTP and HTTP
- P2P/IM recognition and control for BT and other P2P/IM applications
Advanced Security Capabilities
Mail/Web/Application Layer Filtering
- SMTP email address, header, content, and attachment filtering
- HTTP URL filtering and HTTP/HTTPS content filtering
- Application layer filtering with Java Blocking and ActiveX Blocking
- SQL injection attack prevention
NAT & VPN
- Comprehensive NAT support including multiple internal to public address mapping
- One-to-one internal to public address mapping with DNS mapping support
- Configurable valid time for address translation
- Multiple NAT ALGs including DNS, FTP, H.323, ILS, MSN, NBT, PPTP, SIP
- L2TP VPN, IPSec VPN, GRE VPN, SSL VPN support
IPv6 Support
- IPv6-based stateful firewall and attack prevention
- Full IPv6 protocol support including forwarding, ICMPv6, PMTU, Ping6, DNS6
- IPv6 routing with RIPng, OSPFv3, BGP4+, static routes, policy routes
- IPv6 security features including NAT-PT, IPv6 Tunnel, IPv6 Packet Filter
High Reliability & Management
High Availability
- SCF 2:1 virtualization support
- Dual-device state hot standby with Active/Active and Active/Backup modes
- Dual-computer configuration synchronization
- IKE status synchronization for IPSec VPN
- VRRP support for enhanced reliability
Management & Maintenance
- Command-line configuration management
- Remote web-based configuration management
- H3C SSM Security Management Center integration
- SNMPv3 support with backward compatibility for v1 and v2
- Intelligent security policies with redundancy detection and optimization
AI-Powered Features
The F1000-900-AI Series incorporates advanced artificial intelligence capabilities for enhanced threat detection and response:
- Intelligent linkage with situational awareness for real-time threat reporting
- Automatic rule generation for blocking and mitigation during attacks
- IP reputation linkage for filtering risky IP addresses
- AI intelligent fingerprint recognition for files and terminals
- Diversified access methods and authentication strategies
- Active vulnerability scanning for UDP/TCP port and service detection
Next-Generation Multi-Service Features
- Link load balancing with automatic balancing and switching
- Integrated authentication with USB-Key and SMS support
- Data leak prevention (DLP) with comprehensive filtering capabilities
- Intrusion prevention (IPS) for web attack identification
- High-performance antivirus (AV) engine with daily signature updates
- Situational awareness platform integration for rapid threat response
Environmental Certification: Compliant with European strict RoHS environmental protection standards, ensuring eco-friendly operation and manufacturing processes.