Firebox |
M470 |
M570 |
M670 |
Firewall |
19.6 Gbps |
26.6 Gbps |
34 Gbps |
Firewall (IMIX) |
5.6 Gbps |
7.6 Gbps |
11.2 Gbps |
VPN (UDP 1518) |
5.2 Gbps |
5.8 Gbps |
7.6 Gbps |
VPN (IMIX) |
1.8 Gbps |
2.0 Gbps |
2.6 Gbps |
HTTPS (IPS enabled) |
2.0 Gbps |
3.4 Gbps |
4.0 Gbps |
Antivirus |
3.5 Gbps |
5.4 Gbps |
6.2 Gbps |
IPS (fast/full scan) |
5.7/3.0 Gbps |
8.0/4.8 Gbps |
10.4/5.6 Gbps |
UTM (fast/ full scan) |
3.1/2.1 Gbps |
4.4/3.5 Gbps |
5.4/4.2 Gbps |
Interfaces 10/100/1000* |
8 (optional modules available) |
8 (optional modules available) |
8 (optional modules available) |
I/O interfaces |
1 SRL/2 USB |
1 SRL/2 USB |
1 SRL/2 USB |
Concurrent connections |
3,800,000 |
8,300,000 |
8,500,000 |
Concurrent connections (proxy) |
310,000 |
710,000 |
920,000 |
New connections per second |
82,000 |
115,000 |
140,000 |
VLANs |
300 |
500 |
750 |
WSM licenses (incl) |
4 |
4 |
4 |
TDR Host Sensors included |
250 |
250 |
250 |
Authenticated users limit |
Unrestricted |
Unrestricted |
Unrestricted |
VPN TUNNELS |
|
|
|
Branch Office VPN |
250 |
500 |
750 |
Mobile VPN |
250 |
500 |
750 |
Firewall |
Stateful packet inspection, deep packet inspection, proxy firewall |
Application proxies |
HTTP, HTTPS, FTP, DNS, TCP/UDP, POP3, SMTP, IMAP, and Explicit Proxy |
Threat protection |
DoS attacks, fragmented & malformed packets, blended threats & more |
VoIP |
H.323, SIP, call setup and session security |
|
Filtering options |
Browser Safe Search, Google for Business |
|
Cloud providers |
AWS (Static/Dynamic), Azure (Static/Dynamic) |
|
Encryption |
AES 256-128 bit, 3DES, DES |
|
IPSec |
SHA-2, IKEv1/v2 , IKE pre-shared key, 3rd party cert |
|
Single sign-on |
Windows, Mac OS X, mobile operating systems, RADIUS |
Authentication |
RADIUS, LDAP, Windows Active Directory, VASCO, RSA SecurID, internal database, Duo, SMS Passcode |
Logging and notifications |
WatchGuard, Syslog, SNMP v2/v3 |
|
User interfaces |
Centralized console (WSM), Web UI, scriptable CLI |
|
Reporting |
WatchGuard Dimension includes over 100 pre-defined reports, executive summary and visibility tools |
Security |
Pending: ICSA Firewall, ICSA IPSec VPN , CC EAL4+,FIPS 140-2 |
Safety |
NRTL/C, CB |
|
|
Network |
IPv6 Ready Gold (routing) |
|
|
Hazardous substance control |
WEEE, RoHS, REACH |
|
|
Networking |
Routing |
Static, Dynamic (BGP4, OSPF, RIP v1/v2), Policy-based routing |
High Availability |
Active/passive, active/active with load balancing |
|
QoS |
8 priority queues, DiffServ, modified strict queuing |
|
IP address assignment |
Static, DHCP (server, client, relay), PPPoE, DynDNS |
|
NAT |
Static, dynamic, 1:1, IPSec traversal, policy-based, Virtual IP for server load balancing |
Link aggregation |
802.3ad dynamic, static, active/backup |
|
Other features |
Port Independence, Multi-WAN failover and load balancing, server load balancing, host header redirection |