| 接口 | 3 x LAN/DMZ, 1 x WAN, 3 x LAN/DMZ, 1 x WAN, 4 x LAN/DMZ, 2 x WAN, 1x OPT 1 x SFP, 1x OPT 1 x SFP |
|---|
| USB 3.0 ports | 1 1 2 |
|---|
| Console port | RJ-45 RJ-45 DB9 |
|---|
| Rack-mountable | - - Yes |
|---|
| Fanless | Yes Yes Yes |
|---|
| SPI firewall throughput (Mbps)*2 | 1,000 1,000 2,000 |
|---|
| VPN throughput (Mbps)*3 | 300 300 500 600 600 1,200 |
|---|
| Anti-malware throughput (Mbps)*4 | 380 380 630 |
|---|
| UTM throughput | 380 380 600 |
|---|
| Max. TCP concurrent sessions*5 | 300,000 300,000 600,000 |
|---|
| Max. concurrent IPsec VPN tunnels* | 6 40 40 100 |
|---|
| Recommended gateway-to-gateway | 20 20 50 |
|---|
| Concurrent SSL VPN users | 30 30 60 |
|---|
| VLAN interface | 8 8 16 |
|---|
| SPI firewall throughput (Mbps)*7 | 850 850 900 |
|---|
| 安全 | Sandboxing*8 Yes Yes Yes |
|---|
| Service | Web Filtering* 8 |
|---|
| Yes | Yes Yes |
|---|
| Application Patrol* | 8 |
|---|
| Anti-Malware* | 8 |
|---|
| Reputation Filter*8 | Yes Yes Yes |
|---|
| Geo Enforcer | Yes Yes Yes |
|---|
| SecuReporter | Yes Yes Yes Premium*8 |
|---|
| Collaborative Detection Yes | Yes Yes & Response*8 |
|---|
| Device Insight | Yes Yes Yes |
|---|
| Security Profile Sync | Yes Yes Yes (SPS)*8 |
|---|
| SSL (HTTPS) Inspection Yes | Yes Yes 2-Factor Yes Yes Yes |
|---|
| VPN | VPN IKEv2, IPSec, SSL, IKEv2, IPSec, SSL, IKEv2, IPSec, SSL, |
|---|
| Features | L2TP/IPSec L2TP/IPSec L2TP/IPSec |
|---|
| Microsoft Azure | Yes Yes Yes |
|---|
| Amazon VPC | Yes Yes Yes |
|---|
| WLAN | Default number of 8 8 8 |
|---|
| Recommend max. | 10 10 20 AP in 1 AP Group |
|---|
| Secure WiFi | Yes Yes Yes Service*8 |
|---|
| Maximum Number | 6 6 10 of Tunnel-Mode AP |
|---|
| Connectivity Nebula Cloud | Yes Yes Yes |
|---|
| Device HA Pro | - - - |
|---|
| Link Aggregation | - - - (LAG) |
|---|
| Concurrent devices | 64 64 200 logins (max.) |
|---|
| Power input | 12V DC, 2A max. 12V DC, 2A max. 12V DC, 2.5A max. |
|---|
| 最大功耗 | 12.5 12.5 13.3 |
|---|
| Heat dissipation (BTU/hr) | 42.65 42.65 45.38 |
|---|
| Item | Dimensions (WxDxH) 216 x 147.3 x 33/ 216 x 147.3 x 33/ 272 x 187 x 36/ (mm/in.) 8.50 x 5.80 x 1.30 8.50 x 5.80 x 1.30 10.7 x 7.36 x 1.42 |
|---|
| 重量 | 0.85/1.87 0.85/1.87 1.4/3.09 (kg/lb.) |
|---|
| Packing | Dimensions (WxDxH) 284 x 190 x 100/ 284 x 190 x 100/ 427 x 247 x 73/ (mm/in.) 11.18 x 7.48 x 3.94 11.18 x 7.48 x 3.94 16.81 x 9.72 x 2.87 |
|---|
| Included accessories | • Power adapter • Power adapter • Power adapter |
|---|
| • RJ-45 cable | • RJ-45 cable • Rack mounting kit |
|---|
| • RS-232 cable | • RS-232 cable |
|---|
| Operating | Temperature 0°C to 40°C/ 0°C to 40°C/ 0°C to 40°C/ |
|---|
| environment | 32°F to 104°F 32°F to 104°F 32°F to 104°F |
|---|
| Humidity | 10% to 90% 10% to 90% 10% to 90% (non-condensing) (non-condensing) (non-condensing) |
|---|
| Storage | Temperature -30°C to 70°C/ - 30°C to 70°C/ -30°C to 70°C/ |
|---|
| MTBF (hr) | 989,810.8 989,810.8 529,688.2 |
|---|
| Acoustic noise | - - - |
|---|
| EMC | FCC Part 15 (Class B), FCC Part 15 (Class B), FCC Part 15 (Class B), |
|---|
| CE EMC (Class B), | CE EMC (Class B), CE (Class B), C-Tick (Class |
|---|
| BSMI | BSMI B), BSMI |
|---|
| Safety | LVD (EN60950-1), BSMI LVD (EN60950-1), BSMI LVD (EN60950-1), BSMI |
|---|
| System Capacity & Performance* | 1 |
|---|
| VPN throughput (Mbps)* | 3 900 1,200 1,500 1,700 2,200 2,700 |
|---|
| Max. concurrent IPsec VPN tunnels*6 | 300 1,000 1,000 |
|---|
| Application Patrol*8 | Yes Yes Yes |
|---|
| IPS*8 | Yes Yes Yes |
|---|
| Reputation Filter* | 8 |
|---|
| SSL (HTTPS) Inspection | Yes Yes Yes 2-Factor Authentication Yes Yes Yes |
|---|
| Recommend max. AP in 60 | 200 300 1 AP Group |
|---|
| Management Maximum Number of | 18 66 130 Tunnel-Mode AP |
|---|
| Maximum Number of | 72 264 520 Managed AP |
|---|
| Connectivity Nebula Cloud Managed Yes | Yes Yes |
|---|
| Link Aggregation (LAG) Yes | Yes Yes |
|---|
| Max. power consumption (watt) | 24.1 46 46 |
|---|
| • Power cord | • Rack mounting kit • Rack mounting kit • Rack mounting kit |
|---|
| Operating Temperature, | Operating Temperature Operating Temperature 41.5dBA on full FAN speed 46.2dBA on full FAN speed 46.2dBA on full FAN speed |
|---|
| CE EMC (Class A), | CE EMC (Class A), CE EMC (Class A), |
|---|
| C-Tick (Class A), | C-Tick (Class A), C-Tick (Class A), |
|---|
| conditions, and activated applications. | *6: Including Gateway-to-Gateway and Client-to-Gateway. industry standard HTTP performance test (1,460-byte HTTP packets). Testing done *8: Enable or extend feature capacity with Zyxel service license. with multiple flows. |
|---|
| Standard compliance | 802.11 a/b/g/n/ac |
|---|
| Wireless frequency | 2.4 / 5 GHz |
|---|
| Radio | 2 |
|---|
| SSID number | 4 |
|---|
| Maximum transmit power US (FCC) 2.4 GHz | 25 dBm, 3 antennas |
|---|
| EU (ETSI) 2.4 GHz | 20 dBm(EIRP), 3 antennas |
|---|
| EU (ETSI) 5 GHz | 20 dBm(EIRP), 3 antennas |
|---|
| No. of antenna | 3 detachable antennas |
|---|
| 天線增益 | 2 dBi @2.4 GHz 3 dBi @ 5 GHz |
|---|
| Data rate | 802.11n: up to 450 Mbps 802.11ac: up to 1300 Mbps |
|---|
| Frequency Band | 2.4 GHZ USA (FCC) : 2.412 to 2.462 GHz (IEEE 802.11 b/g/n) Europe (ETSI) : 2.412 to 2.472 GHz TWN (NCC) : 2.412 to 2.462 GHz 5 GHZ USA (FCC) : 5.150 to 5.250 GHz; 5.250 to 5.350 GHz; 5.470 to 5.725 GHz; (IEEE 802.11 a/n/ac) 5.725 to 5.850 GHz Europe (ETSI) : 5.15 to 5.35 GHz; 5.470 to 5.725 GHz TWN (NCC) : 5.15 to 5.25 GHz; 5.25 to 5.35 GHz; 5.470 to 5.725 GHz; 5.725 to 5.850 GHz |
|---|
| Receive sensitivity | 2.4 GHZ 11 Mbps ≤ -87 dBm 54 Mbps ≤ -77 dBm HT20 ≤ -71 dBm HT40 ≤ -68 dBm 5 GHZ 54 Mbps ≤ -74 dBm HT40, MCS23 ≤ -68 dBm VHT40, MCS9 ≤ -62 dBm HT20, MCS23 ≤ -71 dBm VHT20, MCS8 ≤ -66 dBm VHT80, MCS9 ≤ -59 dBm |
|---|
| Security Service | • Policy criteria: source and • Streamed-based engine |
|---|
| destination IP address, user group, | • Support SSL inspection*2 |
|---|
| time | • Inspection on various protocols: |
|---|
| • Policy criteria: zone, user*2 | HTTP, FTP, SMTP, POP3, and IMAP • Inspection on various protocols: |
|---|
| modes | Intrusion Prevention System (IPS) HTTPs, FTPs, SMTPs, POP3s, and |
|---|
| • Stateful packet inspection | • Support both intrusion detection and IMAPs*2 |
|---|
| • SIP NAT traversal | prevention • Customizable signature & protection |
|---|
| • H.323 NAT traversal*2 | • Support allowlist (whitelist) to deal profile*2 |
|---|
| • ALG support for customized ports | with false positives involving known • Automatic new signature update |
|---|
| • Protocol anomaly detection and | benign activity*2 mechanism support |
|---|
| 防護等級 | • Support rate-based IPS signatures |
|---|
| • Traffic anomaly detection and | to protect networks against Application Patrol |
|---|
| • Flooding detection and protection | force attacks*2 • Identifies and control thousands of |
|---|
| • DoS/DDoS protection | • Signature-based and behavior- applications and their behaviors |
|---|
| based scanning | • Identify, categorize and control over |
|---|
| • Support exploit-based and | 3,000 apps and behaviors |
|---|
| vulnerability-based protection | • Granular control over the most |
|---|
| • Support Web attacks like XSS and | popular applications Application Patrol, firewall (ACL) SQL injection |
|---|
| • Prioritize and throttle application | Web Filtering • Authentication: MD5, SHA1, SHA2 |
|---|
| bandwidth usage | • HTTPs domain filtering (512-bit) |
|---|
| • Real-time application statistics and | • SafeSearch support • Perfect forward secrecy (DH groups) |
|---|
| reports | • Allow List websites enforcement support 1, 2, 5, 14, 15-18, 20-21 |
|---|
| • Identify and control the use of DOH | • URL Block and Allow List with • PSK and PKI (X.509) certificate (DNS over HTTPS) keyword blocking support |
|---|
| • Customizable warning messages | • IPSec NAT traversal (NAT-T) |
|---|
| Sandboxing | and redirect URL • Dead Peer Detection (DPD) and relay |
|---|
| • Cloud-based multi-engine inspection | • Customizable Content Filtering block detection |
|---|
| • Support HTTP/SMTP/POP3/FTP | page • VPN concentrator |
|---|
| • Wild range file type examination | • URL categories increased to 111 • Route-based VPN Tunnel Interface |
|---|
| • Real-time threat synchronization | • CTIRU (Counter-Terrorism Internet (VTI) |
|---|
| • SSL inspection support*2 | Referral Unit) support • VPN high availability (Failover, LB) |
|---|
| Anti-Malware | • Support DNS base filtering (domain • GRE over IPSec*2 |
|---|
| • High performance query-based scan | filtering) • NAT over IPSec |
|---|
| engine (Express Mode) | • L2TP over IPSec Geo Enforcer |
|---|
| • Works with over 30 billion of known | • SecuExtender Zero Trust VPN Client • Geo IP blocking |
|---|
| malicious file identifiers and still | provisioning • Geographical visibility on traffics |
|---|
| growing | • Support native Windows, iOS/macOS statistics and logs |
|---|
| • Multiple file types supported | and Android (StrongSwan) client • IPv6 address support*2 |
|---|
| • Stream-based scan engine (Stream | provision*2 • GRE Tunnel for Campus AP |
|---|
| Mode) | • Support 2FA Email/SMS*2 |
|---|
| • HTTP, FTP, SMTP, and POP3 protocol | IP Exception SSL VPN*2 |
|---|
| supported | • Provides granular control for target • Supports Windows and macOS |
|---|
| • Automatic signature update | • Supports security service scan • Supports 2-Factor authentication bypass for Anti-malware (including Sandboxing), IPS, IP Reputation, and |
|---|
| URL Threat Filter | Networking query concurrently in action |
|---|
| • Works with local cache and over 30 | Device Insight*2 Secure WiFi |
|---|
| billion databases and growing | • Agentless Scanning for discovery • Secure Tunnel for Remote AP |
|---|
| • HTTP, HTTPS, and FTP protocol | and classification of devicess • L2 access between home office and |
|---|
| wired, wireless, BYOD, IoT, and | • Enforcing 2FA with Google |
|---|
| E-mail Security*2 | Authenticator SecuExtender (remote endpoint) |
|---|
| • Transparent mail interception via | • WPA2 Enterprise (802.1x) supported • Extended view of the inventory on |
|---|
| SMTP and POP3 protocols | • Wireless Storm Control SecuReporter |
|---|
| • Spam, Phishing, mail detection | • Applicable regardless of the On • Visibility of network devices |
|---|
| • Block and Allow List support | Premises/Nebula-managed mode (switches, wireless access points, |
|---|
| firewalls) from Zyxel or 3rd party | WLAN Management*2 |
|---|
| IP Reputation Filter | vendors • Supports AP Controller (APC) version |
|---|
| • IP-based reputation filter | 3.60 Collaborative Detection & Response |
|---|
| • Supports 10 Cyber Threat Categories | • 802.11ax Wi-Fi 6 AP and WPA3 • Support Alert/Block/Quarantine |
|---|
| • Supports external IP blacklist | support containment actions |
|---|
| • Inbound & Outbound traffic filtering | • 802.11k/v/r support • Prevent malicious wireless clients |
|---|
| DNS Threat Filter | • Customizable warning messages and • Scheduled WiFi service |
|---|
| • Block clients to access malicious | redirect URL • Dynamic Channel Selection (DCS) |
|---|
| domain | • Bypass by IP or MAC address with • Client steering for 5 GHz priority and |
|---|
| • Effective against any IP protocol | exempt list sticky client prevention • Auto healing |
|---|
| DoH/DoT | VPN • Customizable captive portal page |
|---|
| • Botnet C&C websites blocking | • Key management: IKEv1 (x-auth, • CAPWAP discovery protocol |
|---|
| • Malicious URL blocking | mode-config), IKEv2 (EAP, • Multiple SSID with VLAN |
|---|
| • Supports External URL blacklist | configuration payload) • Supports ZyMesh |
|---|
| • Encryption: DES, 3DES, AES (256-bit) | • Support AP forward compatibility |
|---|
| • Rogue AP Detection | • Maximum bandwidth • SSO (Single Sign-On) support*2 |
|---|
| • Priority-bandwidth utilization | • Supports 2-factor authentication |
|---|
| • Bandwidth limit per user*2 | (Google Authenticator, SMS/Email) • Bandwidth limit per IP 4G* USB modems System Management • Bandwidth management by |
|---|
| • Auto fallback when primary WAN | • Role-based administration application |
|---|
| recovers | • Multi-lingual Web GUI (HTTPS and • Link Aggregation support*1*2 HTTP) • Command line interface (console, |
|---|
| • Dual stack | Management web console, SSH and telnet)*2 |
|---|
| Nebula Cloud Management*3 | • SNMP v1, v2c, v3 transition tunnel) |
|---|
| • Unlimited Registration & Central | • System configuration rollback*2 |
|---|
| Management (Configuration, | • Configuration auto backup*2 |
|---|
| Monitoring, Dashboard, Location | • Firmware upgrade via FTP, FTP-TLS, |
|---|
| Map & Floor Plan Visual) of Nebula | and web GUI*2 |
|---|
| Devices | • New firmware notify and auto |
|---|
| Connection | • Zero Touch Auto-Deployment of upgrade |
|---|
| • Routing mode | Hardware/Configuration from Cloud • Dual firmware images |
|---|
| • Bridge mode and hybrid mode*2 | • Over-the-air Firmware Management • Cloud CNM SecuManager*2 |
|---|
| • Ethernet and PPPoE | • Central Device and Client Logging and Monitoring |
|---|
| • NAT and PAT | Monitoring (Log and Statistics • Comprehensive local logging |
|---|
| • NAT Virtual Server Load Balancing | Information) and Reporting • Syslog (to up to 4 servers) |
|---|
| • VLAN tagging (802.1Q) | • Security Profile Sync • Email alerts (to up to 2 servers) |
|---|
| • Virtual interface (alias interface) | Authentication • Real-time traffic monitoring |
|---|
| • Policy-based routing (user-aware)*2 | • Local user database • Built-in daily report |
|---|
| • Policy-based NAT (SNAT) | • Cloud user database*3 • Cloud CNM SecuReporter |
|---|
| • GRE*2 | • External user database: Microsoft |
|---|
| • Dynamic routing (RIPv1/v2 and OSPF, | Windows Active Directory, RADIUS, *: For specific models supporting the 3G and 4G |
|---|
| BGP)*2 | dongles on the list, please refer to the Zyxel |
|---|
| LDAP | product page at 3G dongle document |
|---|
| • DHCP client/server/relay | • IEEE 802.1x authentication *1: Supported models ATP500/700/800 |
|---|
| • Dynamic DNS support | • Captive portal Web authentication *2: Only supported in On-Premise mode |
|---|
| • WAN trunk for more than 2 ports | *3: Only supported in Cloud mode • XAUTH, IKEv2 with EAP VPN |
|---|
| • Per host session limit | authentication |
|---|
| • Guaranteed bandwidth | • IP-MAC address binding Secure Tunnel for Remote AP |
|---|
| Product | Remote AP Number of Tunnel Mode AP Supported Remote AP |
|---|
| ATP | ATP100(W) 6 • WAX650S |
|---|
| ATP200 | 10 • WAX610D • WAX510D |
|---|
| ATP500 | 18 • WAC500 |
|---|
| ATP700 | 66 • WAC500H |
|---|
| ATP800 | 130 |
|---|
| USG FLEX | USG FLEX 100(W) 6 |
|---|
| USG FLEX 200 | 10 |
|---|
| USG FLEX 500 | 18 |
|---|
| USG FLEX 700 | 130 |
|---|
| VPN100 | 18 |
|---|
| VPN300 | 130 |
|---|
| VPN1000 | 258 |
|---|
| Models | • NWA5301-NJ • WAX510D* • WAC6103D-I • WAC6502D-E |
|---|
| • NWA5121-NI | • WAC5302D-Sv2 • WAC6503D-S • WAX650S |
|---|
| • NWA5123-AC HD* | • WAC500* • WAC6502D-S • WAX630S |
|---|
| • NWA5123-AC | • WAC500H* • WAC6303D-S • WAX610D |
|---|
| • NWA5123-NI | • WAC6553D-E |
|---|
| • WAC5302D-S | • WAC6552D-S Functions |
|---|
| Central management | Yes Yes |
|---|
| Auto provisioning | Yes Yes |
|---|
| Data forwarding | Local bridge Local bridge / Data tunnel |
|---|
| ZyMesh | Yes Yes *: Support both local bridge and data tunnel for data forwarding. |
|---|
| SFP10G-SR* | 10-Gigabit Duplex LC 850 nm 300 m/ Multi Mode Yes |
|---|
| SFP+ | 328 yd |
|---|
| SFP10G-LR* | 10-Gigabit Duplex LC 1310 nm 10 km/ Single Mode Yes |
|---|
| SFP-1000T | Gigabit RJ-45 - 100 m/ Multi Mode - 109 yd |
|---|
| SFP-LX-10-D | Gigabit Single LC 1310 nm 10 km/ Single Mode Yes 10936 yd |
|---|
| SFP-SX-D | Gigabit Single LC 850 nm 500 m/ Multi Mode Yes 601 yd |
|---|
| SFP-BX1310-10-D*1 | Gigabit Single LC 1310 nm(TX) 10 km/ Single Mode Yes 1490 nm(RX) 10936 yd |
|---|
| SFP-BX1490-10-D*1 | Gigabit Single LC 1490 nm(TX) 10 km/ Single Mode Yes 1310 nm(RX) 10936 yd *:only USG2200 Series supports 10-Gigabit SFP+ *1: SFP-BX1310-10-D & SFP-BX1490-10-D, SFP-BX1310-E & SFP-BX1550-E must be used in pairs. 20/04/22 |
|---|