| 接口 | 3 x LAN/DMZ, 1 x WAN, 3 x LAN/DMZ, 1 x WAN, 4 x LAN/DMZ, 2 x WAN, 1x OPT 1 x SFP, 1x OPT 1 x SFP |
|---|
| USB 3.0 ports | 1 1 2 |
|---|
| Console port | RJ-45 RJ-45 DB9 |
|---|
| Rack-mountable | - - Yes |
|---|
| Fanless | Yes Yes Yes |
|---|
| SPI firewall throughput (Mbps)*2 | 1,000 1,000 2,000 |
|---|
| VPN throughput (Mbps)*3 | 300 300 500 |
|---|
| IPS throughput (Mbps)* | 4 600 600 1,200 |
|---|
| Anti-malware throughput (Mbps)*4 | 380 380 630 |
|---|
| UTM throughput | 380 380 600 |
|---|
| Max. TCP concurrent sessions*5 | 300,000 300,000 600,000 |
|---|
| Max. concurrent IPsec VPN tunnels* | 6 50 50 100 |
|---|
| Recommended gateway-to-gateway | 20 20 50 |
|---|
| VLAN interface | 8 8 16 |
|---|
| SPI firewall throughput (Mbps)*7 | 850 850 900 |
|---|
| 安全 | Sandboxing*8 Yes Yes Yes |
|---|
| Service | Web Filtering*8 Yes Yes Yes |
|---|
| Application Patrol*8 | Yes Yes Yes |
|---|
| Anti-Malware*8 | Yes Yes Yes IPS* 8 |
|---|
| Yes | Yes Yes |
|---|
| Reputation Filter* | 8 |
|---|
| Geo Enforcer | Yes Yes Yes |
|---|
| SecuReporter* | 8 |
|---|
| Collaborative | Yes Yes Yes Detection & Response*8 |
|---|
| Device Insight | Yes Yes Yes |
|---|
| Security Profile Sync*8 | Yes Yes Yes |
|---|
| SSL (HTTPS) Inspection Yes | Yes Yes 2-Factor Yes Yes Yes |
|---|
| VPN Features | VPN IKEv2, IPSec, L2TP/IPSec IKEv2, IPSec, L2TP/IPSec IKEv2, IPSec, L2TP/IPSec |
|---|
| Microsoft Azure | Yes Yes Yes |
|---|
| Amazon VPC | Yes Yes Yes |
|---|
| WLAN | Default number of 8 8 8 |
|---|
| Management | managed AP |
|---|
| Recommend max. AP in 10 | 10 20 1 AP Group |
|---|
| Secure WiFi Service*8 | Yes Yes Yes |
|---|
| Maximum Number of | 6 6 10 Tunnel-Mode AP |
|---|
| Management & Nebula Cloud Mode | Yes Yes Yes |
|---|
| Connectivity Nebula Cloud | Yes Yes Yes Monitoring Mode |
|---|
| Device HA Pro | - - - |
|---|
| Link Aggregation (LAG) - | - - |
|---|
| Concurrent devices | 64 64 200 logins (max.) |
|---|
| Burst login rate | 64 64 200 (users/30sec) |
|---|
| Power input | 12V DC, 2A max. 12V DC, 2A max. 12V DC, 2.5A max. |
|---|
| 最大功耗 | 12.5 12.5 13.3 |
|---|
| Heat dissipation (BTU/hr) | 42.65 42.65 45.38 |
|---|
| Item | Dimensions (WxDxH) 216 x 147.3 x 33/ 216 x 147.3 x 33/ 272 x 187 x 36/ (mm/in.) 8.50 x 5.80 x 1.30 8.50 x 5.80 x 1.30 10.7 x 7.36 x 1.42 |
|---|
| Weight (kg/lb.) | 0.85/1.87 0.85/1.87 1.4/3.09 |
|---|
| Packing | Dimensions (WxDxH) 284 x 190 x 100/ 284 x 190 x 100/ 427 x 247 x 73/ (mm/in.) 11.18 x 7.48 x 3.94 11.18 x 7.48 x 3.94 16.81 x 9.72 x 2.87 |
|---|
| Included accessories | • Power adapter • Power adapter • Power adapter |
|---|
| • RJ-45 cable | • RJ-45 cable • Rack mounting kit |
|---|
| • RS-232 cable | • RS-232 cable |
|---|
| Operating | Temperature 0°C to 40°C/ 0°C to 40°C/ 0°C to 40°C/ |
|---|
| environment | 32°F to 104°F 32°F to 104°F 32°F to 104°F |
|---|
| Humidity | 10% to 90% 10% to 90% 10% to 90% (non-condensing) (non-condensing) (non-condensing) |
|---|
| Storage | Temperature -30°C to 70°C/ - 30°C to 70°C/ -30°C to 70°C/ |
|---|
| MTBF (hr) | 989,811(at 25°C) and 989,811(at 25°C) and 832,102(at 25°C) and 576,237(at 40°C) 576,237(at 40°C) 536,472(at 40°C) |
|---|
| Acoustic noise | - - - |
|---|
| EMC | FCC Part 15 (Class B), FCC Part 15 (Class B), FCC Part 15 (Class B), |
|---|
| CE EMC (Class B), | CE EMC (Class B), CE (Class B), C-Tick |
|---|
| BSMI | BSMI (Class B), BSMI |
|---|
| Safety | LVD (EN60950-1), BSMI LVD (EN60950-1), BSMI LVD (EN60950-1), BSMI |
|---|
| System Capacity & Performance* | 1 |
|---|
| VPN throughput (Mbps)* | 3 900 1,200 1,500 |
|---|
| Max. concurrent IPsec VPN tunnels*6 | 300 500 1,000 |
|---|
| Application Patrol* | 8 |
|---|
| Reputation Filter*8 | Yes Yes Yes |
|---|
| SecuReporter*8 | Yes Yes Yes |
|---|
| Security Profile Sync* | 8 |
|---|
| Recommend max. AP in 60 | 200 300 1 AP Group |
|---|
| Link Aggregation (LAG) Yes | Yes Yes |
|---|
| Connt devices logins | 300 1500 1500 (max.) |
|---|
| Max. power consumption (watt) | 24.1 46 46 |
|---|
| • Power cord | • Rack mounting kit • Rack mounting kit • Rack mounting kit |
|---|
| Operating Temperature, | Operating Temperature Operating Temperature 41.5dBA on full FAN speed 46.2dBA on full FAN speed 46.2dBA on full FAN speed |
|---|
| CE EMC (Class A), | CE EMC (Class A), CE EMC (Class A), |
|---|
| C-Tick (Class A), BSMI | C-Tick (Class A), BSMI C-Tick (Class A), BSMI |
|---|
| conditions, and activated applications. | *6: Including Gateway-to-Gateway and Client-to-Gateway. standard HTTP performance test (1,460-byte HTTP packets). Testing done with *9: ATP100 rev1 is adapting new hardware design equipped with |
|---|
| multiple flows. | 4 x LAN/DMZ, 1 x WAN |
|---|
| Standard compliance | 802.11 a/b/g/n/ac |
|---|
| Wireless frequency | 2.4 / 5 GHz |
|---|
| Radio | 2 |
|---|
| SSID number | 4 |
|---|
| Maximum transmit power US (FCC) 2.4 GHz | 25 dBm, 3 antennas |
|---|
| EU (ETSI) 2.4 GHz | 20 dBm(EIRP), 3 antennas |
|---|
| EU (ETSI) 5 GHz | 20 dBm(EIRP), 3 antennas |
|---|
| No. of antenna | 3 detachable antennas |
|---|
| 天線增益 | 2 dBi @2.4 GHz 3 dBi @ 5 GHz |
|---|
| Data rate | 2.4 GHz: up to 300 Mbps 5 GHz: up to 866 Mbps |
|---|
| Frequency Band | 2.4 GHZ USA (FCC) : 2.412 to 2.462 GHz (IEEE 802.11 b/g/n) Europe (ETSI) : 2.412 to 2.472 GHz TWN (NCC) : 2.412 to 2.462 GHz 5 GHZ USA (FCC) : 5.150 to 5.250 GHz; 5.250 to 5.350 GHz; 5.470 to 5.725 GHz; (IEEE 802.11 a/n/ac) 5.725 to 5.850 GHz Europe (ETSI) : 5.15 to 5.35 GHz; 5.470 to 5.725 GHz TWN (NCC) : 5.15 to 5.25 GHz; 5.25 to 5.35 GHz; 5.470 to 5.725 GHz; 5.725 to 5.850 GHz |
|---|
| Receive sensitivity | 2.4 GHZ 11 Mbps ≤ -87 dBm 54 Mbps ≤ -77 dBm HT20 ≤ -71 dBm HT40 ≤ -68 dBm 5 GHZ 54 Mbps ≤ -74 dBm HT40, MCS23 ≤ -68 dBm VHT40, MCS9 ≤ -62 dBm HT20, MCS23 ≤ -71 dBm VHT20, MCS8 ≤ -66 dBm VHT80, MCS9 ≤ -59 dBm |
|---|
| Security Service | • Policy criteria: source and • Streamed-based engine |
|---|
| destination IP address, user group, | • Support SSL inspection*2 |
|---|
| time | • Inspection on various protocols: |
|---|
| • Policy criteria: zone, user*2 | HTTP, FTP, SMTP, POP3, and IMAP modes • Inspection on various protocols: |
|---|
| • Stateful packet inspection | Intrusion Prevention System (IPS) HTTPs, FTPs, SMTPs, POP3s, and |
|---|
| • SIP NAT traversal | • Support both intrusion detection and IMAPs*2 |
|---|
| • H.323 NAT traversal*2 | prevention • Customizable signature & protection |
|---|
| • ALG support for customized ports | • Support allowlist (whitelist) to deal profile*2 |
|---|
| • Protocol anomaly detection and | with false positives involving known • Automatic new signature update |
|---|
| 防護等級 | benign activity*2 mechanism support |
|---|
| • Traffic anomaly detection and | • Support rate-based IPS signatures |
|---|
| • Flooding detection and protection | application-based DoS and brute • Smart single-pass scanning engine |
|---|
| • DoS/DDoS protection | force attacks*2 • Identifies and control thousands of |
|---|
| • Signature-based and behavior- | applications and their behaviors |
|---|
| based scanning | • Identify, categorize and control over |
|---|
| • Support exploit-based and | 3,000 apps and behaviors |
|---|
| vulnerability-based protection | • Granular control over the most Application Patrol, firewall (ACL) |
|---|
| • Support Web attacks like XSS and | popular applications SQL injection |
|---|
| • Prioritize and throttle application | Web Filtering • Perfect forward secrecy (DH groups) |
|---|
| bandwidth usage | • HTTPs domain filtering support 1, 2, 5, 14, 15-18, 20-21 |
|---|
| • Real-time application statistics and | • SafeSearch support: Google, • PSK and PKI (X.509) certificate |
|---|
| reports | YouTube, and Microsoft Bing*2 support |
|---|
| • Identify and control the use of DOH | • Allow List websites enforcement • IPSec NAT traversal (NAT-T) (DNS over HTTPS) • URL Block and Allow List with • Dead Peer Detection (DPD) and relay |
|---|
| keyword blocking | detection |
|---|
| Sandboxing | • Customizable warning messages • VPN concentrator |
|---|
| • Cloud-based multi-engine inspection | and redirect URL • Route-based VPN Tunnel Interface |
|---|
| • Support HTTP/SMTP/POP3/FTP | • Customizable Content Filtering block (VTI) |
|---|
| • Wild range file type examination | page • VPN high availability (Failover, LB) |
|---|
| • Real-time threat synchronization | • URL categories increased to 111 • GRE over IPSec*2 |
|---|
| • SSL inspection support*2 | • CTIRU (Counter-Terrorism Internet • NAT over IPSec |
|---|
| Anti-Malware | Referral Unit) support • L2TP over IPSec |
|---|
| • High performance query-based scan | • Support DNS base filtering (domain • SecuExtender Zero Trust VPN Client |
|---|
| engine (Express Mode) | filtering) provisioning |
|---|
| • Works with over 30 billion of known | • Support native Windows, iOS/macOS Geo Enforcer |
|---|
| malicious file identifiers and still | and Android (StrongSwan) client • Geo IP blocking |
|---|
| growing | provision*2 • Geographical visibility on traffics |
|---|
| • Multiple file types supported | • Support 2FA Email/SMS*2 statistics and logs |
|---|
| • Stream-based scan engine (Stream | • Support 2FA Google Authenticator • IPv6 address support*2 Mode) |
|---|
| • No file size limitation | IP Exception Networking |
|---|
| • HTTP, FTP, SMTP, and POP3 protocol | • Provides granular control for target |
|---|
| supported | source and destination IP Secure WiFi |
|---|
| • Automatic signature update | bypass for Anti-malware (including • L2 access between home office and |
|---|
| Sandboxing), IPS, IP Reputation, and | HQ (Secured Tunnel) |
|---|
| Hybrid Mode Malware Scanning | URL Threat Filter • GRE Tunnel for Campus AP |
|---|
| • Both stream-based engine and cloud | • Enforcing 2FA with Google |
|---|
| query concurrently in action | Device Insight Authenticator |
|---|
| • Works with local cache and over 30 | • Agentless Scanning for discovery • WPA2 Enterprise (802.1x) supported |
|---|
| billion databases and growing | and classification of devicess • Wireless Storm Control |
|---|
| • HTTP, HTTPS, and FTP protocol | • View all devices on the network, • Applicable regardless of the On |
|---|
| E-mail Security*2 | • Supports AP Controller (APC) version • Visibility of network devices |
|---|
| • Transparent mail interception via | 4.00 (switches, wireless access points, |
|---|
| SMTP and POP3 protocols | • 802.11ax Wi-Fi 6 AP and WPA3 firewalls) from Zyxel or 3rd party |
|---|
| • Spam, Phishing, mail detection | support vendors |
|---|
| • Block and Allow List support | • 802.11k/v/r support |
|---|
| • Supports DNSBL checking | Collaborative Detection & Response • Supports auto AP FW update |
|---|
| • Support Alert/Block/Quarantine | • Scheduled WiFi service |
|---|
| IP Reputation Filter | containment actions • Dynamic Channel Selection (DCS) |
|---|
| • IP-based reputation filter | • Prevent malicious wireless clients • Client steering for 5 GHz priority and |
|---|
| • Supports 10 Cyber Threat Categories | network access with blocking feature sticky client prevention |
|---|
| • Supports external IP blacklist | • Customizable warning messages and • Auto healing |
|---|
| • Inbound & Outbound traffic filtering | redirect URL • Customizable captive portal page |
|---|
| DNS Threat Filter | exempt list • CAPWAP discovery protocol |
|---|
| • Block clients to access malicious | • Multiple SSID with VLAN |
|---|
| domain | VPN • Supports ZyMesh |
|---|
| • Effective against any IP protocol | IPSec VPN • Support AP forward compatibility |
|---|
| • Monitoring or blocking the use of | • Key management: IKEv1 (x-auth, • Rogue AP Detection |
|---|
| DoH/DoT | mode-config), IKEv2 (EAP, Multi-WAN |
|---|
| URL Threat Filter | configuration payload) • Multi-WAN support on ATP200 and |
|---|
| • Botnet C&C websites blocking | • Encryption: DES, 3DES, AES (256-bit) above |
|---|
| • Malicious URL blocking | • Authentication: MD5, SHA1, SHA2 • Dual-WAN support on ATP100/100W |
|---|
| • Supports External URL blacklist | (512-bit) (with OPT port) |
|---|
| Mobile Broadband*2 | • Bandwidth management by • XAUTH, IKEv2 with EAP VPN |
|---|
| • WAN connection failover via 3G and | application authentication 4G* USB modems • Link Aggregation support*1*2 • IP-MAC address binding |
|---|
| • Auto fallback when primary WAN | • SSO (Single Sign-On) support*2 |
|---|
| recovers | Management • Supports 2-factor authentication (Google Authenticator, SMS/Email) |
|---|
| IPv6 Support*2 | Nebula Cloud Mode |
|---|
| • Dual stack | • Unlimited Registration & Central System Management |
|---|
| • IPv4 tunneling (6rd and 6to4 | Management (Configuration, • Role-based administration |
|---|
| transition tunnel) | Monitoring, Dashboard, Location • Multi-lingual Web GUI (HTTPS and |
|---|
| • SLAAC, static IP address | Map & Floor Plan Visual) of Nebula HTTP) |
|---|
| • DNS, DHCPv6 server/client | Devices • Command line interface (console, |
|---|
| • Static/Policy route | • Zero Touch Auto-Deployment of web console, SSH and telnet)*2 |
|---|
| • IPSec (IKEv2 6in6, 4in6, 6in4) | Hardware/Configuration from Cloud • SNMP v1, v2c, v3 |
|---|
| • Over-the-air Firmware Management | • System configuration rollback*2 |
|---|
| • Central Device and Client | • Configuration auto backup*2 |
|---|
| Monitoring (Log and Statistics | • Firmware upgrade via FTP, FTP-TLS, |
|---|
| Information) and Reporting | and web GUI*2 |
|---|
| • Security Profile Sync | • New firmware notify and auto |
|---|
| Nebula Cloud Monitoring Mode | upgrade |
|---|
| • Monitor device on/off status | • Dual firmware images |
|---|
| • Firmware upgrade operation | • Cloud CNM SecuManager*2 |
|---|
| • Policy-based routing (user-aware)*2 | • Manage firewall licenses Logging and Monitoring |
|---|
| • Policy-based NAT (SNAT) | • Access remote GUI (requires Nebula • Comprehensive local logging |
|---|
| • GRE*2 | Pro Pack) • Syslog (to up to 4 servers) |
|---|
| • Dynamic routing (RIPv1/v2 and OSPF, | • Backup and restore firewall • Email alerts (to up to 2 servers) |
|---|
| BGP)*2 | configurations (requires Nebula Pro • Real-time traffic monitoring |
|---|
| • DHCP client/server/relay | Pack) • Built-in daily report |
|---|
| • Dynamic DNS support | Authentication • Cloud CNM SecuReporter |
|---|
| • WAN trunk for more than 2 ports | • Local user database *: For specific models supporting the 3G and 4G |
|---|
| • Per host session limit | • Cloud user database*3 dongles on the list, please refer to the Zyxel |
|---|
| • Guaranteed bandwidth | • External user database: Microsoft product page at 3G dongle document |
|---|
| • Maximum bandwidth | Windows Active Directory, RADIUS, *1: Supported models ATP500/700/800 *2: Only supported in On Premises Mode |
|---|
| • Priority-bandwidth utilization | LDAP *3: Only supported in Nebula Cloud Mode |
|---|
| • Bandwidth limit per user*2 | • IEEE 802.1x authentication |
|---|
| • Bandwidth limit per IP | • Captive portal Web authentication Secure Tunnel for Remote AP |
|---|
| Product | Remote AP Number of Tunnel Mode AP Supported Remote AP |
|---|
| ATP | ATP100(W) 6 • WAX655E |
|---|
| ATP200 | 10 • WAX650S • WAX640S-6E |
|---|
| ATP500 | 18 • WAX630S |
|---|
| ATP700 | 66 • WAX620D-6E |
|---|
| ATP800 | 130 • WAX610D • WAX510D |
|---|
| USG FLEX | USG FLEX 100(AX/W) 6 • WAC500 |
|---|
| USG FLEX 200 | 10 • WAC500H |
|---|
| USG FLEX 500 | 18 |
|---|
| USG FLEX 700 | 130 |
|---|
| VPN | VPN50 10 |
|---|
| VPN100 | 18 |
|---|
| VPN300 | 130 |
|---|
| VPN1000 | 258 |
|---|
| Models | • NWA5123-AC • WAX510D* • WAC6103D-I • WAX650S |
|---|
| • NWA5123-AC HD*1 | • WAC500* • WAC6503D-S • WAX630S |
|---|
| • WAC5302D-S | • WAC500H* • WAC6502D-S • WAX610D |
|---|
| • WAC5302D-Sv2 | • WAX300H • WAC6303D-S • WAX640S-6E |
|---|
| • WAC6553D-E | • WAX620D-6E |
|---|
| • WAC6552D-S | • WAX655E • WAC6502D-E Functions |
|---|
| Central management | Yes Yes |
|---|
| Auto provisioning | Yes Yes |
|---|
| Data forwarding | Local bridge Local bridge / Data tunnel |
|---|
| ZyMesh | Yes Yes *: Support both local bridge and data tunnel for data forwarding. |
|---|
| SFP10G-SR* | 10-Gigabit Duplex LC 850 nm 300 m/ Multi Mode Yes |
|---|
| SFP+ | 328 yd |
|---|
| SFP10G-LR* | 10-Gigabit Duplex LC 1310 nm 10 km/ Single Mode Yes |
|---|
| SFP-1000T | Gigabit RJ-45 - 100 m/ Multi Mode - 109 yd |
|---|
| SFP-LX-10-D | Gigabit Single LC 1310 nm 10 km/ Single Mode Yes 10936 yd |
|---|
| SFP-SX-D | Gigabit Single LC 850 nm 500 m/ Multi Mode Yes 601 yd |
|---|
| SFP-BX1310-10-D*1 | Gigabit Single LC 1310 nm(TX) 10 km/ Single Mode Yes 1490 nm(RX) 10936 yd |
|---|
| SFP-BX1490-10-D*1 | Gigabit Single LC 1490 nm(TX) 10 km/ Single Mode Yes 1310 nm(RX) 10936 yd *:only USG2200 Series supports 10-Gigabit SFP+ *1: SFP-BX1310-10-D & SFP-BX1490-10-D, SFP-BX1310-E & SFP-BX1550-E must be used in pairs. 18/12/24 |
|---|