| 接口 | 3 x LAN/DMZ, 1 x WAN, 3 x LAN/DMZ, 1 x WAN, 4 x LAN/DMZ, 2 x WAN, 1x OPT 1 x SFP, 1x OPT 1 x SFP |
|---|
| USB 3.0 ports | 1 1 2 |
|---|
| Console port | RJ-45 RJ-45 DB9 |
|---|
| Rack-mountable | - - Yes |
|---|
| Fanless | Yes Yes Yes |
|---|
| SPI firewall throughput (Mbps)*2 | 1,000 1,000 2,000 |
|---|
| VPN throughput (Mbps)*3 | 300 300 500 600 600 1,200 |
|---|
| Anti-malware throughput (Mbps)*4 | 380 380 630 |
|---|
| UTM throughput | 380 380 600 |
|---|
| Max. TCP concurrent sessions*5 | 300,000 300,000 600,000 |
|---|
| Max. concurrent IPsec VPN tunnels* | 6 40 40 100 |
|---|
| Recommended gateway-to-gateway | 20 20 50 |
|---|
| Concurrent SSL VPN users | 30 30 60 |
|---|
| VLAN interface | 8 8 16 |
|---|
| SPI firewall throughput (Mbps)*7 | 850 850 900 |
|---|
| 安全 | Sandboxing*8 Yes Yes Yes |
|---|
| Service | Web Filtering* 8 |
|---|
| Yes | Yes Yes |
|---|
| Application Patrol* | 8 |
|---|
| Anti-Malware* | 8 |
|---|
| Reputation Filter*8 | Yes Yes Yes |
|---|
| Geo Enforcer | Yes Yes Yes |
|---|
| SecuReporter*8 | Yes Yes Yes |
|---|
| Collaborative Detection Yes | Yes Yes & Response*8 |
|---|
| Device Insight | Yes Yes Yes |
|---|
| Security Profile Sync | Yes Yes Yes (SPS)*8 |
|---|
| SSL (HTTPS) Inspection Yes | Yes Yes 2-Factor Yes Yes Yes |
|---|
| VPN | VPN IKEv2, IPSec, SSL, IKEv2, IPSec, SSL, IKEv2, IPSec, SSL, |
|---|
| Features | L2TP/IPSec L2TP/IPSec L2TP/IPSec |
|---|
| Microsoft Azure | Yes Yes Yes |
|---|
| Amazon VPC | Yes Yes Yes |
|---|
| WLAN | Default number of 8 8 8 |
|---|
| Recommend max. | 10 10 20 AP in 1 AP Group |
|---|
| Secure WiFi | Yes Yes Yes Service*8 |
|---|
| Maximum Number | 6 6 10 of Tunnel-Mode AP |
|---|
| Connectivity Nebula Cloud | Yes Yes Yes |
|---|
| Device HA Pro | - - - |
|---|
| Link Aggregation | - - - (LAG) |
|---|
| Concurrent devices | 64 64 200 logins (max.) |
|---|
| Power input | 12V DC, 2A max. 12V DC, 2A max. 12V DC, 2.5A max. |
|---|
| 最大功耗 | 12.5 12.5 13.3 |
|---|
| Heat dissipation (BTU/hr) | 42.65 42.65 45.38 |
|---|
| Item | Dimensions (WxDxH) 216 x 147.3 x 33/ 216 x 147.3 x 33/ 272 x 187 x 36/ (mm/in.) 8.50 x 5.80 x 1.30 8.50 x 5.80 x 1.30 10.7 x 7.36 x 1.42 |
|---|
| 重量 | 0.85/1.87 0.85/1.87 1.4/3.09 (kg/lb.) |
|---|
| Packing | Dimensions (WxDxH) 284 x 190 x 100/ 284 x 190 x 100/ 427 x 247 x 73/ (mm/in.) 11.18 x 7.48 x 3.94 11.18 x 7.48 x 3.94 16.81 x 9.72 x 2.87 |
|---|
| Included accessories | • Power adapter • Power adapter • Power adapter |
|---|
| • RJ-45 cable | • RJ-45 cable • Rack mounting kit |
|---|
| • RS-232 cable | • RS-232 cable |
|---|
| Operating | Temperature 0°C to 40°C/ 0°C to 40°C/ 0°C to 40°C/ |
|---|
| environment | 32°F to 104°F 32°F to 104°F 32°F to 104°F |
|---|
| Humidity | 10% to 90% 10% to 90% 10% to 90% (non-condensing) (non-condensing) (non-condensing) |
|---|
| Storage | Temperature -30°C to 70°C/ - 30°C to 70°C/ -30°C to 70°C/ |
|---|
| MTBF (hr) | 989,810.8 989,810.8 529,688.2 |
|---|
| Acoustic noise | - - - |
|---|
| EMC | FCC Part 15 (Class B), FCC Part 15 (Class B), FCC Part 15 (Class B), |
|---|
| CE EMC (Class B), | CE EMC (Class B), CE (Class B), C-Tick (Class |
|---|
| BSMI | BSMI B), BSMI |
|---|
| Safety | LVD (EN60950-1), BSMI LVD (EN60950-1), BSMI LVD (EN60950-1), BSMI |
|---|
| System Capacity & Performance* | 1 |
|---|
| VPN throughput (Mbps)* | 3 900 1,200 1,500 1,700 2,200 2,700 |
|---|
| Max. concurrent IPsec VPN tunnels*6 | 300 500 1,000 |
|---|
| Application Patrol*8 | Yes Yes Yes |
|---|
| IPS*8 | Yes Yes Yes |
|---|
| Reputation Filter* | 8 |
|---|
| SecuReporter* | 8 |
|---|
| SSL (HTTPS) Inspection | Yes Yes Yes 2-Factor Authentication Yes Yes Yes |
|---|
| Recommend max. AP in 60 | 200 300 1 AP Group |
|---|
| Management Maximum Number of | 18 66 130 Tunnel-Mode AP |
|---|
| Maximum Number of | 72 264 520 Managed AP |
|---|
| Connectivity Nebula Cloud Managed Yes | Yes Yes |
|---|
| Link Aggregation (LAG) Yes | Yes Yes |
|---|
| Max. power consumption (watt) | 24.1 46 46 |
|---|
| • Power cord | • Rack mounting kit • Rack mounting kit • Rack mounting kit |
|---|
| Operating Temperature, | Operating Temperature Operating Temperature 41.5dBA on full FAN speed 46.2dBA on full FAN speed 46.2dBA on full FAN speed |
|---|
| CE EMC (Class A), | CE EMC (Class A), CE EMC (Class A), |
|---|
| C-Tick (Class A), | C-Tick (Class A), C-Tick (Class A), |
|---|
| conditions, and activated applications. | *6: Including Gateway-to-Gateway and Client-to-Gateway. industry standard HTTP performance test (1,460-byte HTTP packets). Testing done *8: Enable or extend feature capacity with Zyxel service license. |
|---|
| with multiple flows. | *9: ATP100 rev1 is adapting new hardware design equipped with 4 x LAN/DMZ, 1 x WAN |
|---|
| Standard compliance | 802.11 a/b/g/n/ac |
|---|
| Wireless frequency | 2.4 / 5 GHz |
|---|
| Radio | 2 |
|---|
| SSID number | 4 |
|---|
| Maximum transmit power US (FCC) 2.4 GHz | 25 dBm, 3 antennas |
|---|
| EU (ETSI) 2.4 GHz | 20 dBm(EIRP), 3 antennas |
|---|
| EU (ETSI) 5 GHz | 20 dBm(EIRP), 3 antennas |
|---|
| No. of antenna | 3 detachable antennas |
|---|
| 天線增益 | 2 dBi @2.4 GHz 3 dBi @ 5 GHz |
|---|
| Data rate | 802.11n: up to 450 Mbps 802.11ac: up to 1300 Mbps |
|---|
| Frequency Band | 2.4 GHZ USA (FCC) : 2.412 to 2.462 GHz (IEEE 802.11 b/g/n) Europe (ETSI) : 2.412 to 2.472 GHz TWN (NCC) : 2.412 to 2.462 GHz 5 GHZ USA (FCC) : 5.150 to 5.250 GHz; 5.250 to 5.350 GHz; 5.470 to 5.725 GHz; (IEEE 802.11 a/n/ac) 5.725 to 5.850 GHz Europe (ETSI) : 5.15 to 5.35 GHz; 5.470 to 5.725 GHz TWN (NCC) : 5.15 to 5.25 GHz; 5.25 to 5.35 GHz; 5.470 to 5.725 GHz; 5.725 to 5.850 GHz |
|---|
| Receive sensitivity | 2.4 GHZ 11 Mbps ≤ -87 dBm 54 Mbps ≤ -77 dBm HT20 ≤ -71 dBm HT40 ≤ -68 dBm 5 GHZ 54 Mbps ≤ -74 dBm HT40, MCS23 ≤ -68 dBm VHT40, MCS9 ≤ -62 dBm HT20, MCS23 ≤ -71 dBm VHT20, MCS8 ≤ -66 dBm VHT80, MCS9 ≤ -59 dBm |
|---|
| Security Service | • Policy criteria: source and • Streamed-based engine |
|---|
| destination IP address, user group, | • Support SSL inspection*2 |
|---|
| time | • Inspection on various protocols: |
|---|
| • Policy criteria: zone, user*2 | HTTP, FTP, SMTP, POP3, and IMAP • Inspection on various protocols: |
|---|
| modes | Intrusion Prevention System (IPS) HTTPs, FTPs, SMTPs, POP3s, and |
|---|
| • Stateful packet inspection | • Support both intrusion detection and IMAPs*2 |
|---|
| • SIP NAT traversal | prevention • Customizable signature & protection |
|---|
| • H.323 NAT traversal*2 | • Support allowlist (whitelist) to deal profile*2 |
|---|
| • ALG support for customized ports | with false positives involving known • Automatic new signature update |
|---|
| • Protocol anomaly detection and | benign activity*2 mechanism support |
|---|
| 防護等級 | • Support rate-based IPS signatures |
|---|
| • Traffic anomaly detection and | to protect networks against Application Patrol |
|---|
| • Flooding detection and protection | force attacks*2 • Identifies and control thousands of |
|---|
| • DoS/DDoS protection | • Signature-based and behavior- applications and their behaviors |
|---|
| based scanning | • Identify, categorize and control over |
|---|
| • Support exploit-based and | 3,000 apps and behaviors |
|---|
| vulnerability-based protection | • Granular control over the most |
|---|
| • Support Web attacks like XSS and | popular applications Application Patrol, firewall (ACL) SQL injection |
|---|
| • Prioritize and throttle application | Web Filtering • PSK and PKI (X.509) certificate |
|---|
| bandwidth usage | • HTTPs domain filtering support |
|---|
| • Real-time application statistics and | • SafeSearch support • IPSec NAT traversal (NAT-T) |
|---|
| reports | • Allow List websites enforcement • Dead Peer Detection (DPD) and relay |
|---|
| • Identify and control the use of DOH | • URL Block and Allow List with detection (DNS over HTTPS) keyword blocking • VPN concentrator |
|---|
| • Customizable warning messages | • Route-based VPN Tunnel Interface |
|---|
| Sandboxing | and redirect URL (VTI) |
|---|
| • Cloud-based multi-engine inspection | • Customizable Content Filtering block • VPN high availability (Failover, LB) |
|---|
| • Support HTTP/SMTP/POP3/FTP | page • GRE over IPSec*2 |
|---|
| • Wild range file type examination | • URL categories increased to 111 • NAT over IPSec |
|---|
| • Real-time threat synchronization | • CTIRU (Counter-Terrorism Internet • L2TP over IPSec |
|---|
| • SSL inspection support*2 | Referral Unit) support • SecuExtender Zero Trust VPN Client |
|---|
| Anti-Malware | • Support DNS base filtering (domain provisioning |
|---|
| • High performance query-based scan | filtering) • Support native Windows, iOS/macOS |
|---|
| engine (Express Mode) | and Android (StrongSwan) client Geo Enforcer |
|---|
| • Works with over 30 billion of known | provision*2 • Geo IP blocking |
|---|
| malicious file identifiers and still | • Support 2FA Email/SMS*2 • Geographical visibility on traffics |
|---|
| growing | • Support 2FA Google Authenticator statistics and logs |
|---|
| • Multiple file types supported | • IPv6 address support*2 SSL VPN*2 |
|---|
| • Stream-based scan engine (Stream | • Supports Windows and macOS |
|---|
| Mode) | IP Exception • Supports full tunnel mode |
|---|
| • No file size limitation | • Provides granular control for target • Supports 2-Factor authentication |
|---|
| • HTTP, FTP, SMTP, and POP3 protocol | source and destination IP |
|---|
| supported | • Supports security service scan |
|---|
| • Automatic signature update | Sandboxing), IPS, IP Reputation, and Secure WiFi |
|---|
| URL Threat Filter | • Secure Tunnel for Remote AP |
|---|
| • Both stream-based engine and cloud | Device Insight • L2 access between home office and |
|---|
| query concurrently in action | • Agentless Scanning for discovery HQ (Secured Tunnel) |
|---|
| • Works with local cache and over 30 | and classification of devicess • GRE Tunnel for Campus AP |
|---|
| billion databases and growing | • View all devices on the network, • Enforcing 2FA with Google |
|---|
| • HTTP, HTTPS, and FTP protocol | including wired, wireless, BYOD, IoT, Authenticator |
|---|
| • Visibility of network devices | • Applicable regardless of the On |
|---|
| E-mail Security*2 | (switches, wireless access points, Premises/Nebula-managed mode |
|---|
| • Transparent mail interception via | firewalls) from Zyxel or 3rd party WLAN Management*2 |
|---|
| SMTP and POP3 protocols | vendors • Supports AP Controller (APC) version 3.60 |
|---|
| • Block and Allow List support | Collaborative Detection & Response • 802.11ax Wi-Fi 6 AP and WPA3 |
|---|
| • Supports DNSBL checking | • Support Alert/Block/Quarantine support containment actions |
|---|
| IP Reputation Filter | • 802.11k/v/r support • Prevent malicious wireless clients |
|---|
| • IP-based reputation filter | • Supports auto AP FW update network access with blocking feature |
|---|
| • Supports 10 Cyber Threat Categories | • Scheduled WiFi service • Customizable warning messages and |
|---|
| • Supports external IP blacklist | • Dynamic Channel Selection (DCS) redirect URL |
|---|
| • Inbound & Outbound traffic filtering | • Client steering for 5 GHz priority and • Bypass by IP or MAC address with |
|---|
| • Block clients to access malicious | VPN • WiFi Multimedia (WMM) wireless QoS |
|---|
| domain | IPSec VPN • CAPWAP discovery protocol |
|---|
| • Effective against any IP protocol | • Key management: IKEv1 (x-auth, • Multiple SSID with VLAN |
|---|
| • Monitoring or blocking the use of | mode-config), IKEv2 (EAP, • Supports ZyMesh |
|---|
| DoH/DoT | configuration payload) • Support AP forward compatibility |
|---|
| • Botnet C&C websites blocking | • Authentication: MD5, SHA1, SHA2 (512-bit) Mobile Broadband*2 |
|---|
| • Supports External URL blacklist | • Perfect forward secrecy (DH groups) support 1, 2, 5, 14, 15-18, 20-21 |
|---|
| • WAN connection failover via 3G and | • Bandwidth limit per user*2 (Google Authenticator, SMS/Email) 4G* USB modems • Bandwidth limit per IP System Management |
|---|
| • Auto fallback when primary WAN | • Bandwidth management by • Role-based administration |
|---|
| recovers | application • Multi-lingual Web GUI (HTTPS and • Link Aggregation support*1*2 |
|---|
| IPv6 Support*2 | HTTP) |
|---|
| • Dual stack | • Command line interface (console, |
|---|
| • IPv4 tunneling (6rd and 6to4 | Management web console, SSH and telnet)*2 |
|---|
| transition tunnel) | Nebula Cloud Management*3 • SNMP v1, v2c, v3 |
|---|
| • SLAAC, static IP address | • Unlimited Registration & Central • System configuration rollback*2 |
|---|
| • DNS, DHCPv6 server/client | Management (Configuration, • Configuration auto backup*2 |
|---|
| • Static/Policy route | Monitoring, Dashboard, Location • Firmware upgrade via FTP, FTP-TLS, |
|---|
| • IPSec (IKEv2 6in6, 4in6, 6in4) | Map & Floor Plan Visual) of Nebula and web GUI*2 |
|---|
| Devices | • New firmware notify and auto |
|---|
| • Zero Touch Auto-Deployment of | upgrade |
|---|
| Hardware/Configuration from Cloud | • Dual firmware images |
|---|
| • Over-the-air Firmware Management | • Cloud CNM SecuManager*2 • Central Device and Client |
|---|
| • NAT and PAT | Logging and Monitoring Monitoring (Log and Statistics |
|---|
| • NAT Virtual Server Load Balancing | • Comprehensive local logging Information) and Reporting |
|---|
| • VLAN tagging (802.1Q) | • Syslog (to up to 4 servers) • Security Profile Sync |
|---|
| • Virtual interface (alias interface) | • Email alerts (to up to 2 servers) |
|---|
| • Policy-based routing (user-aware)*2 | Authentication • Real-time traffic monitoring |
|---|
| • Policy-based NAT (SNAT) | • Local user database • Built-in daily report |
|---|
| • GRE*2 | • Cloud user database*3 • Cloud CNM SecuReporter |
|---|
| • Dynamic routing (RIPv1/v2 and OSPF, | • External user database: Microsoft |
|---|
| Windows Active Directory, RADIUS, | *: For specific models supporting the 3G and 4G |
|---|
| BGP)*2 | dongles on the list, please refer to the Zyxel |
|---|
| • DHCP client/server/relay | LDAP product page at 3G dongle document |
|---|
| • Dynamic DNS support | • IEEE 802.1x authentication *1: Supported models ATP500/700/800 |
|---|
| • Captive portal Web authentication | *2: Only supported in On-Premise mode |
|---|
| • WAN trunk for more than 2 ports | *3: Only supported in Cloud mode |
|---|
| • Per host session limit | • XAUTH, IKEv2 with EAP VPN |
|---|
| • Guaranteed bandwidth | authentication |
|---|
| • Maximum bandwidth | • IP-MAC address binding |
|---|
| • Priority-bandwidth utilization | • SSO (Single Sign-On) support*2 • Supports 2-factor authentication Secure Tunnel for Remote AP |
|---|
| Product | Remote AP Number of Tunnel Mode AP Supported Remote AP |
|---|
| ATP | ATP100(W) 6 • WAX655E |
|---|
| ATP200 | 10 • WAX650S • WAX640S-6E |
|---|
| ATP500 | 18 • WAX630S |
|---|
| ATP700 | 66 • WAX620D-6E |
|---|
| ATP800 | 130 • WAX610D • WAX510D |
|---|
| USG FLEX | USG FLEX 100(W) 6 • WAC500 |
|---|
| USG FLEX 200 | 10 • WAC500H |
|---|
| USG FLEX 500 | 18 |
|---|
| USG FLEX 700 | 130 |
|---|
| VPN100 | 18 |
|---|
| VPN300 | 130 |
|---|
| VPN1000 | 258 |
|---|
| Models | • NWA5301-NJ • WAC5302D-Sv2 • WAC6103D-I • WAX650S |
|---|
| • NWA5121-NI | • WAC500* • WAC6503D-S • WAX630S |
|---|
| • NWA5123-AC HD* | • WAC500H* • WAC6502D-S • WAX610D |
|---|
| • NWA5123-AC | • WAC6303D-S • WAX640S-6E |
|---|
| • NWA5123-NI | • WAC6553D-E • WAX620D-6E |
|---|
| • WAC5302D-S | • WAC6552D-S • WAX655E |
|---|
| • WAX510D* | • WAC6502D-E Functions |
|---|
| Central management | Yes Yes |
|---|
| Auto provisioning | Yes Yes |
|---|
| Data forwarding | Local bridge Local bridge / Data tunnel |
|---|
| ZyMesh | Yes Yes *: Support both local bridge and data tunnel for data forwarding. |
|---|
| SFP10G-SR* | 10-Gigabit Duplex LC 850 nm 300 m/ Multi Mode Yes |
|---|
| SFP+ | 328 yd |
|---|
| SFP10G-LR* | 10-Gigabit Duplex LC 1310 nm 10 km/ Single Mode Yes |
|---|
| SFP-1000T | Gigabit RJ-45 - 100 m/ Multi Mode - 109 yd |
|---|
| SFP-LX-10-D | Gigabit Single LC 1310 nm 10 km/ Single Mode Yes 10936 yd |
|---|
| SFP-SX-D | Gigabit Single LC 850 nm 500 m/ Multi Mode Yes 601 yd |
|---|
| SFP-BX1310-10-D*1 | Gigabit Single LC 1310 nm(TX) 10 km/ Single Mode Yes 1490 nm(RX) 10936 yd |
|---|
| SFP-BX1490-10-D*1 | Gigabit Single LC 1490 nm(TX) 10 km/ Single Mode Yes 1310 nm(RX) 10936 yd *:only USG2200 Series supports 10-Gigabit SFP+ *1: SFP-BX1310-10-D & SFP-BX1490-10-D, SFP-BX1310-E & SFP-BX1550-E must be used in pairs. 21/12/22 |
|---|