Сегодня покупают
← Вернуться назад
Нужна помощь с конфигурацией?
Пришлите SKU, спецификацию или список требований. Специалист Apltech проверит совместимость компонентов и найдёт актуальные артикулы
Получить консультацию →

HPE Firewall Series: технические характеристики и документация

В архиве
HPE Firewall Series

Overview

HPE Firewall Series

 

Models

HP F1000-A-EI VPN Firewall Appliance

JG214A


Key features

  • High performance with up to 40 Gbps throughput
  • Advanced virtual firewall
  • Rich VPN functions, IPSec/GRE/L2TP
  • Comprehensive security protection
  • Carrier-grade reliability

Product overview

Built on the latest state-of-the-art multicore CPU platform and with advanced hardware acceleration, the HPE Firewall Series enables advanced scalable network protection from the network core to the network edge with firewall throughput at up to 40 Gbps. The series also features rich VPN abilities, including GRE, L2TP, and IPSec tunneling technologies, which makes it ideal for building VPN gateways. The appliances combine built-in protection against denial-of-service (DoS) attacks, hacking attacks, zonal and virtual stateful packet inspection firewalls, application bandwidth management, audio/video IP multicast routing, and email attachment filtering. The series includes all the advanced security capabilities found in the unified software platform of HPE switches and routers that deliver easy integration, simple management, and network deployment infrastructure, lowering a network's total cost of ownership.


Features and benefits

Firewall

  • High performance
    up to 40 Gbps throughput secures traffic without compromising network performance; a maximum of 4 million concurrent connections and 180,000 new connections per second enables high-volume networks to remain secure under peak traffic
  • Application Specific Packet Filter (ASPF)
    dynamically determines whether to forward or drop a packet by checking its application layer protocol information (such as FTP, HTTP, SMTP, RTSP, and other application layer protocols based on TCP/UDP) and monitoring the connection-based application layer protocol status
  • Zone-based access policies
    groups virtual LANs (VLANs) logically into zones that share common security policies; allows both unicast and multicast policy settings by zones instead of by individual VLANs
  • Virtualization
    multicore architecture enables both multiple zones and multiple separate firewall instances to be created on the same device; support for 256/512 security zones, 256 virtual firewalls, and 4,094 VLANs offers robust protection to all corners of the network; centralized deployment of a single device offering multiple virtual firewalls lowers total cost of ownership through streamlined training, simplified deployment and management, and reduced power consumption
  • Application-level gateway (ALG)
    discovers the IP address and service port information embedded in the application data using deep packet inspection in the firewall; firewall then dynamically opens appropriate connections for specific applications
  • NAT
    fully support NAT applications, including many-to-one, many-to-many, static NAT, dual translation, easy IP, and DNS mapping; supports NAT traversal with multiple protocols, and delivers NAT ALG functions such as DNS, FTP, H.323, and NBT

Virtual private network (VPN)

  • IPSec
    provides secure tunneling over an untrusted network such as the Internet or a wireless network; offers data confidentiality, authenticity, and integrity between two network endpoints
  • Layer 2 Tunneling Protocol (L2TP)
    an industry standard-based traffic encapsulation mechanism supported by many common operating systems; will tunnel thePoint-to-Point Protocol (PPP) traffic over the IP and non-IP networks; may use the IP/UDP transport mechanism in IP networks
  • Generic Routing Encapsulation (GRE)
    transports Layer 2 connectivity over a Layer 3 path in a secured way; enables the segregation of traffic from site to site
  • Manual or automatic Internet Key Exchange (IKE)
    provides both manual or automatic key exchange required for the algorithms used in encryption or authentication; auto-IKE allows automated management of the public key exchange, providing the highest levels of encryption

Management

  • Complete session logging
    provides detailed information for problem identification and
    resolution
  • Manager and operator privilege levels
    provides read-only (operator) and read/write (manager) access on CLI and Web browser management interfaces
  • Secure Web GUI
    provides a secure, easy-to-use graphical interface for configuring the module via HTTPS
  • Command-line interface (CLI)
    provides a secure, easy-to-use CLI for configuring the module via SSH or a switch console; provides direct real-time session visibility
  • SNMPv1, v2c, and v3
    facilitate centralized discovery, monitoring, and secure management of networking devices
  • Remote monitoring (RMON)
    uses standard SNMP to monitor essential network functions; supports events, alarm, history, and statistics group plus a private alarm extension group
  • FTP, TFTP, and SFTP support
    offers different mechanisms for configuration updates; FTP allows bidirectional transfers over a TCP/IP network; trivial FTP (TFTP) is a simpler method using User Datagram Protocol (UDP); Secure File Transfer Protocol (SFTP) runs over an SSH tunnel to provide additional security

Layer 3 routing

  • Static IP routing
    provides manually configured routing; includes ECMP capability
  • Routing Information Protocol (RIP)
    provides RIPv1 and RIPv2 routing
  • OSPF
    includes host-based ECMP to provide link redundancy/scalable bandwidth and NSSA
  • Border Gateway Protocol 4 (BGP-4)
    delivers an implementation of the Exterior Gateway Protocol (EGP) utilizing path vectors; uses TCP for enhanced reliability for the route discovery process; reduces bandwidth consumption by advertising only incremental updates; supports extensive policies for increased flexibility; scales to very large networks
  • Dual IP stack
    maintains separate stacks for IPv4 and IPv6 to ease the transition from an IPv4-only network to an IPv6-only network design
  • Policy routing
    allows custom filters for increased performance and security; supports ACLs, IP prefix, AS paths, community lists, and aggregate policies
  • Layer 3 IPv6 routing
    provides routing of IPv6 at media speed; supports static routes, RIPng, OSPFv3, BGP+, policy route, and PIM-SM/DM

Security

  • Defense against attacks
    provides defense against various attacks, such as DoS/DDoS, ARP spoofing, large ICMP packet, address/port scanning, Tracert, IP packets with the Record Route option, and static and dynamic blacklists; also supports binding of MAC address and IP addresses, as well as intelligent defense of worm viruses
  • Application layer content filtering
    supports mail filtering based on SMTP mail address, titles, attachments, and content; supports Web page filtering, including HTTP URL and content filtering
  • Multiple security authentication services
    support RADIUS and HWTACACS authentications, certificate-based (x.509 format) PKI/CA authentication, user identity management (different users own different rights to execute commands), and levels of user views (users of different levels have different management rights)
  • Centralized management and auditing
    provide logging, traffic statistics and analysis, events monitoring and statistics, and mail notification of alarms

Warranty and support

  • 1-year warranty
    See http://www.hpe.com/networking/warrantysummary  for warranty and support information included with your product purchase.
  • Software releases
    to find software for your product, refer to http://www.hpe.com/networking/support ; for details on the software releases available with your product purchase, refer to http://www.hpe.com/networking/warrantysummary

Configuration

 

Build To Order: BTO

 

 

HP F1000-E VPN Firewall Appliance

JD272A

  • 4 10/100/1000Base-T or SFP (Min 0 // Max 4 SFP Transceivers)
  • 2 I/O module slots

See Configuration NOTE:1, 2

 

 

HP F1000-S-EI VPN Firewall Appliance

JG213A

  • 12 10/100/1000Base-T or SFP (Min 0 // Max 12 SFP Transceivers)
  • 2 I/O module slots
  • Min 1 power supply required

See Configuration NOTE:1

 

 

HP F1000-A-EI VPN Firewall Appliance

JG214A

  • 12 10/100/1000Base-T or SFP (Min 0 // Max 12 SFP Transceivers)
  • 2 I/O module slots
  • Min 1 power supply required

See Configuration NOTE:1

 

 

Configuration Rules:

 

 

 

Note 1

The following SFP Transceivers are supported on this Switch:

 

HPE X120 1G SFP RJ45 T Transceiver

JD089B

HPE X120 1G SFP LC SX Transceiver

JD118B

HPE X120 1G SFP LC LX Transceiver

JD119B

HPE X120 1G SFP LC BX 10-U Transceiver

JD098B

HPE X125 1G SFP LC LH40 1310nm Transceiver

JD061A

HPE X120 1G SFP LC LH40 1550nm Transceiver

JD062A

HPE X125 1G SFP LC LH70 Transceiver

JD063B

HPE X120 1G SFP LC LH100 Transceiver

JD103A

HPE X170 1G SFP LC LH70 1510 Transceiver

JD115A

HPE X170 1G SFP LC LH70 1550 Transceiver

JD109A

HPE X170 1G SFP LC LH70 1570 Transceiver

JD110A

HPE X170 1G SFP LC LH70 1590 Transceiver

JD111A

HPE X170 1G SFP LC LH70 1610 Transceiver

JD112A

 

 

 

Note 2

Localization required. (See Localization Menu for list.)

 

 

 

 

Modules

 

 

JD272A, JG213A, JG214A Only System (std 0 // max 2) User Selection (min 0 // max 2) per switch enclosure

 

 

 

HP F5000 8-port GbE SFP / 4-port GbE Combo Module

JG212A

  • no transceivers

See Configuration NOTE:8

 

 

HPE FlexNetwork 6600 4GbE WAN HIM Router Module

JC163A

  • no transceivers

See Configuration NOTE:2

 

 

HPE FlexNetwork 6600 8GbE WAN HIM Router Module

JC164A

  • no transceivers

See Configuration NOTE:2

 

 

HPE FlexNetwork 6600 1-port 10GbE XFP HIM Router Module

JC168A

  • no transceivers

See Configuration NOTE:2, 7

 

 

HPE FlexNetwork 6600 4-port GbE SFP HIM Router Module

JC171A

  • no transceivers

See Configuration NOTE:2, 8

 

 

HP F1000-S/A 2-port 10GbE SFP+ Module

JG317A

  • no transceivers

See Configuration NOTE:3, 6, 8

 

 

Configuration Rules:

 

 

 

Note 2

Supported only on the JD272A.

 

 

 

 

Note 3

Supported only on the JG213A and JG214A.

 

 

 

 

Note 6

The following SFP+ Transceivers are supported in the SFP+ ports on this Module:

 

 

HPE X130 10G SFP+ LC SR Transceiver

JD092B

 

HPE X130 10G SFP+ LC LRM Transceiver

JD093B

 

HPE X130 10G SFP+ LC LR Transceiver

JD094B

 

HPE X130 10G SFP+ LC ER 40km Transceiver

JG234A

 

 

 

Note 7

The following XFP Transceivers are supported in the XFP ports on this Module:

 

 

HPE X135 10G XFP LC ER Transceiver

JD121A

 

HPE X130 10G XFP LC LR Single Mode 10km 1310nm Transceiver

JD108B

 

HPE X130 10G XFP LC SR Transceiver

JD117B

Note 8

The following SFP Transceivers are supported in the SFP/SFP+ ports on this Module:

 

 

HPE X120 1G SFP LC SX Transceiver

JD118B

 

HPE X120 1G SFP LC LX Transceiver

JD119B

 

HPE X125 1G SFP LC LH70 Transceiver

JD063B

 

HPE X120 1G SFP RJ45 T Transceiver

JD089B

 

 

Transceivers

 

 

 

SFP Transceivers

 

 

 

HPE X170 1G SFP LC LH70 1550 Transceiver

JD109A

HPE X170 1G SFP LC LH70 1570 Transceiver

JD110A

HPE X170 1G SFP LC LH70 1590 Transceiver

JD111A

HPE X170 1G SFP LC LH70 1610 Transceiver

JD112A

HPE X170 1G SFP LC LH70 1510 Transceiver

JD115A

HPE X120 1G SFP LC LH100 Transceiver

JD103A

HPE X125 1G SFP LC LH40 1310nm Transceiver

JD061A

HPE X120 1G SFP LC LH40 1550nm Transceiver

JD062A

HPE X120 1G SFP RJ45 T Transceiver

JD089B

HPE X120 1G SFP LC SX Transceiver

JD118B

HPE X120 1G SFP LC LX Transceiver

JD119B

HPE X125 1G SFP LC LH70 Transceiver

JD063B

HPE X120 1G SFP LC BX 10-U Transceiver

JD098B

HPE X120 1G SFP LC BX 10-D Transceiver

JD099B

HPE X110 100M SFP LC LH40 Transceiver

JD090A

HPE X110 100M SFP LC LH80 Transceiver

JD091A

HPE X115 100M SFP LC FX Transceiver

JD102B

HPE X110 100M SFP LC LX Transceiver

JD120B

 

 

 

 

SFP+ Transceivers

 

 

 

HPE X130 10G SFP+ LC SR Transceiver

JD092B

HPE X130 10G SFP+ LC LRM Transceiver

JD093B

HPE X130 10G SFP+ LC LR Transceiver

JD094B

HPE X130 10G SFP+ LC ER 40km Transceiver

JG234A

 

 

Internal Power Supplies

 

 

JG213A, and JG214A Only System (std 0 // max 2) User Selection (min 1 // max 2) per switch enclosure

 

 

 

HP 5500 150WAC Power Supply

JD362A

 

See Configuration NOTE:1, 3

 

 

HPE FlexNetwork 5500 150WDC Power Supply

JD366A

 

See Configuration NOTE:1

 

 

HPE FlexNetwork 7500 650W AC Power Supply

JD217A

 

See Configuration NOTE:3

 

 

HPE FlexNetwork 7500 650W DC Power Supply

JD209A

 

 

HPE FlexNetwork X351 300W 48-60VDC to 12VDC Power Supply

JG528A

 

 

HPE FlexNetwork X351 300W 100-240VDC to 12VDC Power Supply

JG527A

 

See Configuration NOTE:5

 

 

PDU Cable NA/MEX/TW/JP

JG527A#B2B

  • C15 PDU Jumper Cord (NA/MEX/TW/JP)

 

 

 

PDU Cable ROW

JG527A#B2C

  • C15 PDU Jumper Cord (ROW)

 

 

 

High Volt Switch to Wall Power Cord

JG527A#B2E

  • NEMA L6-20P Cord (NA/MEX/JP/TW)

 

 

 

Configuration Rules:

 

 

 

Note 1

Supported only on the JG213A, JG214A.

 

 

 

 

Note 3

Localization required. (See Localization Menu for list.)

 

 

 

 

Note 5

Localization required on orders without #B2B, #B2C or #B2E options.

 

 

 

Firewall Specific Options

 

 

 

HP F5000-S/C VPN Firewall Fan Module

JG878A

  • Parts List Only

 

 

Compact Flash cards

 

 

 

HPE X600 1G Compact Flash Card

JC684A

 

See Configuration NOTE:1

 

 

HPE X600 512M Compact Flash Card

JC685A

 

See Configuration NOTE:1

 

 

HPE X600 256M Compact Flash Card

JC686A

 

See Configuration NOTE:1

 

 

Configuration Rules:

 

 

 

Note 1

These CF Cards are supported on the following Chassis only:

 

 

HP F1000-E VPN Firewall Appliance

JD272A

 

 

 

Technical Specifications

HP F1000-A-EI VPN Firewall Appliance (JG214A)

I/O ports and slots

12 dual-personality ports; auto-sensing 10/100/1000BASE-T or SFP

2 I/O module slots

Additional ports and slots

1 RJ-45 serial console port

Physical characteristics

Dimensions

17.4(w) x 15.75(d) x 1.73(h) in (44.2 x 40.01 x 4.39 cm)

Weight

12.13 lb (5.5 kg)

Memory and processor

4 GB DDR2 SDRAM, 1 GB flash

Performance

Firewall throughput

4 Gbps

VPN throughput

1 Gbps 3DES/AES

 

Dedicated IPsec VPN tunnels

2,000

 

Connections per second

25,000

 

Concurrent sessions

1 million

 

Number of policies

20,480

 

Number of VLANs

4,000

Environment

Operating temperature

32°F to 113°F (0°C to 45°C)

Operating relative humidity

10% to 95%, noncondensing

Electrical characteristics

Voltage

100 - 120 / 200 - 240 VAC, rated

-48 to -60 VDC, rated

(depending on power supply chosen)

Current

1 A

Maximum power rating

150 W

Frequency

50/60 Hz

Notes

Maximum power rating and maximum heat dissipation are the worst-case theoretical maximum numbers provided for planning the infrastructure with fully loaded PoE (if equipped), 100% traffic, all ports plugged in, and all modules populated.

Emissions

CISPR 22; EN 55022; ICES-003; AS/NZS CISPR 22; FCC Part 15; EN 61000-3-2; EN 61000-3-3; VCCI V-3

Immunity

ESD

EN300 386/EN 55024/EN 61000-4-2/EN301489-1/EN301489-17/IEC 61000-4-2

Radiated

EN300 386/EN 55024/EN301489-1/EN301489-17/EN 61000-4-3/IEC 61000-4-3

EFT/Burst

EN300 386/EN 55024/EN301489-1/EN301489-17/EN 61000-4-4/IEC
61000-4-4

Surge

EN300 386/EN 55024/EN301489-1/EN301489-17/EN 61000-4-5/IEC
61000-4-5

Conducted

EN300 386/EN 55024/EN301489-1/EN301489-17/EN 61000-4-6/IEC
61000-4-6

Power frequency magnetic field

EN 55024/EN 61000-4-8/IEC 61000-4-8

Voltage dips and interruptions

EN300 386/EN 55024/EN301489-1/EN301489-17/EN 61000-4-11/IEC
61000-4-11

Management

IMC - Intelligent Management Center; Command-line interface; Web browser; SNMP manager; Telnet; HTTPS; FTP

Features

Firewall operation mode

- Routing mode

- Transparent mode

- Hybrid mode

AAA service

- Local authentication

- Standard RADIUS

- HWTACACS+

- RADIUS domain authentication

ASPF

- General TCP/UDP application

- FTP/SMTP/HTTP/RTSP/H323 Protocol State Detection

- SIP/MGCP/QQ/MSN Protocol State Detection

- Java/ActiveX blocking and detection

- Port mapping

- Support for fragmented packets

NAT

- NAPT

- PAT

- NAT server

- Port mapping

- Bidirectional NAT

- Static NAT

Network security

- Ability to add blacklist by hand or automatically

Services

Refer to the Hewlett Packard Enterprise website at http://www.hpe.com/networking/services for details on the service-level descriptions and product numbers. For details about services and response times in your area, please contact your local Hewlett Packard Enterprise sales office


Standards and protocols (applies to all products in series)

 

IPv6

RFC 1981 IPv6 Path MTU Discovery

RFC 2460 IPv6 Specification

RFC 3484 Default Address Selection for IPv6

RFC 3513 IPv6 Addressing Architecture

RFC 3587 IPv6 Global Unicast Address Format

RFC 4007 IPv6 Scoped Address Architecture

RFC 4862 IPv6 Stateless Address Auto-configuration

 

Security

IEEE 802.1X:Port-Based Network Access Control (2001)

RFC 1321 The MD5 Message-Digest Algorithm

RFC 1334 PPP Authentication Protocols (PAP)

RFC 1994 PPP Challenge Handshake Authentication Protocol (CHAP)

RFC 2104 Keyed-Hashing for Message Authentication

RFC 2138 RADIUS Authentication

RFC 2618 RADIUS Authentication Client MIB

RFC 2620 RADIUS Accounting Client MIB

RFC 2716 PPP EAP TLS Authentication Protocol

RFC 2865 RADIUS Authentication

RFC 2866 RADIUS Accounting

RFC 2867 RADIUS Accounting Modifications for Tunnel Protocol Support

RFC 2868 RADIUS Attributes for Tunnel Protocol Support

RFC 2869 RADIUS Extensions

draft-grant-tacacs-02 (TACACS)

 

VPN

RFC 1701 Generic Routing Encapsulation (GRE)

RFC 1702 Generic Routing Encapsulation over IPv4 networks.

RFC 1828 IP Authentication using Keyed MD5

RFC 1829 The ESP DES-CBC Transform

RFC 1853 IP in IP Tunneling

RFC 2085 HMAC-MD5 IP Authentication with Replay Prevention

RFC 2401 Security Architecture for the Internet Protocol

RFC 2402 IP Authentication Header

RFC 2403 The Use of HMAC-MD5-96 within ESP and AH

RFC 2404 The Use of HMAC-SHA-1-96 within ESP and AH

RFC 2405 The ESP DES-CBC Cipher Algorithm With Explicit IV

RFC 2406 IP Encapsulating Security Payload (ESP)

RFC 2410 The NULL Encryption Algorithm and Its Use With IPSec

RFC 2411 IP Security Document Roadmap

RFC 2451 The ESP CBC-Mode Cipher Algorithms

RFC 2473 Generic Packet Tunneling in IPv6 Specification

RFC 2529 Transmission of IPv6 over IPv4 Domains without Explicit Tunnels

RFC 2661 Layer Two Tunneling Protocol "L2TP"

RFC 2784 Generic Routing Encapsulation (GRE)

RFC 2868 RADIUS Attributes for Tunnel Protocol Support

RFC 2893 Transition Mechanisms for IPv6 Hosts and Routers

RFC 3602 The AES-CBC Cipher Algorithm and Its Use with IPSec

RFC 4214 Intra-Site Automatic Tunnel Addressing Protocol (ISATAP)

 

IKEv1

RFC 2407 The Internet IP Security Domain of Interpretation for ISAKMP

RFC 2408 Internet Security Association and Key Management Protocol (ISAKMP).

RFC 2409 The Internet Key Exchange (IKE)

RFC 2412 The OAKLEY Key Determination Protocol

RFC 3526 More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE)

RFC 3706 A Traffic-Based Method of Detecting Dead Internet Key Exchange (IKE) Peers

 

PKI

RFC 2510 Internet X.509 Public Key Infrastructure Certificate Management Protocols

RFC 2511 Internet X.509 Certificate Request Message Format

RFC 3279 Algorithms and Identifiers for the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile

RFC 3280 Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile

draft-nourse-scep-06:

PKCS#1

PKCS#10

PKCS#12

PKCS#7

 


 

Features

 

Firewall operation mode

RFC 1981 IPv6 Path MTU Discovery

RFC 2460 IPv6 Specification

RFC 3484 Default Address Selection for IPv6

RFC 3513 IPv6 Addressing Architecture

RFC 3587 IPv6 Global Unicast Address Format

RFC 4007 IPv6 Scoped Address Architecture

RFC 4862 IPv6 Stateless Address Auto-configuration

 

Routing mode

IEEE 802.1X:Port-Based Network Access Control (2001)

RFC 1321 The MD5 Message-Digest Algorithm

RFC 1334 PPP Authentication Protocols (PAP)

RFC 1994 PPP Challenge Handshake Authentication Protocol (CHAP)

RFC 2104 Keyed-Hashing for Message Authentication

RFC 2138 RADIUS Authentication

RFC 2618 RADIUS Authentication Client MIB

RFC 2620 RADIUS Accounting Client MIB

RFC 2716 PPP EAP TLS Authentication Protocol

RFC 2865 RADIUS Authentication

RFC 2866 RADIUS Accounting

RFC 2867 RADIUS Accounting Modifications for Tunnel Protocol Support

RFC 2868 RADIUS Attributes for Tunnel Protocol Support

RFC 2869 RADIUS Extensions

draft-grant-tacacs-02 (TACACS)

 

Transparent mode

RFC 1701 Generic Routing Encapsulation (GRE)

RFC 1702 Generic Routing Encapsulation over IPv4 networks.

RFC 1828 IP Authentication using Keyed MD5

RFC 1829 The ESP DES-CBC Transform

RFC 1853 IP in IP Tunneling

RFC 2085 HMAC-MD5 IP Authentication with Replay Prevention

RFC 2401 Security Architecture for the Internet Protocol

RFC 2402 IP Authentication Header

RFC 2403 The Use of HMAC-MD5-96 within ESP and AH

RFC 2404 The Use of HMAC-SHA-1-96 within ESP and AH

RFC 2405 The ESP DES-CBC Cipher Algorithm With Explicit IV

RFC 2406 IP Encapsulating Security Payload (ESP)

RFC 2410 The NULL Encryption Algorithm and Its Use With IPSec

RFC 2411 IP Security Document Roadmap

RFC 2451 The ESP CBC-Mode Cipher Algorithms

RFC 2473 Generic Packet Tunneling in IPv6 Specification

RFC 2529 Transmission of IPv6 over IPv4 Domains without Explicit Tunnels

RFC 2661 Layer Two Tunneling Protocol "L2TP"

RFC 2784 Generic Routing Encapsulation (GRE)

RFC 2868 RADIUS Attributes for Tunnel Protocol Support

RFC 2893 Transition Mechanisms for IPv6 Hosts and Routers

RFC 3602 The AES-CBC Cipher Algorithm and Its Use with IPSec

RFC 4214 Intra-Site Automatic Tunnel Addressing Protocol (ISATAP)

 

Hybrid mode

RFC 2407 The Internet IP Security Domain of Interpretation for ISAKMP

RFC 2408 Internet Security Association and Key Management Protocol (ISAKMP).

RFC 2409 The Internet Key Exchange (IKE)

RFC 2412 The OAKLEY Key Determination Protocol

RFC 3526 More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE)

RFC 3706 A Traffic-Based Method of Detecting Dead Internet Key Exchange (IKE) Peers

 

AAA service

RFC 2510 Internet X.509 Public Key Infrastructure Certificate Management Protocols

RFC 2511 Internet X.509 Certificate Request Message Format

RFC 3279 Algorithms and Identifiers for the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile

RFC 3280 Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile

draft-nourse-scep-06:

PKCS#1

PKCS#10

PKCS#12

PKCS#7

 

Accessories

 

HPE Firewall Series accessories

 

 

 

Memory

 

HPE X600 1G Compact Flash Card

JC684A

HPE X600 512M Compact Flash Card

JC685A

HPE X600 256M Compact Flash Card

JC686A

 

 

HP F1000-A-EI VPN Firewall Appliance (JG214A)

 

HP F1000-S/A 2-port 10GbE SFP+ Module

JG317A

HP 5500 150WAC Power Supply

JD362A

HPE FlexNetwork 5500 150WDC Power Supply

JD366A

 

 

Accessory Product Details

 

HPE FlexNetwork 7500 650W DC Power Supply (JD209A)

Physical characteristics

Dimensions

13.78(d) x 5.51(w) x 1.57(h) in. (35 x 14 x 4 cm) (1U height)

Weight

4.96 lb. (2.25 kg)

Electrical characteristics

DC voltage

0~-48/-60V

Current

0/25 A

Idle power

97.5 W

Maximum power rating

650 W

PoE power

0 W

Notes

Idle power is the actual power consumption of the device with no ports connected.
Maximum power rating and maximum heat dissipation are the worst-case theoretical maximum numbers provided for planning the infrastructure with fully loaded PoE (if equipped), 100% traffic, all ports plugged in, and all modules populated.

Services

Refer to the Hewlett Packard Enterprise website at http://www.hpe.com/networking/services for details on the service-level descriptions and product numbers. For details about services and response times in your area, please contact your local Hewlett Packard Enterprise sales office


HPE FlexNetwork 7500 650W AC Power Supply (JD217A)

Physical characteristics

Dimensions

13.78(d) x 5.51(w) x 1.57(h) in. (35 x 14 x 4 cm) (1U height)

Weight

5.34 lb. (2.42 kg)

Electrical characteristics

Voltage

100-120/200-240 VAC

Current

0/10 A

Idle power

97.5 W

Maximum power rating

650 W

PoE power

0 W

Frequency

50/60 Hz

Notes

Idle power is the actual power consumption of the device with no ports connected.
Maximum power rating and maximum heat dissipation are the worst-case theoretical maximum numbers provided for planning the infrastructure with fully loaded
PoE (if equipped), 100% traffic, all ports plugged in, and all modules populated.
650W AC Power Supply uses a 10-A AC power cable

Services

Refer to the Hewlett Packard Enterprise website at http://www.hpe.com/networking/services for details on the service-level descriptions and product numbers. For details about services and response times in your area, please contact your local Hewlett Packard Enterprise sales office

Summary of Changes

 

Date of change:

Version History:

Action

Description of change:

27-May-2016

From Version 8 to 9

Changed

Product description updated.

Removed

Removed OBS Models.

01-Dec-2014

From Version 7 to 8

Changed

Overview and Technical Specifications updated

05-Dec-2014

From Version 6 to 7

Changed

Updated the Configuration section.

10-Jun-2014

From Version 5 to 6

Changed

Updated the Configuration section.

25-Feb-2014

From Version 4 to 5

Added

Configuration was added.

18-Feb-2014

From Version 3 to 4

Changed

Updates were made throughout, including adding a new model.

26-Mar-2012

From Version 2 to 3

Changed

Updated the Accessories section.

13-Feb-2012

From Version 1 to 2

Changed

Updated the Features and Benefits and Options sections.

 

 

 

Sign up for updates

 

 

 

© Copyright 2016 Hewlett Packard Enterprise Development LP. The information contained herein is subject to change without notice. The only warranties for Hewlett Packard Enterprise products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. Hewlett Packard Enterprise shall not be liable for technical or editorial errors or omissions contained herein.

To learn more, visit: http://www.hpe.com/networking

Windows and Windows Vista are U.S. registered trademarks of Microsoft Corporation. Java is a registered trademark of Oracle and/or its affiliates.

c04111545 - 14168 - Worldwide - V9 - 27-May-2016