Announcement Frequently Asked Questions (FAQ) Q: What is the? A: The is a high performance network security appliance targeted to small or remote offices in distributed enterprises, including telecommuters, sales offices, and retail outlets. The combines firewall, VPN, DoS protection and traffic management into a single device. It features five /0 Ethernet ports, of which four are Trusted interfaces and one is an Untrusted interface. The also features two serial ports, one as a console port and one modem port for dial backup. The supports 75 Mbps firewall throughput, 20 Mbps 3DES VPN throughput, 2,000 concurrent firewall sessions, and IPSec VPN tunnels. The is available in either a -user version or Plus version (unrestricted users plus advanced features). Q: What is the difference between the -User and the Plus? A: The Plus version offers unrestricted users and advanced networking features. These advanced networking features include Dial-Backup, Dual Untrust, OSPF and and are not available in the -User version. -user Version and Plus Version Features IP Addresses in Trusted Interfaces Routing Protocol Support Dial Backup Support Redundant Connections with Dual Untrust -user Version RIP v.2 Plus Version Q: If one purchases a -user Version, can one upgrade to the Plus version? A:. The -user version can be upgraded to the Plus Version by purchasing a license key. Please see your sales representative for details on how to acquire the license key. Q: What is the performance and capacity of the? A: The offers the following capacities and performance: 75 Mbps Firewall with NAT 2,000 Concurrent Sessions 20 Mbps 3DES VPN IPSec VPN Tunnels Copyright 2003 NetScreen Technologies, Inc. All rights reserved. 1
Q: Will the support antivirus? A:, the will support Anti-Virus (AV) using Trend Micro s scanning technology embedded on the device. The AV upgrade is expected to be available in the second half of 2003, and a customer will be able to add AV to the for an added cost. Q: How does Antivirus on the work? A: Antivirus on the will scan traffic for viruses as it passes through the and drop infected files. The administrator will be able to configure virus scanning on a per policy basis with options to scan mail (SMTP, POP3, Webmail) and web traffic (HTTP). Q: What is the difference between the different versions of the and the NetScreen- 5XT? A: and NetScreen-5XT Version Comparison Features NetScreen- 5GT -user version Plus NetScreen-5XT -user version NetScreen-5XT Elite IP Addresses in Trust Interfaces Routing Protocol Support RIP v.2 Dial Backup Support Redundant Connections With Dual Untrust Certifications ne ne FIPS, Common Criteria FIPS, Common Criteria Upgradeable to Support Embedded Anti-virus (AV)* * Separate purchase required for upgrade te that the -user version does not include the dial backup, dual untrust and OSPF and support, while the NetScreen-5XT -user version includes these features. Q: What are the hardware features of the? A: The offers the following hardware features: Interfaces - 4 auto-sensing /0 Switch Ports (Trusted side) - 1 auto-sensing /0 Switch Port (Untrusted side) - 1 RS-232 DB-9 console port - 1 RS-232 DB-9 high-speed modem port (Modem only supported with Plus option) Power: - The power input to the device will be 12V, 1A Power Supplies the primary power supplies will be region specific. The power cord cannot be replaced to accept different power plug types. - US linear supply 1V Type B - Japan linear supply 0V Modified Type B - Europe linear supply 220V Type C - UK linear supply 240V Type G Copyright 2003 NetScreen Technologies, Inc. All rights reserved. 2
- US Switching supply Can be used in all countries (except Japan) but only comes with US power plug Reset and Asset Recovery Feature Lock Feature: The accepts a Kensington style laptop cable lock Q: What key software features are supported on the? A: The supports ScreenOS 4.0.0-DIAL2 and a fully featured WebUI. The following is a summary of the additional features found in ScreenOS 4.0.0-DIAL2: Home and Work zones for segmenting the network Dial Backup and Dual Untrust (with Plus option) RIP v2 OSPF and (with Plus option) Loopback Interface Q: What port modes or zones does the support? A: The Netscreen-5GT supports four port modes Trust/Untrust Home/Work/Untrust Trust/Dual Untrust (Available with Plus Version) Combined Mode Home/Work/Dual-Untrust (Available with Plus Version) Port Mode Configurations Trust_Untrust (default) 4 ports on Trust zone Dial backup via serial interface 1 Home_Work 2 ports in restricted trust/home zone 2 ports in trust/work zone Dial backup via serial interface 1 Untrust Untrust Untrust Trust Trust Trust Trust Untrust Home Home Work Work Dual_Untrust 1 Direct backup via Ethernet interface 3 ports on Trust zone Serial port disabled Untrust Untrust Trust Trust Trust Combined 1 Direct backup via Ethernet interface 2 ports in restricted trust/home zone 1 port in trust./work zone Restricted = Home, Trust = Work (1) Available in the Plus Untrust Untrust Home Home Work Q: Does the support earlier versions of ScreenOS? A:. The supports ScreenOS 4.0.0-DIAL2 or later. Earlier versions of ScreenOS are not supported. Q: Does NetScreen-Global PRO support the? A:, NetScreen-Global PRO will include support for the in the release 4.1.1, which will be available at product launch. Copyright 2003 NetScreen Technologies, Inc. All rights reserved. 3
Q: Does NetScreen-Global PRO support all of the features? A:, NetScreen-Global PRO will not support the additional features included in ScreenOS-4.0.0-DIAL2 until a later release. The features not supported by NetScreen-Global PRO 4.1.1 include home/work zones, dial backup, dual untrust and dynamic routing support (RIPv2, OSPF, and ). Q: Why would a customer need a? A: Enterprises or service providers requiring a security solution for small offices, retail locations, or teleworkers will benefit from the added performance and ports of the. Customers can take advantage of the s superior performance, simplified install via ease-of-use features, auto-sensing cable capabilities, and dial backup functionality Q: How is the different from the NetScreen-5XP? A: The is a significantly better product than the NetScreen-5XP. The provides improved performance, more Ethernet ports, and additional features for remote office and telecommuter environments. Features/Benefits 4 Ethernet ports in Trusted zone eliminating the need for an additional hub Simplified installation via auto-sensing Ethernet ports Redundant access via dial backup and dual untrust features Separate home and work zones Dynamic routing support with RIP v2, OSPF 1 and 1 Firewall Performance 3DES VPN Performance 1 75 Mbps 20 Mbps NetScreen-5XP 20 Mbps 13 Mbps (1) Available in the Plus Q: What types of customers need a? A: The is best suited to a distributed enterprise environment with large numbers of remote offices or retail outlets, which often require high performance, minimal downtime and ease of deployment and management. Q: Can a NetScreen-5XP be upgraded to a? A:, the uses a different hardware platform. Q: When will the be available to order? And when will it begin shipping? A: The NetScreeen-5GT will be available for order May, 2003 and the product will begin shipping with limited quantities available on May 15, 2003 with quantity for large orders available in June 2003. Q: How long will it take to receive the once I order the product? A: Once the initial backlog is shipped, we expect to ship s within 48 hours of receiving shippable orders. Q: How long will the NetScreen-5XP product be available? A: The product could reach End of Service (EOS) as early as mid August 2003. Copyright 2003 NetScreen Technologies, Inc. All rights reserved. 4
Q: Does the have an ASIC? A:, the was designed without an ASIC as it was determined that an ASIC was not needed to meet the requirements of the target environments. The provides 75 Mbps Firewall and 20 Mbps 3DES VPN performance, which is more than enough performance for the remote office environment it is designed for. NetScreen will always strive to provide appropriate technology for the environment. NetScreen will continue to innovate in ASIC technology to drive security processing performance and content inspection, with a continued focus on the requirements of the high-performance solutions The is a purpose built firewall appliance, based on a RISC processor with hardware accelerated VPN encryption, designed to exceed the requirements of the remote office and telecommuter environments without using the GigaScreen ASIC NetScreen has and will continue to evaluate commercially available network processors, processors and security chips and integrate them when appropriate to ensure suitable levels of programmability, flexibility and performance in the NetScreen hardware platforms. That said, NetScreen sees increased requirements for deeper inspection and application-layer security that will drive us to use NetScreen s existing and future ASICs in the majority of NetScreen s platforms for the foreseeable future. Q: Does this mean that NetScreen is moving away from ASICs? A:. NetScreen believes that ASICs are essential for high performance, deep inspection network security hardware. NetScreen will continue to leverage the tight integration between its ASIC technology and ScreenOS to drive additional security functionality and reduce customers total cost of ownership, without impacting network performance. The exceeds customers requirements for a network security device in remote office and telecommuter environments without using the GigaScreen ASIC. About NetScreen NetScreen Technologies, Inc., is a leading developer of integrated network security solutions that offer the security, performance and total cost of ownership required by enterprises and carriers. NetScreen s innovative solutions provide key security technologies, such as virtual private network, denial of service protection, firewall and intrusion prevention, in a line of easy-to-manage security appliances and systems. NetScreen is located at 805 11th Ave, Sunnyvale, CA 94085. More information on NetScreen s products can be found at http://www.netscreen.com or by calling toll free at 1-800-638-8296. Copyright 2003 NetScreen Technologies, Inc. All rights reserved. NetScreen, NetScreen Technologies, GigaScreen, and the NetScreen logo are registered trademarks of NetScreen Technologies, Inc. IDP, MMD,, NetScreen-5XP, NetScreen-5XT, NetScreen-25, NetScreen-50, NetScreen-204, NetScreen-208, NetScreen-500, NetScreen-5200, NetScreen-5400, NetScreen-IDP, NetScreen-IDP 0 NetScreen-IDP 500, NetScreen-Global PRO, NetScreen-Global PRO Express, NetScreen-Remote, GigaScreen ASIC, GigaScreen ASIC-II, NetScreen ScreenOS and Stateful Signature are trademarks of NetScreen Technologies, Inc. All other trademarks and registered trademarks are the property of their respective companies. Information in this document is subject to change without notice. part of this document may be reproduced or transmitted in any form or by any means, electronic or mechanical, for any purpose, without receiving written permission from NetScreen Technologies, Inc. Copyright 2003 NetScreen Technologies, Inc. All rights reserved. 5