Quidway SVN3000 Security Access Gateway SSL/IPSec VPN Access Gateway HUAWEI TECHNOLOGIES CO., LTD.
Product Overview With the rapid development and popularization of the Internet, informatization of enterprise Internets is increasingly improved and Internets have to meet the ever-growing demands for remote access. How to realize the security access to the Intranet IT information system becomes a critical problem for enterprise IT departments to further improve the IT efficiency. For example, the enterprise branches, personnel on business trip, Small Office Home Office (SOHO) personnel, partners, and customers need to obtain important information in time. To solve the previous problems, Huawei launches the SVN3000, which is a Secure Socket Layer (SSL)/ IP Security Protocol (IPSec) Virtual Private Network (VPN) security access gateway of large capacity and high reliability. Through the SSL VPN function, the SVN3000 provides the secure, easy-to-use, and easy-to-manage remote access for terminals, such as the personnel on business trip, SOHO personnel, partners, and customers. The SVN3000 supports the IPSec function and low-cost remote interconnections among branches. The SVN3000 is based on professional and highly reliable hardware platform and dedicated real-time operation system of Huawei. It provides outstanding system security and reliability and is the best solution for the enterprise VPN network construction. Product Series SVN3000 Product Features Superior SSL/IPSec VPN gateway The SVN3000 deeply integrates VPN technologies and functions, such as the SSL VPN, IPSec VPN and Authentication, Authorization, and Accounting (AAA). Combing their advantages and features, the SVN3000 provides excellent security access solution for the IP VNP networking. The SVN3000 supports the standard Web browser that the remote access terminal adopts. The security access to the Intranet resources can be realized with no installation of customer software. It supports the powerful authentication and fine-granularity control on
authorized access to Intranet resources. It provides encryption and decryption algorithms, such as the Data Encryption Standard (DES), 3DES, and Advanced Encryption Standard (AES). All these provide a hierarchical end-to-end secure protection for remote access. Advanced service support capability The SVN3000 provides the comprehensive remote access function for the intranet applications. It supports the remote terminals implementing the instant application access based on the Web interface. It also supports the application access, such as the Web server security access, file sharing access, Notes, Exchange, File Transfer Protocol (FTP), Oracle, Telnet, Secure Shell (SSH), Reliable Data Protocol (RDP), and Virtual Network Computing (VNC). The abundant service application supports bring unprecedented scalability to enterprise applications. For the fast development of new service applications in the future, the SNV3000 supports the VPN Tunnel mode to realize the supporting capability for all service access. Supporting comprehensive authentication modes The SVN3000 supports the authentication and authorization modes based on user names besides the common authentication modes and external authorization platforms such as Remote Authentication Dial in User Service (RADIUS), Lightweight Directory Access Protocol (LDAP), SecurID, AD,X.509, and USBKey + digital certificate. The diversified authentication and authorization help the administrator configure and manage access users in a centralized way, which dramatically decreases the support cost and maintenance cost. Moreover, the SVN3000 provides system logs, administrator logs, and user access logs. It supports viewing logs in categories and exporting logs in real time. This helps the administrator to perform external analysis and audit for logs. Providing convenient deployment and management For SSL VPN services, the SVN3000 provides abundant and easyto-use WebUI management interface in both Chinese and English. Through the Web management interface, the administrator completes related SSL VPN user configuration and resource configuration, which supports the real-time monitoring and management. As a professional security access gateway, the SVN3000 supports the command line management and Simple Network Management Protocol (SNMP). Supporting the virtual gateway technology The SVN3000 supports the advanced virtual gateway technology. Multiple SSL VPN systems are realized on one set of devices through the virtual gateway technology. Each of these virtual systems has its own administrator, user options, and configuration options, which prevents different systems from communication with each other. The virtual gateway technology brings unprecedented scalability to the devices. It is the core technology for enterprises and carriers to further improve the security and provide secure services, which brings higher return on investment to enterprises and carriers. One single SVN3000 provides up to 128 virtual SSL VPN gateways. Highly reliable security access gateway By adopting the Huawei proprietary highly reliable hardware platform, dedicated real-time operating system, and professional Versatile
Routing Platform (VRP), the SVN3000 security access gateway is able to deliver better performance and higher system security than the traditional VPN service platform that is based on the universal system. The SVN3000 provides the standard dual power supply configuration and supports the hot backup networking. It is the best choice for constructing a highly reliable VPN service network. Typical Networking Servers Headquarter LDAP & Radius & CA Intranet 3000 3000 SVN3000 Network Manager IPSEC VPN SSL VPN Internet Branch SVN3000/USG/Eudemon Branch SVN3000/USG/Eudemon Mobile Office Typical network topology of the SVN3000
Product Specifications Item SVN3000 Fixed interface Three mutually exclusive 10/100/1000 M optical/electrical interfaces, one console interface Expansion slot 2 Reliability Dual power supply, dual-system hot backup Management mode Command line, Web configuration, and SNMP Dimensions (mm) (W D H) 436 420 44.45 Weight 6.0kg Max. power 60W AC: 100 to 240V 50/60 Hz Power supply DC: -48 to 60V Mean time between failures (MTBF) 12.67 years Standard and protocol SSLv2.0, SSLv3.0, TLSv1.0, and others
NO WARRANTY THE CONTENTS OF THIS BROCHURE ARE PROVIDED AS IS. EXCEPT AS REQUIRED BY APPLICABLE LAWS, NO WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE, ARE MADE IN RELATION TO THE ACCURACY, RELIABILITY OR CONTENTS OF THIS MANUAL. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO CASE SHALL HUAWEI TECHNOLOGIES CO., LTD BE LIABLE FOR ANY SPECIAL, INCIDENTAL, INDIRECT, OR CONSEQUENTIAL DAMAGES, OR LOST PROFITS, BUSINESS, REVENUE, DATA, GOODWILL OR ANTICIPATED SAVINGS. Copyright Huawei Technologies Co., Ltd. 2009. All Rights Reserved. The information contained in this document is for reference purpose only, and is subject to change or withdrawal according to specific customer requirements and conditions. HUAWEI TECHNOLOGIES CO., LTD. Add: Huawei Industrial Base Bantian Longgang Shenzhen 518129, P.R. China Tel: +86-755-28780808 Version No.: M3-080030-20090416-C-1.0 www.huawei.com