ICSA-certified firewallRouting and transparent (bridge) modeZone-based access control listStateful packet inspectionUser-aware policy enforcementSIP/H.323 NAT traversalALG supports custom portsIPv6 Support
IPv6 Ready gold logo certifiedDual stackIPv4 tunneling (6rd and 6to4 transition tunnel)Host/Router/FirewallVirtual Private Network (VPN)
ICSA-certified IPSec VPNAlgorithm: AES/3DES/DESAuthentication: SHA-1, SHA-2/MD5Key management: Manual key/IKEPerfect forward secrecy (DH groups) support 1, 2, 5IPSec NAT traversalDead peer detection/relay detectionPKI (X.509) certificate supportCentralize VPN supportSimple wizard supportAuto reconnect VPNVPN HA (redundant remote VPN gateways)SSL VPN
Clientless secure remote accessSupport reverse proxy mode and full tunnel modeUnified policy enforcementSupports two-factor authenticationCustomizable user portalIntrusion Detection and Prevention (IDP)*1 (USG 50/100/100-PLUS/200)
Routing and transparent (bridge) modeZone-based IDP inspectionCustomizable protection profileProtect over 2000 attackAutomatic signature updatesCustom signaturesProtocol anomaly detection and protectionTraffic anomaly detection and protectionFlooding detection and protectionDoS/DDoS protectionApplication Intelligence*1 (Application Patrol)
Identify more than 600 applications, including IM, P2P, social netowrk, stream media, VoIP, and othersSupport application granularity controlManage use of Skype/MSN, GoogleTalk, Facebook at business hours, or neverBlock all use of P2P and Games applications all the time (or during business hours)Bandwidth management for P2P, Stream Media, File Transfer, or particular applicationsDaily check and auto update application signaturesReal-Time statistical reportsAnti-Virus*2 (USG 50/100/100-PLUS/200)
Support Bitdefender and Zyxel Anti-VirusStream-based Anti-Virus engineZone base AV protectionHTTP/FTP/SMTP/POP3/IMAP4 protocol supportAutomatic signature updatesNo file size limitationBlacklist/whitelist supportAnti-Spam
Zone to zone protectionTransparently intercept mail via SMTP/POP3 protocolsPOP3/SMTP port configurableSender-based IP reputation filterCommtouch RPD queryZero-hour virus outbreak protectionX-Header supportBlacklist/whitelist supportSupport DNSBL checkingSpam tag supportStatistics reportHigh Availability (USG 100/200)
Active-Passive modeDevice failure detection and notificationSupport ICMP and TCP ping checkLink monitoringAuto-Sync configurationsContent Filtering (BlueCoat and Commtouch)*3
Social networking controlWeb security—Security threat category (powered by BlueCoat)URL blocking, keyword blockingProfile base settingExempt list (blacklist and whitelist)Blocks java applet, cookies and active XDynamic URL filtering database (powered by BlueCoat and Commtouch)Unlimited user licenses supportCustomize warning messages and redirect URLNetworking
Routing mode/bridge mode/mixed modeLayer 2 port groupingEthernet/PPPoENAT/PATTagged VLAN (802.1Q)Virtual interface (alias interface)Policy-based routing (user-aware)Policy-based NAT (SNAT)Dynamic routing (RIP v1/v2, OSP...