NGFW (Next Generation Firewall)

BDCOM F5100-40MH is a high-performance firewall product designed and launched by BDCOM for large and medium-sized network security scenarios such as large enterprises, data centers, campus network egress, metropolitan area networks, branch headquarters, etc.

Multi-service and High-performance

Accurate Online Behavior Management

Comprehensive Attack Defense

Professional Virus Elimination

Bandwidth Management

Dedicated VPN Module

Flexible Networking Mode

Concise Management and Maintenance

High Reliability

Technical Parameter

Control Port 1 Consle
Service ports 2*10-Gigabit SFP+ ports, 2*Gigabit SFP optical ports
8* Gigabit electrical ports, supporting 2 groups of Bypass
2*USB interfaces
HD hard drive 1TB surveillance level
Expansion slot 2 expansion slots
Throughput 10Gbps
Concurrency 4000,000
Installation 19-inch rack-mounted
Dimensions (WxDxH) 440×330×44mm
Weight 5.5Kg
Power Supply Built-in dual AC power supply
Power Consumption Maximum 75W
Operating temperature 0°C~50°C
Operating humidity 10%~95% (non-condensing)

Features

Network function

Supports three working modes: transparent, routing, and hybrid, as well as link aggregation

Supports Source NAT, Destination NAT, Port NAT, and Static NAT

Supports VLAN and VRF

Supports WLAN and 3G wireless access

Supports DHCP server and DHCP Relay, DNS server, and static DNS

Supports static routing, PBR, ISP routing, and source interface routing

Supports application-based routing

Supports dynamic routing protocols such as OSPF, RIP, and OSPFv3

Supports route detection function

Supports IPv6 static routing, route advertisements, and tunnel translation

Firewall

Supports octuple policies based on user, application, source and destination interfaces, source and destination IP, service, and time

Supports object-oriented addressing, services, scheduling, applications, and user resources

Supports policy-based persistent connections

Supports policy hit counts statistics and reset

Supports policy priority adjustment

Supports IPv6 security policies

Supports session statistics, monitoring, temporary blocking, and global session restrictions

Security protection

Supports IP-MAC binding, ARP spoofing protection, and ARP Flood attack prevention

Supports IPv4 abnormal packet attack protection, including Ping of Death, Land-Base, Tear Drop, TCP Flag Winnuke, Smurf, Jolt2, and others

Supports protection against port scanning and IP scanning

Supports SYN Flood, UDP Flood, ICMP Flood, and DNS Flood attack protection based on interface and IP

Supports a blacklist for manual and automatic attack protection

Supports IPv6 abnormal packet attack protection against threats such as Winnuke, Land-Base, TCP Flag, Fraggle, and IP Spoof

VPN

Supports standard IPSec VPN protocols and deployment methods

Supports policy-based and route-based IPsec VPN

Supports CA centers and X.509 format certificates

Supports VPN Track

Supports SSL VPN tunnel mode

Supports GRE VPN

Supports security protection and bandwidth management under VPN tunnels

Virus Defense

Supports virus filtering based on HTTP, FTP, SMTP, POP3, IMAP protocols

Supports blocking specific file types from passing through

Supports virus scanning for up to 20 layers of compressed files

Supports manual and automatic updates of the virus database

Supports malicious URL filtering

Intrusion Detection

Supports automatic protocol recognition

Supports over 3000 predefined attack signatures

Supports automatic and manual updates of the signature database

Provides security protection against worms, Trojan backdoors, phishing, and other threats

Internet Behavior Management

Supports control over logging in and messaging in IM software

Supports control over software such as P2P and streaming media

Supports control over online gaming

Supports control over stock market information and trading activities

Supports control over sending and receiving emails, including attachment size filtering

Supports URL category filtering 

User Management

Supports local user authentication for the firewall

Supports standard third-party user authentication such as Radius, LDAP, etc.

Supports WeChat user authentication and SMS gateway

Supports Web user authentication

Supports online user monitoring and timeout management

Supports centralized user policy management

Traffic Management

Supports multi-level nested bandwidth management based on channels, interfaces, users, and applications

Supports bandwidth priority management

Supports maximum and minimum bandwidth limitation, and elastic bandwidth

Supports rate limiting per IP

Supports policy troubleshooting

Visualization

Supports real-time statistics of CPU, memory, and interface traffic

Supports traffic statistics of users and applications via pie charts, bar graphs, and trend graphs

Supports real-time display of user and application rankings

Supports real-time alerts for system events and security risks

System Management

Supports system administrators and read-only administrators

Supports administrator privacy check and timeout management

Supports manual system time setting and NTP synchronization

Supports dual system configuration file backup

Supports manual system file upgrades

Supports SNMPv1/v2/v3

Supports hot standby in active-standby and active-active modes

Supports interface status synchronization and status detection

Supports system diagnostics via PING, TRACERT, TCPSYN methods

Supports periodic collection of system information

Ordering Information

BDCOM F5100-40MH
F5100-40MH The F5100-40MH series firewall (standard configuration includes 2 10-Gigabit SFP+ ports, 2 Gigabit SFP optical ports, and 8 Gigabit electrical ports, with a network throughput capacity of 10Gbps and 4 million concurrent connections, built-in HD hard drive and dual AC power supply, supporting 2 high-speed expansion slots; It comes with a 3-year upgrade service for the three-in-one feature library of anti-virus, intrusion detection and WAF.
F5100-4GT4GS F5100-M series expansion module (supports 4 GE SFP ports and 4 GE RJ45 ports)
F5100-4TS F5100-M series expansion module (supports 4 10GE SFP+ ports)
F5140MH-UPDLic-1 F5100-40MH Three-in-one Feature library upgrade service (1 year), multiple options available
F5100-VPN-100 F5100 series universal SSL VPN authorization (concurrent 100 channels), multiple options available

Follow us

Facebook 领英

© 2023 BDCOM. Connecting a Better World