Description
H3C SecPath F5000-AI-20 Hot-swappable Firewall Appliance F5000-AI-20
H3C SecPath F5000-AI firewalls provide customers with professional and robust network security protection to safeguard data centers, IT infrastructure, and data assets. H3C SecPath F5000-AI firewalls can be deployed in multiple modes to address the increasingly complex network and digital environment. Meanwhile, H3C SecPath F5000-AI firewalls integrate a management platform (H3C CloudNet) that supports cloud deployment and offer a variety of subscribed professional security services to assist customers in tackling security challenges.
Hybrid Deployment Architecture
H3C SecPath F5000-AI firewalls can adapt to different scenario requirements. Whether the enterprise environment is complex and changeable or pursuing high-efficiency and agility, they can fit perfectly.
All firewall shares a unified operating system Comware, ensuring operational consistency and convenience, and greatly reducing operation and maintenance costs. With this innovative design, H3C firewalls build an all-round, reliable, and user-friendly network security protection system for customers, fully safeguarding enterprise network security.
Also, firewalls can be managed by H3C management platform, enabling consistent distribution, detailed management and dynamic adjustment of policies based on risk levels across hardware, virtualized, cloud-native, and containerized firewalls. The firewalls also feedback the networking changes, security logs and attack findings back to the platform, helping constructing the security situation. In this regard the firewalls and platform work as a whole.
Comware: One Core, Every Defense
Comware is a unified network security operating system designed based on the TCP/IP architecture. H3C hardware firewall, virtualized firewall, cloud firewall, and containerized firewall all run on this operating system. It supports comprehensive networking and security functions and has high scalability. At the same time, it provides high visibility to simplify operation and maintenance procedures. Sharing this common core system, H3C SecPath F5000-AI firewalls provide every defense in all types of scenarios. Firewall-as-a-service (FWaaS) together with SASE can be easily delivered no matter what the embodiment is.
Comware has a modularized designs presenting abundant features while keeping high reliability. It also quickly reacts to changing technology and realizes rapid delivery.
The comprehensive TCP/IP protocol stack functionality allows the firewall to participate in network deployments with any topology, ensuring seamless integration. Comware supports multi-CPU, multi-core and multi-processing, enhancing data forwarding and processing efficiency.
Carrier-Level High Availability
H3C excels in hardware design. Its elite R&D team meticulously designs from chip to system level, using advanced tech for innovative architecture optimization, ensuring high performance.
Notably, H3C firewalls are highly reliable. They endure rigorous tests. With redundant designs for key components, failure risks are minimized, firmly supporting digital transformation across industries.
Meanwhile, the Comware operating system offers a variety of selectable reliability technologies to ensure high-reliability at the network level.
Supports the RBM (Remote Backup Mechanism) technology, enabling real-time backup of business data and meeting the requirements of active-active and active-standby networking.
Integrated, Flexible and Advanced Protection
H3C SecPath F5000-AI firewalls boast outstanding security capabilities, integrating functions such as intrusion detection, virus protection, and URL filtering. They can accurately identify and block various malicious traffic, preventing the invasion of viruses and Trojans. The powerful application identification technology can manage a vast number of network applications. Meanwhile, intelligent security policies help flexibly address complex threats. From the network perimeter to the interior, it builds a comprehensive security defense line, safeguarding the security of enterprise information assets.
Intrusion prevention system (IPS)
Supports real-time active interception of DOS, brute force disassembly, port scanning, sniffing, worms and other network attacks or malicious traffic protecting internal network information from infringement.
Application layer traffic identification and management
Uses the state machine and traffic exchange inspection technologies to detect traffic of P2P, IM, network game, stock, network video, and network multi-media applications, such as Facebook, X(twitter), Youtube, Thunder, BitTorrent, eMule, eDonkey, WeChat, Weibo, QQ and MSN. H3C firewalls use the deep inspection technology to identify P2P traffic precisely and provides multiple policies to control and manage the P2P traffic flexibly. Also, H3C SecPath F5000-AI firewalls support over 7,000 protocols and over 10,000 applications, which are updated every 2 weeks.
Categorized filtering of massive URLs
Uses the local+cloud mode to provide 143 categorized and 130 million URL rules*, providing basic URL filtering blacklist and whitelist and allows you to query the URL category filtering server on line.
Web Application Firewall (WAF)
Deep web security protection. Supports web application protection. For the most CC attacks, SQL injection, HTTP slow attacks, cross-site-scripts and other common attacks, content detection and verification of various requests from web application clients are carried out to ensure their security and legitimacy, and illegal requests are blocked in real time, So as to effectively protect all kinds of websites.
Data leakage prevention (DLP)
Supports email filtering by SMTP mail address, subject, attachment, and content, HTTP URL and content filtering, FTP file filtering, and application layer filtering (including Java/ActiveX blocking and SQL injection attack prevention).
Unknown threat prevention
Uses the situation awareness platform to quickly detect and locate threats. This ensures that the firewall can take global security measures as soon as a single point is under attack. The firewalls support an enhanced AI feature, which enables a more professional AI-based detection capability for unknown threats. The firewalls can also send the unidentified files to sandbox(H3C SecCenter CSAP-ATD).
Flood Attack protection
Detects and prevents various attacks, including Land, Smurf, Fraggle, ping of death, Tear Drop, IP spoofing, IP fragment, ARP spoofing, reverse ARP lookup, invalid TCP flag, large ICMP packet, IP/port scanning, and common DDoS attacks such as SYN flood, UDP flood, DNS flood, and ICMP flood.
Complete and updated security signature database
H3C has a senior signature database team and professional attack protection labs that can provide a precise and up-to-date signature database.
Security zone
Allows you to configure security zones based on interfaces and VLANs.
Packet filtering
Allows you to apply standard or advanced ACLs between security zones to filter packets based on information contained in the packets, such as UDP and TCP port numbers. You can also configure time ranges during which packet filtering will be performed.
Access control
Supports access control based on users and applications and integrates deep intrusion prevention with access control.
ASPF
Dynamically determines whether to forward or drop a packet by checking its application layer protocol information and state. ASPF supports inspecting FTP, HTTP, SMTP, RTSP, and other TCP/UDP-based application layer protocols.
Blacklist
Supports static blacklist and dynamic blacklist.
- * URL libraries in cloud can be extended to 500 million
Intelligent Management
H3C Cloudnet Capacity
H3C SecPath F5000-AI firewalls can be managed by H3C Cloudnet management platform in the cloud. This integration combines functions such as firewall management, security information and event collection, analysis, and response. Moreover, it enables management across various cloud scenarios, including public clouds, private clouds, hybrid clouds, and traditional IDCs.
H3C SecCenter CSAP-SMP
SMP platform helps customers to manage the firewalls. SMP mainly focuses on local management installed in customer's own environment.
Web GUI and CLI
Web-based management, with simple, user-friendly GUI and integrated CLI-based configuration and management.
Intelligent security policy management
Intelligent security policy management Detects duplicate, redundant or conflicting policies, optimizes policy configurations, detects and proposes security policies dynamically generated in the internal network.
Abundant reports
Include application-based reports and stream-based analysis reports, with various exported report formats, including PDF, HTML, TXT and Microsoft Word. The reports can be customized covering different contents.
Security logs
H3C SecPath F5000-AI firewalls support various logs including operation logs, security policy logs, threat logs, URL filtering logs, traffic logs and NAT logs.
Comprehensive Networking and VPN Features
Comware natively integrates the networking features with security. This allows firewalls to be deployed in any topology to adapt to customers' different requirements.
Routing
Supports static routing, RIP, OSPF, BGP, routing policies, and application- and URL-based policy-based routing. These allow firewalls to integrate into any complicated networking topologies.
NAT
Supports multiple NAT modes, enabling efficient address translation between private networks and the public network. This allows multiple internal network devices to share a public IP for Internet access. It has a precise port mapping function to open internal services as needed. With intelligent address pool management, it allocates resources reasonably.
Integrated link load balancing feature
Uses link state inspection and link busy detection technologies, and applies to a network egress to balance traffic among links.
Integrated SSL VPN feature
Supports 2FA, and the enterprise's existing authentication system to authenticate users, providing secure access of mobile users to the enterprise network.
VPN Tunnels
Supports L2TP, IPsec/IKE, GRE to establish reliable and encrypted data channels.
Industry-leading IPv6 Features
Abundant IPv6 features help customers migrate their businesses from IPv4 to IPv6 smoothly. Various IPv4-IPv6 technologies also allow firewall to be deployed in dual stacks.
NAT46/NAT64/NAT66
IPv6 stateful firewall.
IPv6 related attack protection.
IPv6 data forwarding, IPv6 static routing and dynamic routing, and IPv6 multicast.
IPv6 transition technologies, including NAT-PT, IPv6 over IPv4 GRE tunnel, manual tunnel, 6to4 tunnel, automatic IPv4-compatible IPv6 tunnel, ISATAP tunnel, NAT444, and DS-Lite.
IPv6 ACL and RADIUS.
SD-WAN Security
The H3C SecPath F5000-AI firewalls have powerful SDWAN deployment capabilities. The firewalls can flexibly adapt to various network scenarios, easily integrate different link resources such as broadband and dedicated lines, and achieve intelligent routing. In enterprise branch networks and working with H3C AD-WAN controller, it can quickly build secure and stable WAN connections. Through a centralized management platform, it can uniformly manage firewalls in different locations, optimize network configurations in real-time, reduce operation and maintenance costs, provide efficient and reliable WAN network connection guarantees for enterprises, and help enterprises carry out their businesses efficiently.
Zero-touch deployment
Allows customers to launch network services at low cost and high efficiency.
Comprensive Protection
The comprehensive security capabilities of the firewall protect the security of the headquarters and branch departments.
High Visibility
The unified management platform simplifies firewall management and provides rich visibility to monitor the network and security situation.
IoT Security
H3C SecPath F5000-AI firewalls combined with the management platform can identify various IoT devices based on terminal information such as MAC addresses, IP addresses, and protocols, providing users with visibility into the entire network assets. The firewalls support classifying IoT devices and performing protocol and behavior control on them based on the classifications and various tags, creating a secure operating environment for IoT. It also supports vulnerability scanning and monitoring of IoT devices, providing targeted protection in a timely manner to continuously ensure the security status of IoT devices.
H3C SecPath F5000-AI firewalls also serve as a security platform for OT scenario. The firewalls can deeply identify dozens of industrial control protocols and achieve precise management and control through protocol analysis and behavior modeling. The firewalls support