The ZyWALL USG 100 is a Unified Security Gateway, integrated with complete, enterprise-level and advanced security solutions designed for Small/Medium Business (SMB) recommended for up to 25 PC users. Its flexible configuration helps network administrators set up the network and enforce security policies more efficiently. With certified by ICSA SPI AFirewall and IPSec VPN, the ZyWALL USG 100’s security features also include IPSec VPN, SSL VPN, Firewall, Content Filter, Anti-Virus and IDP (Intrusion Detection and Prevention) for maximum network security protection. It also provides bandwidth management, for QoS of VoIP or mission critical applications, Multiple-WAN Failover and Load Balancing. Moreover, IPSec VPN and SSL VPN design for telecommuters and home workers can access data more easily and safely at home. Remote access with SSL VPN requires only a standard web browser. ZyWALL USG 100’s excellent throughput is the key to implement features of an enterprise level to provide a full-time, non-stop and secure service.
- The ICSA-certified, stateful inspection firewall protects the network and vital Internet services like e-mail, Web browsing, servers, and file transfers.
- For protection against viruses and spyware, choose the ICSA-certified ZyXEL Anti-Virus or one powered by Kaspersky Labs.
- The IDP engine protects your network from intrusions such as Trojans and worms.
- IPSec VPN support allows secure connections to branch offices, partners, and headquarters; road warriors and telecommuters can use SSL to securely access the company network without having to install VPN software; and with the new ZLD3.0 firmware, L2TP support enables iPads, iPhones, and other mobile devices to quickly and easily establish VPN tunnels to remote networks directly from their native settings.
- Application Patrol controls who can use what IM and P2P applications like MSN and BitTorrent, and even who can use specific features within an application.
- The anti-spam feature can tag or discard unsolicited commercial or junk e-mail.
- User-aware configuration lets you control access to applications or resources and apply security scans by user or user group.
- Bandwidth management lets you prioritize time-sensitive applications like VoIP and video conferencing.
- Multiple WAN ports let you use multiple ISP links and load balancing to enhance traffic. Throughput, optimize bandwidth usage, and help ensure continuous uptime if a link goes down.
- Along with your regular user name and password, use the ZyWALL OTP (One Time Password). hardware token* to generate a new PIN code each time you log in.
-
Use the extension card slot and USB ports for multiple 3G wireless WAN connections.
-
IPv6 support is enabled by the new ZLD3.0 firmware, future-proofing USG devices against network changes and upgrades.
*Sold separately
ICSA-certified Firewall
- Zone-Based Access Control List
- Security Zones
- Stateful Packet Inspection
- DoS/DDoS Protection
- User-Aware Policy Enforcement
- ALG Supports Custom Ports
Intrusion Detection and Prevention
- In-line Mode (Routing/Bridge)
- Zone-Based IDP Inspection
- Customizable Protection Profile
- Signature-based Deep Packet Inspection
- Automatic Signature Updates**
- Custom Signatures
- Traffic Anomaly Detection and Protection
- Flooding Detection and Protection
- Protocol Anomaly Detection and Protection:HTTP/ICMP/TCP/UDP
Anti-Virus
- ICSA-Certified ZyXEL Anti-Virus or Kaspersky Anti-Virus
-
Stream-Based Anti-Virus
-
Covers Top Active Viruses in the Wild List
-
Scans HTTP/FTP/SMTP/POP3/IMAP4
-
Automatic Signature Updates**
-
No File Size Limitation
-
Blacklist/Whitelist Support
Hybrid VPN
- ICSA-certified IPSec VPN
- Encryption: AES/3DES/DES
- Authentication: SHA-1/MD5
- Key Management: Manual Key/IKE
- Perfect Forward Secrecy: DH Group 1/2/5
- NAT over IPSec VPN
- Â Dead peer Detection/Relay Detection
- PKI (X.509) Certificate Support
- Certificate Enrollment (CMP/SCEP)
- Xauth Authentication
- L2TP over IPSec Support
-
SSL VPN
-
Clientless Secure Remote Access(Reverse Proxy Mode)
-
SecuExtender (Full Tunnel Mode)
-
 Unified Policy Enforcement
-
Supports Two-factor Authentication
-
Customizable User Portal
Application Patrol
- IM/P2P Granular Access Control
- Apply Schedules, Bandwidth Management
- User-Aware
- IM/P2P Up-to-Date Support (based on IDP signatures)**
- Real-Time Statistical Reports
Bandwidth Management
- Bandwidth Priority
- Policy-Based Traffic Shaping
- Maximum/Guaranteed Bandwidth
- Bandwidth Borrowing
Anti-Spam
- Zone to Zone Protection
- Transparently intercept mail via SMTP/POP3 protocols
- Blacklist/Whitelist support
- Support DNSBL checking
- Statistics report
High Availability
- Device HA (Active-Passive Mode)
- Device Failure Detection
- Link Monitoring
- Auto-Sync Configurations
- Multiple WAN Load Balancing
- VPN HA (Redundant Remote VPN Gateways)
Content Filtering
- URL Blocking, Keyword Blocking
- Exempt List (Blacklist and Whitelist)
- Blocks Java Applet, Cookies and Active X
- Dynamic URL Filtering Database (Powered by BlueCoat)**
User Licenses
Networking
- Routing Mode/Bridge Mode/Mixed Mode
- Layer 2 Port Grouping
- Ethernet/PPPoE/PPTP
- Tagged VLAN (802.1Q)
- Virtual Interface (Alias Interface)
- Policy-Based Routing (User-Aware)
- Policy-Based NAT (SNAT/DNAT)
- RIP v1/v2
- OSPF
- IP Multicasting (IGMP v1/v2)
- DHCP Client/Server/Relay
- Built-in DNS Server
- Dynamic DNS
Authentication
-
Internal User Database
-
Microsoft Windows Active Directory
-
External LDAP/RADIUS User Database
-
ZyWALL OTP (One Time Password)***
-
Forced User Authentication (Transparent Authentication)
System Management
-
Role-Based Administration
-
Multiple Administrator Login
-
Multi-Lingual Web GUI (HTTPS/HTTP)
-
Object-Based Configuration
-
Command Line Interface (Console/Web Console/SSH/TELNET)
-
Comprehensive Local Logging
-
Syslog (send to up to 4 servers)
-
E-mail Alert (send to up to 2 servers)
-
SNMP v2c (MIB-II)
-
Real-Time Traffic Monitoring
-
System Configuration Rollback
-
Text-Based Configuration File
-
Firmware upgrade via FTP/FTP-TLS/Web GUI
-
Advanced Reporting (Vantage Report)
-
Centralized Network Management (Vantage CNM)
3G Support
- Advanced Wireless Security Transmission with WEP Encryption and WPA/WPA2 Support
- PCMCIA: Sierra Wireless AC850*
- USB: Huawei E220*
*: Not included.
**: Requires a valid subscription.
***: Sold separately.
Certifications
- ICSA Certified Firewall
- ICSA Certified IPSec VPN
- ICSA Certified Anti-Virus
Standards Compliance
- HSF (Hazardous Substance Free): RoHS and WEEE
- EMC: FCC Part 15 Class B, CE-EMC Class B, C-Tick Class B, VCCI Class B
- Safety: CSA International (ANS/UL60950-1,CSA60950-1, EN60950-1, IEC60950-1)
Hardware Specifications
- Memory size: 256 MB DDR2 RAM/256 MB Flash
- Interface: GbE x 7 (RJ-45 with)
- Interface: Auto-negotiation and Auto MDI/MDI-X
- Console: RS-232 (DB9F)
- AUX: RS-232 (DB9M)
- LED Indicator: PWR, SYS, AUX, CARD
- Reset Button
- Expansion Card Slot
- 2 USB Ports
Physical Specifications
- Rack Mountable (rack-mount kit included)
- Dimensions: 242 (W) x 175 (D) x 35.5 (H) mm/9.5 (W) x 6.9 (D) x 1.4 (H) inch
- Weight: 1.2 Kg/2.6 lbs
Environmental Specifications
- Operating temperature: 0ºC ~ 50ºC/32ºF ~ 122ºF
- Storage temperature: -30ºC ~ 60ºC/-22ºF ~ 140ºF
- Operating humidity: 5% ~ 90% (noncondensing)
Power Requirements
- Input: 100 ~ 240 V; 1.2 A, 50 ~ 60 Hz
- Output: 12 V; 3.5 A