Zyxel Usgflex100 Hardware Firewall Specifications And Datasheet

Zyxel Usgflex100 Hardware Firewall Specifications And Datasheet

Zyxel-logo

Zyxel USGFLEX100 Hardware Firewall

Zyxel-USGFLEX100-Hardware-Firewall-Product

Introduction

The latest USG FLEX 100 provides one single management platform on the cloud while expanding and strengthening the protection from firewalls to access points with automatic responses. The newly designed USG FLEX Series is capable of minimizing computing power usage and maximizing firewall performance, delivering up to 5x UTM performance with cloud flexibility and collaborative protection to help connect and secure small or mid-sized business users.

Benefits

Zyxel-USGFLEX100-Hardware-Firewall-fig-1

  • Flexibility to adapt to on-premises or Nebula cloud management
  • Precise detection with cloud query express mode
  • High-assurance multi-layered protection
  • DNS and URL content filter ensures the web security
  • Device Insight provides better visibility and control
  • Automatically contains threats at the network edge
  • Secure WiFi guarantees remote work security
  • Add two-factor authentication for an extra layer of protection

Nebula together

USG FLEX firewalls, the new addition to the Nebula cloud management family, strongly empowers the full-blown Zyxel security matrix in Nebula, further optimizing Nebula with holistic security and protection for SMB business networks. Zyxel provides a centralized provisioning security policy to the remote workforce from Nebula and traffic shaping eliminating the network bottleneck to fuel the best business productivity.

Zyxel-USGFLEX100-Hardware-Firewall-fig-2

Zero trust networks security
Remote working is here to stay, USG FLEX series applies the principles of zero trust access. It ensures the same security controls are applied to HQ, branch offices, homes, or wherever your remote workers reside. Create an access policy with device contextual such as OS version or device category to enforce network segmentation. This reduces the attack surface and prevents threats from spreading.

Zyxel-USGFLEX100-Hardware-Firewall-fig-3

High-assurance multi-layered protection
USG FLEX is designed with multi-layer protection against multiple types of threats from in and out. Multiple security services empower you to restrict users’ inappropriate application usage or web access. Zyxel offers a leading-industry DNS content filter, eliminating blind spots in all encrypted traffic with TLS 1.3 without the need to deploy SSL inspection. All together safeguarding your network without any unattended gaps.

Zyxel-USGFLEX100-Hardware-Firewall-fig-4

Best threat intelligence alliance
To ensure your network on getting the best protection, USG FLEX integrates threat intelligence from leading companies and organizations in the cybersecurity field for scaled information about file and real-time threat data. By leveraging a wider malware coverage with multiple-sourced database, this increases the accuracy in threat detection. Web Filtering is also included to safeguard all internet access, especially with CTIRU (Counter-Terrorism Internet Referral Unit) to restrict access to terrorist materials online.

Zyxel-USGFLEX100-Hardware-Firewall-fig-5

Simplified and unified licensing experience
We know the experience from license purchase and renewals are equally important to our partners. We’ve optimized the licensing management platform and brought a consistent migration path between on-premise and our cloud platform. We make sure our partners can quickly adapt to a secure environment without the hassle but retain the flexibility for those who need to practice the same security across network scenarios.

Zyxel-USGFLEX100-Hardware-Firewall-fig-6

Safeguarding remote connectivity to your corporate network
Businesses striking a balance on productivity and security protection becomes a priority with growing number of devices. Whether it is a wired, wireless, or a IoT device, the Secure WiFi service is used to build a secure L2 tunnel for Work-From-Home user to extend the working experience easily and securely, as if you were in the office with the safety of both two-factor authentication and secure tunnel, which boosts up productivity and eases IT support. The Secure WiFi service also unlocks the number of managed APs to maximum for the USG FLEX firewall.

Zyxel-USGFLEX100-Hardware-Firewall-fig-7

Level up security with 2FA network access
Password is not enough to secure your network access. You need a second form of authentication to ensure unauthorized users can’t access your company’s databases, email accounts and more. Zyxel Two-Factor Authentication allows your organizations to authenticate the identities of users accessing your networks through remote desktops and personal mobile devices.

Zyxel-USGFLEX100-Hardware-Firewall-fig-8

Deep Insights into all your devices
Device insight gives you more visibility of your networks including wired, wireless, BYOD, and IoT devices. You can create access policy with device contextual such as OS version or device category to enforce network segmentation. This reduces the attack surface and prevents threats from spreading. It also helps SMB(s) reduce time spent on investigation. Continuing with our goal of providing our customers with increased visibility, Zyxel SecuReporter gives your organization a comprehensive endpoint inventory dashboard.

Zyxel-USGFLEX100-Hardware-Firewall-fig-9

Stay ahead of threats with CDR
Collaborative Detection & Response (CDR) is used to identify threats and risks posed in the more complex organization workforce, workload, and workplace. USG FLEX firewalls to Nebula provide network admins with a rule-based security policy. The firewalls detect a threat on any of the connected clients and will sync with the Nebula control center, then automatically respond to cyber threats and contain the device(s) at the edge (Wireless Access Point) of your network. It is a perfect fit for IT to address the requirements of a decentralized network infrastructure and provide automatic protection.

Zyxel-USGFLEX100-Hardware-Firewall-fig-10

Comprehensive web filtering service
USG FLEX Firewall delivers enhanced web filtering functionality and security through its powerful combination of both reputation and category-based filtering. Dynamic content categorization analyzes the content of a previously unknown website and domain and determines if it belongs to an undesirable category including gambling, pornography, games, and many others. A newly added DNS content filter offers a better approach to inspect web access, particularly when the website is deploying ESNI (Encrypted Server Name Indication) where the traditional URL filtering failed to identify the destination domain.

Zyxel-USGFLEX100-Hardware-Firewall-fig-11

Analytics report and enhanced insights
USG FLEX series dashboard gives user-friendly traffic summary and threat statistic visuals. Utilize SecuReporter for further threat analysis with correlation feature design, making it easy to proactively trackback network status to prevent the next threat event. Centralized visibility of network activities for you to easily manage multiple clients.

Zyxel-USGFLEX100-Hardware-Firewall-fig-12

Comprehensive connectivity
We also provide Wireless Health Monitor giving you visibility into the connection state of client and access point issues, allowing network administrators to easily troubleshoot issues.

Zyxel-USGFLEX100-Hardware-Firewall-fig-13

Hardware Included License

Zyxel-USGFLEX100-Hardware-Firewall-fig-14

  1. UTM Pack Included: 30 Days Trial+1Year / Device Only: 30 Days Trial
  2. Hotspot Management is available on USG FLEX 200/500/700 only
  3. Allowing additional connected clients is available to USG FLEX 500/700 only
  4. Nebula Professional Pack will only be offered to users who have purchased UTM Pack
License ServiceFeature
UTM License
Web FilteringBlock access to malicious or risky web sites
IPSDeep-packet inspection against known attacks from Network
Application PatrolAutomatically categorize and manage the network application usage
Anti-MalwareScan files at the gateway or Zyxel security cloud for malware and other threats
Collaborative Detection & ResponseAutomatically contain threats at the network edge
Email SecurityFast detection to block spam/phishing mail with malicious contents
SecuReporterCloud-based intelligent analytics and report
Security Profile SyncAn easy-to-use tool to help business sync up security profiles across multiple networks
Hospitality License
Hotspot ManagementVarious Network Access Control
Concurrent deviceTop up allowed number of connected clients

Specifications

ModelUSG FLEX 100USG FLEX 100WUSG FLEX 200
Product photoZyxel-USGFLEX100-Hardware-Firewall-Product  

 

 

Hardware Specifications
WiFi Standard802.11 a/b/g/n/ac
10/100/1000 Mbps RJ-45 ports4 x LAN/DMZ, 1 x WAN,

1 x SFP

4 x LAN/DMZ, 1 x WAN,

1 x SFP

4 x LAN/DMZ, 2 x WAN,

1 x SFP

USB3.0 ports112
Console portYes (RJ-45)Yes (RJ-45)Yes (DB9)
Rack-mountableYes
FanlessYesYesYes
System Capacity & Performance*1
SPI firewall throughput (Mbps)*29009001,800
VPN throughput (Mbps)*3270270450
VPN IMIX throughput (Mbps)*3100100160
IPS throughput (Mbps)*45405401,100
AV throughput (Mbps)*4360360570
UTM throughput (AV and IPS)*4360360550
Max. TCP concurrent sessions*5300,000300,000600,000
Max. concurrent IPsec VPN tunnels*64040100
Concurrent SSL VPN users303060
VLAN interface8816
Concurrent devices logins (default/max.)*7*86464200
Speedtest Performance
SPI firewall throughput (Mbps)*11760760810
Security Features
Anti-Malware*7YesYesYes
IPS*7YesYesYes
Application Patrol*7YesYesYes
Email SecurityYesYesYes
Web filtering*7YesYesYes
SecuReporter Premium*7YesYesYes
Collaborative Detection & Response*7YesYesYes
SSL (HTTPS) InspectionYesYesYes
Device InsightYesYesYes
2-Factor AuthenticationYesYesYes
VPN Features
VPNIKEv2, IPSec, SSL, L2TP/IPSecIKEv2, IPSec, SSL, L2TP/IPSecIKEv2, IPSec, SSL, L2TP/IPSec
Microsoft AzureYesYesYes
Amazon VPCYesYesYes
WLAN Management
Default Number of Managed AP888
Recommend max. AP in 1 AP Group101020
Secure WiFi Service*7YesYesYes
Maximum No. of Tunnel-Mode AP6610
Maximum No. of Managed AP242440
ModelUSG FLEX 100USG FLEX 100WUSG FLEX 200
Connectivity Management
Cloud-managed (Nebula) ModeYesYesYes
Hotspot Management*7Yes
Ticket printer support*9/ Support Qty (max.)Yes (SP350E) / 10
Device HA Pro
Power Requirements
Power input12V DC, 2A max.12V DC, 2A max.12V DC, 2.5A max.
Max. power consumption (Watt Max.)12.512.513.3
Heat dissipation (BTU/hr)42.6542.6545.38
Physical Specifications
ItemDimensions (WxDxH) (mm/in.)216 x 147.3 x 33/

8.50 x 5.80 x 1.30

216 x 147.3 x 33/

8.50 x 5.80 x 1.30

272 x 187 x 36/

10.7 x 7.36 x 1.42

Weight (Kg/lb.)0.85/1.870.85/1.871.4/3.09
PackingDimensions (WxDxH) (mm/in.)284 x 190 x 100/

11.18 x 7.48 x 3.94

284 x 190 x 100/

11.18 x 7.48 x 3.94

427 x 247 x 73/

16.81 x 9.72 x 2.87

Weight (kg/lb.)1.40/3.091.40/3.092.23 (W/O bracket)

2.42 (W/ bracket)

Included accessories•  Power adapter

•  RJ-45 – RS-232 cable for console connection

•  Power adapter

•  RJ-45 – RS-232 cable for console connection

•  Power adapter

•  Rack mounting kit

Environmental Specifications
OperatingTemperature0°C to 40°C/

32°F to 104°F

0°C to 40°C/

32°F to 104°F

0°C to 40°C/

32°F to 104°F

Humidity10% to 90%

(non-condensing)

10% to 90%

(non-condensing)

10% to 90%

(non-condensing)

StorageTemperature-30°C to 70°C/

-22°F to 158°F

-30°C to 70°C/

-22°F to 158°F

-30°C to 70°C/

-22°F to 158°F

Humidity10% to 90%

(non-condensing)

10% to 90%

(non-condensing)

10% to 90%

(non-condensing)

MTBF (hr)989810.8989810.8529688.2
Certifications
EMCFCC Part 15 (Class B), CE EMC (Class B),BSMIFCC Part 15 (Class B), CE EMC (Class B),BSMIFCC Part 15 (Class B), CE EMC (Class B),

C-Tick (Class B), BSMI

SafetyLVD (EN60950-1), BSMILVD (EN60950-1), BSMILVD (EN60950-1), BSMI
  1. This matrix with firmware ZLD5.2 or later.
  2. Actual performance may vary depending on system configuration, network conditions, and activated applications.
  3. Maximum throughput based on RFC 2544 (1,518-byte UDP packets).
  4. VPN throughput measurements are based on RFC 2544 (1,424-byte UDP packets); IMIX: UDP throughput based on a combination of 64-byte, 512-byte, and 1424-byte packet sizes.
  5. AV (with Express Mode) and IPS throughput were measured using the industry standard HTTP performance test (1,460-byte HTTP packets). Testing done with multiple flows.
  6. Maximum sessions measured using the industry standard IXIA IxLoad testing tool
  7. Including Gateway-to-Gateway and Client-to-Gateway.
  8. With Zyxel service license to enable or extend the feature capacity.
  9. This is the recommended maximum number of concurrent logged-in devices.
  10. SafeSearch function in CF needs to enable SSL inspection firstly and not for small business models.
  11. With Hotspot Management license support
  12. The Speedtest result is conducted with a 1Gbps WAN link in the real world and it is subject to fluctuation due to the quality of the ISP link.

Wireless Specifications

ModelUSG FLEX 100W
Standard compliance802.11 a/b/g/n/ac
Wireless frequency2.4 / 5 GHz
Radio2
SSID number4
Maximum transmit power (Max. total channel)US (FCC) 2.4 GHz25 dBm, 3 antennas
US (FCC) 5 GHz25 dBm, 3 antennas
EU (ETSI) 2.4 GHz20 dBm(EIRP), 3 antennas
EU (ETSI) 5 GHz20 dBm(EIRP), 3 antennas
No. of antenna3 detachable antennas
Antenna gain2 dBi @ 2.4GHz 3 dBi @ 5 GHz
Data rate•  802.11n: up to 450Mbps

•  802.11ac: up to 1300Mbps

Frequency Band2.4 GHz

(IEEE 802.11 b/g/n)

•  USA (FCC): 2.412 to 2.462 GHz

•  Europe (ETSI): 2.412 to 2.472 GHz

•  TWN (NCC): 2.412 to 2.462 GHz

5 GHz

(IEEE 802.11 a/n/ac)

•  USA (FCC): 5.150 to 5.250 GHz; 5.250 to 5.350 GHz;

5.470to 5.725 GHz; 5.725 to 5.850 GHz

•           Europe (ETSI): 5.15 to 5.35 GHz; 5.470 to 5.725 GHz

•  TWN (NCC): 5.15 to 5.25 GHz; 5.25 to 5.35 GHz;

5.470 to 5.725 GHz; 5.725 to 5.850 GHz

Receive sensitivity2.4 GHz11 Mbps ≤ -87 dBm

54 Mbps ≤ -74 dBm

HT20 ≤ -71 dBm HT40 ≤ -68 dBm
5 GHz54 Mbps ≤ -74 dBm HT40, MCS23 ≤ -68 dBm VHT40, MCS9 ≤ -62 dBmHT20, MCS23 ≤ -71 dBm VHT20, MCS8 ≤ -66 dBm VHT80, MCS9 ≤ -59 dBm

Software Features

Security Service

Firewall 

  • ICSA-certified corporate firewall
  • Routing and transparent (bridge) modes
  • Stateful packet inspection
  • SIP NAT traversal
  • H.323 NAT traversal*2
  • ALG support for customized ports
  • Protocol anomaly detection and protection
  • Traffic anomaly detection and protection
  • Flooding detection and protection
  • DoS/DDoS protection

Unified Security Policy

  • Unified policy management interface
  • Support Content Filtering, Application Patrol, firewall (ACL)
  • Firewall: SSL inspection*2
  • Policy criteria: source and destination IP address, user group, time
  • Policy criteria: zone, user*2

Intrusion Prevention System (IPS)

  • Support both intrusion detection and prevention
  • Support allowlist (whitelist) to deal with false positives involving known benign activity*2
  • Support rate-based IPS signatures to protect networks against application-based DoS and brute force attacks*2
  • Signature-based and behavior-based scanning
  • Support exploit-based and vulnerability-based protection
  • Support Web attacks like XSS and SQL injection
  • Streamed-based engine
  • Support SSL inspection*2
  • Inspection on various protocols: HTTP, FTP, SMTP, POP3, and IMAP
  • Inspection on various protocols: HTTPs, FTPs, SMTPs, POP3s, and IMAPs*2
  • Customizable signature & protection profile*2
  • Automatic new signature update mechanism support

Application Patrol 

  • Smart single-pass scanning engine
  • Identifies and control thousands of applications and their behaviors
  • Support up to 25 application categories
  • Granular control over the most popular applications
  • Prioritize and throttle application
  • Real-time application statistics and reports
  • Identify and control the use of DoH (DNS over HTTPS)

Anti-Malware

  • High performance query-based scan engine (Express Mode)
  • Works with over 30 billion of known malicious file identifiers and still growing
  • Multiple file types supported
  • Stream-based scan engine (Stream Mode)
  • No file size limitation
  • HTTP, FTP, SMTP, and POP3 protocol supported
  • SSL inspection support*2
  • Automatic signature update

E-mail Security*2

  • Transparent mail interception via SMTP and POP3 protocols
  • Spam and Phishing mail detection
  • Block and Allow List support
  • Supports DNSBL checking

URL Threat Filter

  • Botnet C&C websites blocking
  • Malicious URL blocking
  • Supports External URL blacklist

Web Filtering

  • HTTPs domain filtering
  • SafeSearch support
  • Allow List websites enforcement
  • URL Block and Allow List with keyword blocking
  • Customizable warning messages and redirect URL
  • Customizable Content Filtering block page
  • URL categories increased to 111
  • CTIRU (Counter-Terrorism Internet Referral Unit) support
  • Support DNS base filtering (domain filtering)

IP Exception

  • Provides granular control for target source and destination IP
  • Supports security service scan bypass for IPS, Anti-Malware and URL Threat Filter

Device Insight*2

  • Agentless scanning for discovery and classification of devices
  • Provide the dashboard to view all devices on the network, including wired, wireless, BYOD, IoT, and SecuExtender (remote endpoint)
  • Extended view of the inventory on SecuReporter
  • Visibility of network devices (switches, wireless access points, firewalls) from

Collaborative Detection & Response (CDR)

  • Support Alert/Block/Quarantine containment actions
  • Prevent malicious wireless clients network access with a blocking feature
  • Customizable warning messages and redirect URL
  • Bypass by IP or MAC address with exempt list

VPN

IPSec VPN

  • Key management: IKEv1 (x-auth, mode-config), IKEv2 (EAP, configuration payload)
  • Encryption: DES, 3DES, AES (256-bit)
  • Authentication: MD5, SHA1, SHA2 (512-bit)
  • Perfect forward secrecy (DH groups) support 1, 2, 5, 14, 15-18, 20-21
  • PSK and PKI (X.509) certificate support
  • IPSec NAT traversal (NAT-T)
  • Dead Peer Detection (DPD) and relay detection
  • VPN concentrator
  • Route-based VPN Tunnel Interface (VTI)
  • VPN high availability (Failover, LB)
  • GRE over IPSec*2
  • NAT over IPSec
  • L2TP over IPSec
  • SecuExtender Zero Trust VPN Client
  • Support native Windows, iOS/macOS and Android (StrongSwan) client provision*2
  • Support 2FA Email/SMS*2
  • Support 2FA Google Authenticator

SSL VPN*2

  • Supports Windows and Mac OS X
  • Supports full tunnel mode
  • Supports 2-Factor authentication

Networking

Secure WiFi

  • Secure Tunnel for Remote AP
  • L2 access between home office and HQ (Secured Tunnel)
  • GRE Tunnel for Campus AP
  • Enforcing 2FA with Google Authenticator
  • WPA2 Enterprise (802.1x) supported
  • Wireless Storm Control
  • Applicable regardless of the On-premise/Nebula-managed mode of the USG FLEX

WLAN Management*2

  • Supports AP Controller (APC) version 60
  • 11ax Wi-Fi 6 AP and WPA3 support
  • 11k/v/r support
  • Wireless L2 isolation
  • Supports auto AP FW update
  • Scheduled WiFi service
  • Dynamic Channel Selection (DCS)
  • Client steering for 5 GHz priority and sticky client prevention
  • Auto healing
  • Customizable captive portal page
  • WiFi Multimedia (WMM) wireless QoS
  • CAPWAP discovery protocol
  • Multiple SSID with VLAN
  • Supports ZyMesh
  • Support AP forward compatibility
  • Rogue AP Detection

Mobile Broadband*2

  • WAN connection failover via 3G and 4G* USB modems
  • Auto fallback when primary WAN recovers

IPv6 Support*2

  • Dual stack
  • IPv4 tunneling (6rd and 6to4 transition tunnel)
  • SLAAC, static IP address
  • DNS, DHCPv6 server/client
  • Static/Policy route
  • IPSec (IKEv2 6in6, 4in6, 6in4)

Connection

  • Routing mode
  • Bridge mode and hybrid mode*2
  • Ethernet and PPPoE
  • NAT and PAT
  • NAT Virtual Server Load Balancing
  • VLAN tagging (802.1Q)
  • Virtual interface (alias interface)
  • Policy-based routing (user-aware)*2
  • Policy-based NAT (SNAT)
  • GRE*2
  • Dynamic routing (RIPv1/v2 and OSPF, BGP)*2
  • DHCP client/server/relay
  • Dynamic DNS support
  • WAN trunk for more than 2 ports
  • Per host session limit
  • Guaranteed bandwidth
  • Maximum bandwidth
  • Priority-bandwidth utilization
  • Bandwidth limit per user*2
  • Bandwidth limit per IP
  • Bandwidth management by application
  • Link Aggregation support*1 *2

Management

Nebula Cloud Management*3

  • Unlimited Registration & Central Management (Configuration, Monitoring, Dashboard, Location Map & Floor Plan Visual) of Nebula Devices
  • Zero Touch Auto-Deployment of Hardware/Configuration from Cloud
  • Over-the-air Firmware Management
  • Central Device and Client Monitoring (Log and Statistics Information) and Reporting
  • Security Profile Sync

Authentication

  • Local user database
  • External user database: Microsoft Windows Active Directory, RADIUS, LDAP
  • Cloud user database*3
  • IEEE 1x authentication
  • Captive portal Web authentication
  • XAUTH, IKEv2 with EAP VPN authentication
  • IP-MAC address binding
  • SSO (Single Sign-On) support*2
  • Supports 2-factor authentication (Google Authenticator, SMS*2/Email*2)

System Management

  • Role-based administration
  • Multi-lingual Web GUI (HTTPS and HTTP)
  • Command line interface (console, web console, SSH and telnet)*2
  • SNMP v1, v2c, v3
  • System configuration rollback*2
  • Configuration auto backup*2
  • Firmware upgrade via FTP, FTP-TLS*2
  • Firmware upgrade via Web GUI*2
  • New firmware notify and auto upgrade
  • Dual firmware images
  • Cloud CNM SecuManager*2

Logging and Monitoring

  • Comprehensive local logging
  • Syslog (to up to 4 servers)
  • Email alerts (to up to 2 servers)
  • Real-time traffic monitoring
  • Built-in daily report
  • Cloud CNM SecuReporter
  1. For specific models supporting the 3G and
  2. 4G dongles on the list, please refer to the Zyxel product page at the 3G dongle document
  3. Supported models USG FLEX 500/700
  4. Only supported in On-Premise mode
  5. Only supported in Cloud mode

Access Point Compatibility List

Secure Tunnel for Remote AP

FunctionsRemote APNumber of Tunnel Mode APSupported Remote AP
ATPATP100(W)6•  WAX650S

•  WAX610D

•  WAX510D

•  WAC500

•  WAC500H

ATP20010
ATP50018
ATP70066
ATP800130
USG FLEXUSG FLEX100(W)6
USG FLEX20010
USG FLEX50018
USG FLEX700130
VPNVPN5010
VPN10018
VPN30066
VPN1000258

Managed AP Service

ProductUnified APUnified Pro AP
Models•  NWA5301-NJ•  WAC5302D-S•  WAC6103D-I•  WAC6502D-E
•  NWA5121-NI•  WAC5302D-Sv2•  WAC6303D-S•  WAC6553D-E
•  NWA5123-NI•  WAC500*•  WAC6502D-S•  WAX610D
•  NWA5123-AC•  WAC500H*•  WAC6503D-S•  WAX630S*1
•  NWA5123-AC HD*•  WAX510D*•  WAC6552D-S•  WAX650S
Functions
Central managementYesYes
Auto-provisioningYesYes
Data forwardingLocal bridgeLocal bridge/Data tunnel
ZyMeshYesYes
*: Support both local bridge and data tunnel for data forwarding

*1: WAX630S will be available in January 2022

  1. Support both local bridge and data tunnel for data forwarding
  2. WAX630S will be available in January 2022
Service Gateway Printer
ModelFeatureSupported Model
SP350E•  Buttons: 3

•  Paper roll width: 58 (+0/-1) mm

•  Interface: 10/100 Mbps RJ-45 port

•  Power input: 12V DC, 5A max.

•  Item dimensions (WxDxH): 176 x 111 x 114 mm

(6.93” x 4.37” x 4.49”)

•  Item weight: 0.8 kg (1.76 lb.)

•  USG FLEX 200

•  USG FLEX 500

•  USG FLEX 700

•  VPN50

•  VPN100

•  VPN300

•  VPN1000

•  USG60(W)

•  USG110

•  USG210

•  USG310

•  USG1100

•  USG1900

•  USG2200 Series

•  ZyWALL 110

•  ZyWALL 310

•  ZyWALL 1100

*: Hotspot management licenses required
Transceivers (Optional)
ModelSpeedConnectorWavelengthMax. DistanceOptical Fiber TypeDDMI
SFP10G-SR*10-Gigabit

SFP+

Duplex LC850 nm300 m/

328 yd

Multi ModeYes
SFP10G-LR*10-Gigabit

SFP+

Duplex LC1310 nm10 km/

10936 yd

Single ModeYes
SFP-1000TGigabitRJ-45100 m/

109 yd

Multi Mode
SFP-LX-10-DGigabitSingle LC1310 nm10 km/

10936 yd

Single ModeYes
SFP-SX-DGigabitSingle LC850nm550 m/

601 yd

Multi-ModeYes
SFP-BX1310-10-D*1GigabitSingle LC1310 nm(TX)

1490 nm(RX)

10 km/

10936 yd

Single ModeYes
SFP-BX1490-10-D*1GigabitSingle LC1490 nm(TX)

1310 nm(RX)

10 km/

10936 yd

Single ModeYes
*: only USG2200-VPN supports 10-Gigabit SFP+

*1: SFP-BX1310-10-D and SFP-BX1490-10-D are must used in pairs.

For more product information, visit us on the web at www.zyxel.com
Copyright © 2021 Zyxel and/or its affiliates. All rights reserved. All specifications are subject to change without notice. Datasheet ZyWyWALL USALL USG FLEX 100G FLEX 100/100W/100W/2/20000/500/500/7/70000

Zyxel-USGFLEX100-Hardware-Firewall-fig-15

FAQ’s

What is the Zyxel USGFLEX100 Hardware Firewall?

The Zyxel USGFLEX100 is a hardware firewall designed to protect networks from external threats by providing advanced security features and network segmentation capabilities.

What security features does the USGFLEX100 offer?

The USGFLEX100 firewall offers a range of security features, including stateful packet inspection (SPI), intrusion detection and prevention system (IDPS), application control, web filtering, antivirus, anti-malware, and VPN support.

What is network segmentation, and how does the USGFLEX100 support it?

Network segmentation is the practice of dividing a network into smaller subnetworks to enhance security and control. The USGFLEX100 supports network segmentation by allowing administrators to create multiple virtual networks (VLANs) and define access rules between them.

What is SPI (Stateful Packet Inspection)?

SPI is a firewall technology that examines incoming and outgoing packets at the network layer to determine whether they should be allowed or blocked based on predefined security policies. The USGFLEX100 utilizes SPI to provide advanced traffic filtering and protection.

Does the USGFLEX100 support VPN (Virtual Private Network) connections?

Yes, the USGFLEX100 firewall supports VPN connections, allowing secure remote access to the network and enabling site-to-site connectivity between different locations.

Can the USGFLEX100 be managed remotely?

Yes, the USGFLEX100 can be managed remotely using Zyxel's security management software or web-based interface. It provides administrators with convenient access to configure and monitor the firewall from anywhere.

What is the throughput of the USGFLEX100 firewall?

The throughput of the USGFLEX100 firewall depends on various factors such as the selected security features, network conditions, and configuration. It is recommended to refer to the product specifications or consult with Zyxel for specific throughput information.

Does the USGFLEX100 provide protection against DDoS attacks?

Yes, the USGFLEX100 firewall offers protection against Distributed Denial of Service (DDoS) attacks by leveraging its IDPS and traffic filtering capabilities to identify and mitigate such attacks.

Can the USGFLEX100 integrate with existing security systems?

Yes, the USGFLEX100 supports integration with other security systems through its comprehensive set of APIs and protocols. This allows for seamless coordination with third-party security solutions for enhanced network protection.

What is the warranty period for the USGFLEX100?

The warranty period for the USGFLEX100 hardware firewall may vary. It is recommended to refer to the product documentation or contact Zyxel directly for specific warranty details.

Is technical support available for the USGFLEX100 firewall?

Yes, Zyxel provides technical support for the USGFLEX100 firewall. Customers can reach out to Zyxel's support channels for assistance with installation, configuration, and troubleshooting.

Can the USGFLEX100 be used in small and medium-sized businesses (SMBs)?

Yes, the USGFLEX100 is suitable for deployment in small and medium-sized businesses (SMBs) that require robust network security features. Its scalable design and ease of management make it a viable option for SMB network protection.

Download This PDF Link: Zyxel USGFLEX100 Hardware Firewall Specifications And Datasheet

Documents / Resouces

Download manual
Here you can download full pdf version of manual, it may contain additional safety instructions, warranty information, FCC rules, etc.


Related Manuals