
Model Comparison
Features Common to Both Models
ICSA-certified Firewall
• Zone-Based Access Control List
• Security Zones
• Stateful Packet Inspection
• DoS/DDoS Protection
• User-Aware Policy Enforcement
• ALG Supports Custom Ports
Intrusion Detection and Prevention
• In-line Mode (Routing/Bridge)
• Zone-Based IDP Inspection
• Customizable Protection Profile
• Signature-based Deep Packet Inspection
• Automatic Signature Updates**
• Custom Signatures
• Traffic Anomaly Detection and Protection
• Flooding Detection and Protection
• Protocol Anomaly Detection and Protection:
HTTP/ICMP/TCP/UDP
Anti-Virus
• ICSA-Certified ZyXEL Anti-Virus or Kaspersky
Anti-Virus
• Stream-Based Anti-Virus
• Covers Top Active Viruses in the Wild List
• Scans HTTP/FTP/SMTP/POP3/IMAP4
• Automatic Signature Updates**
• No File Size Limitation
• Blacklist/Whitelist Support
Hybrid VPN
ICSA-certified IPSec VPN
• Encryption: AES/3DES/DES
• Authentication: SHA-1/MD5
• Key Management: Manual Key/IKE
• Perfect Forward Secrecy: DH Group 1/2/5
• NAT over IPSec VPN
• Dead peer Detection/Relay Detection
• PKI (X.509) Certificate Support
• Certificate Enrollment (CMP/SCEP)
• Xauth Authentication
• L2TP over IPSec Support
SSL VPN
• Clientless Secure Remote Access
(Reverse Proxy Mode)
• SecuExtender (Full Tunnel Mode)
• Unified Policy Enforcement
• Supports Two-factor Authentication
• Customizable User Portal
Application Patrol
• IM/P2P Granular Access Control
• Apply Schedules, Bandwidth Management
• User-Aware
• IM/P2P Up-to-Date Support (based on IDP
signatures)**
• Real-Time Statistical Reports
Bandwidth Management
• Bandwidth Priority
• Policy-Based Traffic Shaping
• Maximum/Guaranteed Bandwidth
• Bandwidth Borrowing
Anti-Spam
• Zone to Zone Protection
• Transparently intercept mail via SMTP/POP3
protocols
• Blacklist/Whitelist support
• Support DNSBL checking
• Statistics report
High Availability
• Device HA (Active-Passive Mode)
• Device Failure Detection
• Link Monitoring
• Auto-Sync Configurations
• Multiple WAN Load Balancing
• VPN HA (Redundant Remote VPN Gateways)
Content Filtering
• URL Blocking, Keyword Blocking
• Exempt List (Blacklist and Whitelist)
• Blocks Java Applet,Cookies and Active X
• Dynamic URL Filtering Database (Powered by
BlueCoat)**
User Licenses
• Unlimited
Networking
• Routing Mode/Bridge Mode/Mixed Mode
• Layer 2 Port Grouping
• Ethernet/PPPoE/PPTP
• Tagged VLAN (802.1Q)
• Virtual Interface (Alias Interface)
• Policy-Based Routing (User-Aware)
• Policy-Based NAT (SNAT/DNAT)
• RIP v1/v2
• OSPF
• IP Multicasting (IGMP v1/v2)
• DHCP Client/Server/Relay
• Built-in DNS Server
• Dynamic DNS
Authentication
• Internal User Database
• Microsoft Windows Active Directory
• External LDAP/RADIUS User Database
• ZyWALL OTP (One Time Password)***
• Forced User Authentication (Transparent
Authentication)
System Management
• Role-Based Administration
• Multiple Administrator Login
• Multi-Lingual Web GUI (HTTPS/HTTP)
• Object-Based Configuration
• Command Line Interface (Console/Web
Console/SSH/TELNET)
• Comprehensive Local Logging
• Syslog (send to up to 4 servers)
• E-mail Alert (send to up to 2 servers)
• SNMP v2c (MIB-II)
• Real-Time Traffic Monitoring
• System Configuration Rollback
• Text-Based Configuration File
• Firmware upgrade via FTP/FTP-TLS/Web GUI
• Advanced Reporting (Vantage Report)
• Centralized Network Management (Vantage CNM)
3G Support
• Advanced Wireless Security Transmission with WEP
Encryption and WPA/WPA2 Support
• PCMCIA: Sierra Wireless AC850*
• USB: Huawei E220*
Model Name ZyWALL USG 100 ZyWALL USG 200
p to 25
p to 50
00 M
s
50 M
s
0 Mbps
5 Mbps
4 Mbps
0 Mbps
,
,
,
,4
0
00
, up
radeable to 5**
, up
radeable to 10**
1
AN1,WAN2
LAN
WLAN
DMZ
r
PT Port
Use as WAN/LAN1/LAN2/DMZ
LAN
WLAN
DMZ Ports
*: Not included.
**: Requires a valid subscription.
***: Sold separately.
inside