Logo of NSFOCUS
English Version Chinese Version Japanese Version
Products
NSFOCUS WAF
NSFOCUS ADS
NSFOCUS NTA
NSFOCUS NIPS
NSFOCUS RSAS
NSFOCUS WebSafe
Solutions
SP MAN Core Network
SP Netbar and Dedicated Internet Access
MAN IDC
NSFOCUS Network Intrusion Prevention System
Overview

Security threats and attacks at the application layer are becoming more complex and more sophisticated. More than ever, you need to achieve the highest level of effective network intrusion security; it's critical to maintaining the high level of protection that keeps your business running.

NSFOCUS's Network Intrusion Prevention System (NIPS) provides the answer. It is a next-generation inline-deployed security gateway, providing a comprehensive and easy-to-use solution that identifies, classifies and stops known and unknown malicious traffic and threats to your network. With its advanced built-in web reputation evaluation, online behavior management and traffic control engines, NSFOCUS's NIPS delivers high-performance security effectiveness, manageability, stability and reliability in threat detection and protection, ensuring network availability and business continuity.

Features and Benefits
  • Bi-directional Intrusion Prevention at Layer 2-7
    Blocks Trojans, web-based malware and other attacks, utilizing functions like web reputation and Internet behavior management. Additionally, NIPS protects servers from malicious scanning, buffer overflow, denial of service, SQL injection, XSS, and so on.
  • Intelligent Protocol Discovery and Analysis Technology
    Identifies common/uncommon attacks to protect hundreds of main application protocols, with minimum false positives.
  • Zero-Day Attack Prevention
    NSFOCUS's exclusive "Virtual PatchSM" technology protects users from "zero-day" attacks and new threats, before vulnerabilities can be exploited.
  • Intrusion Prevention
    Provides proactive and real-time protection against potential network or information breaches.
  • Extendable and Customized Prevention
    Supports self-defining prevention policies that help companies meet customized requirements (e.g., based on compliance demands) and to create new policies for the prevention of newly discovered threats.
  • Comprehensive Web Threat Prevention
    Provides all-around, in-depth analysis to HTTP protocols. A dynamic, comprehensive and reliable website reputation database efficiently blocks users' access to potentially dangerous URLs. Stops web-based malware, ActiveX controls and more.
  • Traffic Control
    Blocks all unauthorized traffic and optimizes bandwidth for key applications, ensuring maximum IT output.
  • Behavior Management
    Monitors and manages online behavior such as Instant Messaging (IM), Peer-to-Peer (P2P) downloads, online games, online videos, and online stock transactions, helping administrators identify and limit unauthorized traffic, as well as better implement security and usage policies.

  • Powerful Processing Capability
    Supports multi-core parallel processing for increased efficiency, higher throughput and lower performance delay rate. NIPS' multi-gigabit processing capacity handles 64-byte to 1518-byte packets, delivering efficient traffic filtering and management without affecting business operations.
  • High Availability
    Offers high availability solutions and supports "Active/Active" and "Active/Standby" configurations, as well as built-in bypass and hardware bypass deployment solutions, thus allowing for automated redundancy and failover, and ensuring constant uptime.


 
Application Scenario
NSFOCUS's NIPS is tailored to protect both the network border and intranet in sophisticated network deployments typically found in enterprises with both headquarters and branch offices, providing a blended solution that simplifies deployment and achieves full-featured protection.

 
Specifications

Model
Specification

NIPS 200 Series

NIPS 600 Series

NIPS 1000 Series

NIPS 1200 Series

NIPS
2000 Series

NIPS
4000 Series

 

Physical Interface

Operation Interface

4*100M copper port

8*100M copper port

10*1000M interface (SMF, MMF, and copper optional)

8*1000M interface (SMF, MMF, and copper optional)

8*1000M interface (SMF, MMF, and copper ports optional)

2*1000M copper port
4* slot (SMF, MMF, copper, and SFP+ mode optional)

Serial Port

1*RS232

1*RS232

1*RJ45

1*RJ45

1*RJ45

1*RJ45

 

Performance Index

Throughput

≤ 200Mbps

≤ 600Mbps

≤ 800Mbps

≤ 1.2Gbps

≤ 3Gbps

≤ 5Gbps

Concurrent TCP Sessions

≤ 150,000

≤ 200,000

≤ 500,000

≤ 1,000,000

≤ 1,500,000

≤ 4,000,000

New TCP Sessions Per Second

≤ 100,000

≤ 150,000

≤ 200,000

≤ 300,000

≤ 500,000

≤ 800,000

Packet Processing Capability

≤200,000 pps

≤320,000 pps

≤600,000 pps

≤1,000,000 pps

≤3,000,000 pps

≤5,000,000 pps

Delay 

<100 μs

<100 μs

<100 μs

<100 μs

<100 μs

<100 μs

Max. Number of Policies

500

1,000

2,000

4,000

6,000

8,000

 

Physical Characteristics

Dimension (D*W*H)

320*428*44.5mm (1U)

320*428*44.5mm (1U)

440*392*88mm (2U)

528*426*88mm (2U)

512*430*88mm (2U)

546*430*88mm (2U)

Weight 

5.4 kg

5.4 kg

12 kg

14 kg

14 kg

18kg

Power
Supply

100-240V , AC, (50-60HZ), 4A, 180W

100-240V , AC, (50-60HZ), 4A, 180W

100-240V, AC, (50-60HZ), 5-8A, 350W

100-240V, AC, (50-60HZ), 5-8A, 350W

100-240V, AC, (50-60HZ), 5-8A, 400W

100-240V, AC, (50-60HZ), 5-10A, 600W

-36--72V, DC, 25A, 350W

-36--72V, DC, 25A, 350W

-36-72V, DC, 25A, 400W

-36-72V, DC, 25A, 600W

Mean Time Between Failure (MTBF)

 > 100,000 hours

 > 100,000 hours

 > 100,000 hours

 > 100,000 hours

 > 100,000 hours

 > 100,000 hours

  ©2010