---
title: "Firewall types"
sidebar_label: "Firewall types"
sidebar_position: 1
description: "Comparison of hardware and virtual firewalls, specifications of available models"
---

import Formbricks from '@theme/MDXComponents/Formbricks'
import {CustomTable} from 'docs-kit/components'

# Firewall types

You can rent two types of firewalls:

* [hardware firewall](#hardware-firewalls) — a dedicated device for traffic processing;
* [virtual firewall](#virtual-firewalls) — software deployed in a virtual environment, for example, on a [cloud server](/cloud-servers/) or in a [public VMware-based cloud](/public-cloud/).

## Comparison of hardware and virtual firewalls \{#hardware-and-virtual-firewalls-comparison}

<CustomTable>
  <table>
    <thead>
      <tr>
        <th />

        <th>[Hardware](#hardware-firewalls)</th><th>[Virtual](#virtual-firewalls)</th>
      </tr>
    </thead>

    <tbody>
      <tr>
        <th>In what form it is provided</th><td>Firewall mounted in a rack and connected to the public and local network</td><td>Licensed firewall image.<br />You deploy the image yourself in the selected product — on a cloud server, or in a public or private VMware-based cloud</td>
      </tr>

      <tr>
        <th>FSTEC certification</th><td>Type A certificates (Continent and UserGate models are certified)</td><td>Type B certificates</td>
      </tr>

      <tr>
        <th>Changing the configuration (number of vCPUs, amount of RAM, and disk size)</th><td>[Order](/firewalls/order/order-hardware-firewall.mdx) a different model and reconfigure it</td><td>[Order](/firewalls/order/order-virtual-firewall.mdx) the service again and change the configuration of the server on which the image is deployed. No reconfiguration required</td>
      </tr>

      <tr>
        <th>Connectivity with the protected infrastructure in one private subnet</th><td>Possible with dedicated servers in one pool. Otherwise, you must use a [Global Router](/global-router/about-global-router.mdx) to establish connectivity</td><td>Possible with cloud servers in one pool or virtual machines in one VMware organization. Otherwise, you must use a [Global Router](/global-router/about-global-router.mdx) to establish connectivity</td>
      </tr>

      <tr>
        <th>What is included in the price</th><td>Hardware firewall with a public address</td>

        <td>
          Firewall image with license:

          * for the selected functionality;
          * and [additional modules](#additional-modules).

          The infrastructure where the image is deployed is paid for separately
        </td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## Hardware firewalls \{#hardware-firewalls}

<CustomTable>
  <table data-sticky>
    <thead>
      <tr>
        <th />

        <th>Selectel</th><th>Fortinet FG-100E</th><th>Fortinet FG-500E</th><th>UserGate C150</th><th>UserGate D200</th><th>UserGate D500</th><th>Cisco 5508</th><th>Continent 4 IPC-R550</th><th>CheckPoint Quantum Spark 1800</th>
      </tr>
    </thead>

    <tbody>
      <tr>
        <th>Firewall throughput,<br />Gbit/s</th><td>0.9</td><td>7.4</td><td>36</td><td>3.8</td><td>18</td><td>20</td><td>0.5</td><td>6</td><td>7.5<br />17 for 1518 UDP</td>
      </tr>

      <tr>
        <th>IPS throughput,<br />Gbit/s</th><td>0.9</td><td>✗</td><td>✗</td><td>0.4</td><td>1.8</td><td>2</td><td>0.125</td><td>2</td><td>5.5</td>
      </tr>

      <tr>
        <th>IPSec VPN throughput,<br />Gbit/s</th><td>0.9</td><td>4</td><td>20</td><td>3</td><td>14</td><td>16</td><td>0.175</td><td>1</td><td>4</td>
      </tr>

      <tr>
        <th>SSL-VPN throughput,<br />Gbit/s</th><td>0.9</td><td>0.25</td><td>5</td><td>3</td><td>14</td><td>16</td><td>0.125</td><td>✗</td><td>2</td>
      </tr>

      <tr>
        <th>Available interfaces</th><td>2×1GE RJ45</td><td>16×1GE RJ45</td><td>8×1GE RJ45<br />2×10GE SFP</td><td>8×1GE RJ45</td><td>5×1GE RJ45<br />2×1GE SFP</td><td>5×1GE RJ45<br />2×1GE SFP</td><td>8×1GE RJ45</td><td>4×1GE RJ45<br />2x10GE SFP<br />2xCombo RJ45<br />2xCombo SFP</td><td>16×1GE RJ45</td>
      </tr>

      <tr>
        <th>FSTEC certification</th><td>✗</td><td>✗</td><td>✗</td><td>✓</td><td>✓</td><td>✓</td><td>✗</td><td>✓</td><td>✗</td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## Virtual firewalls \{#virtual-firewalls}

To ensure throughput reaches stated values, the server on which the image is deployed must meet the [configuration requirements](#configuration-requirements).

<CustomTable>
  <table data-sticky>
    <thead>
      <tr>
        <th />

        <th>UserGate VE100</th><th>UserGate VE250</th><th>UserGate VE500</th><th>UserGate VE1000</th><th>UserGate VE2000</th><th>UserGate VE4000</th><th>UserGate VE6000</th>
      </tr>
    </thead>

    <tbody>
      <tr>
        <th>Firewall throughput, UDP,<br />Gbit/s</th><td>0.8</td><td>8</td><td>9</td><td>10</td><td>11</td><td>11.5</td><td>12</td>
      </tr>

      <tr>
        <th>Recommended number of users</th><td>Up to 100</td><td>Up to 250</td><td>Up to 500</td><td>Up to 1 000</td><td>Up to 2 000</td><td>Up to 4 000</td><td>Up to 6 000</td>
      </tr>

      <tr>
        <th>Concurrent TCP sessions</th><td>2 000 000</td><td>2 000 000</td><td>5 000 000</td><td>8 000 000</td><td>16 000 000</td><td>20 000 000</td><td>24 000 000</td>
      </tr>

      <tr>
        <th>New sessions per second</th><td>24 000</td><td>100 000</td><td>120 000</td><td>130 000</td><td>150 000</td><td>155 000</td><td>160 000</td>
      </tr>

      <tr>
        <th>SSL inspection,<br />Gbit/s</th><td>0.05</td><td>0.3</td><td>0.32</td><td>0.35</td><td>0.6</td><td>0.65</td><td>0.7</td>
      </tr>

      <tr>
        <th>IPS throughput,<br />Gbit/s</th><td>0.6</td><td>1.3</td><td>1.35</td><td>1.4</td><td>1.8</td><td>2.1</td><td>2.4</td>
      </tr>

      <tr>
        <th>Content filtering (when ordering [additional module](#additional-modules) ATP),<br />Gbit/s</th><td>0.15</td><td>1.3</td><td>1.5</td><td>1.8</td><td>2.5</td><td>2.8</td><td>3.1</td>
      </tr>

      <tr>
        <th>L7 application control (when ordering [additional module](#additional-modules) ATP),<br />Gbit/s</th><td>0.7</td><td>1.5</td><td>1.7</td><td>1.8</td><td>2.5</td><td>2.8</td><td>3.1</td>
      </tr>

      <tr>
        <th>Stream Antivirus (when ordering [additional module](#additional-modules) Stream Antivirus),<br />Gbit/s</th><td>0.15</td><td>1.3</td><td>1.5</td><td>1.8</td><td>2.5</td><td>2.8</td><td>3.1</td>
      </tr>

      <tr>
        <th>FSTEC certification</th><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td>
      </tr>
    </tbody>
  </table>
</CustomTable>

### Configuration requirements \{#configuration-requirements}

Specified are the required parameters for the server on which the corresponding image will be deployed. The server of the selected configuration is not included in the virtual firewall price and is [paid for](/firewalls/about/payment-virtual.mdx) separately.

<CustomTable>
  <table>
    <thead>
      <tr>
        <th />

        <th>UserGate VE100</th><th>UserGate VE250</th><th>UserGate VE500</th><th>UserGate VE1000</th><th>UserGate VE2000</th><th>UserGate VE4000</th><th>UserGate VE6000</th>
      </tr>
    </thead>

    <tbody>
      <tr>
        <th>10/100/1000Base-T ports</th><td>Up to 8</td><td>Up to 8</td><td>Up to 8</td><td>Up to 8</td><td>Up to 8</td><td>Up to 8</td><td>Up to 8</td>
      </tr>

      <tr>
        <th>10GBase SFP+ ports</th><td colspan="7">Up to 8 when using VMXNET3 virtual adapters</td>
      </tr>

      <tr>
        <th>Number of vCPUs</th><td>Up to 2</td><td>Up to 4</td><td>Up to 6</td><td>Up to 8</td><td>Up to 16</td><td>Up to 24</td><td>Up to 32</td>
      </tr>

      <tr>
        <th>RAM,<br />GB</th><td>8</td><td>8</td><td>16</td><td>16</td><td>32</td><td>32</td><td>64</td>
      </tr>

      <tr>
        <th>Disk,<br />GB</th><td>100</td><td>300</td><td>300</td><td>300</td><td>300</td><td>300</td><td>500</td>
      </tr>
    </tbody>
  </table>
</CustomTable>

### Additional modules \{#additional-modules}

Additional modules allow you to expand the functionality of the UserGate VE firewall: enable deep packet inspection and protection against external threats.

Additional modules are included in the price of the firewall image.

If you have already ordered a firewall without additional modules and want to connect them, [cancel the service](/firewalls/about/disable-virtual-firewall.mdx) and [order a firewall](/firewalls/order/order-virtual-firewall.mdx) again at the new price.

<CustomTable>
  <table>
    <tbody>
      <tr>
        <th>Intrusion Detection and Prevention System (IDS/IPS)</th><td>Detects and blocks malicious activity inside the network or from the internet. The system uses heuristic analysis and pattern analysis of known attacks. Upon detecting malicious activity, the system terminates the connection, notifies the administrator, and saves an attack record</td>
      </tr>

      <tr>
        <th>Advanced Threat Protection (ATP)</th><td>Content and internet traffic filtering based on morphological analysis in accordance with RF legal requirements, ad blocking, and social media access control</td>
      </tr>

      <tr>
        <th>Stream Antivirus (AV)</th><td>Scans traffic for malicious code by analyzing signatures of received files and applications. This allows you to block the majority of malicious files with practically no impact on system performance. Rules are developed using information from various computer incident response centers, including FinCERT of the Bank of Russia and GOV-CERT of the National Coordination Center for Computer Incidents (NCCCI)</td>
      </tr>

      <tr>
        <th>Mail Security</th><td>Protects email from spam and viruses. Filtering is performed in several stages — by connection, source address, destination address, and email content. The sender's SMTP server IP address is blocked at the SMTP connection creation stage, which helps offload other spam and virus scanning methods</td>
      </tr>
    </tbody>
  </table>
</CustomTable>

<Formbricks />
