Skip to main content

Firewall types

Last update:

You can rent two types of firewalls:

Comparison of hardware and virtual firewalls

HardwareVirtual
In what form it is providedFirewall mounted in a rack and connected to the public and local networkLicensed firewall image.
You deploy the image yourself in the selected product — on a cloud server, or in a public or private VMware-based cloud
FSTEC certificationType A certificates (Continent and UserGate models are certified)Type B certificates
Changing the configuration (number of vCPUs, amount of RAM, and disk size)Order a different model and reconfigure itOrder the service again and change the configuration of the server on which the image is deployed. No reconfiguration required
Connectivity with the protected infrastructure in one private subnetPossible with dedicated servers in one pool. Otherwise, you must use a Global Router to establish connectivityPossible with cloud servers in one pool or virtual machines in one VMware organization. Otherwise, you must use a Global Router to establish connectivity
What is included in the priceHardware firewall with a public address

Firewall image with license:

The infrastructure where the image is deployed is paid for separately

Hardware firewalls

SelectelFortinet FG-100EFortinet FG-500EUserGate C150UserGate D200UserGate D500Cisco 5508Continent 4 IPC-R550CheckPoint Quantum Spark 1800
Firewall throughput,
Gbit/s
0.97.4363.818200.567.5
17 for 1518 UDP
IPS throughput,
Gbit/s
0.90.41.820.12525.5
IPSec VPN throughput,
Gbit/s
0.9420314160.17514
SSL-VPN throughput,
Gbit/s
0.90.255314160.1252
Available interfaces2×1GE RJ4516×1GE RJ458×1GE RJ45
2×10GE SFP
8×1GE RJ455×1GE RJ45
2×1GE SFP
5×1GE RJ45
2×1GE SFP
8×1GE RJ454×1GE RJ45
2x10GE SFP
2xCombo RJ45
2xCombo SFP
16×1GE RJ45
FSTEC certification

Virtual firewalls

To ensure throughput reaches stated values, the server on which the image is deployed must meet the configuration requirements.

UserGate VE100UserGate VE250UserGate VE500UserGate VE1000UserGate VE2000UserGate VE4000UserGate VE6000
Firewall throughput, UDP,
Gbit/s
0.889101111.512
Recommended number of usersUp to 100Up to 250Up to 500Up to 1 000Up to 2 000Up to 4 000Up to 6 000
Concurrent TCP sessions2 000 0002 000 0005 000 0008 000 00016 000 00020 000 00024 000 000
New sessions per second24 000100 000120 000130 000150 000155 000160 000
SSL inspection,
Gbit/s
0.050.30.320.350.60.650.7
IPS throughput,
Gbit/s
0.61.31.351.41.82.12.4
Content filtering (when ordering additional module ATP),
Gbit/s
0.151.31.51.82.52.83.1
L7 application control (when ordering additional module ATP),
Gbit/s
0.71.51.71.82.52.83.1
Stream Antivirus (when ordering additional module Stream Antivirus),
Gbit/s
0.151.31.51.82.52.83.1
FSTEC certification

Configuration requirements

Specified are the required parameters for the server on which the corresponding image will be deployed. The server of the selected configuration is not included in the virtual firewall price and is paid for separately.

UserGate VE100UserGate VE250UserGate VE500UserGate VE1000UserGate VE2000UserGate VE4000UserGate VE6000
10/100/1000Base-T portsUp to 8Up to 8Up to 8Up to 8Up to 8Up to 8Up to 8
10GBase SFP+ portsUp to 8 when using VMXNET3 virtual adapters
Number of vCPUsUp to 2Up to 4Up to 6Up to 8Up to 16Up to 24Up to 32
RAM,
GB
881616323264
Disk,
GB
100300300300300300500

Additional modules

Additional modules allow you to expand the functionality of the UserGate VE firewall: enable deep packet inspection and protection against external threats.

Additional modules are included in the price of the firewall image.

If you have already ordered a firewall without additional modules and want to connect them, cancel the service and order a firewall again at the new price.

Intrusion Detection and Prevention System (IDS/IPS)Detects and blocks malicious activity inside the network or from the internet. The system uses heuristic analysis and pattern analysis of known attacks. Upon detecting malicious activity, the system terminates the connection, notifies the administrator, and saves an attack record
Advanced Threat Protection (ATP)Content and internet traffic filtering based on morphological analysis in accordance with RF legal requirements, ad blocking, and social media access control
Stream Antivirus (AV)Scans traffic for malicious code by analyzing signatures of received files and applications. This allows you to block the majority of malicious files with practically no impact on system performance. Rules are developed using information from various computer incident response centers, including FinCERT of the Bank of Russia and GOV-CERT of the National Coordination Center for Computer Incidents (NCCCI)
Mail SecurityProtects email from spam and viruses. Filtering is performed in several stages — by connection, source address, destination address, and email content. The sender's SMTP server IP address is blocked at the SMTP connection creation stage, which helps offload other spam and virus scanning methods