Search By Category
Search By Keyword
Elementary Performance
Product Name
NGS 1351HF

Maximum connections: 2,000,000 | New connections per second: 65,000 | Maximum processing speed: 4.2Gbps | VPN performance: 650Mbps | Antivirus performance: 750Mbps | IPS performance: 750Mbps | Email scans/day: 3,100,000

1 LAN / 5 definable PORT | All Giga Port (10/100/1,000M)
Support VPN such as IPSEC / SSL / PPTP / L2TP (available for IOS)
Support 3G / 4G / LTE USB mobile wireless network card
Built-in 3rd party application and 3rd party URL database control for 2 year

Optional items: Kaspersky Anti-Virus / 3rd party application (from the 3rd year) / 3rd party URL database (from the 3rd year)

Data storage: SSD

Product Specification
Product Manual
NGS 1351HF is a network security device that complies with Next Generation UTM specifications. It features high operating efficiency, multiple security protection mechanisms, and hierarchical authorization management. It is the preferred network security and management device for medium and large enterprises. NGS 1351HF has the powerful functions of next-generation firewall, including Deep Packet Inspection (DPI) -based application identification and control, In-Line IPS, SSL analysis and blocking, Web Filtering, bandwidth management, anti-virus, spam filtering, and Supports external authentication integration and other functions, which can prevent hackers from sneaking into malicious attacks or unauthorized access to internal network resources. In addition, NGS 1351HF also supports dual-machine backup mechanism (HA), which can ensure the continuous operation of equipment. 
Feature Of Product
NGS 1351HF is also a core switch supporting Layer 2-Layer 7, which can directly replace the traditional Layer 3 core switch and meet the requirements of the next generation Software Defined Network (SDN) core switch. Integrate the centralized management of wireless base stations and network-managed switches to create integrated wired and wireless security protection, allowing managers to take care of both inside and outside, Can be used as the second layer as an intranet security firewall (ISFW).             
Balancing performance and functionality
HERHSIANG NGS 1351HF, its hardware platform is carefully designed, using X86 hardware equipment, the purpose is to allow enterprise users to fully feel the security protection features provided by HERHSIANG Next Generation UTM. For customers with high connection capacity requirements, we provide high-performance security modules to improve connection capacity and support USB fast restore mechanism.
IP v4 / v6 dual frequency technology
There is a shortage of IP v4 addresses, and the age of IP v6 is coming sooner or later, so HERHSIANG has already integrated this trend when developing the next-generation UTM. The same network interface, whether it is defined as WAN or LAN, can be bound at the same time. v4 or v6 IP address, so whether it is in a pure v4 environment, a mixed v4 / v6, or a pure v6 environment, NGS 1351HF is the same.
Support SDN controller
Support SDN controller, can make more than 1 port to form ZONE, directly managed by the SDN controller, and ZONE and ZONE packet transmission will also pass NGS 1351HF packet detection. And with VLAN 802.1Q function, it can cut the internal network into several independent sub-network segments, each of which operates independently without interference.


SSL encrypted connection detection
With the ability to detect SSL traffic, when facing SSL-encrypted connection traffic, you can apply intrusion detection defense, gateway anti-virus, content filtering, and application bandwidth control.
Load balancing
Provides outbound and inbound load balancing, and provides multiple load balancing algorithms. When one of the lines is disconnected, all network packets will automatically switch to another normal line to ensure that the internal user network is unblocked. When the line is restored, the packet It will be assigned automatically again. Enterprises can set load balancing rules according to their own needs, and network access can refer to the set rules to implement network traffic load balancing guidance. The algorithms are: automatic allocation, manual allocation, allocation based on source IP, and allocation based on destination IP.

IPS Intrusion Prevention
IPS It will check the content corresponding to layers 4 to 7 of the OSI model, whether there are malicious attack programs and viruses, hidden in the TCP / IP communication protocol. After detailed content inspection, the qualified feature code will be Mark out, once discovered, you can block the packets immediately, so that these malicious packets through the firewall have nothing to hide.

WAF (Web Application Firewall)

Web Application Firewall is a product that specifically protects web server applications by implementing a series of security policies for HTTP / HTTPS.

The work of WAF is to analyze the data of the Web application layer, to force multiple conversions of different encoding methods to restore the plaintext of the attack, and to combine the deformed characters and analyze them, which can be better than the combined attacks from the Web layer.

Provide application layer rules. WEB applications are usually customized. Traditional rules for known vulnerabilities are often not effective. WAF provides dedicated application layer rules and has the ability to detect deformation attacks, such as detection of mixed attacks in SSL encrypted traffic.             

Threat Detection Defense
Provide enterprises with the most complete defense-in-depth mechanism. Today's network attacks cannot rely on a single point of protection but require complete defense-in-depth. Only through different levels of defense technology can there be a way to reduce the potential threats to the enterprise. In addition to providing firewalls, intrusion detection systems (IPS), and anti-virus as the basis for corporate security protection, Hexiang NGS 1351HF can strengthen the detection of malicious programs for traffic, web pages, and emails. Through the analysis of related security mechanisms , Play the role of defense in depth.
Mail Gateway Protection
The company already has a mail host, but the spam filtering performance is not good. You can use NGS 1351HF as the mail gateway mode to supplement the original mail server's insufficient functions, such as spam filtering and virus filtering. After filtering the virus and advertisement mail through NGS 1351HF, send the clean mail to the mail host.
Virus filtering (optional for Kaba driver anti-virus)
The system provides Clam AV anti-virus engine for free, which can detect more than millions of viruses, worms, and Trojan horse programs. It can automatically scan for viruses in emails, update virus files through the Internet daily, and provide virus mail search condition. The administrator can set the processing method of poisoned mail by himself, including automatic deletion, storage of poisoned mail extension and the subject of poisoned mail notification letter. With the new generation of UTM Kabbah anti-virus engine, customers can purchase and continue to enjoy the Kaspersky anti-virus engine leader with the highest scanning rate and the strongest virus repair.
Spam filtering
Both internal and external mail can be filtered, and ST-IP network letter review, Bayesian filtering, Bayesian filtering automatic learning mechanism, automatic whitelisting mechanism, spam feature filtering and fingerprint identification are provided. , White list comparison and intelligent identification learning database (Auto-Learning), you can even set personalization rules, flexibly formulate filtering rules, handle spam, and ensure comprehensive protection without misjudgment. The accuracy rate is more than 95%. Mail filtering, which can forward, delete, and block the letters that meet the filter conditions set by the administrator.
Anomaly IP analysis
Any network behavior, no matter what kind of software the user runs, from the perspective of network packets, it is roughly divided into the number of uploads and downloads (Connect Session), flow (Flow) and duration (Time), by detecting these The combination of the numbers estimates that the user is using the Internet normally or has abnormal behavior. When abnormal behaviors of internal users are discovered, the manager can adopt a variety of strategies, such as blocking the Internet, immediately limiting its maximum bandwidth, enabling a cooperative defense mechanism to notify the switch to block it or notifying the manager.
Bandwidth Management (QoS)
Assist network administrators to control the network, effectively reduce the obstruction of corporate network, improve serviceability and bandwidth usage. With QoS (bandwidth management) function, it can distribute limited bandwidth to all users. The difference from ordinary bandwidth controllers is that in addition to providing maximum bandwidth and priority management, NGS 1351HF also has a guaranteed bandwidth function. And it also has a personalized bandwidth management design, which can be set for individual users. Bandwidth tube  When used with a personalized bandwidth tube, the bandwidth pre-defined by the bandwidth management function can be allocated to users below the enterprise, which can effectively prevent the band from being exclusively occupied by users.
Content filtering
Provide Web Filter (web page filtering) function, can block the access to inappropriate web pages (such as pornography, violence) and offensive web pages (such as hackers, viruses), and can set filter conditions to block inappropriate websites.
URL database management [optional 3rd party database (optional), Built for 2 years]
The built-in "cloud URL database" automatically categorizes web pages. As long as the administrator can prevent harmful URLs from blocking, it can be easily controlled without having to enter website IP addresses and keywords one by one to block. Clicking on harmful URLs arbitrarily is the source of evil. The best way to prevent blocking is to prohibit the use of the Internet. If it cannot be completely banned, the constantly updated URL database is the best protection mechanism.
Full record of online behavior
Some employees of the company use the Internet during work hours to do non-work-related tasks, with small chats and leaks. NGS 1351HF can not only limit the user's permission to use related applications, but also record related online behaviors, including browsing the web and sending emails. When a company leaks information, the saved information is the best evidence to present as evidence.
Traffic Analysis
Provide traffic analysis tools, whether it is the internal user's computer power on and off, real-time network traffic display, communication protocol allocation and traffic rankings. When the line is full, you can immediately find the traffic killer.
Application management [optional 3rd party database (optional), Built for 2 years]
Not only is it difficult to manage a variety of network applications, it is also easier to become the best channel for data leakage and virus attacks. NGS 1351HF has a variety of built-in application management functions, including instant messaging, audio and video services, file transfer, P2P software, remote control, browser, VOIP, online games, network protocols, etc., which can easily control employees' use of application software. Permissions to protect corporate network security.
Graphical traffic report
Provide web interface traffic reports, draw the system's historical status into charts, so that managers can grasp the current system operating status at any time. NGS 1351HF provides system status charts (including CPU load chart, memory load chart, system load), network traffic chart (LAN traffic, WAN1 ~ WAN5 traffic), and provides query conditions to quickly search the history of each traffic status .


VPN function

Use IPSec, PPTP, L2TP, SSL VPN to securely connect between Site to Site, Point to Site and remote users. Through these VPN mechanisms, users can connect to different devices from different locations, including home, external public information service stations, and the Internet, such as laptops, branch offices, business locations, mobile communication devices, or home. …Wait.

Among them, SSL VPN is the most important long-distance secure transmission connection between most enterprises, customers and partners.             


Definition of UTM

IDC's definition of UTM security hardware devices is: It includes multiple security functions integrated into a single hardware device, which must include network firewalls, network intrusion detection and defense, and gateway antivirus. It is not necessary to use all the functions on this device, but it must be built in, and individual components cannot be cut.

In order to test these devices, NSS Group more clearly defines UTM devices as a single device combination of firewall, VPN, IDS / IPS, anti-virus, anti-spam, URL filtering, content filtering and other functions. The detailed definitions are as follows:

* Firewall: Deployed at the network boundary, a strong stateful NAT firewall is required.

* VPN: It is often deployed in corporate WAN as a branch network solution, and basically needs to be able to establish a small number of secure VPN tunnels.

* IDS / IPS: The firewall can only enforce policies. If the policy allows inbound HTTP traffic to the web server in the DMZ zone, the firewall cannot prevent hackers from damaging the target web server from the HTTP protocol. The IPS function will detect and block intrusions that attempt to use network boundaries to prevent malicious network traffic from reaching the server. The IDS function can detect intrusions and issue alerts, but it cannot block malicious traffic.

* Anti-virus: Gateway anti-virus filtering can prevent inbound virus traffic at the network boundary, strengthen computer desktop security, and block them before they reach the desktop. The solution can also prevent internal computers from being infected by viruses from outside the corporate network. .

* Anti-Spam: Gateway Anti-Spam can mark incoming emails and allow further processing by computer-filtered solutions. The solution prevents internal hosts from sending spam to outside the enterprise.

* URL filtering: Using a constantly updated database of URL classifications, a gateway URL filtering solution prevents employees from accessing unpleasant or inappropriate websites from the corporate network.

* Content filtering: Scans specific content of web pages and email traffic. Gateway content filtering solutions can prevent unpleasant or inappropriate content from passing through or being sent out by corporate networks.              

File Download

HERHSIANG Information Co., Ltd.

TEL: 886-7-3494097 FAX: 886-7-3596785

3F, No.5, Dinghe St., Sanmin District, Kaohsiung City Taiwan 

Business hours: Monday ~ Friday 8:30 ~ 12:00 / 13:30 ~ 1800 

(Except holidays and national holidays)
Copyright © 2002~2021