1-1
1 Product Overview
Introduction
The H3C SecPath U200 Series Unified Threat Management Products are new-generation UTM devices
designed for enterprise users.
The U200 series comprises three models:
z U200-A: Designed for large- and medium-sized enterprise users
z U200-M: Designed for medium-sized enterprise users
z U200-S: Designed for small- and medium-sized enterprise users
In addition to traditional firewall functions, the U200 series protect network security by providing a wide
range of functions including virtual firewall, security zone, intrusion detection and protection, gateway
anti-virus, anti-spam, P2P traffic control, and URL filtering. With the application specification packet filter
(ASPF) technology, a U200 series device can monitor connection setup processes and illegal
operations, and dynamically filter packets based on ACLs. Moreover, the U200 series support multiple
VPN services including IPSec VPN, L2TP VPN, and GRE VPN, and thereby can be used for
constructing a variety of VPN networks. The series deliver abundant routing capabilities and support
RIP and OSPF. Adopting a high-performance multi-core CPU, the U200-A, U200-M and U200-S can
support up to 10, 8, and 7 GE interfaces respectively, delivering high scalability for user investment
protection.
The U200 series are available with AC power supply to ensure high reliability, fully satisfy requirements
for network maintenance, update, and optimization, support detection of chassis internal temperature,
support network management, and provide a Web management interface.
The U200-A provides two MIM expansion slots for future service expansion. Currently, the slots support
the NSQ1GT2UA0 and NSQ1GP4U0 MIM modules.
The U200-M provides one MIM expansion slot and currently supports the same MIM as the U200-A
does.
The U200-S provides a mini expansion slot for future service expansion. Currently, the device supports
the 2-GE and NSQ1WLAN0 interface modules.
Features
The U200 series deliver the following features:
Powerful hardware platform
The U200 series perfectly fit in enterprise networks thanks to the adoption of MIPS64-based CPUs and
integrated high-performance hardware-based VPN accelerators.
Abundant security protection functions
z Security zone management: You can create security zones based on physical interfaces, logical
interfaces, Layer-2 Ethernet interfaces, or combinations of Layer-2 Ethernet interfaces and VLANs.
Interfaces belonging to the same security zone share the same security requirements in security