- Solid IPSec implementation, support route based IPSec (i.e. Cisco VTI style IPSec ) up to 1000 peers;
- Solid routing protocol implementation, mainly BGP;
- Solid VRF lite implementation (route leaking, static NAT cross VRFs)
- Can do 10Gbps+ IPSec, 30 million packet per second firewall throughput for small packets (whatever that translates to bps value)
- Solid netconf implementation
- Support clustering (we need a single control plane)
- Support gprs inspection (sctp application and gtpc/u)
Edit:
We basically need something like AWS’s VGW functionality plus NAT and firewalling, but we don’t have the man power to develop that in house . Juniper SRX-HE can do it but its IPSec implementation is disappointing, we are looking for an alternative
No comments:
Post a Comment