WatchGuard Firebox M500 Firewall
Comprehensive Protection with High Port Density
Sorry, this unit has been discontinued and is no longer available for purchase, replace by Firebox M270, M370, M470, M570. If you currently own this Model, please click here to participate in the WatchGuard Trade-Up Program! You can also purchase available renewals below. End of Sale (EOS): 01 Apr 2020. End of Life (EOL) for the Firebox-M500 is 31 Dec 2022 - you will not be able receive support after this date even with a 1 Year contract.
WatchGuard Firebox M400 & M500 Overview:
Firebox M400 and M500 firewalls are specifically engineered for mid-sized and distributed enterprises that are struggling to effectively and affordably secure networks in the face of explosive growth in bandwidth rates, encrypted traffic, video use, and connection speeds.
With an operating system built on the latest generation of processors from Intel, the M400 and M500 have all the power they need to run their security scanning engines in parallel, without causing a bottleneck in performance. This ensures network pros never have to compromise network security for performance.
- Comprehensive Protection - Best-of-breed security services boost protection in critical attack areas, including gateway AV, URL and web content filtering, intrusion prevention, app control, and spam blocking.
- Real-time Visibility - A suite of big-data style visibility and reporting tools are included at no additional cost. Use the Policy Map dashboard to quickly find active and misconfigured policies and drill down as needed.
- Maximum Network Uptime - High availability capabilities - active/active and active/passive - ensure your network is always up and running. Buy two M400s or M500s for a high availability pair and receive 50% off the cost of the second device.
- Outstanding Performance - Up to 8 Gbps firewall throughput and 1.7 Gbps UTM throughput. Turn on optional security services and still see up to 1.7 Gbps throughput.
- 3 Ways to Manage Your Appliance - You have the power to choose how you manage your WatchGuard appliance, including WatchGuard System Manager, the command line interface, and a web UI for access from anywhere, anytime.
- Quick and Secure Setup - Take advantage of innovative features like drag-and-drop VPN creation and RapidDeploy technology to make fast work of extending your network.
- Advanced Networking - Intuitive management console enables quick copying of corporate policy across multiple appliances.
- Remote Connectivity Options - Includes SSL and IPSec VPN for flexibility in remote access with support for Apple iOS devices such as the iPhone, iPad, and iPod touch.
- Application Control - Control the use of Web 2.0 and other applications on your network for tighter security, better use of bandwidth, and greater productivity.
Features:
Highest UTM Performance in the Industry:
- Firewall throughput of up to 8 Gbps to keep traffic moving.
- Best UTM throughput in its class - up to 1.7 Gbps - even with strong security enabled.
- No need to compromise protection for strong performance or vice versa. Multi-layered, interlocking security protects the network while throughput remains high.
- Gigabit Ethernet ports support high-speed LAN backbone infrastructures & gigabit WAN connections, including 2 SFP ports for fiber or copper.
Best-of-Breed Security:
- Application-layer content inspection recognizes & blocks threats that stateful packet firewalls cannot detect.
- Powerful subscription-based security services boost protection in critical attack areas for multiple layers of defense. By partnering with leading technology providers, WatchGuard is able to integrate best-of-breed security components into one platform for stronger security at big cost savings.
- APT Blocker is a cloud-based service that uses a combination of sandboxing and full system emulation to detect and block highly sophisticated Advanced Persistent Threats (APTs).
- Application Control keeps unproductive, inappropriate, and dangerous applications off-limits.
- Intrusion Prevention Service (IPS) delivers in-line protection from malicious exploits, including buffer overflows, SQL injections, and cross-site scripting attacks.
- WebBlocker controls access to sites that host objectionable material or pose network security risks.
- Gateway AntiVirus (GAV) scans traffic on all major protocols to stop threats.
- spamBlocker delivers continuous protection from unwanted and dangerous email.
- Reputation Enabled Defense ensures faster, safer web surfing with cloud-based reputation look-up.
- Data Loss Prevention automatically inspects data in motion for corporate policy violations.
- Advanced networking features, such as dynamic routing and link aggregation, allow you to add security without needing to change existing network infrastructure.
- Multiple VPN choices (IPSec, SSL, L2TP) for secure remote access include support for Android and Apple iOS devices.
Easy To Manage:
- WatchGuard Dimension™, a public and private cloud-ready visibility solution, instantly turns raw data into security intelligence.
- Interactive, real-time monitoring and reporting - at no additional charge - give an unprecedented view into network security activity so you can take immediate preventive or corrective actions.
- RapidDeploy™ enables quick, secure configuration at remote locations without technical staff.
- Intuitive management console centrally manages all security functions.
- WAN and VPN failover provide redundancy for increased reliability.
- Extend best-in-class UTM security to the WLAN by adding WatchGuard's Wireless Access Points.
- Drag-and-drop Branch Office VPN setup - three clicks and your remote office is connected.
Specifications:
WatchGuard Firebox M400 & M500 Detailed Specs | ||
---|---|---|
Models: |
Firebox M400 |
Firebox M500 |
Performance | ||
Firewall Throughput | 8 Gbps | 8 Gbps |
VPN Throughput | 4.4 Gbps | 5.3 Gbps |
AV Throughput | 2.5 Gbps | 3.2 Gbps |
IPS Throughput | 4 Gbps | 5.5 Gbps |
UTM Throughput | 1.4 Gbps | 1.7 Gbps |
Interfaces 10/100/1000* | 6 + 2SFP | 6 + 2SFP |
I/O Interfaces | 1 SRL/2 USB | 1 SRL/2 USB |
Concurrent connections (bi-directional) | 3,800,000 | 9,200,000 |
New connections per second | 84,000 | 95,000 |
VLANs | 300 | 500 |
WSM licenses (incl) | 4 | 4 |
Authenticated users limit | Unrestricted | Unrestricted |
VPN Tunnels | ||
Branch Office VPN | 100 | 500 |
Mobile VPN IPSec | 150 | 500 |
Mobile VPN SSL/L2TP | 150 | 500 |
Security | ||
Firewall | Stateful packet inspection, deep packet inspection, proxy firewall | |
Application Proxies | HTTP, HTTPS, SMTP, FTP, DNS, TCP, POP3 | |
Threat Protection | DoS attacks, fragmented & malformed packets, blended threats & more | |
VoIP | H.323, SIP, call setup and session security | |
Filtering options | Browser Safe Search, YouTube for Schools | |
Security Subscriptions | Application Control, IPS, WebBlocker, GAV, Data Loss Prevention, spamBlocker, Reputation Enabled Defense, APT Blocker | |
VPN & Authentication | ||
Encryption | DES, 3DES, AES 128-, 192-, 256-bit | |
IPSec | SHA-1, SHA-2, MD5, IKE pre-shared key, 3rd party cert | |
Single Sign-On | Supports Windows, Mac OS X, mobile operating systems | |
Authentication | RADIUS, LDAP, Windows Active Directory, VASCO, RSA SecurID, internal database | |
Management | ||
Logging and notifications | WatchGuard, Syslog, SNMP v2/v3 | |
User interfaces | Centralized console (WSM), Web UI, scriptable CLI | |
Reporting | WatchGuard Dimension includes 70 pre-defined reports, executive summary and visibility tools | |
Certifications | ||
Security | Pending: ICSA Firewall, ICSA IPSec VPN, CC EAL4+, FIPS 140-2 | |
Safety | NRTL/C, CB | |
Network | IPv6 Ready Gold (routing) | |
Hazardous substance control | WEEE, RoHS, REACH | |
Networking | ||
Routing | Static, Dynamic (BGP4, OSPF, RIP v1/v2), Policy-based VPN | |
High Availability | Active/passive, active/active with load balancing | |
QoS | 8 priority queues, DiffServ, modified strict queuing | |
IP Address Assignment | Static, DHCP (server, client, relay), PPPoE, DynDNS | |
NAT | Static, dynamic, 1:1, IPSec traversal, policy-based, Virtual IP for server load balancing | |
Link aggregation | 802.3ad dynamic, static, active/backup | |
Other Features | Port Independence, Multi-WAN failover and load balancing, server load balancing, transparent/drop-in mode | |
Hardware | ||
Product Dimensions | 17" x 1.75" x 12" (431 x 44 x 305 mm) | |
Shipping Dimensions | 18" x 21" x 5.25" (45.7 x 53.3 x 13.3 cm) | |
Weight | 17 lb (7.7 kg) | |
AC Power | 100-240 VAC Autosensing | |
Power Consumption | U.S. 75 Watts (max), 256 BTU/hr (max) | |
Rack Mountable | 1U rack mount kit included | |
Environment | Operating | Storage |
Temperature | 32° F to 104° F 0° C to 40° C | -40° F to 158° F -40° C to 70° C |
Relative Humidity | 10% to 85% non-condensing | 10% to 95% non-condensing |
Altitude | 0 to 9,843 ft at 95° F (3,000 m at 35° C) | 0 to 15,000 ft at 95° F (4,570 m at 35° C) |
MTBF | 51,644 hours @ 77° F (25° C) |
Options & Upgrades:
WatchGuard Security Services
WatchGuard offers the most comprehensive portfolio of network security services, from traditional IPS, GAV, application control, spam blocking, and web filtering to more advanced services for protecting against advanced malware, ransomware, and the loss of sensitive data. WatchGuard also offers a full suite of network visibility and management services.
Fundamental Security Services
IPS uses continually updated signatures to scan traffic on all major protocols to provide realtime protection against network threats, including spyware, SQL injections, cross-site scripting, and buffer overflows.
A powerful, cloud-based reputation lookup service that protects web users from malicious sites and botnets, while dramatically improving web processing overhead.
A subscription-based service for Firebox appliances that generates a visual map of all nodes on your network so you can easily see where you may be at risk.
In addition to automatically blocking known malicious sites, WebBlocker’s granular content and URL filtering tools enable you to block inappropriate content, conserve network bandwidth, and increase employee productivity.
Selectively allow, block, or restrict access to applications based on a user’s department, job function, and time of day and to then see, in real-time, what’s being accessed on your network and by whom.
Leverage our continuously updated signatures to identify and block known spyware, viruses, trojans, worms, rogueware and blended threats - including new variants of known viruses. At the same time, heuristic analysis tracks down suspicious data constructions and actions to make sure unknown viruses don’t slip by.
Real-time spam detection for protection from outbreaks. Our spamBlocker is so fast and effective, it can review up to 4 billion messages per day.
Advanced Security Services
APT Blocker uses an awardwinning next-gen sandbox to detect and stop the most sophisticated attacks including ransomware, zero day threats and other advanced malware.
This service prevents accidental or malicious data loss by scanning text and common file types to detect sensitive information attempting to leave the network.
Access Portal provides central location for access to cloud-hosted applications, and secure, clientless access to internal resources with RDP and SSH.
Correlate network and endpoint security events with enterprise-grade threat intelligence to detect, prioritize and enable immediate action to stop malware attacks. Improve visibility by evolving your existing security model to extend past prevention, to now include correlation, detection and response.
Reduce malware infections by detecting and blocking malicious DNS requests, redirecting users to a safe page with information to reinforce security best practices.
Dimension translates data collected from all appliances across your network into actionable network and threat intelligence. Dimension Command gives you the power to take action to mitigate those threats instantly, from one central console.
One Appliance, One Package, Total Security
Simplicity is our mission at WatchGuard and that mission extends beyond how the product is built to how it is packaged. While all of our services are offered à la carte, we have worked to develop two packages that simplify the decision-making process. The Total and Basic Security Suite packages are available on our Firebox T and M Series appliances, as well as our Firebox Cloud and FireboxV virtual models.
- The Basic Security Suite includes all of the traditional network security services typical to a UTM appliance: IPS, GAV, URL filtering, application control, spam blocking and reputation lookup. It also includes our centralized management and network visibility capabilities, as well as, our standard 24x7 support.
- The Total Security Suite includes all services offered with the Basic Security Suite plus advanced malware protection, data loss protection, enhanced network visibility capabilities, a secure access portal, and the ability to take action against threats right from Dimension, our network visibility platform.
Documentation:
Download the WatchGuard Firebox M400 & M500 Datasheet (PDF).
Pricing Notes:
- All Prices are Inclusive of GST
- Pricing and product availability subject to change without notice.
Our Price: Request a Quote
Our Price: Request a Quote
Our Price: Request a Quote
Our Price: Request a Quote
Our Price: Request a Quote
Our Price: Request a Quote