Network equipment security certification

"Aboutpublishing <key network equipment and network security-specific catalog(first)> announcement" (National Internet Information Office, Ministryof Industry and Information Technology, Ministry of Public Security, thenational commission in 2017 Notice No. 1, (Hereinafter referred to asAnnouncement No. 1 of 2017) and "Announcement on ImplementationRequirements for Security Certification of Network Key Equipment and NetworkSecurity Dedicated Products" (Announcement No. 24, 2018 of NationalInternet Information Office of the CNCA), China Security Review NetworkTechnology and Certification Center (hereinafter referred to as "NetworkSecurity Center") was in July 2018 formally accepted the key networkequipment and network security-specific product safety certificationapplication, And the implementation of certification based on "key networkequipment and network security-specific product safety certificationrules" (CNCA-CCIS-2018). For products that originally fall within thescope of "IT Product Information Security Certification", If it meetsthe requirements of the scope of the product catalogue announced in No. 1 of2017,And have obtained the "security certification for network criticalequipment and special products for network security", The "IT ProductInformation Security Certification" is no longer issued.



The key network equipment and networksecurity specific products catalog:

Equipment or product category

scope

1.Router

Whole system throughput (two-way) 12Tbps

The entire system routing table capacity is 550,000 entries

2. Switch

Whole system throughput (two-way) 30Tbps

The entire system packet forwarding rate 10Gpps

3. Server (rack type)

Number of CPUs 8

Number of single CPU cores 14

256G in memory capacity

4. Programmable logic controller (PLC equipment)

Controller instruction execution time 0.08 microseconds

5. Data backup machine

Backup capacity according to 20T

Backup speed according to 60MB / s

Backup interval 1 hour

6. Firewall (hardware)

Machine throughput wall 80Gbps

Maximum concurrent connections 3 million

250,000 new connections per second

7.WEB Application Firewall (WAF)

6Gbps for machine application throughput

The maximum number of concurrent connections HTTP 200 Wan

8. Intrusion detection system (IDS)

Full inspection rate 15Gbps

The maximum number of concurrent connections G500 Wan

9. Intrusion Prevention System (IPS)

Throughput 1Gbps

System delay 15ms

10. Security isolation and information exchange products (gatekeeper)

Connection processing rate (connection / second)> 100

Average delay time <100ms

11. Anti-Spam Products

Ethereal speed 5Gbps

Recording event capacity: G50 thousand pieces / second

12. Network comprehensive audit system

The maximum number of concurrent scans IP 60 months

13. Network Vulnerability Scanning Products

TPC-E tpsE (tradable number per second) 4,500

14. Security Database System

TPC-E tpsE (tradable number per second) 4,500

15. Website Recovery Products (Hardware)

Recovery time net 2ms

Station's longest path 10 levels