In rows where columns are merged, the left value applies to the right; for example, all SPG models are hardware appliances, as defined by the first (type) row. Since the HSP is a hosted service, and the VSP is a virtual machine, the number of users depends on the license only, and the throughput on the virtual host.

Specifications

HSPVSPSPG-150SPG-300SPG-400SPG-500
TypeHostedVMware/XenHardware
Accounts1 to ∞125 to ∞1100 to 20010005000
ThroughputN/A500 K mail/h2190 K mail/h390 K mail/h390 K mail/h420 K mail/h
Form factorN/AN/A1U rack-mountable
BuyBuyBuyBuyBuyBuy
TryDownloadEvaluate

Threat protection
Zero maintenanceThe real-time protection is maintenance free, thus making “training” obsolete
Multi-layer anti-spamBy weighting multiple trusted anti-spam engines, achieving near-zero false positives
Multi-layer anti-virusOne engine for each phase of infection; outbreak, early detection, and mature viruses
GlobalView™Award-winning IP protection blocking >98% spam and DDoS attacks
RPD™Zero-hour spam, virus and phishing protection with less than 1 in 5 million false positives
KasperskyProactive virus protection with heuristic analyzer for unparalleled malware detection

Security
DNSSECInternal DNS cache with DNSSEC validation
DKIMSigning, verification and assessment (on mail content flow/script-level) up to 2048-bit RSA
TLS/SSLEncryption (STARTTLS) and verification (on mail transport level) up to 256-bit AES
DDoS protectionAsynchronous IP-layer “botnet” protection using outbreak data
SYN protectionCombined SYN cache and cookies
Rate controlLimits on all layers (IP, AUTH, RCPT, DATA, etc) using blocks or rate() function
SPFSender verification using the recipient flow block or the spf() function

Mail operations
IP PolicyThe IP (firewall) flow executing GlobalView, etc., which can also send a one-packet reply
TransparencyFiltering is in-line, yielding SMTP errors in conformance with European government regulations
Domains (relay table)The flows and transports are configured per domain (can be open relay; “any”)
AuthenticationVerification of authentication against back-end server using SMTP, LDAP or a script
RecipientVerification of sender and recipient against a back-end server with SMTP, LDAP or a script
Universal cacheAny data may be cached, either using blocks or the flexible cache control structure
Transports (delivery)Multiple transports to servers or MX (lookup-mx) with SASL support

Quarantine
User interfaceWeb-based XHTML e-mail client imitating interface with multi-select
ManageabilityEnd-user, domain-, quarantine-, and global (H/OS user) administrator managed
AuthenticationActive Directory, LDAP (with aliases), internal database and single-sign-on links
ExecutionUsing a block or function, may be combined with others such as reject, deliver or defer
Black/whitelistUser-managed black/whitelisting in addition to system (flow) lists
ClusteringE-mail indexes, passwords, whitelists, etc. are synchronized in a master-master scheme
BrandingHostname (virtual host) based branding with logotypes, translation and templates

Administration
ClusteringMaster-master scheme clustering using shared configuration with private settings
APIComplete control using SOAP (XML) with included WSDL
Web interfaceWeb 2.0 (Ajax) application with remote management support over HTTP(S)
Console interfaceN/ASSH and consoleSSH and RS-232
ConfigurationHuman-readable and revision-based, which can be imported without a restart
Central managementMultiple appliances can be administered and monitored from one web interface
SNMPMonitoring and statistics over SNMP 1/2c/3 with tailored MIB
SyslogRemote logging to multiple servers with filters over UDP/TCP
FTPUpload e-mail (pickup), images, templates for branding, lists for file functions, etc.
Recovery firmwareN/AConsoleRS-232

Network
IP addressesMultiple addresses may be configured per Ethernet or VLAN interface
IPv6 supportThe appliances fully support and operates with IPv6
VLAN and routingVLAN interfaces and routes can be configured for customer separation, etc

License
Quarantine×
GlobalView™
Outgoing modeAdd-onAdd-on
Network storage××Add-onAdd-on
Number of listeners
Number of transports

Hardware
TypeHostedVMware/XenHardware
CPUN/AN/A1.5 GHz2 × 2.13 GHz2 × 2.13 GHz2 × 2.13 GHz
RAMN/A>768 MB1 GB2 GB2 GB4 GB
Storage diskN/A>2 GB160 GB160 GB240 GB500 GB
EthernetN/AN/A4 × 1 Gbps3 × 1 Gbps3 × 1 Gbps3 × 1 Gbps
WeightN/AN/A7 Kg8.5 Kg8.5 Kg8.5 Kg
DimensionsN/AN/A43 × 24.8 × 4.4 cm43 × 30 × 4.4 cm
FCC (A), CE & RoHSN/AN/A
PowerN/AN/A41 W200 W200 W200 W
VoltageN/AN/A120-250 V at 50-60 Hz
Operating temp.N/AN/A0 to 45°C
Storage temp.N/AN/A-20 to 75°C
HumidityN/AN/A5 to 95% (NC, 40°C)


1 The number of users is defined by the license only
2 Measured on one CPU core at 2 GHz with 2 GB RAM on Sun Fire X2250 running VMware ESXi 4.0.0