In rows where columns are merged, the left value applies to the right; for example, all SPG models are hardware appliances, as defined by the first (type) row. Since the HSP is a hosted service, and the VSP is a virtual machine, the number of users depends on the license only, and the throughput on the virtual host.
Specifications
| HSP | VSP | SPG-150 | SPG-300 | SPG-400 | SPG-500 | |
|---|---|---|---|---|---|---|
![]() | ![]() | ![]() | ![]() | |||
| Type | Hosted | VMware/Xen | Hardware | |||
| Accounts | 1 to ∞1 | 25 to ∞1 | 100 to 200 | 1000 | 5000 | ∞ |
| Throughput | N/A | 500 K mail/h2 | 190 K mail/h | 390 K mail/h | 390 K mail/h | 420 K mail/h |
| Form factor | N/A | N/A | 1U rack-mountable | |||
| Buy | Buy | Buy | Buy | Buy | Buy | |
| Try | Download | Evaluate | ||||
Threat protection | ||||||
| Zero maintenance | The real-time protection is maintenance free, thus making “training” obsolete | |||||
| Multi-layer anti-spam | By weighting multiple trusted anti-spam engines, achieving near-zero false positives | |||||
| Multi-layer anti-virus | One engine for each phase of infection; outbreak, early detection, and mature viruses | |||||
| GlobalView™ | Award-winning IP protection blocking >98% spam and DDoS attacks | |||||
| RPD™ | Zero-hour spam, virus and phishing protection with less than 1 in 5 million false positives | |||||
| Kaspersky | Proactive virus protection with heuristic analyzer for unparalleled malware detection | |||||
Security | ||||||
| DNSSEC | Internal DNS cache with DNSSEC validation | |||||
| DKIM | Signing, verification and assessment (on mail content flow/script-level) up to 2048-bit RSA | |||||
| TLS/SSL | Encryption (STARTTLS) and verification (on mail transport level) up to 256-bit AES | |||||
| DDoS protection | Asynchronous IP-layer “botnet” protection using outbreak data | |||||
| SYN protection | Combined SYN cache and cookies | |||||
| Rate control | Limits on all layers (IP, AUTH, RCPT, DATA, etc) using blocks or rate() function | |||||
| SPF | Sender verification using the recipient flow block or the spf() function | |||||
Mail operations | ||||||
| IP Policy | The IP (firewall) flow executing GlobalView, etc., which can also send a one-packet reply | |||||
| Transparency | Filtering is in-line, yielding SMTP errors in conformance with European government regulations | |||||
| Domains (relay table) | The flows and transports are configured per domain (can be open relay; “any”) | |||||
| Authentication | Verification of authentication against back-end server using SMTP, LDAP or a script | |||||
| Recipient | Verification of sender and recipient against a back-end server with SMTP, LDAP or a script | |||||
| Universal cache | Any data may be cached, either using blocks or the flexible cache control structure | |||||
| Transports (delivery) | Multiple transports to servers or MX (lookup-mx) with SASL support | |||||
Quarantine | ||||||
| User interface | Web-based XHTML e-mail client imitating interface with multi-select | |||||
| Manageability | End-user, domain-, quarantine-, and global (H/OS user) administrator managed | |||||
| Authentication | Active Directory, LDAP (with aliases), internal database and single-sign-on links | |||||
| Execution | Using a block or function, may be combined with others such as reject, deliver or defer | |||||
| Black/whitelist | User-managed black/whitelisting in addition to system (flow) lists | |||||
| Clustering | E-mail indexes, passwords, whitelists, etc. are synchronized in a master-master scheme | |||||
| Branding | Hostname (virtual host) based branding with logotypes, translation and templates | |||||
Administration | ||||||
| Clustering | Master-master scheme clustering using shared configuration with private settings | |||||
| API | Complete control using SOAP (XML) with included WSDL | |||||
| Web interface | Web 2.0 (Ajax) application with remote management support over HTTP(S) | |||||
| Console interface | N/A | SSH and console | SSH and RS-232 | |||
| Configuration | Human-readable and revision-based, which can be imported without a restart | |||||
| Central management | Multiple appliances can be administered and monitored from one web interface | |||||
| SNMP | Monitoring and statistics over SNMP 1/2c/3 with tailored MIB | |||||
| Syslog | Remote logging to multiple servers with filters over UDP/TCP | |||||
| FTP | Upload e-mail (pickup), images, templates for branding, lists for file functions, etc. | |||||
| Recovery firmware | N/A | Console | RS-232 | |||
Network | ||||||
| IP addresses | Multiple addresses may be configured per Ethernet or VLAN interface | |||||
| IPv6 support | The appliances fully support and operates with IPv6 | |||||
| VLAN and routing | VLAN interfaces and routes can be configured for customer separation, etc | |||||
License | ||||||
| Quarantine | × | |||||
| GlobalView™ | ||||||
| Outgoing mode | Add-on | Add-on | ||||
| Network storage | × | × | Add-on | Add-on | ||
| Number of listeners | ∞ | ∞ | ∞ | ∞ | ∞ | ∞ |
| Number of transports | ∞ | ∞ | ∞ | ∞ | ∞ | ∞ |
Hardware | ||||||
| Type | Hosted | VMware/Xen | Hardware | |||
| CPU | N/A | N/A | 1.5 GHz | 2 × 2.13 GHz | 2 × 2.13 GHz | 2 × 2.13 GHz |
| RAM | N/A | >768 MB | 1 GB | 2 GB | 2 GB | 4 GB |
| Storage disk | N/A | >2 GB | 160 GB | 160 GB | 240 GB | 500 GB |
| Ethernet | N/A | N/A | 4 × 1 Gbps | 3 × 1 Gbps | 3 × 1 Gbps | 3 × 1 Gbps |
| Weight | N/A | N/A | 7 Kg | 8.5 Kg | 8.5 Kg | 8.5 Kg |
| Dimensions | N/A | N/A | 43 × 24.8 × 4.4 cm | 43 × 30 × 4.4 cm | ||
| FCC (A), CE & RoHS | N/A | N/A | ||||
| Power | N/A | N/A | 41 W | 200 W | 200 W | 200 W |
| Voltage | N/A | N/A | 120-250 V at 50-60 Hz | |||
| Operating temp. | N/A | N/A | 0 to 45°C | |||
| Storage temp. | N/A | N/A | -20 to 75°C | |||
| Humidity | N/A | N/A | 5 to 95% (NC, 40°C) | |||
1 The number of users is defined by the license only
2 Measured on one CPU core at 2 GHz with 2 GB RAM on Sun Fire X2250 running VMware ESXi 4.0.0






