H3C NS-SecPath M9000-X10 Sec Path M9000-X10 Multi-Service Security Gateway Device

H3C NS-SecPath M9000-X10
H3C NS-SecPath M9000-X10 Sec Path M9000-X10 Multi-Service Security Gateway Device. Dimensions (W x H x D): 440mm×264mm×857mm(6RU). Supervisor Engine Module Slot Count: 2. Weight (kg): < 120kg
Key Specifications
Need configuration help?
Our CCIE certified engineers can help you verify compatibility.
Fast Dispatch
Global logistics network aiming for same-day handover.
Guaranteed Quality
Every unit undergoes rigorous 38-point inspection test.
Global Reach
Trusted by enterprise clients across 6 continents.
Expert Support
Certified network engineers ready to assist with configuration.
Overview
Specifications
| Catalog Description | |
|---|---|
| Description | H3C Sec Path M9000-X10 Multi-Service Security Gateway Device |
| Key Specifications | |
| Dimensions (W x H x D) | 440mm×264mm×857mm(6RU) |
| Weight (kg) | < 120kg |
| Ambient temperature | Operating: 0~40℃; Non-operating: -40~70℃ |
| Supervisor Engine Module Slot Count | 2 |
| Service Module Slot Count | 8 |
| Fabric Module Slot Count | 4 |
| Product Specifications | |
| Supervisor Engine Module Slot Count | 2 |
| Service Module Slot Count | 8 |
| Fabric Module Slot Count | 4 |
| Redundancy design | Supervisor Engine Module, Fabric Module, Power Supply, Fan |
| Dimensions (W x H x D) | 440mm×264mm×857mm(6RU) |
| Weight (kg) | < 120kg |
| Ambient temperature | Operating: 0~40℃; Non-operating: -40~70℃ |
| Operating Mode | Routing mode, transparent mode, bridge mode |
| AAA Services | Portal authentication, RADIUS authentication, HWTACACS authentication, PKI/CA (X.509 format) authentication, domain authentication supports manual key, IKEv2, redundant VPN gateway, EAP authentication, IKEv2 redirection |
| Multi-service Security Gateway | Virtual multi-service security gateway supports security zone division, can defend against a variety of malicious attacks including Land, Smurf, Fraggle, Ping of Death, Tear Drop, IP Spoofing, IP fragmented packets, ARP spoofing, active ARP reverse query, illegal TCP packet flag bits, oversized ICMP packets, address scanning, port scanning, SYN Flood, UDP Flood, ICMP Flood, DNS Flood, etc. It features dynamic packet filtering, application layer packet filtering, static and dynamic blacklist functions, MAC and IP binding function, MAC-based access control list, and supports ICMPv6, DHCPv6, 802.1q VLAN transparent transmission, MLD, ND |
| Security Policy | Supports access control lists based on domain name (domain name group), service, user, application, time period and other elements. Supports policy risk level division, supports application risk tuning, supports fuzzy query, can retrieve redundant and unhit policies, supports policy grouping, can connect to third-party platforms through the NETCONF interface to perform operations such as creating, deleting, modifying and moving policies. Security monitoring based on state legitimacy supports access control based on blacklists and whitelists, and supports one-click setting of blacklists and whitelists based on alarms |
| Routing Features | Supports static routing and dynamic routing: routing protocols such as RIP, OSPF, BGP, ISIS, etc. Supports policy routing based on source/destination IP, source/destination port, service, application type, user and user group, in/out interface, link status, etc. |
| Virus Protection | Supports virus signature detection and protection based on IPv4 and IPv6 dual stack, can scan and kill viruses including email viruses, web application viruses, common file viruses, Trojans, worms, malicious web pages, compressed data, packed and compressed package (zip, gzip, tar) viruses. Supports manual and automatic upgrade of virus signature database, supports manual import of signature database, supports cloud-based virus signature database packet stream processing mode. Supports HTTP, FTP, SMTP, POP3 protocols. Supported virus types: Backdoor, Email-Worm, IM-Worm, P2P-Worm, Trojan, Ad Ware, Virus, etc. Supports virus logs and reports |
| Web Security Protection | Supports Web security detection, supports CC attack protection, supports server abnormal outbound connection detection, supports custom learning parameters. Supports protection against attacks such as webpage trojan planting, Trojan, etc. Supports detection and protection against password brute-force attacks on common Web services (including HTTP, FTP, SSH, SMTP, IMAP, etc.) and common database software (MySQL, Oracle, MSSQL) |
| In-depth Security Protection | Supports defense against attacks such as hacker attacks, worms/viruses, Trojans, malicious code, spyware/adware, etc. It can subdivide strategies and formulate intrusion prevention templates according to different scenarios. Supports defense against application layer (HTTP, HTTPS, DNS, FTP, SIP, etc.) Flood attacks, can set learning time and threshold through machine self-learning, and automatically generate DDoS prevention strategies based on results. Supports defense against attacks such as buffer overflow, SQL injection, IDS/IPS evasion, etc. Supports classification (by attack type, target system) and grading (four levels: high, medium, low, alert) of attack signature database. Supports manual and automatic upgrade of attack signature database (via TFTP and HTTP). Supports identification and control of P2P/IM applications such as BT. Supports URL identification, supports malicious URL blocking, can connect with cloud URL server to expand the size of URL address library. For unknown threat attacks, it supports docking with local and cloud sandboxes to detect APT attacks in real time. Supports docking and management with unified security management platform, facilitating global network security situation protection |
| Encrypted Traffic Protection | Supports HTTPS proxy, SSL offloading, can perform content detection and filtering, auditing and attack protection on decrypted HTTPS encrypted traffic. It can perform fine-grained classification and decryption of URLs to improve protection effectiveness |
| Email/Web/Application-Layer Filtering | Email FilteringSMTP Email Address Filtering Email Header Filtering Email Content Filtering Email Attachment Filtering Web FilteringHTTP URL FilteringHTTP Content Filtering Application Layer Filtering Java Blocking ActiveX BlockingSQL Injection Attack Prevention |
| Intelligent Bandwidth Control | Supports bandwidth guarantee based on user, IP, interface and service, supports traffic shaping, supports maximum/minimum traffic and connection number rate limiting management per IP and per user. Supports setting flow control policies based on application layer protocols, can set maximum/minimum bandwidth, guaranteed bandwidth, protocol flow priority, etc., supports 8-level management and control |
| Load Balancing | Supports application layer link load balancing based on HTTP and HTTPS, supports DNS transparent proxy, supports DNS filtering, supports intelligent DNS, supports server load balancing, supports global load balancing, supports link health status detection, supports intelligent link selection |
| NAT | Supports mapping multiple internal addresses to the same public network address; supports mapping multiple internal addresses to multiple public network addresses; supports one-to-one mapping from internal addresses to public network addresses; supports port multiplexing technology to increase the upper limit of NAT translation; supports simultaneous translation of source address and destination address, and provides real-time alarm when the usage of source NAT address pool exceeds the limit; supports external network hosts accessing internal servers; supports direct mapping of internal addresses to the public IP address of the interface; supports DNS mapping function; supports configurable effective time for address translation; supports multiple NAT ALGs, including DNS, FTP, H.323, ILS, MSN, NBT, PPTP, SIP, etc.; supports NAT444, NAT44, NAT64, NAT46, NAT66 |
| VPN | L2TP VPN, IPSec VPN, GRE VPN, MPLS VPN, SSL VPNSupports IPv6 over IPv4 GRE tunnels |
| IPv6 | IPv6 stateful firewall, IPv6 inter-domain policy, IPv6 attack prevention, IPv6 connection limit. IPv6 protocols: ICMPv6, PMTU, Ping6, DNS6, TraceRT6, Telnet6, DHCPv6 Client, DHCPv6 Relay, etc. IPv6 routing: RIPng, OSPFv3, BGP4+, static routing, policy-based routing, PIM-SM, PIM-DM, etc. IPv6 transition technologies: NAT-PT, IPv6 Tunnel, NAT64(DNS64), DS-LITE, etc. |
| High Reliability | Supports RBM dual-device state hot backup (two working modes: Active/Active and Active/Backup); supports asymmetric paths; supports IKE state synchronization for IPSec VPN; supports VRRP; supports static and dynamic link aggregation; supports In-Service Software Upgrade (ISSU); supports hot patch technology for smooth upgrade, and supports dual-device hot backup for software of different versions; supports BFD link detection |
| Maintainability | Supports command-line based configuration management. Supports remote configuration management via Web. Supports device management through H3C iMC management platform. Supports standard network management SNMPv3, and is compatible with SNMP v1 and v2. Through simulated deployment, it can compare the learning results obtained based on service access relationships with to-be-deployed policies, which facilitates operation and maintenance personnel to manage security policies. Meanwhile, it supports compliance inspection of security policies via methods including black and white lists, application type, policy risk, security rules, mixed rules, etc. It supports security policy logs, NAT logs, security protection logs, and URL logs, and can include log fields of all the above types. NAT logs support port segment allocation, and device logs can be sent via polling |
| Environmental Protection and Certification | Supports Europe's strict RoHS environmental certification |
| Ordering Information | |
| Main Control Engine Board | |
| 0231AG1R | NSQM7SUPA0 - H3C Sec Path M9000-X Supervisor Engine Module, Class A |
| 0231AKK4 | NSQM7SUPA0-CN - H3C Sec Path M9000-X Supervisor Engine Module, Class A, Locally Produced |
| 0231ANBD | NSQM7SUPC0-G - H3C Sec Path M9000-X Supervisor Engine Module, Class C (G) |
| 0231AQQ6 | NSQM7SUPC0-G1 - H3C Sec Path M9000-X Supervisor Engine Module, Class C (G1) |
| Power Supply | |
| 0231ABYC | PSR2400-54A-E - 2400WAC Power Module |
| 0231ABYA | PSR2400-54D-E - 2400WDC Power Module |
| 0231ABYB | PSR3000-54A-E - 3000W AC power Module |
| 0231ABYD | PSR3000-54AHD-E - 3000W AC & 240V–380V High-Voltage DC power Supply Module |
| Cable | |
| 04042967 | CAB-CON-1.8m - Configuration Serial Cable—1.8 m—(DB9 Female to 8-pin Ethernet Port) |
| 0404A1EE | CAB-Console-1.8m-W31R - Configuration Port Cable-1.8m-(RJ45P)-(UL2725(3C28AWG))-(USB AP) |
| Fan Options | |
| 0231AG1M | FAN-120B-3-A10 - H3C Fan Tray Module (10, A, Rear Exhaust) |
| Rack Rail | |
| 0231A0PL | LSTM2KSGD0 - Installation Slide Rail Accessories—500 mm to 800 mm |
| 0231A4EK | LSXM1BSR - 1U Adjustable Rack Rail—630 mm to 900 mm |
| Custom Development Authorization Letter Selection | |
| 3130A4S4 | LIS-SeerEngine-Sec-CDC - H3C Seer Engine-Sec Security Controller Custom Development (1 person-day) Authorization Letter |
| Sec Pathlicense certificate | |
| 3130A3XS | LIS-M9000-SSL-10000 - H3C Sec Path M9000 SSL VPN license certificate 10000 x User |
| 3130A3XV | LIS-M9000-SSL-5000 - H3C Sec Path M9000 SSL VPN license certificate 5000 x User |
| 3130A382 | LIS-M9000-URL-1Y - H3C Sec Path M9000 URLsignature database update service license certificate,1 year |
| 3130A381 | LIS-M9000-URL-3Y - H3C Sec Path M9000 URLsignature database update service license certificate,3 years |
| 3130A48C | LIS-M9000-TI-1Y - H3C Sec Path M9000 Threat Intelligence Upgrade Authorization, 1 Year |
| 3130A48B | LIS-M9000-TI-3Y - H3C Sec Path M9000 Threat Intelligence Upgrade Authorization, 3 Year |
| 3130A1RT | LIS-M9000-ACG-1Y - H3C Sec Path M9000,application identificationsignature database update service,1 year |
| 3130A1RU | LIS-M9000-ACG-3Y - H3C Sec Path M9000,application identificationsignature database update service,3 years |
| 3130A1TR | LIS-M9000-AV-1Y - H3C Sec Path M9000,AV anti-virus security license,1 year |
| 3130A1TS | LIS-M9000-AV-3Y - H3C Sec Path M9000,AV anti-virus security license,3 years |
| 3130A1RR | LIS-M9000-IPS-1Y - H3C Sec Path M9000,IPS signature database update service,1 year |
| 3130A1RS | LIS-M9000-IPS-3Y - H3C Sec Path M9000,IPS signature database update service,3 years |
| 3130A1RW | LIS-M9000-SSL-200 - H3C Sec Path M9000,SSL VPN 200 x User |
| 3130A1RX | LIS-M9000-SSL-500 - H3C Sec Path M9000,SSL VPN 500 x User |
| 3130A1RY | LIS-M9000-SSL-1000 - H3C Sec Path M9000,SSL VPN 1000 x User |
| 3130A1S0 | LIS-M9000-SSL-3000 - H3C Sec Path M9000,SSL VPN 3000 x User |
| 3130A3QD | LIS-M9000-WAF-1Y - H3C Sec Path M9000, WAF Signature Database Upgrade License, 1 year |
| 3130A3QE | LIS-M9000-WAF-3Y - H3C Sec Path M9000, WAF Signature Database Upgrade License, 3 years |
| 3130A6Q4 | LIS-SecPath-AI-IOM - H3C Sec Path Series AI Intelligent Operation and Maintenance Packet Tracing Function Authorization Letter |
| IMCSSLlicense certificate | |
| 3130A2WY | LIS-IMC7-SVM9KC-1K - H3C iMC-SSL VPN Authentication Client-M9000-1000 License |
| 3130A2WA | LIS-IMC7-SVM9KA-200 - H3C iMC-SSL VPN Authentication Client-M9000-200 License |
| 3130A2WC | LIS-IMC7-SVM9KD-3K - H3C iMC-SSL VPN Authentication Client-M9000-3000 License |
| 3130A2WB | LIS-IMC7-SVM9KB-500 - H3C iMC-SSL VPN Authentication Client-M9000-500 License |
| Specialized Services | |
| 8814A125 | SV-PS-EDS-OS - Overseas Experts Day |
| Product Identity | |
| Brand | H3C |
| Series | H3C M9000-X Series Products |
Reviews
No reviews yet
Be the first to review this enterprise product.
Warranty
Standard Warranty Policy
All hardware sold by ITMall includes our 3-Year Free Maintenance and 1-Year RMA Replacement Service. Please refer to our Warranty Policy for details.
- 1-Year Advance Replacement (RMA)
- 3-Year Free Repair Service
- Full coverage for functionality defects
Hassle-Free RMA Process
We streamlined the return process to minimize your network downtime. Our engineering team provides pre-return diagnostics to ensure hardware is truly defective.
- 30-Day satisfaction guarantee return window
- Automated RMA portal access for instant tracking
- Restocking fee waived for functionality issues
Certified Engineering Support
Our products are backed by CCIE-certified engineers who provide expert guidance on compatibility, configuration, and troubleshooting at no extra cost.
- Free pre-sales topology consultation
- Remote troubleshooting & firmware advice
- Simulation lab testing before dispatch
Global Logistics & Packaging
We ship to 85+ countries using premium anti-static packaging to ensure safety. Orders placed before 14:00 (GMT+8) are typically dispatched the same day.
- Double-walled boxes with customer molded foam
- Blind shipping support for channel partners
- Real-time tracking via FedEx / DHL / UPS
Resources
FAQ
Is this product Brand New?
What is the warranty period?
Do you offer volume discounts?
How fast can you ship?
Still have questions?