|Number of USB 2.0 Ports||1|
ZyXEL ZyWALL USG20 Internet Security Firewall with 4 Gigabit LAN/DMZ Ports, 2 IPSec VPN, SSL VPN, and 3G WAN Support
- Enter your model number to make sure this fits.
- Hybrid VPN, both SSL and IPSec VPNs supported for flexible deployment.
- Comprehensive threat protection with firewall, VPN and content filtering.
- Flexible security zone using VLAN technology to segregate local networks.
- User-aware policy engine can set bandwith or network access based on user login.
- Bandwidth management for traffic prioritization for VoIP or mission critical applications.
There is a newer model of this item:
Customers who bought this item also bought
What other items do customers buy after viewing this item?
Compare to similar items
This item ZyXEL ZyWALL USG20 Internet Security Firewall with 4 Gigabit LAN/DMZ Ports, 2 IPSec VPN, SSL VPN, and 3G WAN Support
|Shipping||—||FREE Shipping||FREE Shipping||FREE Shipping||FREE Shipping||FREE Shipping|
|Sold By||—||Zyxel®||2020 PC||Amazon.com||Nebraska Blvd||Olivabel|
|Data Transfer Rate||150||400||300||1,000||1||1,000 MB per second|
|Item Dimensions||1.2 x 5.83 x 8.66 in||6 x 9 x 1 in||6 x 14 x 10 in||2.68 x 11.22 x 8.78 in||11 x 3.25 x 9.5 in||5.5 x 8.6 x 2.3 in|
|Item Weight||0.8 lb||2 lbs||7.45 lbs||1.81 lbs||1.39 lbs||1.58 lbs|
|Total LAN Ports||4||4||5||4||4||4|
|Wireless Compatibility||802.11bgn||802.11 a/b/g/n||802.11abg||—||802.11 a/b/g/n||802.11n|
The ZyWALL USG 20 is a Unified Security Gateway, integrated with complete, enterprise-level and advanced security solutions designed for Small/Medium Business (SMB) recommended for up to 5 PC users. Its flexible configuration helps network administrators set up the network and enforce security policies more efficiently. With certified by ICSA SPI Firewall and IPSec VPN, the ZyWALL USG 20’s security features also include IPSec VPN, SSL VPN, Firewall and Content Filter. It also provides bandwidth management, for QoS of VoIP or mission critical applications. Moreover, IPSec VPN and SSL VPN design for telecommuters and home workers can access data more easily and safely at home. Remote access with SSL VPN requires only a standard web browser. ZyWALL USG 20’s excellent throughput is the key to implement features of an enterprise level to provide a full-time, non-stop and secure service.
From the Manufacturer
Big Security for Small Businesses -Unified Security Gateway ZyWALL USG20
The ZyWALL USG20 is a Unified Security Gateway designed to provide complete, enterprise-level advanced security solutions to Small and Home Office networks, recommended for up to 5 PC users. Its flexible configuration is designed to help network administrators efficiently set up, manage, and enforce network security policies.
The USG20’s web-content filtering engine goes a step beyond simple URL blocking. It allows users to manage the level of content filtering, giving complete control over what types of websites that can be accessed on the network. Administrators can choose between BlueCoat and Commtouch web filtering services.
To further defend networks and provide greater control and ease of use, the USG20 also employs an anti-spam service to flag and discard commercial and unwanted e-mail messages, protecting important information from getting lost in the clutter.
Application Patrol gives you detailed control over the applications allowed to run on your network, while the built-in 150Mbps throughput firewall and web-content filtering protect your network from DoS attacks, phishing, and other threats.
Built with powerful Integrated High Performance Security architecture designed for Gigabit connections, a VPN throughput of 75Mbps, up to 6,000 max sessions and 5 concurrent IPSec VPN tunnels, the USG20 has the power to monitor and protect your network without sacrificing network performance.
- Robust hybrid VPN (IPSec, SSL, and L2TP*)
- Easily connect with mobile devices
- IPv6 Support
- QoS options for latency-sensitive applications
- Compatible with Vantage Reporting and Management software
- 30day trial of the antivirus software
* Enabled by ZLD3.0 firmware upgrade
Flexible, secure VPN options
The USG20 is designed to allow secure VPN connections no matter what device or network settings are being used. IPSec VPN support allows secure connections to branch offices, partners, and headquarters; road warriors and telecommuters can use SSL to securely access the company network without having to install VPN software.
Easy Mobile Access
The new ZLD3.0 firmware upgrade enables L2TP support on all USG devices, making it easy for Android, iOS, and other mobile devices to establish VPN tunnels to remote networks directly from their native settings.
With the advent of the new ZLD3.0 firmware, the USG20 is fully compatible with both IPv4 and IPv6 networks. Full backward compatibility allows VPN tunnels to be created between networks newly upgraded to IPv6 and older IPv4 networks, ensuring a seamless transition and painless network upgrades.
The USG20’s network optimization functionality makes it far more than a network security device. Bandwidth management options let administrators prioritize latency-sensitive applications like VoIP and videoconferencing, ensuring high-quality connections without lag or performance issues.
Vantage Management and Reporting
The USG20 supports the use of ZyXEL’s Vantage CNM and Vantage Reporting software, allowing centralized management and monitoring of multiple ZyWALL devices on a single network.
Vantage Reporting offers a comprehensive set of real-time and historical reports including firewall attacks, bandwidth usage, Website usage, and more - all organized into an automated, easy-to-read format that can be viewed from anywhere. Administrators can use this data to easily identify security problems and their causes and take prompt action.
Vantage CNM provides a suite of diagnostic and management tools that allows management of multiple ZyWALL devices from a centralized interface, reducing the time, cost, and complexity involved in VPN and security management. VPN monitoring allows network administrators to actively troubleshoot VPN problems as they occur, while centralized configuration of UTM functionality allows network administrators to manage license subscriptions, update devices, and isolate and repair security problems across all ZyWALL devices on a network.
Powerful Email security
The ZyWALL USG Series delivers industry-leading email protection against spam, phishing and virus-laden emails, powered by Commtouch. The high performance Commtouch technology comes from the unique recurrent pattern detection (RPD) mechanism that scours millions of new patterns each day (24x7x365) to block spam messages in real-time. In addition, the ZyWALL USG applies sender-based IP reputations to remove over 80% of unwanted mails and to offer zero-hour virus outbreak protection, capable of blocking or delaying suspicious messages hours before commercial anti-virus signatures are available.
ZyWALL USG Series Firewall Comparison
| || |
|Recommended number of PC Users||1-5||1-5||1-10||10-25||25-50||50-75||75-200||200-500|
|Unlimited User (No Per Node Limitation)|| || || || || || || || |
|High Performance multi-layer threat Protection|| || || || || || || || |
|10/100/1000 Interfaces (ALL GbE Copper)||4x LAN/DMZ, 1x WAN||4x LAN/DMZ, 1x WAN||4x LAN/DMZ, 2x WAN||5x LAN/DMZ, 2x WAN||5x LAN/DMZ, 2x WAN |
|7x Configurable||5x Configurable||6x Configurable|
System Capacity and Performance
|SPI Firewall Throughput (Mbps) (Largest Packet Size)||150||150||180||180||250||300||400||2000|
|VPN Throughput (AES)(Mbps) |
(Largest Packet Size)
|UTM Throughput (AV+IDP) (Mbps)(Largest Packet Size)||24||30||40||80||100||400|
|Max Concurrent IPSec VPN Tunnels||5||5||5||50||100||200||1000||2000|
|Max Concurrent SSL VPN Tunnels||1||1||5||5||10||25||250||750|
|Included SSL VPN Users||1||1||2||2||2||2||5||5|
|VPN Support||IPSec / SSL||IPSec / SSL||IPSec / SSL||IPSec / SSL/L2TP||IPSec / SSL/L2TP||IPSec / SSL/L2TP||IPSec / SSL/L2TP||IPSec / SSL/L2TP|
|Multiple WAN Load Balance / Fail Over|| || || || || || |
|iCard Antispam (Commtouch) 1 Year||ICAS1YUSG20WC||ICAS1YUSG20C||ICAS1YUSG50C||ICAS1YUSG100C||ICAS1YUSG200C||ICAS1YUSG300C||ICAS1YUSG1000C||ICAS1YUSG2000C|
|Anti-Virus (ZyXEL or Kaspersky) 1 Year|| |
|IDP (ZyXEL) 1 Year||ICID1YUSG50||ICID1YUSG100||ICID1YUSG200||ICID1YUSG300||ICID1YUSG1000||ICID1YUSG2000|
|iCard Content Filtering (BlueCoat or Commtouch) 1 Year|| |
|Total Security Service Kit(1 Year Kaspersky AV, 1 Year ZyXEL IDP, 1 Year BlueCoat CF bundle)||ICTS1YUSG50||ICTS1YUSG100||ICTS1YUSG200||ICTS1YUSG300||ICTS1YUSG1000||ICTS1YUSG2000|
|iCard SSL Upgrade Licenses(One Time)||2-5 Users SSL2TO5USG50||2-5 Users SSL2TO5USG100||2-10 Users |
2-10 Users SSL2TO10USG300
5-250 Users SSL5TO250USG2000
Top customer reviews
When I contact ZyXEL support, they say that this device is fully supported and not end of life however they recommend that I purchase a next gen device if I want the above fixed.
Plus dude: features are fantastic. UI is pretty good. CLI is nice if you want it. You REALLY need to spend some time going through all the menu's and getting a feel for all the groups, and categories and all that. Dont change stuff until you go through it all. Like all firewalls, take your time and configure it. All the features I ever needed are there, just took me a bit to go through all of them. I only have one problem and it's minimal, but needs to be noted.
The enclosure/case is REALLY REALLY cheap. The plastic feels like styrofoam or super brittle plastic. I personally don't care because I sit it on a shelf and I will never touch it but they could invest a LITTLE BIT in the case. I would pay an extra $20 to get aluminum or metal or some sort so it's stackable or atleast doesnt feel like it would shatter if it got bumped! I would NOT stack anything near this guy and if you think it might move or be moved often... this thing is NOT rugged!
On the other hand, trying to register it through ZyXEL's procedure doesn't work at all. The process requires visiting portal.myzyxel.com and setting up an account. I did that and received a popup stating, "You will receive an email with instructions on how to confirm your email address in a few minutes." That was yesterday morning.
After waiting about six hours and having clicked on the "Resend Confirmation" link several times, I submitted a request to ZyXEL customer service. Several hours later I received an email response from Miguel, saying, "We check on our system the e-mail address that you provided and still shows unconfirmed. Please check your spam, junk or any other firewall folder on your e-mail that may be preventing you from receiving the confirmation e-mail."
Well, yes, it is unconfirmed because I never received the instructions telling me how to confirm it. And I don't have a spam folder or a junk folder or any other firewall folder that would prevent me from receiving the confirmation email.
Interestingly, I registered two switches with ZyXEL at the same time yesterday. These do not "qualify" for the special myzyxel registration , so I registered them over the web. I immediately received confirmation emails for both of them. I also received Miguel's email. So I wonder why my system would be suspected of trapping the confirmation email for the USG 50.
I did reply to Miguel last night and, not surprisingly, have heard nothing back. In the meantime I have waited over 28 hours for their gimmicky registration process to process my registration.
However, please note this: if you are looking for something that will do content filtering AV inspection of SSL/TLS encrypted traffic, then you should probably look at the next gen models, because this one only supports plaintext protocols. I now see that for just $100 over the price I paid ($550 total - $250 for the USG50 + $299 for the AV/filtering licenses), you can get the USG110 and the purported inspection of SSL/TLS traffic. Perhaps I should have done additional requirements analysis here, but feel a bit miffed since the price diff was minimal. And given the trend for malware and other attacks to increasingly occur over encrypted channels, it just feels pointless to only offer inspection of plaintext protocols. For this, I took a star away from the rating.
Another issue I have is that this is a security device that still has SSLv3 enabled by default on its management interfaces (haven't tested it with the SSL vpn feature though) and with no perceivable way to disable it. I won't opine as to why SSLv3 should not be used any longer (just google it), but I feel compelled to take away a star on my rating for this.
Nonetheless, this little guy is able to keep up with the small office needs in terms of throughput (save for full bore vulnerability scans that have to be appropriately throttled). You aren't going to find a magic bullet for your network security needs. It just doesn't exist. But this is a great layer in your defenses that can't be beat for the price.
Most recent customer reviews
Two internet providers connected and so far running perfect.Read more
They are hard to set up but work well if you can get them set up.Read more
See the Top Rated Wireless Routers in our Wireless Router Reviews.