VCL Products > Firewall > VCL-MX-5020-R-ES-4E1
VCL-MX-5020-R-ES-4E1: Router with Enhanced Security
VCL-MX-5020-R-ES-4E1 is an IEC 61850-compliant industrial router with enhanced security and integrated firewall capabilities, featuring E1 interfaces and support for VPN, L2TPv3, IPSec, OSPF, BGP, IS-IS. It is purpose-built to secure critical infrastructure such as utilities, substations, smart grid networks, transportation systems, and enterprise IT environments. The router is ideal for highreliability applications across energy, transport, and financial sectors. It supports a wide range of interfaces, including RJ45 Electrical, SFP Optical, and ITU-T G.703 compliant E1 ports and encryption.
Highlights:
- High-reliability hardware
- Easy installation and management
- Suitable for installation in sub-stations, SCADA and industrial networks / harsh environments
- Supports for Gigabit Ethernet, Optical Ports, ITU-T G.703 Compliant E1 Interfaces (with 128/256 bit encryption)
- Detailed system logging, built-in reporting and monitoring tools including real-time graphs
- Export logs locally or on a Syslog server
- Network Flow Monitoring
- Suitable for 1+0 non-redundant and 1+1 redundant installation with automatic failover*. Support Active-Active mode
- High availability functionality with Active-Active and Active-Passive features
- Secure Boot
- Secure Web Gateway (SWG)
- Data Loss Prevention (DLP)
- Resistance to Denial of Service (DoS) Attack
- Prevention of DDoS & DoS-added
- Content filtering and Brute Force attack mitigation
- Non-volatile Access Log with capability to "fingerprint" all successful and failed log-in attempts and keep a log of the IP addresses of all successful and failed logins / login attempts.
- Integrated threat control includes prevention of network attacks
- Intelligent protection of endpoints includes authentication, authorization and control
- Support out of band management through management port / console
- In service / remote software upgrade
- SYN cookie protection
- Zone based IP spoofing
- Malformed packet protection
- Software and Hardware Token Supported (TOTP)
- IEEE 1613
- IEC 61850-3, IEC 60068-2-27, IEC 60068-2-6 compliance
VCL-MX-5020-R-ES offers a wide range of VPN technologies ranging from modern SSL VPN's to IPsec. Site-to-Site and road warrior setups are possible and with the integrated OpenVPN client exporter, the client can be configured within minutes.
*Redundant device Failover switching with VCL-Ethernet Failover Switch.
Firewall Security:
- Inclusion Policy—Access Control based upon White List IP addresses, MAC address and IP Domain
- Exclusion Policy—Access Control based on Black-List Continuous monitoring of the TLS connection to nullify MitM attacks.
Interfaces Options:
- 4 x 1G Optical (SFP) Ethernet Interfaces
- 4 x 10/100/1000 BaseT RJ45 Electrical Ethernet Interfaces
- 4 x ITU-T G.703 Compliant E1 Interfaces, 120 Ohms OR
- 8 x 10/100/1000 BaseT RJ45 Electrical Ethernet Interfaces
- 4 x ITU-T G.703 Compliant E1 Interfaces, 120 Ohms
E1 Clock Synchronization Interface Options:
- External Clock: 1 PPS, 10MHz
- Internal Clock: Stratum 3E or higher
E1 Encryption Options:
- AES-128, AES-256
- 3 DES, DES
Throughput:
- Router with E-SEC : 14.40 Gbit/s
- Network Firewall : 14.08 Gbit/s
- IPSEC VPN Throughput / port : 120 Mbit/s
Network Management (NMS) and Monitoring Ports:
- 1 x 10/100/1000BaseT RJ45 Electrical Ethernet dedicated Secure Management Port
- 1 x RS232 (RJ45) Console Port for local access and management
Routing Features and Capabilities:
- GUI and CLI based
- Static and Dynamic IP addressing for physical and logical interfaces
- IPv4 and IPv6 IP addressing format supported
- Support for multiple IP address
- ARP, IP forwarding
- Static routing, Default routing, VLAN based routing, CARP redundancy
- Routing Protocols: RIPv1, RIPv2, OSPFv2 and OSPFv3, BGPv4
- Layer 2, Layer 3 routing
- TCP/IP, UDP, DHCPv4, DHCPv6
- SNMPv2, SNMPv3
- ACL Layer 2, Layer 3 Security
- QoS, Traffic Shaper
- Supports 802.1Q VLAN
- System Authentication and remote access via RADIUS
- SSH (Secure Access Control) with encrypted password protection.
GUI Features:
- Comprehensive Dashboard for centralized overview of diagnostics, monitoring, device health, systemstatus, and keymetrics
- Smart quick and efficient search functionality for streamlined user experience
- Detailed system information, Interface status and monitoring, and network overview
- Granular usermanagement with role-based access control for secure system access
- Real-time surveillance for identifying and responding to live threat and network fluctuations
- Comprehensive functionality for tracking and logging system, network and user activities and events.
Security - Features and Capabilities:
- Next Generation Firewall (NGFW)
- Allows firewall rule creation for each port, independently
- May be installed in non-redundant 1+0 or redundant 1+1 in an automatic failover* configuration. Support Active-Active mode
- High availability functionality with Active-Active and Active-Passive features
- Deep Packet Inspection (DPI)
- Point-to-Point and Point-to-Multipoint applications
- Unified NMS – Up to 1000 devices may be configured and managed through unified NMS
- HTTP based smart GUI for individual nodes
- Per-frame/packet authentication
- Support NAT, PAT, Policy based NAT/PAT, Mapped IP (MIP), Virtual IP (VIP), VoIP protocols
- Authentication protocols: RADIUS, LDAP
- Supports IKE, IKEv2, PKI (X.509)
- 802.1Q VLANs : 4,094
- Stateful inspection firewall
- Virtual Private Network (OpenVPN site to site and remote VPN client support)
- Supports up to 500 IPSec Site to Site Tunnels
- Filtering of protocols like FTP, SMTP, HTTP, HTTPS, SNMP, UDP, ICMP, RPC, DNS, DHCP, ARP, TCP, POP3
- Whitelist and blacklist options:
- Allows traffic based on user configured rules
- MAC layer filtering
- Two-factor Authentication with time-based OTP for secure access
- Forward Caching Proxy (transparent) with Blacklist support
- Network Flow Monitoring
- DNS Server, DNS Forwarder, Dynamic DNS
- DHCP Server and Relay
- Granular control over state table
- VXLAN supported
- Transparent to network and applications
- LDAP user authentication support
- Export logs locally or on a server.
- *Redundant device Failover switching with VCL-Ethernet Failover Switch.
Security and traffic filtering:
- Port based, MAC based, IP Address based
- IP Domain based
- Protocol type
- URL based
Technical Specifications:
- Integrated Storage Drive: 16GB High Performance SATA Drive
- Additional Storage Options: M.2 SATA—256GB, 512GB, 1TB SSD
- Power Supply: Dual (1+1) Redundant Power Inputs* (Power Supply Options)
- Indicators: 2 x Power Supply Indicators
- Processor: Dual Core up to 1.6 GHz
- RAM (DDR 3): 4GB
- Performance: Industrial System
- MTBF (hours): 101292
- IP Level Protection: IP20
- Power Consumption @ 48VDC: < 30 Watts
- Power Consumption @ 80~240, 50/60Hz VAC: < 34 Watts
Typical VCL-MX-5020-R-ES-4E1 Deployments:
- Utilities—Power, Oil, and Gas Installations
- Industrial Applications
- Campus IP Networks, for all types of data, voice, and video over IP applications
- MPLS meshed networks
- Metro Ethernet and VPLS networks
- Cloud applications.
Supported Hash Algorithms:
- MD5, AES-XCBC
- SHA 1, SHA 256, SHA 384, SHA 512
Supported Encryption Algorithms:
- AES-128, AES-192, AES-256
- 128 bit AES-GCM with 128 bit ICV
- 192 bit AES-GCM with 192 bit ICV
- 256 bit AES-GCM with 256 bit ICV
- Camellia 128, 192, 256
- Blowfish 128, 192, 256
- RSA, ECDSA
- 3DES, CAST 128,DES
CE Compliance:
- Low Voltage Directive 2014/35/EU (48V DC Version)
- Electromagnetic Compatibility 2014/30/EU
Other Regulatory Compliances:
- RoHS,
- CE Marking
- Complies with FCC Part 68 and EMC FCC Part 15
VCL-MX-5010-R-ES: Router with Enhanced Security VCL-MX-5040-R-ES: Router with Enhanced Security VCL-MX-5050-R-ES: Router with Enhanced Security VCL-MX-5010-R: MPLS Router VCL-MX-5020-R: MPLS Router VCL-MX-5040-R: MPLS Router VCL-MX-5050-R: MPLS Router VCL-5051, 10G Optical repeater VCL-2143, Network MouseTrαp VCL-2140: IEC -104, MODBUS RTU Firewall VCL-2702: Network Isolation (Kill) Switch VCL-5001: Network Traffic Sniffer VCL-2457: Cyber-Smart Rack Monitoring and Control Unit VCL-UNMS: Unified Network Management System