Firebox M570


Firebox® M470, M570 & M670 firewalls are specifically engineered for midsize and distributed enterprises that are struggling to effectively and affordably secure networks in the face of explosive growth in bandwidth rates, encrypted traffic, video use, and connection speeds. What’s more, the ability to add network modules for greater port density gives you the flexibility to adapt as the network grows and evolves.



Every network needs a full arsenal of scanning engines to protect against spyware, viruses, malicious apps, data leakage, botnets and more. WatchGuard’s award-winning network security platform not only provides the most complete suite of unified security controls on the market today, but we have consistently been the first to offer solutions for addressing new and evolving network threats including ransomware and advanced malware.

Typically deployed at the corporate headquarters, these appliances serve as the “hub” appliance, responsible for centrally managing and securing all communications between the head office and all remote employee and small business sites. WatchGuard Dimension, which is included at no additional cost, provides a suite of big data visibility and reporting tools that instantly identify and distill key network security threats, issues and trends, accelerating the ability to set meaningful security policies across the entire network.

Network environments are more diverse than ever, offering a vast array of options to choose from. With Firebox M470, M570, and M670, IT pros can customize their port configuration with expansion modules to meet current needs, while ensuring the flexibility to adapt as their network evolves. Firebox M470, M570, and M670 include a single slot for an expansion module, with options for 8 x 1 Gb fiber, 4 x 10 Gb fiber, or 8 x 1 Gb copper.


  • Up to 34 Gbps firewall throughput. Turn on all security scanning engines and still see up to an amazing 5.4 Gbps throughput
  • All logging and reporting functions included with purchase, with over 100 dashboards and reports including PCI and HIPAA
  • Gain critical insights about network security, from anywhere and at any time, with WatchGuard Dimension
  • Customize your port configuration to meet current needs, knowing you have the flexibility to adapt as the network evolves. This is how to future-proof your network and eliminate costly rip-and-replace scenarios
  • High availability capabilities ensure maximum uptime. Buy two Firebox M470, M570 & M670s for an active/passive high availability pair and receive 50% off the cost of the second device
WatchGuard FireBox M570
Firewall (UDP 1518)26.6 Gbps
Firewall (IMIX)7.6 Gbps
VPN (UDP 1518)5.8 Gbps
VPN (IMIX)2.0 Gbps
HTTPS (IPS enabled)3.4 Gbps
AntiVirus5.4 Gbps
IPS(fast/full scan)8.0/4.8 Gbps
UTM(fast/full scan)4.4/3.5 Gbps
Interfaces 10/100/1000*8 (optional
modules available)
I/O interfaces1 serial/2 USB
Concurrent connections8,300,000
Current connections (proxy)710,000
New connections per second115,000
WSM licenses (incl)4
TDR Host Sensors included250
Authenticated users limitUnrestricted
Branch Office VPN500
Mobile VPN IPSec500
FirewallStateful packet inspection, deep packet inspection, proxy firewall
Application proxiesHTTP, HTTPS, FTP, DNS, TCP/UDP, POP3, POP3S, SMTP, IMAP, IMAPS, and Explicit Proxy
Threat protectionDoS attacks, fragmented & malformed packets, blended threats & more
VoIPH.323, SIP, call setup and session security
Filtering optionsBrowser Safe Search, YouTube for Schools, Google for Business
Cloud providersAWS (Static/Dynamic), Azure (Static/Dynamic)
EncryptionAES 256-128 bit, 3DES, DES
IPSecSHA-2, IKE v1/v2, IKE pre-shared key, 3rd party cert, Suite B
Single sign-onWindows, Mac OS X, mobile operating systems, RADIUS, SAML 2.0
AuthenticationRADIUS, LDAP, Windows Active Directory, VASCO, RSA SecurID, internal
database, SAML 2.0, SMS Passcode
Logging and notificationsWatchGuard, Syslog, SNMP v2/v3
User interfacesCentralized console (WSM), Web UI, scriptable CLI
ReportingWatchGuard Dimension includes over 100 pre-defined reports, executive summary and visibility tools
SecurityPending: ICSA Firewall, ICSA IPSec VPN , CC EAL4+, FIPS 140-2
SafetyNRTL/C, CB
NetworkIPv6 Ready Gold (routing)
Hazardous substance controlWEEE, RoHS, REACH
RoutingStatic, Dynamic (BGP4, OSPF, RIP v1/v2), Policy-based routing
High AvailabilityActive/passive, active/active with load balancing
QoS8 priority queues, DiffServ, modified strict queuing
IP address assignmentStatic, DHCP (server, client, relay), PPPoE, DynDNS
NATStatic, dynamic, 1:1, IPSec traversal, policy-based, Virtual IP for server load balancing
Link aggregation802.3ad dynamic, static, active/backup
Other featuresPort Independence, Multi-WAN failover and load balancing, server load balancing, host header redirection, USB modem as a dedicated interface