Valid

GB/T 31499-2026Cybersecurity technology - Technical specification for unified threat management products (English PDF)

网络安全技术 统一威胁管理产品(UTM)技术规范

Open the GB/T 31499-2026 preview as PDF

Preview — first pages of GB/T 31499-2026 (full document: 91 pages)

This is a limited preview

Buy now to download the full PDF (91 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

April 30, 2026

Implementation date

November 1, 2026

Scope

GB/T 31499-2026 is the English-translated version of 网络安全技术 统一威胁管理产品(UTM)技术规范.

GB/T 31499-2026 is the Chinese national standard covering the UTM appliance - firewall, intrusion prevention, antivirus, content filtering and VPN in one box, with the functional requirements for each and the performance that must be sustained when they run together rather than one at a time. At 26,500 words it replaces GB/T 31499-2015 and has been in force since 1 November 2026. It was issued on 30 April 2026 and takes effect on 1 November 2026, replacing GB/T 31499-2015. The document is under the responsibility of the Standardization Administration of China. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.

Document preview — GB/T 31499-2026

National Standard of the People's Republic of China

ICS
35.030
Classification
L 80
Replacing
GB/T 31499-2015

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 2 Schematic diagram of product testing environment deployment
  • 6 Safety Technical Requirements
  • 6.1 Safety Function Requirements
  • 6.1.1 Access Control
  • 6.1.3 Intrusion Prevention
  • 6.1.4 Malicious Program Prevention
  • 6.1.5 Secure Networking
  • 6.1.6 Safety Management
  • 6.1.7 Security Audit
  • 6.2 Self-safety requirements
  • 6.2.6 Resistance to Attacks
  • 6.3 Performance Requirements
  • 6.4 Environmental adaptability requirements
  • 6.5 Safety Assurance Requirements
  • 6.5.2 Design and Development
  • 7 Assessment Methods
  • 7.2 Security Function Evaluation
  • 7.2.1 Access Control
6.1.1 Access Control

6.1.1.1 Bandwidth Management The product should have bandwidth management functionality, with the following requirements.

a) Supports limiting traffic to a specified value based on conditions such as source IP address, destination IP address, protocol, application type, and time;

b) Supports bandwidth guarantees, ensuring that in the event of congestion, the stream will be re-encoded for a specified source IP address, destination IP address, protocol, application type, and time. The data is prioritized and forwarded according to a pre-set strategy.

6.1.1.2 Network Layer Access Control The product should have network layer access control functionality, with the following requirements.

a) The security policy uses the principle of least security, meaning that it prohibits anything unless explicitly permitted;

b) The security policy includes access control based on source IP address, destination IP address, transport protocol, source port, and destination port;

c) The security policy includes MAC address-based access control;

d) The security policy includes time-based access control;

e) Supports user-defined security policies, including MAC address, IP address, port, transport protocol, and time information. Or all combinations;

f) Supports automatic or manual binding of IP and MAC addresses. When the host's IP address and MAC address are bound to the IP/MAC address binding table... If there is a discrepancy, prevent its flow from passing through.

6.1.1.3 Application Layer Access Control The product should have application-layer access control functionality, with the following requirements.

a) Supports user authentication-based access control functions, including local user authentication and integration with third-party authentication systems;

b) Supports URL-based access control and includes a URL classification library;

c) Supports file type detection and filtering based on common protocols such as FTP, HTTP, HTTPS, POP3, IMAP, and SMTP. The interception criteria include file types that must at least include text, images, and audio/video.

6.1.3 Intrusion Prevention

6.1.3.1 Intrusion Detection The product should be able to detect intrusion activities on the network, and at least support the detection of the following intrusion activities.

a) Trojan backdoors, denial-of-service attacks, buffer overflows, etc.;

b) SQL injection attacks, XSS attacks, third-party component vulnerability attacks, etc.

6.1.3.2 Intrusion Blocking The product should support intelligent analysis and interception of detected intrusions to prevent them from entering the target network.

6.1.3.3 Custom Features The product should allow authorized administrators to customize event characteristics, and packets that match the customized characteristics can be blocked.

6.1.3.4 Attack Evasion Recognition The product should be able to detect behaviors that evade or deceive detection, and should at least support. IP fragment reassembly, TCP stream reassembly, protocol port relocation, and URL resizing. String manipulation and shell code manipulation.

6.1.4 Malicious Program Prevention

6.1.4.1 Transmission Detection The product should have the ability to detect malicious programs transmitted via protocols such as FTP, HTTP, POP3, IMAP, and SMTP.

6.1.4.2 Transmission Blocking The product should have the ability to block malicious programs transmitted via protocols such as FTP, HTTP, POP3, IMAP, and SMTP.

6.1.4.3 Compressed File Detection The product should have the ability to detect malicious programs in compressed files and should at least support ZIP and RAR compression formats.

6.1.5 Secure Networking

6.1.5.1 Network Address Translation The product should have SNAT and DNAT functions.

6.1.5.2 Routing 6.1.5.2.1 Static Routing The product should have static routing functionality and be able to configure static routes. 6.1.5.2.2 Dynamic Routing The product should have dynamic routing capabilities, including one or more dynamic routing protocols such as RIP, OSPF, and BGP. 6.1.5.2.3 Policy Routing Products with multiple network interfaces of the same attributes (multiple external, internal, or DMZ network interfaces) should support policy routing functionality. Please provide the following.

a) Policy-based routing based on source and destination IP addresses;

b) Interface-based policy routing;

c) Policy-based routing based on protocol and port;

d) Policy-based routing based on application type;

e) Automatically select routes based on multi-link load conditions.

6.1.5.3 Virtual Private Network The product should have VPN functionality, with the following requirements.

a) The cryptographic techniques used in the configuration of the Virtual Private Network comply with the relevant requirements of GB/T 36968-2018;

b) Supports basic IKE rule configuration, such as. IKE name, type, address, protocol, authentication method, etc.;

c) Supports basic tunnel configuration, such as tunnel name, address, VPN rules, etc.

d) Supports real-time monitoring and querying of the status of established VPN tunnels, such as. name, type, local information, peer information, and traffic status. State, etc.

6.1.6 Safety Management

6.1.6.1 Unified Security Policy Configuration The product should have the ability to configure security policies uniformly for multiple threats, as required below.

a) Supports unified interface and processes for various security measures such as access control, intrusion prevention, malware prevention, and anti-spam. It provides centralized configuration and management functions, enabling the coordinated use of multiple threat protection capabilities;

b) Provide matching conditions for unified security policies, detection and analysis of contradictory or redundant policies, and effective enforcement measures;

c) Provide unified security policy management functions, including querying, creating, modifying, deleting, starting and stopping, etc.

6.1.6.2 Incident Monitoring and Handling The product should have the function of unified monitoring and handling of various security incidents, with the following requirements.

a) Supports monitoring of abnormal traffic events by source IP address, destination IP address, port, time, or protocol, or a combination thereof;

b) Supports unified monitoring of security incidents such as intrusion attempts, malware, and spam;

c) Supports unified correlation and analysis of various security events such as abnormal traffic, unauthorized access, intrusion behavior, malware, and spam. analytical ability;

d) Supports coordinated handling of multiple security incidents, including abnormal traffic, unauthorized access, intrusion attempts, malware, and spam. ability.

6.1.6.3 Security Alarms The product should have a safety alarm function, with the following requirements.

a) Issue security alerts when intrusion attempts, malware, spam, or other security incidents are detected;

b) Supports one or more security alert methods such as email, SMS, pop-up, sound, and SNMPTrap.

6.1.6.4 Management Control 6.1.6.4.1 Local Management The product should support configuration management via local CLI or a graphical management interface. 6.1.6.4.2 Remote Management The product should support secure remote management, such as remote management based on SSH or HTTPS protocols. 6.1.6.4.3 Product Upgrade The product should have upgrade functionality, with the following requirements.

a) Supports online or offline upgrades of system versions and various security capability signature libraries;

6.1.7 Security Audit

6.1.7.1 Log Recording The product should support logging functionality, with the following requirements.

a) Supports a unified logging system for monitoring abnormal traffic, unauthorized access, intrusion attempts, malware, spam, and other security vulnerabilities. The ability to centrally record and manage events;

b) Log records include information such as date, time, source IP address, destination IP address, source port, destination port, and protocol;

c) The log is stored in a non-volatile storage medium that is susceptible to power loss;

d) Diary entries must be kept for at least six months;

e) Use cryptographic techniques to protect the confidentiality and integrity of the logs;

f) The communication process between the log agent and the log center should employ cryptographic techniques to ensure the confidentiality and integrity of the communication data.

6.1.7.2 Event Visualization The product should have event visualization capabilities, with the following requirements.

a) Provide a unified graphical display interface to showcase detected or intercepted security events;

b) Event information should include at least. the date and time of the event, the event name or type, the source IP address, the source port, and the destination IP address. Destination port, hazard level, etc.;

c) It has intelligent analysis function for attack stages, which can intelligently identify and classify attack stages and present them in the form of charts.

6.1.7.5 Event Classification The product should support the classification of events based on their severity.

6.1.7.6 Event Statistics The product should have security incident statistics capabilities, including at least abnormal traffic, unauthorized access, intrusion behavior, malicious programs, and spam.

6.1.7.7 Security Incident Retrieval The product should have real-time and historical data on security incidents such as abnormal traffic, unauthorized access, intrusion attempts, malware, and spam. Search capabilities.

6.2 Self-safety requirements

6.2.1 General Requirements Products should comply with the requirements of Chapter 5 of GB 42250-2022 regarding identification and authentication, self-access control, self-security auditing, and communication security. It meets the requirements for comprehensive support system security, product upgrades, user information security, and cryptography.

6.2.2 Identification and Marking The product should support identification and authentication capabilities, with the following requirements.

a) Provide login failure handling functionality and take measures such as limiting the number of consecutive login failures;

b) Provide a login timeout handling function to automatically log out when the login connection exceeds the set time limit;

c) Provide two or more combinations of authentication techniques to authenticate the user, one of which is a cryptographic technique;

d) Supports functionality for use with third-party authentication systems, such as RADIUS or LDAP authentication.

6.2.3 Self-access control The product should support its own access control capabilities, with the following requirements.

a) Provide authorized administrators with the ability to set, query, modify, and delete access control policies;

b) It can execute access control based on access control policies that consider security attributes such as the remote management host IP address and user roles;

c) Distinguish authorized administrator roles, classifying them into system administrators, security operators, and security auditors, with checks and balances between them;

d) Ensure the integrity of your access control policy after the upgrade.

6.3 Performance Requirements

6.3.1 Network Layer Throughput The network layer throughput of hardware products varies depending on the product's speed. Assuming the main security protection functions are operating effectively, it is necessary to... Please provide the following.

a) The bidirectional throughput target that a pair of ports with corresponding speeds should achieve. 1) For 64-byte short packets, the speed should be no less than 15% of the line speed for 100Mbps products and no less than 25% of the line speed for Gigabit and

10 Gigabit products; 2) For 512-byte medium-length packets, the speed should be no less than 60% of the line speed for 100Mbps products and no less than 70% of the line speed for Gigabit and

10 Gigabit products; 3) For 1518-byte long packets, the speed of 100 Mbps products should not be less than 80% of the line speed, and the speed of Gigabit and

10 Gigabit products should not be less than 85% of the line speed.

b) For high-performance

10 Gigabit products, the overall throughput should reach at least

80 Gbit/s for 1518-byte long packets.

6.4 Environmental adaptability requirements

6.4.1 Supports IPv6 network environments The product should support IPv6 network environments, with the following requirements.

a) The product should support normal operation in an IPv6 network environment and be able to effectively operate its security functions and its own security features;

b) In an IPv6 network environment, the product should support network address translation from IPv4 to IPv6, from IPv6 to IPv4, or from IPv6 to IPv6. Function.

6.4.2 Supports dual protocol stacks The product should support normal operation in an IPv4/IPv6 dual-stack network environment and be able to effectively run its security functions and its own security functions.

6.4.3 High Availability Deployment The product should support high-availability deployments such as dual-machine and cluster deployments.

6.4.4 Virtualization Deployment If the product is virtualized, it should support deployment on a virtualization platform and be subject to unified management by the platform, with the following requirements.

a) Integrate with a virtualization platform to achieve elastic scaling of product resources, dynamically adjusting resources based on the load of the virtualized product;

b) Combine with the virtualization platform to achieve fault migration, enabling automatic updates and replacements when virtualization products fail.

6.5 Safety Assurance Requirements

6.5.1 General Requirements Products should comply with the requirements of Chapter 6 of GB 42250-2022 regarding supply chain security, design and development, production and delivery, and operation and maintenance services. Requirements regarding security and user information protection.

7 Assessment Methods

7.1 Testing Environment and Tools A typical test environment for the Unified Threat Management (UTM) product is shown in Figure 2, where UTMA and UTMB represent a dual-machine deployment. The testing tools include, but are not limited to. dedicated network performance analyzers, network packet capture software, scanning tools, and attack toolkits. Figure

7.2.1 Access Control

7.2.1.1 Bandwidth Management The evaluation method for bandwidth management is as follows:

a) Testing and evaluation methods. 1) Configure traffic limiting policies based on source IP address, destination IP address, protocol, application type, and time, and send matching data to the product. The traffic is configured according to a strategy, and the traffic is gradually increased until it exceeds the bandwidth limit. 2) Configure a bandwidth guarantee policy based on specified source IP address, destination IP address, protocol, application type, and time, and send it to the product. Send traffic according to the matching strategy, and increase the traffic above the guaranteed bandwidth, then send other traffic to the product in an attempt to preempt the aforementioned traffic. Check the bandwidth used and see if the bandwidth guarantee policy is in effect.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 91 pages — is available in the English PDF.

Editions of GB/T 31499

EditionTitleRevisionStatus
GB/T 31499-2026Cybersecurity technology - Technical specification for unified threat management productscurrent editionCurrent
GB/T 31499-2015Cybersecurity technology - Technical specification for unified threat management productsprevious editionIn force until 1 November 2026

This page sells the current edition, GB/T 31499-2026. Earlier editions are listed for reference only.

How to Buy GB/T 31499-2026

  1. 1Add to cart. Click the "Buy GB/T 31499-2026" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
91 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 31499-2026

$785.00

$665.00for partners