Valid

GB/T 44810.1-2024Technical requirement for IPv6 network security equipment—Part 1: Firewall (English PDF)

IPv6网络安全设备技术要求 第1部分:防火墙

Open the GB/T 44810.1-2024 preview as PDF

Preview — first pages of GB/T 44810.1-2024 (full document: 17 pages)

This is a limited preview

Buy now to download the full PDF (17 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

October 26, 2024

Implementation date

February 1, 2025

Scope

GB/T 44810.1-2024 is the English-translated version of IPv6网络安全设备技术要求 第1部分:防火墙.

GB/T 44810.1-2024 is the Chinese national standard covering a firewall that must filter IPv6 as well as IPv4 — the network environment and the deployment modes, the network, traffic and application control, the attack protection, the audit, alarm and statistics, the throughput, delay, connection rate and concurrent connections, the fault tolerance and overload control, and the self-security clauses on authentication, upgrade and the protocol stack of the device itself, exposed the moment it is put on the wire. Part 1 of the GB/T 44810 series, with the intrusion prevention part GB/T 44810.3-2024. First edition, under the Ministry of Industry and Information Technology. In force from 1 February 2025. Issued on 26 October 2024, it has been in force since 1 February 2025.

Document preview — GB/T 44810.1-2024

National Standard of the People's Republic of China

ICS
33.040.40
Classification
M 32

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • Preface III Introduction IV 1 Scope1
  • 2 Normative references1
  • 3 Terms and Definitions1
  • 4 Abbreviations1
  • 5 Functional requirements2
  • 5.1 Network Environment2
  • 5.2 Networking and Deployment3
  • 5.3 Network Control4
  • 5.4 Traffic Management5
  • 5.5 Application Control5
  • 5.6 Attack Protection6
  • 5.7 Security Audit, Alarm, and Statistics6
  • 5.8 Security Policy Settings7
  • 6 Performance Requirements8
  • 6.1 Throughput8
  • 6.2 Delay8
  • 6.3 Connection Rate8
  • 6.4 Concurrent connections8
  • 7 Compatibility Requirements8
  • 8 Reliability Requirements8
  • 8.1 System Fault Tolerance8
  • 8.2 Fault Monitoring and Recovery9
  • 8.3 Hot Standby9
  • 8.4 Overload Control9
  • 8.5 Backup and Recovery9
  • 8.6 Exception Handling Mechanism9
  • 9 Self-security requirements9
  • 9.1 Identification and Authentication9
  • 9.2 Self-Access Control9
  • 9.3 Self-security audit9
  • 9.4 Communication security9
  • 9.5 Support System Security9
  • 9.6 Product Upgrade10
  • 9.7 User Information Security10
  • 9.8 Password Requirements10
  • 9.9 Protocol Stack Security10
  • References11

Foreword

This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents". Drafting is required.

This document is Part 1 of GB/T 44810 "Technical Requirements for IPv6 Network Security Equipment". GB/T 44810 has been published as follows part. Part 1: Firewall;- Part 2: Web Application Protection System (WAF);- Part 3: Intrusion Prevention Systems (IPS). - Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.

This document is proposed by the Ministry of Industry and Information Technology of the People's Republic of China.

This document is under the jurisdiction of the National Communications Standardization Technical Committee (SAC/TC 485).

This document was drafted by: China Academy of Information and Communications Technology, Huawei Technologies Co., Ltd., Beijing Tianrongxin Network Security Technology Co., Ltd., Beijing Shenzhou Green Alliance Technology Co., Ltd., Zhengzhou Xindajiean Information Technology Co., Ltd., Beijing Haohan Deep Information Technology Co., Ltd.

Computer Network Emergency Response Technology Coordination Center, China Telecom Group Co., Ltd., Tianyi Security Technology Co., Ltd., Hangzhou Di Pu Technology Co., Ltd., Beijing Tonghe Shiyi Telecommunications Science and Technology Research Institute Co., Ltd., National Industrial Information Security Development Research Center, China Welfare Institute International Peace Maternal and Child Health Hospital, New H3C Technologies Co., Ltd., Beijing Trustworthy Huatai Information Technology Co., Ltd., Hangzhou Anhengxin Information Technology Co., Ltd., Beijing Guotai Internet Information Technology Co., Ltd., Shenzhen University, and Yunnan Power Grid Co., Ltd.

The main drafters of this document are: Meng Nan, Dong Yue, Wang Yuchen, Li Xiang, Huang Yajing, Lei Xiaofeng, Peng Xiaojun, Ye Jianwei, Liu Weihua, Pang Shaomin, Cao Zheng, Yan Dingyu, Qin Jiawei, Zhang Jianyu, Kang He, Zhang Xi, Wu Qing, Zuo Hong, Huang Shu, Zhang Dachao, Cheng Xi, Zhou Hao, Chen Changjie, Chen Lei, Wan Xiaolan, Du Jun, Duan Guna, Tian Lidan, Li Xin, Li Yuanzheng, Jiang Kui, Xiao Peng, and Wang Hailin.

Introduction

According to the Notice on Accelerating the Scale Deployment and Application of Internet Protocol Version 6 (IPv6), in order to better cope with the complex network environment, In order to meet the security challenges brought by the proliferation of IPv6 and the expansion of user scale, China has developed a series of IPv6 security standards.

Among them, GB/T 44810 "Technical Requirements for IPv6 Network Security Equipment" is to standardize the applicability of network security products in IPv6.

The technical standard is planned to consist of three parts.

Part 1: Firewall. The purpose is to ensure the effective application of firewalls in the new network environment after IPv6 deployment.

Part 2: Web Application Protection System (WAF). The purpose is to protect the Web application protection system after IPv6 deployment.

Effective application of WAF in the new network environment.

Part 3: Intrusion Prevention System (IPS). The purpose is to ensure that the Intrusion Prevention System (IPS) is used in the new network after IPv6 is deployed.

Effective application in network environment.

Technical Requirements for IPv6 Network Security Equipment Part 1: Firewall

1 Scope

This document specifies the security technical requirements for firewall devices that support IPv6.

This document applies to the design, development, deployment, use, maintenance, and testing of firewall devices that support IPv6.

2 Normative references

GB/T 20281-2020

GB/T 25069-2022

GB 42250-2022

GB/T 44810.3-2024

3 Terms and Definitions

The terms and definitions defined in GB/T 25069-2022, GB/T 20281-2020 and the following apply to this document.

3.1 firewall

A network security product that parses passing data streams and implements access control and security protection functions.

Note. In this document, firewall refers only to "network firewall".

[Source. GB/T 20281-2020, 3.1]

3.2 authorized administrator

Users with firewall management permissions can obtain different management permissions based on their roles.

Note. Such as system administrator, security administrator and security auditor.

4 Abbreviations

The following abbreviations apply to this document.

ALG. Application Layer Gateway BGP4.Border Gateway Protocol Version 4 DHCPv6.Dynamic Host Configuration Protocol for IPv6 DMZ. Demilitarized Zone DNS. Domain Name System DNSv6.Domain Name System for IPv6 FTP. File Transfer Protocol

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 17 pages — is available in the English PDF.

Referenced standards

Editions of GB/T 44810.1

EditionTitleRevisionStatus
GB/T 44810.1-2024Technical requirement for IPv6 network security equipment - Part 1: Firewallcurrent editionCurrent

This page sells the current edition, GB/T 44810.1-2024. Earlier editions are listed for reference only.

How to Buy GB/T 44810.1-2024

  1. 1Add to cart. Click the "Buy GB/T 44810.1-2024" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
17 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 44810.1-2024

$305.00

$260.00for partners