McAfee
Network Security Platform
Faster time to protection. Faster time to resolution. Faster time to confidence.

More pricing below, click here
McAfee Network Security Platform Overview:
McAfee Network Security Platform (NSP) provides industry-leading threat protection. It delivers security that is automated, actionable, scalable, and easily integrated and managed. It identifies, blocks, and mitigates threats while providing full visibility into your security infrastructure. With McAfee NSP, you can substantially improve your security, while you reduce effort and cost.
| Key Advantages: | |
|---|---|
Enterprise-wide coverage
McAfee SRM integration
Fast, accurate decisions
|
Reliable, network-class platforms; next-generation network protection
Operational efficiency
|
Description:
How intelligent is your network security?
Enterprises today can't afford a security breach, compromised network performance, or unplanned downtime. These events translate into lost revenue, lost productivity, and even damage to a company's reputation. To reduce risk and ensure compliance, enterprises must employ tighter security measures.
Consider a smarter, more efficient approach to security risk management. McAfee Network Security Platform (NSP) network intrusion prevention gives you more visibility and more relevant information, so you can quickly make the right decisions.
McAfee NSP is a single, integrated solution that gives you real-time insight into what's putting your network and systems at risk, and what you need to do about it. The time that it takes to identify and mitigate attacks shrinks from days to clicks.
With McAfee NSP action-oriented security, you automatically manage risk and meet compliance requirements—while reducing dependency on IT resources.
To provide the highest level of security, McAfee NSP collaborates with your security infrastructure and integrates with other McAfee products, including McAfee ePolicy Orchestrator (ePO), McAfee Network Access Control (MNAC), and McAfee Vulnerability Manager.
Get the highest uptime and port density available with a platform that’s easy to manage, configure, administer, and monitor. McAfee Network Security Platform is the perfect fit for Class A, mission-critical global enterprise networks.
With the Network Security Platform action-oriented security, you automatically manage risk and meet compliance requirements—while reducing IT resource dependency. With Network Security Platform you get:
- A network-class platform for any enterprise that needs absolute security confidence
- Collaborative security for integrated, intelligent protection to defend against attacks and secure your infrastructure
- Award-winning broad, accurate, and efficient protection for every network-connected device
Network Security Platform is a single, integrated solution that gives you insight into what's putting your network and systems at risk and what you need to do about it—in real time. The time it takes to acknowledge an attack to its final resolution shrinks dramatically. And the process is accurate and complete.
Network Security Platform makes network security smarter because it collaborates with your security infrastructure and integrates with other McAfee products:
- McAfee ePolicy Orchestrator® (ePO™)
- McAfee Network Access Control (MNAC)
- McAfee Vulnerability Manager
Get more visibility into your network on demand all in one place—including threat and risk relevance. Add it all up, and you have prioritized, pertinent information that enables Network Security Platform to act on the most pressing issues.
The Network Security Platform portfolio of high-performance, scalable appliances offers the highest up-time and port density available. It’s easy to manage, configure, administer, and monitor all Network Security Platform IPS appliances across widely distributed deployments with McAfee Network Security Manager (formerly McAfee IntruShield® Security Manager (ISM) ). Network Security Platform is the perfect fit for Class A, mission-critical global enterprise networks.
The Network Security Central Manager |
|
|
|
Benefits and Features:
Benefits:
|
Features:
|
Network Security Platform Specifications:
Which Network Security Platform is right for you?
| McAfee Network Security Platform Specifications | ||||
|---|---|---|---|---|
![]() |
||||
| Sensor Hardware Components | M-8000 | M-6050 | M-4050 | M-3050 |
| Performance | ||||
| Real-World Throughput | 10 Gbps | 5 Gbps | 3 Gbps | 1.5 Gbps |
| Max Throughput (UDP 1512 Byte Packets) | Up to 20 Gbps | Up to 10 Gbps | Up to 4 Gbps | Up to 2.5 Gbps |
| Maximum Concurrent Connections | 4,000,000 | 2,000,000 | 1,500,000 | 750,000 |
| New Connections per Second | 120,000 | 60,000 | 36,000 | 18,000 |
| Throughput with SSL Decryption (based on 10% SSL traffic) | 8.8 Gbps | 4.4 Gbps | 2.7 Gbps | 1.3 Gbps |
| Maximum SSL Flow Count | 400,000 | 200,000 | 150,000 | 75,000 |
| SSL Keys Imported | 64 | 64 | 64 | 64 |
| Profiles | ||||
| Number of Virtual IPS Systems | 1,000 | 1,000 | 1,000 | 1,000 |
| Maximum DoS Profiles | 5,000 | 5,000 | 5,000 | 5,000 |
| ACL Rules | 1,000 | 1,000 | 1,000 | 1,000 |
| Ports | ||||
| Gigabit Ethernet—Fixed Copper Ports | – | – | – | – |
| Gigabit Ethernet—SFP Ports | 16 | 8 | 8 | 8 |
| 10-Gigabit Ethernet | 12 | 8 | 4 | 4 |
| Dedicated response ports (GigE) | 1 | 1 | 1 | 1 |
| Dedicated management ports (GigE) | 1 | 1 | 1 | 1 |
| Ports with Built-in Fail-Open Capabilities | – | – | – | – |
| Control Ports for External Fail-Open k=Kits | 14 | 8 | 6 | 6 |
| Physical | ||||
| Dimensions | 2x 2RU Rack mountable 16.75 (W) x 3.05 (H) x 30.00 (D) | 2RU Rack mountable 16.75 (W) x 3.05 (H) x 30.00 (D) | 2RU Rack mountable 16.75 (W) x 3.05 (H) x 30.00 (D) | 2RU Rack mountable 16.75 (W) x 3.05 (H) x 30.00 (D) |
| Weight | 94 lbs. (2x47) | 47 lbs. | 47 lbs. | 47 lbs. |
| Power | 100-240VAC (50/60Hz) | |||
| Power consumption | 900w (2x450w) | 450w | 450w | 450w |
| DC Power available | Optional | Optional | Optional | Optional |
| Temperature | 0° to 35° C (operating) –40° to 70° C (non-operating) |
|||
| Relative humidity (non-condensing) | Operational: 10% to 90% Non-operational: 5% to 95% |
|||
| Altitude | 0 to 10,000 feet | |||
| Safety certification | UL 1950, CSA-C22.2 No. 950, EN-60950, IEC 950, EN 60825, IEC 60825, 21CFR1040 CB license and report covering all national country deviations. | |||
| EMI certification | FCC Part 15, Class A (CFR 47) (USA) ICES-003 Class A (Canada), EN55022 Class A (Europe), CISPR22 Class A (Int'l) | |||
| Sensor Hardware Components | M-2950 | M-2850 / M-2750 | M-1450 | M-1250 |
| Performance | ||||
| Real-World Throughput | 1.0Gbps | 600 Mbps | 200 Mbps | 100 Mbps |
| Max Throughput (UDP 1512 Byte Packets) | Up to 1 Gbps | Up to 1 Gbps | Up to 300 Mbps | Up to 150 Mbps |
| Maximum Concurrent Connections | 750,000 | 750,000 / 250,000 | 80,000 | 40,000 |
| New Connections per Second | 15,000 | 10,000 | 4,000 | 2,000 |
| Throughput with SSL Decryption (based on 10% SSL traffic) | 900 Mbps | 550 Mbps | N/A | N/A |
| Maximum SSL Flow Count | 25,000 | 25,000 | N/A | N/A |
| SSL Keys Imported | 64 | 64 | N/A | N/A |
| Profiles | ||||
| Number of Virtual IPS Systems | 100 | 100 | 32 | 16 |
| Maximum DoS Profiles | 5,000 | 300 | 120 | 100 |
| ACL Rules | 1,000 | 400 | 100 | 50 |
| Ports | ||||
| Gigabit Ethernet—Fixed Copper Ports | 8 | 8 / – | 8 | 8 |
| Gigabit Ethernet—SFP Ports | 12 | 12 / 20 | – | – |
| 10-Gigabit Ethernet | – | – | – | – |
| Dedicated response ports (GigE) | 1 | 1 | 1 | 1 |
| Dedicated management ports (GigE) | 1 | 1 | 1 | 1 |
| Ports with Built-in Fail-Open Capabilities | 8 | 8 / – | 8 | 8 |
| Control Ports for External Fail-Open k=Kits | 6 | 6 / 10 | – | – |
| Physical | ||||
| Dimensions | 2RU Rack mountable 15.88(W) x 3.3(H) x 24.5(D) | 2RU Rack mountable 15.88 (W) x 3.3 (H) x 24.5 (D) | 1RU Rack mountable 17.37 (W) x 1.65 (H) x 13.5 (D) | 1RU Rack mountable 17.37 (W) x 1.65 (H) x 13.5 (D) |
| Weight | 40 lbs. | 40 lbs. | 12 lbs. | 12 lbs. |
| Power | 100-240VAC (50/60Hz) | |||
| Power consumption | 450w | 450w | 120w | 120w |
| DC Power available | Optional | Optional | No | No |
| Temperature | 0° to 40° C (operating) –40° to 70° C (non-operating) |
|||
| Relative humidity (non-condensing) | Operational: 10% to 90% Non-operational: 5% to 95% |
|||
| Altitude | 0 to 10,000 feet | |||
| Safety certification | UL 1950, CSA-C22.2 No. 950, EN-60950, IEC 950, EN 60825, IEC 60825, 21CFR1040 CB license and report covering all national country deviations. | |||
| EMI certification | FCC Part 15, Class A (CFR 47) (USA) ICES-003 Class A (Canada), EN55022 Class A (Europe), CISPR22 Class A (Int'l) | |||
| Built-in Next Generation Features | ||||||||
|---|---|---|---|---|---|---|---|---|
| Sensor Software Components | M-8000 | M-6050 | M-4050 | M-3050 | M-2750 | M-1450 | M-1250 | |
| Stateful traffic inspection | IP defragmentation and TCP stream reassembly | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Detailed protocol analysis | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Asymmetric traffic monitoring | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Protocol normalization | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Advanced evasion protection | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Forensic data collection | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Protocol tunneling | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Protocol discovery | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Stacked VLAN | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Signature detection | User-defined signatures | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Real-time signature updates | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Anomaly detection | Statistical anomaly | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Protocol anomaly | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Application anomaly | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| DoS detection | Threshold-based detection | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Self-learning profile-based detection | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Maximum DoS profiles | 5,000 | 5,000 | 5,000 | 5,000 | 300 | 120 | 100 | |
| Intrusion prevention | Stop attacks in progress in real time | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Drop attack packets/sessions | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Host quarantine | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Initiate TCP reset, ICMP unreachable | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Packet logging | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Automated and user-initiated prevention | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| Internal firewall | Blocks unwanted and nuisance traffic | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Granular security policy enforcement | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
| High availability | Stateful failover | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Management | Command line interface (console) | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Manager communication | Secure channel | Secure channel | Secure channel | Secure channel | Same for all models | Same for all models | Same for all models | |
McAfee Network Security Platform M-Series:
Multi-gigabit security and performance for next-generation 10 Gigabit Ethernet networks
Award-winning, industry-leading McAfee® Network Security Platform (formerly McAfee IntruShield®) extends network intrusion prevention system (IPS) technology to protect today’s next-generation 10 Gigabit Ethernet (10GigE) networks. Its extensible and integrated architecture delivers enterprise-wide protection and compliance that brings reliable, high-performance intrusion prevention to data center and service provider networks.
| Key Advantages: | |
|---|---|
Next-generation network protection
McAfee SRM
|
McAfee collaborative security infrastructure
Reliable, network-class appliance
|
Enterprise-wide Network Security Platform
McAfee Network Security Platform delivers unprecedented knowledge-driven security. Together with McAfee’s security
risk management (SRM) framework, Network Security Platform collaborates with McAfee Vulnerability Manager (formerly McAfee
Foundstone® Enterprise) McAfee ePolicy Orchestrator® (ePO™), and McAfee Network Access Control (MNAC) to provide
intelligent and real-time security that’s exponentially more accurate and efficient than traditional point products.
Network Security Platform is simply the world’s most advanced and comprehensive network intrusion prevention solution. Its action-oriented security allows you to automatically manage risk and meet compliance—while reducing IT resource dependency. Its network-class platform is for any enterprise that needs absolute security confidence, up to 10 Gbps performance, and collaborative security for integrated and intelligent enterprise-wide protection that prevents attacks and secures your infrastructure. No other network security solution protects your business more broadly, accurately, and efficiently.
High-performance, network-class IPS platforms |
|
McAfee Network Security Platform M-8000 |
![]() McAfee Network Security Platform M-6050 |
Award-winning Protection
Network Security Platform’s integrated protection and ASIC-based, easy-to-use platform delivers broad asset protection, maximized business
availability, reduced liability, and security cost avoidance. Network Security Platform’s highly accurate prevention technology provides
built-in protection against a wide range of threats and attacks, including:
- Zero-day attacks, cyber-attacks, and malware
- Spyware, phishing, and other unwanted programs
- Voice over IP (VoIP) threats and vulnerabilities
- Denial of service (DoS), distributed DoS (DDoS), and SYN flood attacks
- Encrypted attacks, worms, Trojans, and evasions Instant messaging and peer-to-peer applications
- Protocol-based dynamic rate limiting
- Infrastructure quality of service
Knowledge-driven Network Security, Real-time Security Confidence
Smart network and system security integration delivers real-time security that’s not just automated, but actionable.
With the click of a mouse, you’ve got intelligent IPS that provides critical host details, top host intrusion and spyware
attacks, and accurate threat and risk relevance, on demand. A real-time security solution empowers real-time security decisions,
giving you:
- Faster time-to-protection with system-aware ePO integration, built-in host quarantine, and adaptive rate limiting
- Faster time-to-confidence with a right-click to Vulnerability Manager scanning support, built-in host quarantine, and adaptive rate limiting
Advanced Enforcement
- Adaptive rate limiting - Real-time, adaptive protocol rate shaping allows you to easily and effectively control your network bandwidth while blocking unwanted and risky applications
- Comprehensive threat prevention - Proactively protects the network from known, zero-day, DoS, and encrypted attacks, as well as threats like spyware, VoIP vulnerabilities, malware, IM, botnets, network worms, Trojans, and peer-to-peer applications
- Built-in host quarantine - Real-time quarantine protection provides automated host quarantine

Network Security Platform Security Manager's clean and simple interface
Documentation:
![]()
Download the McAfee Network Security Platform Datasheet (PDF).
![]()
Download the McAfee Network Security Platform Multi-Gigabit Series Datasheet (PDF).



