Modular network security software platform with content filtering, IPS, VPN, and bandwidth shaping, deployable on dedicated hardware appliances from the Q4 (10-50 users) to Q20 (enterprise) or on virtual and cloud infrastructure.
NG Firewall is a modular network security software platform that consolidates content filtering, intrusion prevention, VPN, and application-based bandwidth shaping into a single product deployable across a range of hardware appliances, virtual machines, and cloud environments. The modular architecture allows organisations to activate the security capabilities they need without paying for capabilities they do not (an organisation that requires only content filtering and VPN does not need to operate the bandwidth shaping or IPS modules), while leaving a clear upgrade path as requirements grow. The browser-based management interface provides a single dashboard for configuring and monitoring the security posture of individual appliances or a distributed estate of appliances across multiple sites, without requiring a separate management server or a client application installed on the operator's workstation.
The appliance range spans from the Q4 to the Q20, covering deployments from 10-user branch offices to multi-hundred-user enterprise sites. The Q4 (the entry-level model) uses a quad-core Intel Atom X6413E processor, 8 GB DDR4, 128 GB eMMC storage, and 4 GbE interfaces, sized for locations with up to 50 users and 150 devices. The Q20 at the high end uses 32 GB DDR4 and provides 17 GbE interfaces with SFP options, for environments where the port count and processing headroom of the entry-level appliance would be insufficient. Virtual and cloud deployment options allow the same software to be run on KVM or VMware infrastructure without hardware procurement, or hosted in a cloud environment for organisations that have moved their perimeter security function to cloud-based infrastructure. The same NG Firewall codebase runs in all deployment modes, ensuring consistent policy behaviour between hardware, virtual, and cloud instances managing the same network segments.
Content filtering inspects outbound web traffic against category and reputation databases, blocking access to categories defined as out of policy (malware distribution sites, phishing pages, prohibited content categories) and returning a block page to the user when a request is denied. Advanced threat protection extends this with behavioural analysis that identifies threats not yet present in reputation databases, catching malware delivered via compromised legitimate domains that would pass a reputation-only filter. For organisations with acceptable use policies that specify which web categories staff may access on company equipment, the content filter provides both the technical enforcement and the audit log that demonstrates the policy is being enforced, a combination that is required for compliance frameworks that mandate acceptable use controls.
The NG Firewall IPS module inspects network traffic against a continuously updated rule set that covers known attack patterns, exploit signatures, and protocol anomalies, blocking traffic that matches an attack pattern before it reaches the targeted service. Unlike perimeter firewalls that enforce access control at the port and protocol level, an IPS operates at the content level: a request to TCP port 443 that passes a firewall rule permitting HTTPS traffic will still be inspected by the IPS for payload patterns consistent with a web application exploit or a command-and-control protocol tunnelled inside HTTPS. The IPS rule set is updated continuously as new vulnerability disclosures and attack techniques are documented, providing protection against newly disclosed vulnerabilities within hours of the rule being published rather than waiting for a scheduled firmware update cycle.
Bandwidth shaping in NG Firewall operates at the application layer rather than the IP or port layer, allowing policies to prioritise or limit traffic by application regardless of the port or protocol the application uses. An organisation that wants to prioritise VoIP and video conferencing traffic over file sharing and streaming media does not need to maintain port-based ACLs that quickly become stale as applications change the ports they use. The shaping policy references the application category, and the classification engine identifies the application from traffic patterns. Bandwidth limits can be applied to specific application categories to prevent a single application from consuming disproportionate WAN capacity, and priority queuing ensures latency-sensitive applications (VoIP, video, interactive remote desktop) receive transmission priority over bulk transfers during periods of link saturation.
NG Firewall runs on dedicated hardware appliances (Q4 through Q20), on KVM or VMware virtual machines where hardware procurement is not preferred, and in cloud environments for organisations hosting their perimeter security function in cloud infrastructure. The same software codebase operates in all three deployment modes, which means that a policy configured on a hardware appliance and the equivalent policy on a virtual instance produce identical filtering behaviour; there is no feature parity gap between hardware and virtual deployment. For organisations managing a mixed estate of hardware branch appliances and virtual data centre instances, this parity allows the same administrator to manage all sites from the same dashboard without needing separate tooling or training for hardware versus virtual deployments.
Full specifications for NG Firewall
Download product documentation and resources
Explore other configurations and models that might suit your needs.
Recommended#Arista-7130E
Recommended#Arista-EDGE-THREAT-MANAGEMENT-SOLUTIONS
Recommended#Arista-MSS
Our team of experts is ready to help you find the perfect solution for your business needs. Get personalized advice and competitive quotes.
We're here to help with any questions