SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Secure Network · Firewall · Live

SD-WAN Firewall

Protect against external threats. A next-generation firewall for the wide area network, with built-in intrusion detection, a curated block list and a zoning concept that keeps policies maintainable. Operated 24/7 by Level-3 engineers.

Overview

Protect the WAN without a policy jungle.

Protect wide area networks from external threats with a next-generation firewall that blocks malicious traffic and applies a policy management concept designed to avoid the security gaps that complex rulebases create.

Built-in intrusion detection and hybrid policy management give you extensive traffic monitoring, threat detection and response, and a firewall service that stays maintainable as you grow.

How we protect your network

Four things it does.

Advanced filtering

Deep packet inspection detects applications automatically, so one application rule replaces several rules for protocols, ports and destination IPs.

Threat protection

We curate and maintain a block list of malicious domains. Firewall, Secure Web Gateway and Secure Email Gateway share this layer as part of the service.

Intrusion detection

Built-in IDS adds real-time monitoring and detection. Our Level-3 engineers triage, investigate and remediate around the clock.

Hybrid management

Global IT sets the corporate policy through zone transitions. Local IT maintains local objects and defines exceptions in agreement with global IT.

How it works

Zones instead of one-to-one rules.

Through the zoning concept, many network segments or interfaces are summarized into one zone of a given security level. One zone transition policy then replaces a long list of individual access rules.

Global IT

  • Defines the corporate security policy through general zone transitions
  • Keeps one consistent baseline across every region

Local IT

  • Maintains and updates local firewall objects
  • Defines exceptions or new zones together with global IT
Multi-zone approach

Security and trust, segment by segment.

Our firewall architecture introduces distinct security zones. These zones segment the global network into different levels of security and trust, and communication between zones is controlled explicitly.

Traffic is filtered at every transition between zones while security is maintained inside each zone. The integrity of the SD-WAN is shielded not only from internet threats, but also from doubtful internal sources in untrusted zones.

Resources

Go deeper.

Already a customerEverything you use today keeps running.