Every connection, verified at the gate.

NXSgate splits your network into zones and checks every connection that moves between them: which app it is, who's using it, and whether it's safe. One policy covers your branch offices, your data center and your cloud.

  • Zone-based segmentation
  • Single-pass inspection
  • Hardware, virtual & cloud

Built for networks in

  • Financial services
  • Healthcare
  • Education
  • Public sector
  • Retail
  • Manufacturing
Zone-based security

Split the network into zones. Check everything that crosses.

Put your interfaces, VLANs, VPN tunnels and cloud subnets into zones like LAN, DMZ, Guest and IoT. Nothing moves between zones until a rule allows it, and anything that is allowed still gets inspected.

  • Blocked by default. Traffic can't cross from one zone to another unless a rule says so.
  • A rule for each direction. LAN → WAN and WAN → DMZ get their own rules, each with its own app, user and threat settings.
  • Attackers stay put. If a camera in the IoT zone gets hacked, it still can't reach your servers.
  • The same zones everywhere. Branches, data centers and cloud all share one zone setup.
See how zones work
The platform

One engine instead of a stack of boxes.

At every zone boundary, one engine looks at the app, the user and the content at the same time. You don't need a separate product for each job, so there are no gaps between them for threats to slip through.

Application control

Recognize apps whatever port or protocol they use, even when they try to hide. Then allow, limit or block them by name.

Learn more

Intrusion prevention

Block exploits, brute-force attacks and attackers moving around inside your network. Signatures update constantly, and odd protocol behavior gets flagged.

Learn more

Encrypted traffic inspection

Decrypt and inspect TLS 1.3 traffic, and leave private things like banking and health sites alone.

Learn more

Advanced threat protection

Unknown files are opened in a cloud sandbox first. Once one turns out to be malicious, every gateway you own blocks it.

Learn more

URL & DNS security

Block phishing sites, malware domains and brand-new domains before anyone can connect to them.

Learn more

Identity-aware policy

Write rules for people and teams instead of IP addresses. It plugs into your directory and single sign-on.

Learn more
How it works

Every connection is checked once, not five times.

Older firewalls bolt on extra engines, and each one scans the same packet all over again. NXSgate works out which zones a connection is crossing, decodes it once and runs every check side by side. That means you can switch everything on without slowing the network down.

  1. 01

    Match zones

    Every interface, VLAN and tunnel belongs to a zone, so NXSgate always knows which boundary a connection is crossing.

  2. 02

    Identify

    It works out the app, the user, the device and the content in one go.

  3. 03

    Inspect

    All the threat engines read the same decoded stream. Nothing gets scanned twice.

  4. 04

    Enforce & log

    The rule for that pair of zones decides whether to allow, limit, decrypt or block. Then it's logged with all the details.

Centralized management

Policy that reads like plain English.

Run every NXSgate gateway from one console, whether it's a box, a VM or a cloud instance. Write rules from one zone to another around apps and people, and NXSgate keeps the rule list tidy for you.

  • Rules that name their zones. You can tell what a rule is for just by reading it.
  • One policy for every site. Push a change to hundreds of gateways in one commit.
  • No more rule clutter. NXSgate points out rules that are hidden by others, duplicated or never used.
  • Ready for automation. Manage policy as code with the REST API and Terraform provider.
See management features
Deployment

Run it wherever your traffic is.

Same engine, same policy, whether it's a box in a branch office closet or an auto-scaling group in the cloud.

Hardware appliances

Purpose-built hardware for branch offices, campuses, and data centers.

  • Desktop and rackmount models
  • Zero-touch provisioning
  • Redundant power on larger models

Virtual firewalls

Run NXSgate on the hypervisors you already use.

  • VMware ESXi, KVM, Hyper-V
  • Flexible vCPU-based licensing
  • Micro-segmentation for east-west traffic

Public cloud

Protect your VPCs and VNets with built-in cloud integrations.

  • AWS, Microsoft Azure, Google Cloud
  • Auto-scaling and load-balancer integration
  • Tag-based dynamic policy

See what's really crossing your network.

Book a 30-minute walkthrough with one of our security engineers. We'll show you NXSgate and put together a traffic risk report for your network.