Application control
Recognize apps whatever port or protocol they use, even when they try to hide. Then allow, limit or block them by name.
Learn moreNXSgate splits your network into zones and checks every connection that moves between them: which app it is, who's using it, and whether it's safe. One policy covers your branch offices, your data center and your cloud.
Built for networks in
Put your interfaces, VLANs, VPN tunnels and cloud subnets into zones like LAN, DMZ, Guest and IoT. Nothing moves between zones until a rule allows it, and anything that is allowed still gets inspected.
| From ↓ To → | WAN | LAN | DMZ | Guest | IoT |
|---|---|---|---|---|---|
| WAN | — | Deny | Inspect | Deny | Deny |
| LAN | Inspect | — | Allow | Deny | Limit |
| DMZ | Inspect | Deny | — | Deny | Deny |
| Guest | Limit | Deny | Deny | — | Deny |
| IoT | Limit | Deny | Deny | Deny | — |
At every zone boundary, one engine looks at the app, the user and the content at the same time. You don't need a separate product for each job, so there are no gaps between them for threats to slip through.
Recognize apps whatever port or protocol they use, even when they try to hide. Then allow, limit or block them by name.
Learn moreBlock exploits, brute-force attacks and attackers moving around inside your network. Signatures update constantly, and odd protocol behavior gets flagged.
Learn moreDecrypt and inspect TLS 1.3 traffic, and leave private things like banking and health sites alone.
Learn moreUnknown files are opened in a cloud sandbox first. Once one turns out to be malicious, every gateway you own blocks it.
Learn moreBlock phishing sites, malware domains and brand-new domains before anyone can connect to them.
Learn moreWrite rules for people and teams instead of IP addresses. It plugs into your directory and single sign-on.
Learn moreOlder firewalls bolt on extra engines, and each one scans the same packet all over again. NXSgate works out which zones a connection is crossing, decodes it once and runs every check side by side. That means you can switch everything on without slowing the network down.
Every interface, VLAN and tunnel belongs to a zone, so NXSgate always knows which boundary a connection is crossing.
It works out the app, the user, the device and the content in one go.
All the threat engines read the same decoded stream. Nothing gets scanned twice.
The rule for that pair of zones decides whether to allow, limit, decrypt or block. Then it's logged with all the details.
Run every NXSgate gateway from one console, whether it's a box, a VM or a cloud instance. Write rules from one zone to another around apps and people, and NXSgate keeps the rule list tidy for you.
| Rule | Zones | Application | Action |
|---|---|---|---|
| Block high-risk apps | Any → WAN | BitTorrent, Tor | Block |
| Finance SaaS | LAN → WAN | Salesforce, NetSuite | Allow |
| Public web servers | WAN → DMZ | HTTPS | Allow + inspect |
| Guest internet | Guest → WAN | Web browsing | Limit 10 Mbps |
| Default deny | Any → Any | Any | Block + log |
Same engine, same policy, whether it's a box in a branch office closet or an auto-scaling group in the cloud.
Purpose-built hardware for branch offices, campuses, and data centers.
Run NXSgate on the hypervisors you already use.
Protect your VPCs and VNets with built-in cloud integrations.
Book a 30-minute walkthrough with one of our security engineers. We'll show you NXSgate and put together a traffic risk report for your network.