Platform

Everything NXSgate does, in one place

Zones, app control, threat prevention, TLS inspection, VPN and SD-WAN in one product, all managed from one console. Here's how each part works.

Security zones

Set up your zones once. Enforce them everywhere.

Every NXSgate policy starts with zones. Put interfaces, VLANs, VPN tunnels and cloud subnets into zones that match how your network is actually used, then decide exactly what's allowed to cross between them.

  • Almost anything can join a zone. Physical ports, VLANs, link aggregates, IPsec and SSL VPN tunnels, and cloud subnets.
  • Blocked until you allow it. Traffic between zones is denied until a rule lets it through. You choose how each zone treats traffic inside itself.
  • Every crossing is inspected. Allowed traffic gets app control, IPS and TLS inspection without any extra setup.
  • Protected edges. Each zone boundary is guarded against floods, scans and spoofed traffic.
Application control

Know which apps are running, and decide what they can do.

A port number doesn't tell you what's really going on. NXSgate recognizes the app itself, even when it hops ports, hides inside HTTPS or tries to dodge detection, so your rules match what people actually do.

  • Rules down to the feature. Allow Microsoft 365 but block personal OneDrive. Allow Slack but block file uploads.
  • A risk score for every app. Based on how it behaves, what data it can expose and its known vulnerabilities.
  • Find shadow IT. See which unapproved SaaS and AI tools people are using.
  • Rules for people. Tie traffic to users and groups from your directory or SSO provider.
Threat prevention

Stop known and new threats before they get in.

All the prevention engines share one decoded stream, so you can leave every one of them switched on. When something new shows up, NXSgate analyzes it and turns the result into protection for every gateway.

  • Intrusion prevention. Blocks exploits, brute-force attempts and protocol abuse.
  • Anti-malware and file control. Scans files as they stream through, with rules by file type and direction.
  • Cloud sandboxing. Unknown files are opened in a sandbox, and the verdict is shared automatically.
  • URL and DNS security. Stops phishing, command-and-control traffic and DNS tunneling at the first lookup.
Encrypted traffic

Look inside encrypted traffic, and still respect privacy.

Most web traffic is encrypted now, and attackers count on that. NXSgate decrypts and inspects TLS where it matters, and your policy decides what stays private.

  • TLS 1.3 inspection. Works with modern ciphers and forward secrecy.
  • Skip what's private. Leave health, banking and other sensitive sites alone.
  • Handles pinned certificates. Spots apps that break when inspected and lets them through automatically.
  • Hardware acceleration. Appliance models have dedicated chips for the encryption work.
Secure connectivity

Connect every office and every remote worker.

Run your WAN and remote access on the same gateway that handles security. Every path gets inspected, and every tunnel follows the same rules.

  • Site-to-site VPN. IKEv2 IPsec with modern ciphers. Mesh and hub-and-spoke layouts are set up for you.
  • Remote access. VPN with or without a client app, plus MFA and device health checks.
  • SD-WAN. Sends each app down the best link, whether that's MPLS, broadband or LTE/5G.
  • High availability. Active/passive and active/active clusters that fail over without dropping connections.
SD-WAN IPsec IPsec SSL VPN HQ data centerNXS-5000 · HA pair Branch officeNXS-100 Cloud VPCNXS-V Retail siteNXS-100 Remote usersVPN client + MFA
Management & automation

Manage one gateway or a thousand.

One console for every gateway, with the reports your security team needs and the APIs your platform team expects.

  • One console. In the cloud or on your own servers, with role-based access and change approvals.
  • Reports that answer questions. Dashboards for threats, apps and users, plus scheduled compliance reports.
  • Send logs anywhere. Syslog, CEF and built-in connectors for the major SIEMs.
  • Policy as code. REST API, Terraform provider and Ansible collection.
Models & specifications

A gateway for every location.

Every model runs the same software and is managed from the same console, so your policy goes wherever your network grows.

Three NXSgate appliances side by side: a compact desktop model, a 1U rack-mount model and a 2U rack-mount model.
Concept design. Final hardware may differ.

Swipe sideways to see every model.

Specification NXS-100Branch & small office NXS-500Mid-size & campus NXS-2000Large enterprise NXS-5000Data center NXS-VVirtual & cloud
Form factorDesktop1U rackmount1U rackmount2U rackmountVM / cloud image
Firewall throughput4 Gbps12 Gbps40 Gbps120 GbpsUp to 20 Gbps
Threat prevention throughput1.2 Gbps4 Gbps14 Gbps45 GbpsUp to 8 Gbps
IPsec VPN throughput1.5 Gbps5 Gbps18 Gbps60 GbpsUp to 10 Gbps
Concurrent sessions500K2M8M32MUp to 4M
Interfaces8 × 1GbE16 × 1GbE
4 × 10GbE SFP+
8 × 10GbE SFP+
4 × 25GbE SFP28
16 × 25GbE SFP28
4 × 100GbE QSFP28
Up to 16 vNICs
High availabilityActive/passiveA/P, A/AA/P, A/AA/P, A/A, clusteringA/P, A/A

Throughput numbers are lab estimates. Ask for the full datasheets to see how we test.

Integrations

Works with the tools you already use.

Share identity, logs and threat intel with the systems your teams rely on.

Identity

Active DirectoryMicrosoft Entra IDOktaLDAPRADIUSSAML 2.0

SIEM & SOAR

SplunkMicrosoft SentinelElasticIBM QRadarSyslog / CEF

Automation

REST APITerraformAnsibleWebhooks

Threat intelligence

STIX / TAXIIMISPCustom IOC feedsExternal dynamic lists

Put NXSgate in front of your own traffic.

We're letting a small group of organizations try NXSgate before launch. Run it on your own network and see exactly which apps, users and threats are crossing it.