Firewall Solutions (NGFW)
Build NGFW architecture for branch, campus, data center and cloud: sizing, POC, HA design, migration and policy optimization from a single source.
Do Not Merely Protect Your Network — See and Control All the Traffic
While traditional firewalls largely provide access control through IP address, port and protocol, today's cyber threats require far more advanced security controls.
Because of cloud applications, encrypted traffic, remote users, SaaS services, mobile devices and advanced malware, port-based traffic control alone is no longer enough for organizations.
Next-Generation Firewall – NGFW brings traditional firewall capabilities together with advanced security technologies such as;
IPS + Application Control + URL Filtering + Anti-Malware + SSL Inspection + VPN + SD-WAN + Zero Trust + Threat Intelligence
and similar capabilities.
Within SecureSys Firewall Solutions we build security architectures with Fortinet FortiGate, Palo Alto Networks and Sophos Firewall technologies for organizations' branch, campus, data center, internet edge, cloud and hybrid infrastructure.
What Is a Firewall?
A firewall is the core network security component that controls data traffic between trusted and untrusted networks according to defined security policies.
Traditional firewall systems mostly carry out traffic control using;
- Source IP
- Destination IP
- Source port
- Destination port
- Protocol
information.
Modern NGFW systems, by contrast, bring into the assessment not only where traffic comes from and goes to but also;
Which user? Which application? Which device? Which content? Which threat? Which risk level?
these questions.
What Is NGFW – Next Generation Firewall?
A next generation firewall is the combination of classic firewall capabilities with advanced threat prevention technologies.
NGFW platforms typically hold security functions such as;
- Stateful Firewall
- Intrusion Prevention System – IPS
- Application Control
- Web / URL Filtering
- Anti-Malware
- Antivirus
- SSL/TLS Inspection
- DNS Security
- IPsec VPN
- SSL VPN / Remote Access
- SD-WAN
- Identity-Based Policies
- Threat Intelligence
- Sandbox integration
- Zero Trust / ZTNA
- Central management
and similar functions.
Application Control
A significant part of modern applications use the standard HTTP/HTTPS ports.
Port-based security policies alone are therefore not enough to establish the real identity of an application.
NGFW technologies analyze traffic to identify the applications in use and allow application-based security policies to be built.
For example, an organization;
can permit the use of Microsoft Teams while blocking certain file sharing services, or apply different policies to social media applications by department.
IPS – Intrusion Prevention System
IPS analyzes attack attempts in network traffic in real time.
IPS technologies help detect and block attack behavior such as;
- Exploit attempts
- Known vulnerabilities
- Malicious network traffic
- Protocol anomaly
- Command & Control communication
- Network reconnaissance
- Brute-force activity
and similar patterns.
Web and URL Filtering
Web filtering allows users' internet access to be controlled in line with organizational policy.
Web sites can be controlled through different categories such as;
- Malware
- Phishing
- Gambling
- Social Media
- File Sharing
- Proxy / Anonymizer
- Newly Registered Domains
- Risky content
and similar classifications.
SSL / TLS Inspection
The vast majority of internet traffic is now encrypted over HTTPS.
This creates a significant problem from a security perspective.
When the firewall cannot analyze the content of encrypted traffic, attackers can hide malware or Command & Control communication inside HTTPS traffic.
SSL Inspection technology allows encrypted traffic to be passed through security controls within appropriate security and privacy policies.
DNS Security
DNS is one of the important components of modern attacks.
Malware can make use of DNS services to connect to Command & Control infrastructure, redirect to phishing domains or hide attack infrastructure.
In next generation firewall solutions, DNS Security technologies help detect and block malicious or suspicious domain communication.
Site-to-Site VPN
IPsec VPN technologies allow organizations to build encrypted connections between headquarters, the data center and branches.
For example;
Head Office ↕ IPsec VPN Data Center ↕ Branches
a secure WAN architecture can be built in this way.
Remote Access VPN
Remote Access VPN solutions can be used so remote users reach corporate resources securely.
In modern structures, the VPN approach is increasingly assessed together with ZTNA – Zero Trust Network Access technologies providing user, device and application based access.
SD-WAN
SD-WAN allows different internet and WAN connections to be used dynamically according to application and performance criteria.
For example, at a branch;
Fiber + MPLS + 5G
these connections can be used together.
The firewall can select the appropriate connection automatically according to the importance of the application, latency, packet loss and link status.
This approach offers significant advantages for connection continuity and performance, particularly in multi-branch estates.
Zero Trust and the Firewall
In modern network security, the "the internal network is safe" approach alone is not enough.
The core principle of the Zero Trust approach can be summarized as:
Never Trust, Always Verify
this principle.
User, device, application and access context are assessed continuously so only the necessary level of access to the necessary resource is granted.
Firewall High Availability – HA
Because the firewall is one of the critical components of an organization's internet and network access, it must not create a single point of failure.
In critical estates, firewall devices are therefore usually placed in an HA architecture.
Firewall-1 ↕ HA Firewall-2
Should one of the devices fail, the other firewall takes over the traffic and maintains service continuity.
Network Segmentation
A firewall is not used only at the internet edge.
Firewall segmentation can also be applied to separate critical networks inside the organization from one another.
For example;
User Network ↓ Server Network ↓ Database Network ↓ Management Network ↓ OT / IoT Network
controlled security policies can be built between these zones.
This approach helps prevent an attacker who has compromised a single endpoint from moving laterally through the corporate network with ease.
Fortinet FortiGate
Convergence of Security and Networking
Fortinet FortiGate is a Next-Generation Firewall platform usable in physical, virtual and cloud environments.
One of FortiGate's important characteristics is the combination of network and security functions within the same platform.
On FortiOS, different functions such as;
- NGFW
- IPS
- Application Control
- Web Filtering
- Anti-Malware
- DNS Security
- SSL Inspection
- IPsec VPN
- Secure SD-WAN
- ZTNA
can be used together.
FortiGuard Security Services
The security services of FortiGate devices are supported by the threat intelligence and security services provided by FortiGuard.
This structure helps new malware, attack infrastructure, phishing sites and other threats be carried into security policies quickly.
Fortinet Security Fabric
FortiGate can be positioned not only as a standalone firewall but as one of the central security components of the Fortinet Security Fabric architecture.
FortiGate;
FortiManager + FortiAnalyzer + FortiClient + FortiEDR + FortiMail + FortiWeb + FortiSandbox
can build integrated security architectures with these other Fortinet technologies.
Secure SD-WAN
One of FortiGate's standout areas is Secure SD-WAN.
Having firewall and SD-WAN capabilities within the same platform offers significant advantages, particularly in multi-branch estates, in terms of;
- connection optimization,
- central management,
- application-based routing,
- WAN redundancy,
- secure branch connections
and similar factors.
Who Is FortiGate Suitable For?
FortiGate;
- SME
- Enterprise
- Multi-branch organizations
- Data centers
- Campus networks
- Public sector
- Finance
- Retail
- Manufacturing
- Service providers
can be positioned across these very different scales.
Palo Alto Networks Next-Generation Firewall
Application and Identity Centred Network Security
The Palo Alto Networks NGFW is a Next-Generation Firewall platform placing application, user, device and content visibility at the centre of security policy.
The core technologies standing out in the Palo Alto Networks architecture are positioned as;
App-ID + User-ID + Device-ID + Content-ID
these components.
App-ID
App-ID allows the applications in network traffic to be identified independently of port and protocol.
Security policies can then be built on the real application rather than on IP or port alone.
User-ID
User-ID technology allows firewall policies to be related to users and user groups rather than IP addresses.
For example;
Finance Department → may reach finance applications
or
Guest User → may not reach the corporate server network
identity-based policies of this kind can be applied.
Content-ID
Content-ID helps analyze the content and threats in network traffic.
Malware, exploit attempts and other threats can be assessed within security policy.
Advanced Threat Prevention
Palo Alto Networks' advanced threat prevention services provide security capabilities for detecting and blocking known and unknown attacks at network level.
WildFire
WildFire is an advanced malware analysis ecosystem for analyzing suspicious files and content.
It can be used to analyze unknown threats and carry the resulting threat intelligence into security controls.
Who Is Palo Alto Networks Suitable For?
It can be evaluated particularly in;
- Large corporate networks
- Critical data centers
- Financial institutions
- Telecom
- Public sector
- Critical infrastructure
- Multi-cloud environments
- Zero Trust architectures
estates requiring high security and detailed application visibility.
Sophos Firewall
Endpoint and Firewall Security Working Together
Sophos Firewall is a network security platform combining NGFW security functions with central management and the Sophos security ecosystem.
Sophos' XGS Series firewall family can be positioned in organization and branch infrastructure at different scales.
Sophos Firewall supports security functions such as;
- IPS
- Application Control
- Web Protection
- Malware Protection
- TLS Inspection
- VPN
- SD-WAN
- Email Protection
- Policy-Based DLP
and similar capabilities.
Sophos Synchronized Security
One of Sophos' most distinctive differentiators is the Synchronized Security approach.
Security information can be shared between Sophos Firewall and Sophos endpoint security technologies.
For example, when a threat is detected on an endpoint, the firewall can use that information to restrict the network access of the device automatically.
This structure;
Endpoint + Firewall + MDR
allows these security layers to work in a more coordinated way.
Sophos Central
Sophos Firewall devices can be managed centrally through Sophos Central.
This approach makes it easier for organizations with several branches in particular to manage firewall operations from a single point.
Who Is Sophos Suitable For?
Sophos Firewall;
- SME
- Mid-sized businesses
- Multi-branch estates
- Educational institutions
- Retail
- Manufacturing
- Organizations using Sophos Endpoint
is suitable for these organizations.
Fortinet, Palo Alto or Sophos?
It is not correct to define a single vendor as "the best firewall" for every organization.
Fortinet FortiGate
It is a strong alternative particularly in projects where network + security convergence, Secure SD-WAN, a broad product family and the Security Fabric approach matter.
Palo Alto Networks
It stands out in Enterprise architectures requiring application visibility, user-based policies, advanced threat prevention and high security.
Sophos Firewall
It forms a strong alternative in estates where Endpoint + Firewall integration, central management and operational simplicity are the priority.
The right firewall choice should be made according to the organization's real need rather than the brand name.
What Should You Consider When Choosing a Firewall?
Looking only at the maximum firewall throughput figure stated by the vendor is not the correct approach to firewall selection.
The performance that really needs to be assessed is the real performance obtained while security services such as;
IPS + Application Control + Threat Prevention + SSL Inspection
are active.
In addition, the;
- Number of users
- Internet bandwidth
- Number of concurrent sessions
- New sessions/second requirement
- SSL Inspection performance
- Number of VPN users
- Number of Site-to-Site VPNs
- Number of branches
- SD-WAN requirement
- HA requirement
- 1/10/25/40/100 GbE requirement
- Log volume
- SIEM integration
- Central management
- Cloud usage
- 3–5 year capacity growth
should be assessed together.
SecureSys Firewall Solutions
At SecureSys we do not treat firewall projects as device sales alone.
Before the project, the existing network structure and security requirements are analyzed and the appropriate vendor, model, licence and architecture are determined.
The process;
Discovery → Capacity Analysis → Product Comparison → POC → Sizing → Licensing → HA Design → Deployment → Migration → Policy Optimization → VPN / SD-WAN → SIEM/SOC Integration → Operations & Support
can be carried out in this way.
In projects where existing firewall infrastructure has to be moved to Fortinet, Palo Alto Networks or Sophos, the existing NAT, policy, object, VPN and routing structures are analyzed and a controlled migration plan can be prepared.
Your Firewall Security Does Not End with Device Deployment
A firewall's security level is not determined by the technical specifications of the device alone.
Incorrectly defined rules, unnecessary open services, old firmware versions, unused policies, insufficient logging and faulty SSL Inspection policies can render even a powerful NGFW device ineffective.
In the SecureSys approach, therefore, the;
Right Product + Right Sizing + Right Architecture + Right Policy + Continuous Monitoring
are assessed together.
Protect the Edges of Your Network with Next Generation Security
Build consistent security policies at the different points of your network, from the internet edge to the data center and from branches to cloud infrastructure.
Build the next generation firewall architecture that suits your organization with SecureSys, using Fortinet FortiGate, Palo Alto Networks and Sophos Firewall solutions.
Request a demo, POC and quote for Firewall Solutions.
Want to learn more about this service?
Our expert team will reach out for a free consultation as soon as possible.