Security · Solution

Inspect traffic with policy that understands more than ports.

A next-generation firewall combines network control with application awareness and selected threat-prevention capabilities at an enforcement point.

How it works Concept model
1 2 3
  1. 01 · See Identify traffic and context Application · user · destination
  2. 02 · Inspect Apply security controls Policy · threat · content
  3. 03 · Enforce Permit, block or investigate Access · event · response

A conceptual sequence used to explain the service—not a customer deployment.

Overview

What it is

A firewall platform that can make policy decisions using application, identity and threat context in addition to network addresses and ports.

  1. 01

    Application-aware traffic policy

  2. 02

    Identity integration where required

  3. 03

    Threat-prevention capabilities

  4. 04

    Logging, review and policy lifecycle

Right fit

Who it is for

Perimeter refresh

Existing controls no longer provide the needed context.

Segmentation

Internal boundaries require deliberate enforcement.

Policy simplification

Rules have grown difficult to understand and maintain.

Outcomes

What you get

Context

Policy can use more than addresses and ports.

Control

Traffic treatment follows approved rules.

Visibility

Events and decisions are available for review.

Lifecycle

Rules can be documented and revisited.

Engagement

How we deliver it

  1. Step 1

    Review

    Assess traffic flows, existing rules and required boundaries.

  2. Step 2

    Design

    Define zones, policy, inspection and management requirements.

  3. Step 3

    Migrate

    Move rules and traffic through a controlled change process.

  4. Step 4

    Validate

    Test access, logging and the approved security behaviour.

Questions, answered directly

What buyers usually need to establish

How is a next-generation firewall different?

It can use application, identity and threat context in addition to traditional network information when applying policy.

Should every existing rule be copied?

Not automatically. A refresh is an opportunity to review purpose, ownership and continued need before migration.

CDS can also run it Meraki Managed Security — the operated, recurring service

Start with the conditions around next-generation firewall.

Describe the current environment, the change you are considering and what the result must support.