ASG-4500-S1051 NGFW
The Next-Generation Firewall( NGFW) is an independently developed firewall product with multiple interfaces and high stability.
As network environments become increasingly complex, traditional firewalls alone may not provide sufficient visibility and control over modern security threats. The Next-Generation Firewall (NGFW) is designed to provide comprehensive protection across L2-L7 network layers while combining intrusion prevention, virus protection, application control, URL filtering, and access auditing in one security platform.
Built on a high-performance multi-core architecture with an integrated processing engine, this NGFW is developed for organizations that need stable network security, detailed traffic inspection, and flexible policy management. With multiple network interfaces, 2 Gbps throughput, support for up to 1,000,000 concurrent connections, and 11,000 new connections per second, it provides a practical security foundation for demanding network environments.
Comprehensive Protection From Layer 2 to Layer 7
Modern network attacks are no longer limited to simple unauthorized access attempts. Threats can appear through applications, files, websites, emails, vulnerabilities, and abnormal traffic patterns.
The NGFW addresses these risks by providing security inspection across L2-L7 network layers.
Instead of relying on a single protection mechanism, it combines several security functions within one platform. This allows network administrators to establish policies based on users, applications, content, traffic behavior, and security events.
The result is a more centralized approach to network protection, where security policies can be managed and adjusted according to the actual risks within the network.
Advanced Intrusion Detection and Prevention
Intrusion prevention is one of the core capabilities of the NGFW.
The system includes more than 10,000 attack signatures covering 12 major categories. These signatures are designed to identify different types of network attacks, including vulnerability scanning, directory traversal, security bypass attempts, and other malicious behaviors.
Both manual and automatic signature updates are supported, allowing the security database to remain adaptable as new threats emerge.
For organizations with more specific security requirements, the firewall also supports custom IPS rules. Administrators can configure detailed matching conditions using fields such as protocol information, operation types, and payload content.
This provides greater control than relying exclusively on predefined signatures.
Flexible IPS Alert Management
Security events can generate a large volume of alerts in active network environments. The NGFW provides alarm log merging and advanced IPS alert capabilities to help administrators organize security information more effectively.
Detailed configuration options allow security teams to focus on relevant session information and attack details.
This makes it easier to distinguish meaningful security incidents from repetitive or less important events and provides useful information for subsequent investigation.
Integrated Virus Protection
Malicious files remain an important source of network security risks.
The NGFW provides virus detection for multiple traffic scenarios, including:
-
Website access
-
File transfers
-
Email traffic
-
Compressed files
Its virus protection system supports a database containing millions of virus entries, with regular database update services available to improve detection coverage.
The system can inspect 20 types of file formats and compressed files, helping organizations identify malicious content that may otherwise enter the network through routine business activities.
A trusted file whitelist is also supported. This allows administrators to define files or trusted content that should be excluded from unnecessary inspection according to the organization's security policies.
Application Identification and Control
Modern enterprise networks contain a wide range of applications. Employees may use web services, instant messaging, cloud platforms, file-sharing tools, e-commerce websites, office applications, P2P services, and online games.
Simply controlling traffic by IP address or port is often not enough to determine how network resources are actually being used.
The NGFW can identify more than 5,000 applications across web, PC, and mobile environments.
This application recognition capability allows administrators to create policies based on application type rather than relying only on traditional network parameters.
For example, an organization can establish different access rules for:
-
Social networking
-
P2P downloads
-
File transfers
-
E-commerce
-
Instant messaging
-
Office software
-
Online gaming
-
Other application categories
The system also supports custom application signatures, providing additional flexibility when an organization's internal applications or specific traffic patterns are not adequately covered by standard signatures.
Application and Website Auditing
Security is not only about blocking threats. Visibility into network activity is equally important.
The NGFW supports auditing of application and website access according to different dimensions, including users, applications, behaviors, and content.
This allows administrators to understand how network resources are being accessed and identify activities that may violate internal policies.
For organizations managing large numbers of users, this type of multi-dimensional auditing can make security management more structured.
Instead of asking only whether traffic was allowed or blocked, administrators can investigate who accessed a resource, which application was involved, what behavior occurred, and what content was transmitted.
Powerful URL Filtering
Websites are another major source of security and productivity risks.
The NGFW provides access to a URL database containing more than 10 million predefined URLs across over 100 categories. This extensive classification system allows administrators to establish web access policies based on website categories and security requirements.
Custom URLs are also supported, allowing organizations to add their own websites or domains to the policy system.
For easier administration, the firewall supports batch URL import and export, which can simplify policy deployment in larger network environments.
Administrators can define different actions for specific URL categories or websites, including:
-
Drop
-
Redirect
-
Log
This makes URL filtering more than a simple blocking mechanism. It can become part of a broader access-control strategy for managing web traffic.
Multi-Dimensional Access Control
One of the important advantages of a next-generation firewall is its ability to make security decisions using multiple traffic characteristics.
The NGFW supports identification and access control based on factors such as:
Users: Apply different network policies according to user identity or group.
Applications: Control which applications are permitted, restricted, or monitored.
Content: Inspect traffic content and identify potentially harmful data.
Behavior: Monitor and manage network activities based on observed traffic behavior.
This approach provides administrators with more detailed control over network access than conventional rule sets based solely on addresses and ports.
Stable 1U Rackmount Design
The NGFW uses a 1U rackmount form factor, making it suitable for standard server racks and centralized network infrastructure.
Its hardware configuration includes:
-
8 × Gigabit Ethernet ports
-
2 × Gigabit SFP ports
-
Built-in single AC power supply
The combination of copper Ethernet interfaces and Gigabit SFP ports provides practical connectivity options for different network deployment environments.
The compact 1U design also helps organizations integrate the firewall into existing server-room or network-rack infrastructure without requiring excessive rack space.
Performance Designed for Busy Networks
Security functions must operate without becoming a bottleneck for network traffic.
The NGFW provides a rated throughput of up to 2 Gbps, supporting high-speed traffic processing for applicable network environments.
It also supports up to 1,000,000 concurrent connections, allowing the firewall to maintain a large number of active network sessions.
With a capacity of 11,000 new connections per second, the system is designed to handle environments where new sessions are established continuously.
These specifications make the platform suitable for organizations that require both security inspection and stable traffic processing within a single network security device.
A Centralized Security Protection Hub
Managing separate security devices for intrusion prevention, virus detection, application control, and web filtering can increase the complexity of network infrastructure.
The NGFW integrates these functions into one platform.
This centralized architecture can simplify security policy management while giving administrators a more complete view of network activity.
Instead of managing isolated security controls, organizations can establish a coordinated protection strategy covering:
Threat Detection → Intrusion Prevention → Virus Inspection → Application Control → URL Filtering → Traffic Auditing
This integrated approach helps organizations build a more controllable and efficient network security environment.
Designed for Practical Network Security
The value of a firewall is ultimately determined by how effectively it can be deployed and managed in a real network.
The NGFW combines high-performance hardware with multiple security functions and configurable policies. Its support for custom IPS rules, custom application signatures, trusted file whitelists, and custom URLs gives administrators room to adapt security policies to specific operational requirements.
At the same time, automatic database updates for attack signatures, applications, and virus definitions can help maintain security coverage as network threats and application environments change.
Key Specifications at a Glance
| Item | Specification |
|---|---|
| Product Type | Next-Generation Firewall |
| Security Coverage | L2-L7 |
| Form Factor | 1U Rackmount |
| Ethernet Interfaces | 8 × Gigabit Ethernet |
| SFP Interfaces | 2 × Gigabit SFP |
| Power Supply | Built-in Single AC Power Supply |
| Throughput | 2 Gbps |
| Concurrent Connections | 1,000,000 |
| New Connections/Second | 11,000 |
| IPS Signatures | 10,000+ |
| Application Identification | 5,000+ Applications |
| URL Database | 10 Million+ URLs |
| URL Categories | 100+ |
| Virus Database | Millions of Entries |
| Supported File Types | 20 Types |
Conclusion
The Next-Generation Firewall provides an integrated approach to modern network protection by combining traffic inspection, intrusion prevention, virus detection, application identification, URL filtering, and access auditing.
Its ability to inspect security risks across L2-L7 layers allows organizations to move beyond basic network access control and establish more detailed policies based on users, applications, content, and behavior.
With a 2 Gbps throughput, 1,000,000 concurrent connections, and 11,000 new connections per second, the 1U rackmount platform is designed to balance security functionality with network processing performance.
For organizations looking to establish a centralized and manageable security gateway, the NGFW provides a flexible foundation for controlling network access, identifying threats, monitoring applications, and responding to increasingly complex network security challenges.







Reviews
There are no reviews yet.