Forcepoint · Network Security

Forcepoint NGFW / SD-WAN

High-performance network security and intelligent branch connectivity.

Forcepoint Next-Generation Firewall (NGFW) combined with Secure SD-WAN delivers a unified platform that protects your network perimeter while intelligently connecting your branches, data centers, and cloud environments. It's the only solution that pairs fast, flexible SD-WAN networking with industry-leading firewall and intrusion prevention — all managed from a single console.

Whether you're securing a large enterprise data center, connecting hundreds of branch offices, or extending consistent policy to cloud workloads, Forcepoint NGFW and SD-WAN give your team full visibility, control, and resilience — without the complexity.

Forcepoint NGFW + SD-WAN — One Unified PlatformSecure Management Console (SMC)Manage up to 2,000 appliancesUNIFIED SOFTWARE · ONE POLICY FRAMEWORKNext-Gen FirewallDPI · IPS · SSL · App Control · ZTNASecure SD-WANSteering · Multi-Link · FailoverBranch OfficesZero-touch SD-WANData CenterClustering · HAMulti-CloudAWS · Azure · GCPClick any part of the platform to see what it does
Forcepoint NGFW and SD-WAN unified platform managed by the Secure Management Console

Next-Generation Firewall — Core Capabilities

A single, high-throughput engine combines deep inspection, intrusion prevention, encrypted-traffic visibility, and Zero Trust access — with the anti-evasion technology Forcepoint is known for.

Core NGFW capabilities

Deep Packet Inspection

Inspects traffic at higher TCP/IP layers to detect threats based on anomalous behavior and attack signatures — far beyond what a stateful firewall can see.

Intrusion Prevention (IPS)

A built-in IPS engine blocks known exploits, zero-day threats, and evasion techniques in real time — without sacrificing throughput.

SSL/TLS Inspection

Decrypts and inspects encrypted traffic to catch threats hidden inside HTTPS, TLS, and other encrypted protocols.

Application Control

Identifies and controls thousands of applications regardless of port, protocol, or encryption — including SaaS and shadow IT.

Advanced Malware Detection

Sandboxing and behavioral analysis detect and block advanced malware, ransomware, and unknown threats before they enter the network.

Zero Trust Network Access

Enforce least-privilege access policies per user, device, and application — natively integrated within the NGFW platform.

Anti-Evasion Technology

Detects and neutralizes evasion techniques that disguise attacks inside fragmented packets, protocol violations, and encoding tricks.

VPN & Remote Access

Built-in site-to-site and client VPN with multi-factor authentication — no separate VPN appliance required.

Secure SD-WAN — Intelligent Branch Connectivity

Secure SD-WAN steers each application over the best available path, bonds multiple ISP links for resilience, and provisions new sites in minutes — and every path is inspected by the same NGFW engine, so there are no security gaps.

Secure SD-WAN — Intelligent Path SelectionSD-WANSteering Engineintelligent path selectionFiberBroadbandLTE / 5GBranch OfficeZero-touch siteData Center / CloudAWS · Azure · GCP · HQClick any node — Branch, SD-WAN, Data Center, or an ISP link — for details
Secure SD-WAN intelligent path selection across fiber, broadband, and LTE links

Core SD-WAN capabilities

Dynamic Traffic Steering

Monitors application health and ISP link quality in real time, automatically routing traffic over the best available path.

Multi-Link Aggregation

Bond multiple ISP connections (fiber, broadband, LTE) to maximize bandwidth and eliminate single points of failure at every site.

Zero-Touch Provisioning

Activate new branch sites remotely via the cloud — no on-site engineer. New locations are secured and online in minutes.

Full-Mesh Connectivity

Dynamically builds encrypted tunnels between any combination of sites, data centers, and cloud gateways — scaling to thousands of locations.

MPLS Replacement

Replace costly MPLS circuits with secure broadband while maintaining performance SLAs for critical apps like Office 365 and UCaaS.

Application Prioritization

Define QoS policies per application to guarantee performance for voice, video, and business-critical traffic across all links.

ISP Failover & Resiliency

Automatic failover to backup ISP links with sub-second switchover — ensuring uninterrupted connectivity for distributed operations.

Security-First SD-WAN

All SD-WAN traffic is inspected by the NGFW engine — no security gaps when traffic is redirected to alternate paths.

Centralized Management — Secure Management Console (SMC)

The Forcepoint Secure Management Console (SMC) is the single pane of glass for your entire NGFW and SD-WAN deployment — from a handful of firewalls to a global network of 2,000+ appliances.

  • Configure, monitor, and update up to 2,000 NGFW appliances from one console
  • Unified policy management across physical, virtual, and cloud deployments
  • Role-based administration with granular access controls for security teams
  • Real-time traffic visualization, event correlation, and threat dashboards
  • Automated policy push — deploy security changes to all sites in seconds
  • Audit logging and compliance reporting built in

Deployment Models

Forcepoint NGFW runs the same unified software across every deployment type — so security policy and management stay consistent no matter how or where it runs.

Physical appliances

Purpose-built hardware covering every site, from branch offices to high-throughput data centers.

NGFW Appliance Lineup — One Software, Every Site2200 SeriesFirewallUp to 120 GbpsNGFWUp to 13.5 GbpsInterfacesUp to 252100 SeriesFirewall60–80 GbpsNGFW5–7.5 GbpsInterfacesUp to 281100 SeriesFirewall50–60 GbpsNGFW1.5–3 GbpsInterfacesUp to 16300 SeriesFirewall4–7 GbpsNGFW350 Mbps–1 GbpsInterfacesUp to 8Click any model to see which deployments it fits
Forcepoint NGFW physical appliance lineup with throughput and interface specifications

Virtual & cloud

VMware vSphere / NSX-T

Full NGFW and SD-WAN capabilities in virtualized data centers.

Amazon Web Services (AWS)

Available on AWS Marketplace for cloud workload protection.

Microsoft Azure

Deploy virtual NGFW alongside Azure workloads with centralized SMC management.

Google Cloud Platform (GCP)

Consistent policy enforcement across multi-cloud environments.

Use cases

Enterprise Campus & Data Center

Protect high-throughput core networks with deep inspection, clustering up to 16 nodes, and active-active high availability.

Branch Office Security

Replace expensive MPLS links with secure broadband SD-WAN at every branch — zero-touch provisioned from HQ.

Multi-Cloud Connectivity

Deploy virtual NGFW on AWS, Azure, and VMware to extend consistent security policy into cloud workloads.

Retail & Distributed Sites

Rapidly secure hundreds of stores with policy-consistent, centrally managed NGFW and SD-WAN from a single console.

Industrial & OT Security

Segment IT/OT networks and protect industrial control systems with firewall rules tailored for operational environments.

Secure Remote Access

Provide employees and third parties Zero Trust Network Access (ZTNA) without deploying separate VPN infrastructure.

Why Forcepoint NGFW / SD-WAN?

Security + SD-WAN in one

No separate SD-WAN appliance — security and connectivity are delivered from a single platform.

Scales to 2,000+ sites

Manage your entire global network — thousands of appliances, one console, one policy framework.

Proven anti-evasion

Industry-recognized technology that detects evasion techniques other NGFWs consistently miss.

Zero-touch branch deployment

New branch sites activated in minutes from the cloud — no truck rolls, no on-site configuration.

Consistent policy everywhere

The same policy enforced on physical hardware, VMs, AWS, Azure, and GCP — no gaps.

HA & clustering built in

Active-active clustering up to 16 nodes ensures zero-downtime operations even during hardware upgrades.

Ready to secure your network with Forcepoint NGFW / SD-WAN?

Contact iconnet for a consultation, demo, or proof-of-concept deployment.