In development · Not yet released

NXSgate - zone-based next-generation firewall

NXSgate is the firewall NexusSec is building. It splits a network into zones, blocks traffic between them by default, and inspects every connection it does allow. It has not been released yet: a free Community Edition and two paid plans are planned.

Overview

What is NXSgate?

NXSgate is NexusSec's own firewall product, with its own site at nxsgate.com. Most NexusSec work is deploying and managing firewalls from other vendors for clients. NXSgate is the firewall we are building ourselves, around the zone-based design we recommend on client networks and describe in zones first.

It is in development. There is no release date, price list or download yet. The features and plans below are what NXSgate plans to ship, as published on nxsgate.com, and they may change before launch.

How it works

Zones, and one pass over every connection

Planned design, as described on nxsgate.com.

▦

Zones

Interfaces, VLANs, VPN tunnels and cloud subnets are grouped into zones such as LAN, DMZ, Guest and IoT. Nothing crosses between zones until a rule allows it.

⇄

A rule per direction

LAN to WAN and WAN to DMZ are separate rules, each with its own application, user and threat settings.

◎

Single-pass inspection

A connection is decoded once, and the application, user and content checks all run on the same stream instead of scanning it again in separate engines.

◆

Applications and people

Rules name applications and users rather than ports and IP addresses, using your directory and single sign-on.

▣

Threat prevention

Intrusion prevention, anti-malware, URL and DNS filtering, and TLS 1.3 inspection that leaves private categories such as banking and health alone.

⚙

Runs where you need it

Planned as an ISO installer and as images for VMware ESXi, KVM and Proxmox, and Hyper-V, plus AWS, Azure and Google Cloud marketplace listings.

Planned plans

A free edition and two paid plans

None of these is available yet. Prices for the paid plans will be published at launch.

Community Edition

Free

Self-managed, community support

  • Zone-based stateful firewall, NAT and routing
  • Application identification and control
  • Site-to-site and remote-access VPN
  • Basic URL filtering
  • Local web console

Advanced

Paid, per gateway

Everything in Community Edition, plus

  • Intrusion prevention, anti-malware and DNS security
  • TLS 1.3 inspection and advanced URL filtering
  • Identity-aware policy
  • Active/passive high availability
  • SIEM integration, REST API and Terraform
  • 24×7 support

Enterprise

Paid, custom pricing

Everything in Advanced, plus

  • Cloud sandboxing for unknown files
  • SD-WAN and active/active clustering
  • Multi-tenant management
  • 365-day log retention
  • A technical account manager
  • A 1-hour critical response target

Planned minimums for Community Edition, to be confirmed with the first release: a 64-bit x86 processor with 2 cores (AES-NI recommended for VPN and TLS inspection), 4 GB of memory or 8 GB with TLS inspection, 20 GB of storage, and at least two network ports.

Why NexusSec

Why a deployment firm is building a firewall

  • It comes from the deployment side. NexusSec engineers deploy, migrate and review other vendors' firewalls for clients. NXSgate is designed around the problems that work keeps turning up: rule lists nobody can read, and inspection switched off because it slowed the network down.
  • Zones by default. The zone-based policy we recommend on client networks is how NXSgate is built, rather than a configuration someone has to remember to set up.
  • The services stay the same. NexusSec continues to deploy and support Fortinet, Sophos, Palo Alto, WatchGuard and other platforms. NXSgate will be one more option once it is released, not a replacement for that work.
Plainly

What NXSgate does not claim yet

NXSgate has not been released. There are no published prices, performance figures, certifications or customer deployments, and no hardware on sale. Do not plan a purchase around a launch date. If you need a firewall now, we deploy the platforms already on the market; see firewall and network security.

FAQ

NXSgate questions, answered

Is NXSgate a NexusSec product?

Yes. NXSgate is the zone-based next-generation firewall NexusSec is building. Its own site is nxsgate.com.

Can I buy or download NXSgate today?

Not yet. NXSgate has not been released. Join the waitlist on nxsgate.com for early access and launch pricing.

Will there be a free version?

Yes. A free Community Edition is planned, to run on your own hardware or in a virtual machine, for home labs, learning and small networks.

How will the paid plans be priced?

As a subscription for each gateway, where a gateway is any appliance or virtual machine running NXSgate. Prices will be published at launch.

Does NexusSec still deploy other firewalls?

Yes. NexusSec continues to deploy and support Fortinet, Sophos, Palo Alto, WatchGuard and other platforms. NXSgate will be one more option once it is released.

How do I report a security issue in NXSgate?

Email security@nxsgate.com.

Want early access to NXSgate?

Join the waitlist on nxsgate.com for early access and launch pricing. Need a firewall today? We deploy and manage the platforms already on the market.

or email sales@nxsgate.com