Smarter AI-Powered Defense

Sangfor Athena NGFW (previously known as Sangfor Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.

  1. Leverages real-time, cloud-delivered AI to block over 99% of external threats at the network perimeter.
  2. The world's 1st NGFW integrated with NGWAF, delivering network and web application security in a single appliance.
  3. The world's 1st NGFW with a built-in SOC Lite module, enabling rapid threat assessment and incident response.
  4. The world's 1st NGFW that natively integrates with a holistic security ecosystem, including Athena EPP, SWG, NDR, XDR, MDR, and SASE.
Watch More Videos
Watch More Videos

Comprehensive and Reliable Protection From L2 to L7

 

Comprehensive and Reliable Protection From L2 to L7

 

Athena NGFW Key Features and Capabilities

AI-Powered Malware Inspection

Athena NGFW integrates with Sangfor Engine Zero, an AI-powered malware detection engine. Engine Zero was developed using advanced machine learning models and AI algorithms, enabling Athena NGFW to achieve a 99.76% detection rate for both known and unknown malware across the internet.

AI-Powered Malware Inspection

Real-Time Threat Intelligence

Athena NGFW leverages Sangfor Neural-X, a cloud-based, AI-powered threat intelligence and analytics platform.

Neural-X is continuously updated to protect against the latest indicators of compromise (IOCs) and adversary tactics, techniques, and procedures (TTPs). For example, Athena NGFW can submit a suspicious DNS address to Neural-X for analysis. If it is identified as a known command-and-control (C&C) server, Athena NGFW automatically blocks communications to prevent further damage.

Real-Time Threat Intelligence

Anti-Ransomware

Athena NGFW integrates with Athena Endpoint Protection Platform (EPP) as part of Sangfor’s Anti-Ransomware solution.

Forensic threat intelligence data—collected from both network and endpoints—is visualized via the Athena NGFW GUI to reveal hidden ransomware processes. The solution also offers a "one-click quarantine" feature to remove the encryption-controlling application from all infected hosts.

Anti-Ransomware

Web Attack Prevention

Athena NGFW includes Sangfor’s Next-Generation Web Application Firewall (NGWAF) to provide robust protection for web applications.

Using semantic analysis and the industry’s first WAF with a built-in virtual execution system (VES), Sangfor NGWAF secures web applications from advanced attacks, such as SQL injection and cross-site scripting.

Web Attack Prevention

Simplified Operation

Sangfor believes that firewalls should make life easier for security administrators. Athena NGFW includes a SOC Lite feature that simplifies security operations and incident response.

Instead of analyzing tons of security logs, security administrators can intuitively assess the threat levels of users and hosts through Athena NGFW’s management console. What's more, it provides actionable guidance on how to respond to detected threats.

Athena NGFW Use Cases

icon plus flip icon cross flip
icon

Robust Perimeter Security

Robust Perimeter Security

Combines antivirus, intrusion prevention system, AI-powered malware detection and real-time threat intelligence to block over 99% of threats at the network perimeter.

icon plus flip icon cross flip
icon

Secure SD-WAN

Secure SD-WAN

Offers built-in SD-WAN capabilities to secure access for various scenarios, including HQ-to-branch, branch-to-branch, and work-from-anywhere (WFX).

icon plus flip icon cross flip
icon

Second-tier Firewall

Second-tier Firewall

Supplement your existing firewall with a next-generation firewall equipped with AI-powered threat detection, the latest threat intelligence, and NGWAF.

Athena NGFW Competitive Advantages

Athena NGFW has achieved the highest rating (AAA and Recommended) in the CyberRatings Enterprise Firewall Test for three consecutive evaluations, performing on par with, or better than, leading NGFW vendors in terms of security effectiveness.

Athena NGFW delivers comparable security capabilities and effectiveness to leading NGFW vendors—but at much lower price points. This results in an industry-leading cost-to-performance ratio, making it an ideal choice for organizations seeking maximum ROI.

Powered by Sangfor Neural-X, Athena NGFW benefits from a comprehensive threat intelligence feed and automatic global intelligence sharing, enabling rapid detection and mitigation of emerging threats.Additionally, Sangfor collaborates with major security platforms such as CVE, VirusTotal, and CNVD to ensure timely updates on newly discovered vulnerabilities. 

Sangfor offers complete security solutions rather than just a firewall. Starting with Athena NGFW, organizations can build a fully integrated security framework with enhanced capabilities, simpler management, and reduced costs.

Recommended Rating in the CyberRatings Enterprise Firewall Test

The CyberRatings.org Enterprise Firewall Test is an independent evaluation of leading firewall solutions, assessing their security effectiveness, performance, SSL/TLS capabilities, and resilience against evasions.

In this exclusive video, Vikram Phatak, CEO of CyberRatings.org, shares his insights on why Sangfor's Next-Generation Firewall has achieved the Recommended rating.

Athena NGFW Market Recognition

 

Gartner Magic Quadrant
"Visionary" Vendor
Recognized as "Visionary" vendor in 2022 Gartner Magic Quadrant for Network Firewalls

Learn More

Gartner 'Voice of the Customer' icon
Gartner 'Voice of the Customer'
Strong Performer in Gartner® Peer Insights™ Voice of the Customer

Learn More

ICSA Labs Certification icon
ICSA Labs Certification
Tested and Proven for Total Security, Endorsed by ICSA Labs in 2021

Learn More

AAA Rating from CyberRatings icon
Top Rating in CyberRatings
Recommended Top Rating in CyberRatings' Enterprise Firewall Test

Learn More

Frost & Sullivan 2023 Company of the Year
Frost & Sullivan Company of the Year
Frost & Sullivan recognizes Sangfor with the 2023 Company of the Year Award

Learn More

Cybersecurity Excellence Awards icon
Cybersecurity Excellence Awards
Sangfor Named Best & Most Innovative Cybersecurity Company in the 2024

Learn More

 

Gartner Peer Insight Reviews

gartner peer insight

Powerful product functions, rich expansion modules, excellent technical support services. 

Manager of IT Services, Transportation Industry

Manager, IT PMO & GRC, Healthcare & Biotech Industry

Provide strong network protection, reduce bandwidth costs, and maintain stable performance under heavy loads. 

Manager, IT PMO & GRC, Healthcare & Biotech Industry

IT Manager, Manufacturing Industry

Having both Sangfor NGFW and Sangfor Endpoint Secure deployed has created a more cohesive and proactive security ecosystem… 

IT Manager, Manufacturing Industry

Director of IT, Banking Industry

The product is quite good and the team is fast responding when it comes to products and services. Good quality overall. 

Director of IT, Banking Industry

gartner peer insight white logo_

We have been using since 2017 and has been proven to protect our assets ever since. 

IT Assistant Vice President, Government Sector

 
Sangfor Network Secure
 

Videos

Sangfor Network Secure Introduction: Technologies & Use Cases | Sangfor Product Series

video-image
Sangfor Network Secure Introduction: Technologies & Use Cases | Sangfor Product Series
video-image
Samudera Indonesia's IT Transformation: Powering Logistics Excellence with Sangfor Technologies
video-image
Unveiling IT Transformation at PT. CJ Indonesia | Sangfor Tech Talk
video-image
CEO of CyberRatings.org Explains Why Sangfor NGAF Achieved Recommended Ratings
video-image
Interview with IBA Karachi's Head of ICT Wajeeh Zaidi - Customer Testimonial
video-image
Interview with Jatin Doshi, BDM | Spollex Distribution Computer Trading LLC (UAE)
video-image
PT Bank Victoria International Tbk x Sangfor: Success Story
video-image
Customer Testimonial – Royal Malaysian Customs Department x Sangfor NGAF Next-Generation Firewall

Success Stories

Discover the success stories of Sangfor customers across various industries, including enterprise, government, healthcare, and education.

Meyer Aluminium (Thailand) Company Limited
Customers

Meyer Aluminium (Thailand) Company Limited

Multinet Trust Exchange LLC
Customers

Multinet Trust Exchange LLC

Mahasarakham University (MSU)
Customers

Mahasarakham University (MSU)

Suan Sunandha Rajabhat University (SSRU)
Customers

Suan Sunandha Rajabhat University (SSRU)

Meyer Aluminium (Thailand) Company Limited

Meyer Aluminium (Thailand) Company Limited

Multinet Trust Exchange LLC

Multinet Trust Exchange LLC

Mahasarakham University (MSU)

Mahasarakham University (MSU)

Suan Sunandha Rajabhat University (SSRU)

Suan Sunandha Rajabhat University (SSRU)

Athena NGFW Models

ModelsNSF-1030A-INSF-1050A-INSF-1100A-INSF-1200A-INSF-3100A-INSF-3200A-INSF-3400A-INSF-7100A-INSF-7200A-INSF-7300A-INSF-7500A-I
Firewall Throughput1, 22Gbps10Gbps20Gbps20Gbps30Gbps40Gbps55G70Gbps70Gbps80Gbps170Gbps
Application Control Throughput1, 3750Mbps6Gbps12Gbps14Gbps20Gbps28Gbps32Gbps40Gbps45Gbps50Gbps90Gbps
NGFW Throughput1, 4380Mbps1.5Gbps3Gbps3.5Gbps7Gbps10Gbps16Gbps25Gbps28Gbps32Gbps60Gbps
Threat Prevention Throughput1, 5300Mbps820Mbps1.5Gbps2Gbps3.6Gbps4Gbps12Gbps15Gbps18Gbps24Gbps38Gbps
Web Application Protection Throughput1, 6N/A950Mbps2.3Gbps2.5Gbps3.2Gbps4Gbps9.5Gbps20Gbps20Gbps23Gbps30Gbps
IPsec VPN Throughput1, 7220Mbps600Mbps1.5Gbps1.8Gbps3.5Gbps4Gbps7Gbps10Gbps10Gbps10Gbps40Gbps
Max IPsec VPN Tunnels1001001,0001,0004,0006,00010,00020,00020,00020,00025,000
Concurrent Connections(TCP)800,000800,0002,000,0002,000,0004,000,0004,100,00010,000,00025,000,00025,000,00027,000,00050,000,000
New Connections(TCP)30,00020,00090,00090,000180,000180,000500,000600,000600,000600,0001,500,000
Virtual Domains(Recommended/Max)1/11/63/63/65/105/1010/2024/4824/4824/4825/225
Click to Downloadpdf filepdf filepdf filepdf filepdf filepdf filepdf filepdf filepdf filepdf filepdf file

Remarks

  1. All throughput performance data is measured in the laboratory. The performance may vary depending on the actual configuration & network environment. For more performance information, please refer to each model’s datasheet.
  2. Firewall Throughput is measured with 1518 Bytes UDP packets.
  3. Application Control throughput is measured with firewall and Application Control enabled. 64K HTTP packets
  4. NGFW Throughput is measured with Firewall, Application Control, Bandwidth Management and IPS enabled. 64K HTTP packets
  5. Threat Prevention Throughput is measured with Firewall, Application Control, Bandwidth Management, IPS, and Anti-Virus enabled. 64K HTTP packets
  6. Web Application Protect Throughput is measured with Firewall, Application Control, Bandwidth Management, IPS and WAF enabled. 64K HTTP packets.
  7. IPsec VPN Throughput includes Sangfor to Sangfor device connection scenario and Sangfor to 3rd party device scenario.

Sangfor Athena NGFW Frequently Asked Questions

A firewall is a network security tool that inspects and filters traffic between devices in a private computer network and the internet. Firewalls allow or deny incoming and outgoing network traffic based on defined rules. This enables users to block unauthorized data as well as prevent malware and other security threats from breaching the network.

Network Firewalls generally come as hardware network devices or software applications. Hardware firewalls are placed in a central network location to filter traffic for an entire network. Software firewalls are installed on endpoints to filter traffic to and from specific devices.

There are also different types of firewalls, including packet filtering firewalls, stateful inspection firewalls, proxy firewalls, network address translation (NAT) firewalls, and next generation firewalls (NGFW).

Next generation firewalls (NGFWs) are the newest generation of firewall technology. NGFWs use something called deep packet inspection (DPI) to inspect the content (payload) of data packets. This allows users to create more granular firewall rules based on specific types of data, applications, devices, and users.

Moreover, NGFWs are a type of unified threat management (UTM) solution. UTMs integrate multiple security features into one device. In the case of NGFW’s, this includes antivirus, intrusion detection system, threat intelligence, application control, email security, and more.

Traditional firewalls like packet filtering and stateful inspection firewalls only support rules based on packet header information, namely the source and destination IP address, protocol, and port number. This is very limited and does not offer much flexibility.

Next generation firewalls use something called deep packet inspection (DPI). DPI allows NGFWs to inspect the content (payload) of data packets and is a key enabler of enhanced firewall protection. One the one hand, users can create granular firewall rules based on specific types of data, applications, services, devices, and users. The allows NGFWs to block malicious data that exploit specific applications and services. DPI also provides the basis for the additional security features of NGFWs to function. With visibility into the data, antivirus can scan traffic for malware and the integrated intrusion prevention system can detect suspicious traffic activity.

Next generation firewalls are a type of unified threat management (UTM) solution that integrates multiple security features into one device. Typical features of NGFWs include:

  • Antivirus: Detects the presence of malware in traffic.
  • Intrusion Detection System (IDS): Detects suspicious traffic activity that might indicate an attack.
  • Intrusion Prevention System (IPS): Responds to detected suspicious traffic activity.
  • Threat Intelligence: Provides real-time threat intelligence to detect emerging threats.
  • Sandboxing: Executes suspicious files in a test environment to check for maliciousness.
  • Application Awareness and Control: Identifies applications and controls which apps are allowed to communicate with the internet.
  • URL Filtering: Blocks access to URLs that are malicious or unauthorized by the user.
  • Email Protection: Filters out malicious and unwanted email.
  • Web Application Firewall (WAF): A firewall dedicated to protecting web applications.

Granular Traffic Filtering: Thanks to DPI, next generation firewalls have visibility into the type of data and the applications, services, devices, and users processing the data. This allows organizations to create firewall rules to enforce granular access policies. DPI also enables NGFWs block malicious data that targets specific apps and services.

Early Threat Detection: NGFWs are integrated with security features like antivirus and intrusion detection system to detect malware and cyber-attacks before they can breach the network. This is important because threats are harder to detect after a breach, which increases the likelihood of a successful attack.

Security Logging: NGFWs support security logging, which is important for several reasons. For example, security analysts can analyze logs to hunt for threats that were missed by the firewall. Security logs are also needed to meet compliance requirements in certain industries and jurisdictions.

An organization should deploy a next generation firewall if compromise of its data and systems lead to material impact. This can be anything from significant financial loss, business downtime, business loss, and reputation damage. Given the sophistication of today’s security threats and the limitations of traditional firewalls to detect them, NGFWs should be the default firewall of choice for organizations looking for robust protection. NGFW vendors typically offer models of varying specifications and capabilities to suit the needs of different organizations, from small businesses to large enterprises.

Next generation firewalls provide superior protection to enterprise networks. This ultimately helps organizations minimize the chances of experiencing a cyber-attack. Considering how damaging cyber-attacks are, effective defense against them is vital for business continuity and prosperity.

NGFWs are also more cost-effective and reduce complexity by integrating various security features that would otherwise be deployed separately. This is especially beneficial for SMBs that lack the resources and expertise to deploy and manage disparate tools.

Next generation firewalls are relatively harder to use than traditional firewalls and may require a dedicated professional to operate and maintain. However, NGFW vendors are responsible for creating the complex firewall and IDS rules that detect and block security threats. Users simply need to keep their firewall up to date. NGFWs require extra work when organizations wish to create their own firewall rules, but NGFWs may come with templates to aid this process.

Because multiple security features are integrated into one device, NGFWs can be managed from a single interface. This in fact makes NGFWs easier to manage compared to separate security tools.

Next generation firewalls do a great job at keeping threats out of the network. However, cyber criminals are constantly refining and evolving their tactics, techniques, and procedures (TTP), so no single cyber security tool can always achieve total protection. That is why it is standard practice for organizations to deploy other security tools in addition to a firewall.

For example, antivirus or more advanced Endpoint Detection and Response (EDR) solutions are needed to detect threats that managed to evade the firewall and land on endpoints. For advanced persistent threats (APTs) that hide and spread in the network for a long period, a User and Entity Behavior Analytics (UEBA) solution like Network Detection and Response (NDR) works best.

NGFW vendors generally offer various models to suit different needs. Organizations should choose a firewall that fits their unique situation to get the best out of their NGFW. Important factors to consider include the NGFWs security capabilities, specifications such as throughput, cost, deployment mode, ease of operation, service, etc. For a more detailed discussion on choosing the right NGFW, feel free to read our enterprise firewall buyer’s guide.

Customer reviews are also an excellent source of reference. For example, Gartner Peer Insights provides vetted and verified reviews to help prospective buyers gain objective and trustworthy insight into the NGFW products of different vendors.

Get in Touch With Us

Name
Email Address
Business Phone Number
Tell us about your project requirements
icon notification