LAN Firewall
Simplify and enhance LAN security. A dedicated firewall for local traffic removes the bottleneck from your SD-WAN firewall, keeps policies maintainable and limits lateral movement through proper segmentation.
Give the LAN its own firewall.
Once a site reaches a certain size, headquarters and branch locations have to cover many different endpoints: guest wifi, printers and scanners, R&D equipment, IoT devices. That means many local access cases, from an internal user printing a document to guest wifi reaching the internet.
Handling that traffic on the SD-WAN firewall leads to performance bottlenecks. The local policy is then usually kept loose, which creates security gaps. If it is not kept loose, it becomes complex, because it has to cover local, internet and WAN cases at once.
That is why a dedicated LAN firewall belongs on this task, together with proper LAN segmentation.
Two decisions that matter.
A dedicated firewall
Running SD-WAN and LAN traffic on a single appliance is technically possible, but once complexity rises they should be split. Policies stay simpler to maintain and the performance bottleneck disappears.
LAN segmentation
To limit lateral movement after a breach, the LAN needs thorough segmentation. We provide the technical support to implement it, which raises the security posture measurably.
Split the traffic, simplify the policy.
What stays on the SD-WAN firewall
- Internet-bound traffic and WAN transitions
- Corporate zone transitions defined by global IT
What moves to the LAN firewall
- Local access cases: printing, guest wifi, building services
- Segmentation between IT, IoT, R&D and guest networks
