| Next-Generation Firewall | Perimeter and internal traffic protection | Stateful inspection, application control, intrusion prevention, URL filtering, malware protection, and policy-based segmentation | Physical appliance, virtual machine, or cloud-based service | IPv4, IPv6, NAT, TLS, IPsec, BGP, OSPF, and VLANs | Branch offices, data centers, internet gateways, and regulated environments |
| Secure SD-WAN Edge | Application-aware connectivity across branches and cloud resources | Dynamic path selection, traffic steering, link monitoring, centralized policies, and encrypted overlays | Branch appliance, virtual edge, or cloud-hosted edge | IPsec, GRE, BGP, OSPF, QoS, IPv4, and IPv6 | Distributed enterprises using broadband, leased lines, 4G, or 5G links |
| SD-WAN Orchestration Platform | Centralized provisioning, monitoring, and lifecycle management | Zero-touch deployment, role-based access, configuration templates, telemetry, and policy automation | Cloud management portal or centralized controller | REST APIs, HTTPS, TLS, NETCONF, telemetry, BGP, and IPsec | Organizations managing many sites across multiple countries |
| Secure Web Gateway | Protection and policy enforcement for web access | DNS filtering, URL categorization, malware inspection, acceptable-use controls, and cloud application visibility | Cloud service, on-premises gateway, or hybrid deployment | HTTPS, TLS, DNS, HTTP, IPv4, and IPv6 | Remote workforces, internet-facing branches, and compliance-focused companies |
| Zero Trust Network Access | Application-level access for users and devices | Identity-based access, least-privilege policies, device posture checks, session controls, and continuous verification | Cloud-delivered service with connectors to private applications | TLS, HTTPS, SAML, OAuth 2.0, OpenID Connect, and RADIUS | Hybrid workforces and enterprises replacing broad network-level VPN access |
| Secure Access Service Edge | Converged networking and security for users, branches, and cloud applications | SD-WAN, secure web access, cloud application controls, firewall functions, and zero-trust access | Globally distributed cloud service with optional branch connectivity | IPsec, TLS, DNS, HTTPS, SAML, OAuth 2.0, and REST APIs | Organizations seeking a unified security architecture across regions |
| Network Access Control | Admission control for wired, wireless, and IoT endpoints | Device identification, authentication, posture assessment, guest access, and dynamic segmentation | On-premises server, virtual appliance, or cloud-managed platform | 802.1X, RADIUS, EAP, DHCP, LDAP, and VLANs | Campuses, healthcare facilities, education networks, and IoT-heavy environments |
| Network Security Analytics | Threat detection, investigation, and operational visibility | Flow analysis, anomaly detection, event correlation, dashboards, alerting, and incident investigation | Cloud analytics platform, virtual appliance, or hybrid architecture | IPFIX, NetFlow, syslog, HTTPS, SNMP, and REST APIs | Security operations teams requiring centralized visibility across distributed networks |