A firewall
that understands traffic.
A next-generation firewall driven by SYLink AI: L7 application filtering, built-in IPS, categories and reputation — on the perimeter and between your VLANs, blocking in real time.
A conventional firewall filters on ports and IPs. The UniSOC AI firewall filters on the real application (L7 DPI), the category and the reputation — and lets SYLink AI decide in real time. It protects the perimeter, and also the internal traffic between VLANs, which is where ransomware spreads.
From threat to evidence, in real time.
The module captures the signal, SYLink AI correlates it and decides — you keep control.
The firewall, wired into the rest of the SOC.
A firewall that only talks to itself is only half a firewall. Here, every flow is cross-checked against the machines and the identities.
Real-time syslog collection

Where the traffic comes from, and to which application

Correlated with the other pillars

Real screenshots of the UniSOC portal. The data shown comes from a demonstration environment.
The technology, in detail.
What the module actually does — functions, not promises.
L7 application filtering
- Identifies the real application (nDPI), not just the port
- Blocking by category (anonymisers, mining, adult…)
- IP and domain reputation (50+ CTI sources)
- GeoIP: blocks countries you have no business with
- Micro-segmentation between VLANs
Built-in IPS / IDS
- Signatures plus behavioural detection
- Online exploits and scans blocked
- Anti-DoH / anti-tunnel
- Rules updated continuously
- Complete logging of every block
Driven by SYLink AI
- A blocking decision with context
- Correlated with DPI, EDR and HoneyPot
- Rule recommendations
- Fewer false positives
- Human review (DORA audit)
Sovereign & traceable
- Closed appliance, administration on loopback
- No foreign cloud dependency
- HMAC-signed audit chain
- Processing and hosting in France
- NIS2 & DORA compliant
What is it actually for?
Block a C2 hidden inside port 443
The DPI sensor sees the encrypted C2 tunnel on the HTTPS port and cuts it — where a conventional firewall sees "legitimate 443 traffic".
Stop it spreading internally
Micro-segmentation between VLANs stops a compromised machine reaching the servers — the ransomware stays contained.
Filter by category and country
Anonymisers, mining, irrelevant countries: blocked in one click, with evidence for compliance.
Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.
One building block of the SOC — never on its own.
Each module feeds the others through SYLink AI.
Ready to see what is really
happening on your network?
First trial free, no credit card, no commitment. On your existing infrastructure.
