AI firewall · Perimeter

A firewall
that understands traffic.

A next-generation firewall driven by SYLink AI: L7 application filtering, built-in IPS, categories and reputation — on the perimeter and between your VLANs, blocking in real time.

L7 NGFWBuilt-in IPSCategories & GeoIPAI-driven
L7
Application filtering (DPI)
Real time
blocage des menaces
1 clic
isolate a VLAN

A conventional firewall filters on ports and IPs. The UniSOC AI firewall filters on the real application (L7 DPI), the category and the reputation — and lets SYLink AI decide in real time. It protects the perimeter, and also the internal traffic between VLANs, which is where ransomware spreads.

How it works

From threat to evidence, in real time.

The module captures the signal, SYLink AI correlates it and decides — you keep control.

Internet / VLAN
All the traffic
AI firewall
L7 filtering + IPS
SYLink AI
Decides in real time
Allowed / blocked
Perimeter and internal
In the portal

The firewall, wired into the rest of the SOC.

A firewall that only talks to itself is only half a firewall. Here, every flow is cross-checked against the machines and the identities.

01

Real-time syslog collection

console.unisoc.fr/firewall
Real-time syslog collection
49k events over 24 h, 249k appliance logs, 242,820 IPS blocks — the SYLink appliance and third-party firewalls in one view.
02

Where the traffic comes from, and to which application

console.unisoc.fr/firewall
Where the traffic comes from, and to which application
The thick ribbons are the big flows; an unexpected ribbon towards a sensitive application is exactly what we investigate.
03

Correlated with the other pillars

console.unisoc.fr/firewall
Correlated with the other pillars
Protocols, ports, DPI applications, split between internal, outbound and inbound: inbound traffic is 2% of the flows and the whole of your exposure.

Real screenshots of the UniSOC portal. The data shown comes from a demonstration environment.

Capabilities

The technology, in detail.

What the module actually does — functions, not promises.

L7 application filtering

  • Identifies the real application (nDPI), not just the port
  • Blocking by category (anonymisers, mining, adult…)
  • IP and domain reputation (50+ CTI sources)
  • GeoIP: blocks countries you have no business with
  • Micro-segmentation between VLANs

Built-in IPS / IDS

  • Signatures plus behavioural detection
  • Online exploits and scans blocked
  • Anti-DoH / anti-tunnel
  • Rules updated continuously
  • Complete logging of every block

Driven by SYLink AI

  • A blocking decision with context
  • Correlated with DPI, EDR and HoneyPot
  • Rule recommendations
  • Fewer false positives
  • Human review (DORA audit)

Sovereign & traceable

  • Closed appliance, administration on loopback
  • No foreign cloud dependency
  • HMAC-signed audit chain
  • Processing and hosting in France
  • NIS2 & DORA compliant
Use cases

What is it actually for?

Block a C2 hidden inside port 443

The DPI sensor sees the encrypted C2 tunnel on the HTTPS port and cuts it — where a conventional firewall sees "legitimate 443 traffic".

Stop it spreading internally

Micro-segmentation between VLANs stops a compromised machine reaching the servers — the ransomware stays contained.

Filter by category and country

Anonymisers, mining, irrelevant countries: blocked in one click, with evidence for compliance.

The method, in four steps
From raw signal to defensible evidence.
Detect
Understand
Decide
Prove
01The module captures the raw signal — traffic, behaviour or indicator.signal captured
Specifications
FilteringL7 (nDPI) plus categories and GeoIP
IPSSignatures + behavioural
SegmentationInter-VLAN (micro-segmentation)
ThroughputDepending on the model (Box / Pro)
ControlSYLink AI + SOC
DeploymentOn-premise · inside your own infrastructure
Natively integrated with
SYLink AI — real-time decision
DPI sensor — the same L7 engine
EDR agent — coordinated blocking
HoneyPot — attacking IPs propagated
Compliance module — NIS2 evidence
Sovereign

Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.

Live in under 48 hours

Ready to see what is really
happening on your network?

First trial free, no credit card, no commitment. On your existing infrastructure.

Cookie settings

We use cookies to improve your experience on our site. By continuing to browse, you accept our privacy policy and our use of cookies under the GDPR.