Security / Firewall

Firewall

Identity-aware
L3 and L4.

One rule set across every site and cloud. IP lists, a simulator, and the same identity that already gates your apps. Enforced at your gateways.

L3/L4 · IP lists · rule simulator · one policy plane
L3/L4
Enforcement layer
1
Rule set, every site
IP
Lists you control
0
Per-site copies

How a rule decides

Who, where, and whether the list already said so.

01 · IDENTITY

The rule knows who is asking.

Firewall decisions use the same user and group as access policy. An IP allowlist without an identity is the old model.

  • SSO / SCIM identity on the flow
  • Group-aware exceptions

02 · DESTINATION

Address, port and protocol.

L3/L4 rules cover CIDR, host and port. Use them for the paths that are not an application name yet.

  • IPv4 CIDR and host rules
  • TCP and UDP ports

03 · LISTS

Shared IP lists, not one-off rows.

Threat and allow lists attach to rules instead of being pasted into every site. Update a list once; every gateway sees it.

  • Shared allow and deny lists
  • One change, every site

04 · SIMULATE

See the match before it ships.

The rule simulator walks the same stages the gateway will: identity, destination, list, verdict. No guessing in production.

  • Stage-by-stage decision
  • Logged when it goes live

One rule set · every gateway

Write it once.
Stop copying it per site.

Firewall rules live on the same policy plane as web filtering and access. Identity, IP lists and a simulator travel with the rule, so a new gateway does not get a new spreadsheet.

firewall · eng-payments-db simulated
allow eng-payments matched
deny contractor blocked
allow any · managed standby
matched eng-payments-db · identity + list · ✓ audited

Test before you trust

Simulate any access decision before it ships.

Pick a user, a device and a service, and watch the decision resolve stage by stage, from posture and device to access and egress, with the exact policy that matched. No guessing in production.

policy simulator
# simulate · who can reach what, and why
user     dana@acme.com
device   macbook-dana · managed
service  payments-api

 posture   ✓ pass  # disk encryption · screen lock
 device    ✓ pass  # managed · agent up to date
 access    ✓ allow # matched policy: eng-payments
 egress    orbit · eu-central # region pinned

decision ALLOW

Plans

Firewall unlocks at Business.

Security includes the identity-aware firewall from Business and above. Core keeps the network. No extra appliance to stand up.

Core

For small teams getting started with zero trust access.

  • Full Network product
  • DNS-layer web filtering
  • Firewall & access policies

Enterprise

For organizations with advanced security and compliance needs.

  • Everything in Business
  • Posture & trust score enforcement
  • Custom audit retention & SLAs

Full feature breakdown on the pricing page →

Better together

Network comes with every plan.

Security runs on the Pulse Network, and Network is included in every tier, including yours. The policy plane that enforces your traffic also routes it, with managed gateways, egress and DNS built in.

  • You already have it. Network ships in every plan.
  • One policy model across network and security.
  • Application-aware routing and enforcement, together.
Explore Network