Products / Business
Valar 2 is designed for the typical mid-sized company. Office network, production and guests can be separated into their own zones. Two units can run as a pair, so the failure of one unit does not interrupt operations.

Overview
Valar 2 at a glance.
Valar 2 is the typical appliance for companies with a few dozen to around a hundred workstations. It fits into any 19-inch rack and has enough performance to inspect all traffic, including encrypted connections.
Because a firewall failure can bring the whole business to a halt, Valar 2 can run as a pair. Both units continuously synchronise configuration and connections. If one fails, the other takes over and existing connections are kept.
Key facts
| Suited for | Mid-sized companies with one or a few sites |
|---|---|
| Users | up to approx. 100 workstations |
| Inspection throughput | up to 5 Gbit/s |
| Form factor | 1U, 19-inch rack |
| Highlight | High-availability pair |
Preliminary figures from the pilot program. Binding data sheets are available on request.
Use cases
Typical use.
- 01
Separating office and production networks
Machines and controllers only reach the systems they need. An attack in the office network cannot simply jump over to production.
- 02
Replacing older firewalls
Existing rules are carried over and cleaned up along the way. The switch can be prepared and carried out in a short maintenance window.
- 03
Connecting remote sites
Branches, warehouses and home offices are connected via VPN, with the same rules as at headquarters.
Data sheet
Valar 2 Technical data.
| Class | Business |
|---|---|
| Suited for | Mid-sized companies with one or a few sites |
| Users | up to approx. 100 workstations |
| Inspection throughput | up to 5 Gbit/s |
| Form factor | 1U, 19-inch rack |
|---|---|
| High availability | Pair (active/passive) |
| Highlight | High-availability pair |
| Ports, dimensions, power consumption | in the full data sheet, on request |
| Firewall | stateful, rules by network, service, user |
|---|---|
| NAT | port forwarding, 1:1, outbound |
| Networks | VLAN (802.1Q), IPv4 and IPv6 |
| Country rules | GeoIP, address groups |
| Multiple internet lines | load balancing and failover |
| Prioritisation | traffic shaping (QoS) |
| Site-to-site | IPsec |
|---|---|
| Mobile staff | WireGuard, OpenVPN |
| Authentication | certificate, user account, one-time password (2FA) |
| Intrusion prevention | inline IPS, rule sets with automatic updates |
|---|---|
| SSL inspection | configurable per zone |
| Web filter | categories and block lists, including transparent mode |
| Behaviour detection | NeoI |
| Guest access | captive portal with vouchers |
| Interface | web interface, API |
|---|---|
| Multiple appliances | central management |
| Users | Active Directory, LDAP, RADIUS |
| Analysis | reports, NetFlow, packet capture |
| Configuration | change history with rollback, encrypted backup |
| Network services | DHCP, DNS (including encrypted), dynamic DNS |
| Scope | all features included, no add-on modules |
|---|---|
| Term | as agreed |
| During the term | updates, security updates, detection data |
Preliminary figures from the pilot program. Binding data sheets are available on request.
neonotu GmbH · Edelsbergstraße 8 · 80686 Munich, Germany · +49 89 2000 79 750 · mail@valarsecure.com · www.valarsecure.com
Included
The same features as every Valar.
Zone-based firewall
Rules by network segment, application and user. Office, production, guests and servers stay separate.
Intrusion prevention (IPS)
Known attacks are detected in network traffic and blocked before they reach systems on the network.
SSL inspection
Encrypted traffic can be inspected. For each zone you decide where this makes sense and where it does not.
VPN
Sites and mobile staff are connected over encrypted links, for example via IPsec.
Web filter
Access to malicious or unwanted websites is blocked by category.
NeoI
neonotu’s own AI detects unusual behaviour even where no signature exists yet.
Operations
Easy to run.
Central management
Several units and sites are managed in one place. Rules apply consistently, deviations stand out.
High availability
From Valar 2 upwards, two units work as a pair. If one fails, the other takes over. Valar 4 can be extended into a cluster.
One licence
The licence depends on the model and the term. There are no features that have to be bought separately later.
Questions
Frequently asked questions.
Do we need two appliances?
Not necessarily. A pair is worth it if a firewall failure would stop your operations, for example in production or for services that must be available around the clock.
Can we carry over our existing rules?
Usually, yes. We review the current configuration and transfer the rules that are still needed.
What is included in the licence?
All protection features: firewall, intrusion prevention, SSL inspection, VPN, web filter and NeoI. The licence depends only on the model and the term; there are no add-on modules.
What happens when we grow?
You move to the next model. Because all models run the same software, rules and settings are carried over.
Who sets up the appliance?
Your IT service provider or one of our partners. On request, neonotu can also run the firewall for you as a managed service.
Is this the right model for your network?
Tell us briefly how many users and sites you have. We will recommend the right model and prepare a quote.
Ask for advice