Products / Enterprise
Valar 3 protects larger networks with many zones and high traffic. Redundant power supplies and fast fibre ports are designed for use in the data centre.

Overview
Valar 3 at a glance.
Valar 3 is designed for larger networks with many zones and high traffic, for example in hospitals, universities or public administrations. Fast fibre ports connect the appliance to the data centre core network.
Redundant power supplies ensure that a faulty power supply does not cause an outage. Combined with pair operation, the firewall stays available even during maintenance.
Key facts
| Suited for | Larger companies, hospitals, public administration |
|---|---|
| Users | up to approx. 1,000 users |
| Inspection throughput | up to 20 Gbit/s |
| Form factor | 2U, 19-inch rack |
| Highlight | Redundant power supplies |
Preliminary figures from the pilot program. Binding data sheets are available on request.
Use cases
Typical use.
- 01
Corporate data centre
Servers, workstations, management and external services are separated, with high throughput between the zones.
- 02
Hospital or university
Many areas with different protection needs, from medical technology to open Wi-Fi for students or visitors.
- 03
Municipal administration
Specialist applications, citizen services and the administrative network are cleanly separated, with evidence for audits and tenders.
Data sheet
Valar 3 Technical data.
| Class | Enterprise |
|---|---|
| Suited for | Larger companies, hospitals, public administration |
| Users | up to approx. 1,000 users |
| Inspection throughput | up to 20 Gbit/s |
| Form factor | 2U, 19-inch rack |
|---|---|
| High availability | Pair (active/passive) |
| Highlight | Redundant power supplies |
| Ports, dimensions, power consumption | in the full data sheet, on request |
| Firewall | stateful, rules by network, service, user |
|---|---|
| NAT | port forwarding, 1:1, outbound |
| Networks | VLAN (802.1Q), IPv4 and IPv6 |
| Country rules | GeoIP, address groups |
| Multiple internet lines | load balancing and failover |
| Prioritisation | traffic shaping (QoS) |
| Site-to-site | IPsec |
|---|---|
| Mobile staff | WireGuard, OpenVPN |
| Authentication | certificate, user account, one-time password (2FA) |
| Intrusion prevention | inline IPS, rule sets with automatic updates |
|---|---|
| SSL inspection | configurable per zone |
| Web filter | categories and block lists, including transparent mode |
| Behaviour detection | NeoI |
| Guest access | captive portal with vouchers |
| Interface | web interface, API |
|---|---|
| Multiple appliances | central management |
| Users | Active Directory, LDAP, RADIUS |
| Analysis | reports, NetFlow, packet capture |
| Configuration | change history with rollback, encrypted backup |
| Network services | DHCP, DNS (including encrypted), dynamic DNS |
| Scope | all features included, no add-on modules |
|---|---|
| Term | as agreed |
| During the term | updates, security updates, detection data |
Preliminary figures from the pilot program. Binding data sheets are available on request.
neonotu GmbH · Edelsbergstraße 8 · 80686 Munich, Germany · +49 89 2000 79 750 · mail@valarsecure.com · www.valarsecure.com
Included
The same features as every Valar.
Zone-based firewall
Rules by network segment, application and user. Office, production, guests and servers stay separate.
Intrusion prevention (IPS)
Known attacks are detected in network traffic and blocked before they reach systems on the network.
SSL inspection
Encrypted traffic can be inspected. For each zone you decide where this makes sense and where it does not.
VPN
Sites and mobile staff are connected over encrypted links, for example via IPsec.
Web filter
Access to malicious or unwanted websites is blocked by category.
NeoI
neonotu’s own AI detects unusual behaviour even where no signature exists yet.
Operations
Easy to run.
Central management
Several units and sites are managed in one place. Rules apply consistently, deviations stand out.
High availability
From Valar 2 upwards, two units work as a pair. If one fails, the other takes over. Valar 4 can be extended into a cluster.
One licence
The licence depends on the model and the term. There are no features that have to be bought separately later.
Questions
Frequently asked questions.
Which ports does Valar 3 have?
In addition to copper ports, Valar 3 has fast fibre ports for connecting to the data centre. The exact configuration is in the data sheet, which we are happy to send you.
Can Valar 3 be expanded later?
For more performance, you move to Valar 4. Rules and settings are carried over.
What is included in the licence?
All protection features: firewall, intrusion prevention, SSL inspection, VPN, web filter and NeoI. The licence depends only on the model and the term; there are no add-on modules.
What happens when we grow?
You move to the next model. Because all models run the same software, rules and settings are carried over.
Who sets up the appliance?
Your IT service provider or one of our partners. On request, neonotu can also run the firewall for you as a managed service.
Is this the right model for your network?
Tell us briefly how many users and sites you have. We will recommend the right model and prepare a quote.
Ask for advice