Products / Critical
Valar 4 is built for large and distributed networks. Several units work as a cluster, including across two data centres. Findings from NeoI can be passed on to an existing SOC.

Overview
Valar 4 at a glance.
Valar 4 is built for large and distributed networks: enterprises, energy suppliers, providers. The modular chassis offers many fast ports and can be adapted to growing requirements.
Several appliances work together as a cluster, including across two data centres. Findings from NeoI can be passed on to an existing security operations centre (SOC), so the security team sees all alerts in one place.
Key facts
| Suited for | Large enterprises and critical infrastructure operators |
|---|---|
| Users | 5,000+ users, further scalable |
| Inspection throughput | up to 80 Gbit/s |
| Form factor | Rack, modular |
| Highlight | Cluster-capable |
Preliminary figures from the pilot program. Binding data sheets are available on request.
Use cases
Typical use.
- 01
Critical infrastructure, e.g. energy and water
High availability, strict separation of control and office networks, and evidence of where software and updates come from.
- 02
Enterprise network with several data centres
Consistent rules for all sites, managed centrally, with resilience across two data centres.
- 03
Providers and service companies
Many customer networks on one platform, cleanly separated and managed centrally.
Data sheet
Valar 4 Technical data.
| Class | Critical |
|---|---|
| Suited for | Large enterprises and critical infrastructure operators |
| Users | 5,000+ users, further scalable |
| Inspection throughput | up to 80 Gbit/s |
| Form factor | Rack, modular |
|---|---|
| High availability | Pair and cluster |
| Highlight | Cluster-capable |
| Ports, dimensions, power consumption | in the full data sheet, on request |
| Firewall | stateful, rules by network, service, user |
|---|---|
| NAT | port forwarding, 1:1, outbound |
| Networks | VLAN (802.1Q), IPv4 and IPv6 |
| Country rules | GeoIP, address groups |
| Multiple internet lines | load balancing and failover |
| Prioritisation | traffic shaping (QoS) |
| Site-to-site | IPsec |
|---|---|
| Mobile staff | WireGuard, OpenVPN |
| Authentication | certificate, user account, one-time password (2FA) |
| Intrusion prevention | inline IPS, rule sets with automatic updates |
|---|---|
| SSL inspection | configurable per zone |
| Web filter | categories and block lists, including transparent mode |
| Behaviour detection | NeoI |
| Guest access | captive portal with vouchers |
| Interface | web interface, API |
|---|---|
| Multiple appliances | central management |
| Users | Active Directory, LDAP, RADIUS |
| Analysis | reports, NetFlow, packet capture |
| Configuration | change history with rollback, encrypted backup |
| Network services | DHCP, DNS (including encrypted), dynamic DNS |
| Scope | all features included, no add-on modules |
|---|---|
| Term | as agreed |
| During the term | updates, security updates, detection data |
Preliminary figures from the pilot program. Binding data sheets are available on request.
neonotu GmbH · Edelsbergstraße 8 · 80686 Munich, Germany · +49 89 2000 79 750 · mail@valarsecure.com · www.valarsecure.com
Included
The same features as every Valar.
Zone-based firewall
Rules by network segment, application and user. Office, production, guests and servers stay separate.
Intrusion prevention (IPS)
Known attacks are detected in network traffic and blocked before they reach systems on the network.
SSL inspection
Encrypted traffic can be inspected. For each zone you decide where this makes sense and where it does not.
VPN
Sites and mobile staff are connected over encrypted links, for example via IPsec.
Web filter
Access to malicious or unwanted websites is blocked by category.
NeoI
neonotu’s own AI detects unusual behaviour even where no signature exists yet.
Operations
Easy to run.
Central management
Several units and sites are managed in one place. Rules apply consistently, deviations stand out.
High availability
From Valar 2 upwards, two units work as a pair. If one fails, the other takes over. Valar 4 can be extended into a cluster.
One licence
The licence depends on the model and the term. There are no features that have to be bought separately later.
Questions
Frequently asked questions.
What does cluster operation mean?
Several Valar 4 units share the workload and stand in for each other. Performance grows with your needs, and the failure of one unit has no effect on operations.
Does Valar support tenders?
Yes. For procurement procedures, we provide technical data sheets and supply chain documentation.
What is included in the licence?
All protection features: firewall, intrusion prevention, SSL inspection, VPN, web filter and NeoI. The licence depends only on the model and the term; there are no add-on modules.
What happens when we grow?
You move to the next model. Because all models run the same software, rules and settings are carried over.
Who sets up the appliance?
Your IT service provider or one of our partners. On request, neonotu can also run the firewall for you as a managed service.
Is this the right model for your network?
Tell us briefly how many users and sites you have. We will recommend the right model and prepare a quote.
Ask for advice