Software
One software for every model.
Valar 1 and Valar 4 run the same software. Rules, management and updates are identical. Only the hardware performance differs.
01 / Features
Included in every licence.
Zone-based firewall
Rules by network segment, application and user. Office, production, guests and servers stay separate.
Intrusion prevention (IPS)
Known attacks are detected in network traffic and blocked before they reach systems on the network.
SSL inspection
Encrypted traffic can be inspected. For each zone you decide where this makes sense and where it does not.
VPN
Sites and mobile staff are connected over encrypted links, for example via IPsec.
Web filter
Access to malicious or unwanted websites is blocked by category.
NeoI
neonotu’s own AI detects unusual behaviour even where no signature exists yet.
Features in detail
What the software can do in detail.
The following features are available on all models. How much of it makes sense at the same time depends on the performance of the model.
Firewall and network
- Stateful firewall with rules by network, service and user
- Network address translation (NAT): port forwarding, 1:1 and outbound
- Virtual networks (802.1Q VLAN) and IPv6
- Country-based rules (GeoIP) and address groups
- Multiple internet lines with load balancing and failover
VPN
- IPsec for site-to-site connections
- WireGuard and OpenVPN for mobile staff
- Authentication via certificates, user accounts or one-time password
Detection and filtering
- Inline intrusion detection and prevention (IPS)
- Rule sets that update automatically
- NeoI: detection of unusual behaviour
- Web filter with categories and block lists, including transparent mode
- SSL inspection per zone
Access and guests
- Guest access (captive portal) with vouchers, e.g. for guest Wi-Fi
- Two-factor login to the management interface
- Integration with Active Directory, LDAP and RADIUS
Availability and traffic
- High availability: a second unit takes over, existing connections are kept
- Configuration is synchronised to the second unit automatically
- Traffic prioritisation, e.g. for telephony (QoS)
Network services
- DHCP server and DHCP relay
- DNS resolver and forwarding, including encrypted DNS
- Dynamic DNS
Operations and monitoring
- Clear web interface and API
- Reports, traffic flow analysis (NetFlow) and system health
- Packet capture for troubleshooting
- History of all configuration changes with comparison and rollback
- Encrypted configuration backup
- One-click updates
02 / NeoI
Detection, even without a signature.
Traditional firewalls mainly recognise attacks by known patterns. New attacks often go unnoticed until a signature exists.
NeoI also looks at behaviour: which devices are unusually active, who are they talking to and when? Deviations like these can point to an attack. The analysis runs on the device, and insights from many installations flow back through daily updates.
03 / Operations
Easy to manage.
- 01
Central management
Several units and sites are managed in one place. Rules apply consistently, deviations stand out.
- 02
High availability
From Valar 2 upwards, two units work as a pair. If one fails, the other takes over. Valar 4 can be extended into a cluster.
- 03
One licence
The licence depends on the model and the term. There are no features that have to be bought separately later.