CatalogueHardware & Equipment MarketplaceFirewalls, Security Appliances & Identity Hardware
Hardware & Equipment Marketplace

Firewalls, Security Appliances & Identity Hardware

Security gateways, hardware security modules, authentication devices and related appliances for network, data and identity protection.

Who this is for
  • Security teams
  • Regulated organizations
  • Data centers
  • Multi-site businesses
Outcomes it serves
  • Controlled network access
  • Higher assurance for keys and identities
  • Centralized threat protection
  • Supported security lifecycle
Capabilities
  • Next-generation firewalls and secure gateways
  • Web and email security appliances
  • Hardware security modules and key management
  • MFA tokens and smart-card readers
  • Secure access and zero-trust appliances
  • Licensing, configuration and managed security options
What is delivered
  • Approved bill of materials or manufacturer part selection
  • Technical datasheets and compatibility record
  • Warranty, authenticity and regulatory documentation
  • Configuration, staging or asset tagging when purchased
  • Shipping, installation and acceptance records
  • Support, replacement and end-of-life information
Options
  • Branch firewall
  • Enterprise edge
  • Data-center security
  • Identity and MFA kit
  • HSM solution
  • Managed security bundle
What may change the price
  • Brand, model and technical specification
  • Quantity, stock and supplier price validity
  • Configuration, licenses and accessories
  • Warranty and support level
  • Freight, installation, taxes and duties
  • Compatibility and lifecycle availability

Content on this page comes from the governed ARRIX catalogue record HW-04; pricing is confirmed only through a reviewed quotation.

What This Is

Firewalls, Security Appliances & Identity Hardware

Security appliances are the dedicated devices that sit between an organisation's network and everything outside it, deciding what traffic and which people are allowed through.

A firewall is the locked door of a network. Everything arriving from the internet has to pass it, and it decides what gets in, what gets out, and what gets recorded. Modern security appliances go further than a door: they inspect what is inside the traffic, block known-malicious destinations, give remote staff a private way back into the office network, and keep a log of who did what. Identity hardware - security keys, card readers, token devices - answers the other half of the question: not what is allowed through, but who is actually asking.

Reduced likelihood of a business-stopping incident

Known-malicious destinations, unpatched-service exposure and unauthorised inbound connections are blocked before they reach an endpoint or server.

Contained damage when something does get in

Segmentation between user, server, guest, payment and device networks stops a single compromised machine from reaching everything else.

Safe remote working

An encrypted remote-access tunnel terminating on the appliance lets staff reach internal systems without those systems being published to the internet.

Demonstrable controls for insurers, clients and auditors

Policy, logging and multi-factor enforcement produce the evidence that questionnaires and cyber-insurance renewals request.

Account takeover becomes far harder

Hardware security keys and token devices require physical possession, which a stolen or phished password alone cannot satisfy.

Why It Matters

The problems this answers

Perimeter security is the control most organisations already assume they have and most often have in name only. A consumer router supplied by an internet provider performs address translation and is frequently mistaken for a firewall; it does not inspect content, does not segment internal traffic, does not log usefully, and receives security updates on the provider's schedule rather than the organisation's. A business security appliance changes three things: it enforces a written policy rather than a default, it produces evidence of what happened, and it is maintained under a support subscription that keeps its threat intelligence current. The purchasing decision is rarely about the box. It is about throughput once inspection is switched on, the subscription that keeps it useful, and whether anyone is responsible for reading what it reports.

  • Internet-facing systems exposed with no inspection, policy or logging beyond an internet provider's default router
  • Remote and hybrid staff needing access to internal systems without exposing those systems to the whole internet
  • A flat internal network where one compromised laptop can reach servers, cameras, payment terminals and backups alike
  • Passwords alone protecting accounts that control money, customer data or administrative systems
  • Insurance, client or regulatory questionnaires asking for controls and evidence that the organisation cannot currently produce
Where it is used, and what changes as a result
OrganisationNeedWhat the equipment doesOutcome
A professional services firmStaff working from home need the file server and practice systemFirewall with remote-access VPN and multi-factor enforcementInternal systems stay unpublished; access requires both credentials and a second factor.
A retailer taking card paymentsKeeping payment terminals off the same network as staff laptops and guest Wi-FiFirewall enforcing segmentation between payment, staff, device and guest networksScope for payment compliance narrows and a compromised laptop cannot reach the terminals.
A multi-site organisationBranches sharing systems hosted at head officeSite-to-site VPN between appliances at each locationBranches operate as one network over the public internet without exposing services.
A clinic or practice holding sensitive recordsDemonstrating that access to records is controlled and recordedFirewall logging plus hardware-backed multi-factor on administrative accountsAccess is provably restricted and a record exists of what was reached and when.
An organisation with a small internal IT teamSecurity that does not require a full-time analystCloud-managed appliance with a maintained subscription and alertingPolicy is applied and updated centrally; attention is spent on exceptions rather than daily upkeep.
How To Choose

Types, and when each one is the right answer

Sizing matters more than brand here. ARRIX specifies to the requirement rather than to a fixed model list.

Internet-provider router

Not a business security control. Adequate only where nothing internal is shared and no compliance obligation exists - treat it as a modem, and put a firewall behind it.

Small-office firewall appliance

A single site with a modest user count that needs real policy, segmentation, logging and remote access.

Next-generation firewall

Inspection of encrypted traffic, application-level policy and intrusion prevention are required; sizing must account for the throughput cost of inspection.

Unified threat management appliance

A smaller organisation wants filtering, gateway anti-malware, intrusion prevention and VPN from one maintained device rather than several.

High-availability firewall pair

Loss of internet access or remote access would stop the business; two appliances fail over without manual intervention.

Cloud-managed security appliance

Multiple sites need consistent policy and no site has on-hand technical staff.

VPN concentrator or dedicated remote-access appliance

Remote-access volume is high enough that terminating it on the main firewall would consume the throughput budget.

Hardware security keys and token devices

Administrative, financial or remote-access accounts need a second factor that cannot be phished or copied like a code.

Hardware security module or secure key storage

Cryptographic keys, certificates or signing operations must be held in tamper-resistant hardware rather than on a general-purpose server.

Network access control appliance

The organisation needs to decide what a device is and whether it is compliant before it is allowed onto the network at all.

What decides the choice

  • Inspection throughput, not headline throughput - a figure quoted with all inspection disabled will not be met in service
  • Concurrent user and connection counts against realistic peak, including remote-access sessions
  • Whether segmentation is genuinely required, because it drives interface and licensing choices more than raw speed does
  • Subscription scope and term, since threat intelligence and filtering stop being useful the day the subscription lapses
  • Management model - on-appliance, on-premises controller or cloud - matched to who will actually operate it
  • Support and replacement terms, because a failed perimeter device removes internet access entirely
  • Whether anyone is accountable for reading the logs and alerts the appliance produces
Specification Detail

For whoever has to sign it off

Open only what you need. Nothing here is hidden from print or from a browser without JavaScript.

Specifications that actually decide the outcome
SpecificationWeightWhat it meansWhy it mattersSpecify higher when
Firewall throughputCriticalTraffic the appliance can pass with basic filtering.Sets the ceiling for the internet connection it can serve without becoming the bottleneck.The internet link is fast, or many users are active at once.
Threat-prevention throughputCriticalTraffic the appliance can pass with inspection features enabled.This is the number that applies in real service; it is often a fraction of the headline figure.Deep inspection, intrusion prevention or encrypted-traffic inspection will be switched on.
Concurrent sessionsImportantHow many simultaneous connections can be tracked.Modern applications open many connections per user; exhaustion presents as unexplained slowness.User counts are high or applications are chatty.
VPN throughput and tunnel countCriticalEncrypted remote-access and site-to-site capacity.Determines how many staff or branches can connect before performance degrades.Remote working is routine or several sites must be joined.
Interface count and speedImportantPhysical ports available for internal, external and segmented networks.Segmentation and second internet links both consume ports.Several isolated networks or redundant internet links are required.
High-availability supportImportantWhether two units can operate as a failover pair.Removes the perimeter as a single point of failure.Internet or remote access is business-critical.
Logging and retention capabilityCriticalHow much detail is recorded and for how long, locally or to an external collector.Without retained logs an incident cannot be investigated and an auditor cannot be answered.A compliance obligation or client contract specifies retention.
Subscription and licence termCriticalThe maintained services that keep filtering and intelligence current.An appliance out of subscription degrades to a basic filter while still appearing to work.Filtering, intrusion prevention or malware protection are relied upon.
Authenticator standard supportImportantWhich multi-factor and hardware-key standards the identity hardware and appliance both support.Determines whether one key can be used across the systems the organisation actually runs.Several platforms and cloud services must all accept the same factor.
What it has to work with
  • Internet service type and hand-off determine the external interface required; a fibre service may need a specific optical module or an operator-supplied device in bridge mode
  • Segmentation depends on managed switches and access points capable of carrying separated networks - a firewall alone cannot segment a flat switch estate
  • Remote-access clients must be supported on the operating systems staff actually use, including mobile
  • Directory and identity integration determines whether policy can be written about people rather than addresses
  • Hardware security keys must match both the connector and the standards accepted by the organisation's identity provider and applications
What it costs to own, not just to buy
  • Appliance purchase is frequently the smaller part; annual security subscriptions are recurring and mandatory for the protective features
  • Configuration and policy design is a real professional cost - a business appliance configured with defaults is a consumer router with a larger invoice
  • Support contracts covering advance replacement matter because the appliance sits in the only path to the internet
  • Segmentation may require switch or cabling work at the same time
  • Time spent reviewing alerts and logs is an ongoing operational cost that should be assigned rather than assumed
Risks and things worth knowing first
  • Undersizing for inspection is the most common failure and appears as slow internet rather than as a security problem
  • An expired subscription leaves an appliance that still passes traffic and no longer protects it
  • Policy drift - temporary rules that are never removed - gradually reopens the perimeter
  • Encrypted-traffic inspection has privacy, legal and application-compatibility implications that must be decided before it is enabled
  • A firewall does not address a compromised account, a malicious email or an unpatched endpoint; it is one control among several
Mistakes that are common and expensive
  • Treating the internet provider's router as a firewall
  • Buying to the headline throughput figure and finding the appliance cannot sustain it with inspection enabled
  • Letting the security subscription lapse because the device appears to keep working
  • Opening inbound ports to internal systems as a shortcut instead of using remote access
  • Deploying the appliance and appointing nobody to read what it reports
When you may not need this at all

An organisation with no internal shared systems, no remote access requirement and no compliance obligation - where every service used is a public cloud application reached from managed endpoints - may reasonably invest first in endpoint protection and identity controls rather than a perimeter appliance. Security still has to live somewhere; in that model it lives on the device and the account.

Common Questions

Answered plainly

Is the router from my internet provider a firewall?

It performs address translation, which hides internal addresses, and that is often mistaken for a firewall. It does not inspect traffic content, cannot separate internal networks, logs very little, and is updated on the provider's schedule. For a business with shared internal systems or any compliance obligation, treat it as a modem and place a firewall behind it.

Which firewall model do you stock?

ARRIX does not hold a fixed firewall catalogue at family level. Perimeter appliances are specified to the site - internet speed, user count, whether inspection and segmentation are needed, and whether failover is required - then sourced. Share those details and ARRIX will return a specified quotation rather than a model from a shelf.

Why is the firewall slower than its advertised speed?

Headline throughput is usually measured with inspection disabled. Once intrusion prevention, malware scanning or encrypted-traffic inspection is switched on, real throughput can fall to a fraction of that figure. Size against the threat-prevention throughput, which is the number that applies in service.

Do I still need a firewall if everything we use is in the cloud?

The emphasis shifts rather than disappearing. With no internal shared systems, identity controls and endpoint protection carry more weight. A perimeter appliance still provides segmentation, filtering, logging and a controlled path for any on-site equipment - cameras, terminals, printers - that cannot defend itself.

What does the annual subscription actually buy?

The maintained parts: threat intelligence, malicious-destination lists, intrusion signatures, malware definitions and often the management service. When it lapses the appliance keeps passing traffic and quietly stops protecting it, which is why lapse is more dangerous than failure.

Are hardware security keys better than authenticator codes?

For accounts that matter, yes. A one-time code can be read out over the phone or entered into a convincing fake page; a hardware key checks the site it is talking to and cannot be used remotely by an attacker. The usual approach is hardware keys on administrative, financial and remote-access accounts, with app-based factors elsewhere.

Can one firewall separate our guest Wi-Fi, payment terminals and staff network?

It can enforce the rules between those networks, but the separation must also exist in the switching and wireless. A firewall with one internal port behind a flat switch estate has nothing to keep apart. Segmentation is a network design, not a single device setting.

Request A Quotation

Tell ARRIX the situation, not the part number

ARRIX sources this family to requirement. A specified quotation is faster than a catalogue search, and these are the questions it answers.

  • How many people and how many devices will pass through this appliance at peak?
  • What is the speed and type of the internet connection it will sit behind?
  • Do staff need remote access to internal systems, and roughly how many at once?
  • Do you need to keep separate networks apart - guest, payment, cameras, operational equipment?
  • Are there several sites that need to be joined together?
  • Is there a compliance, insurance or client requirement that specifies particular controls or log retention?
  • Would loss of internet access stop the business, and for how long is that tolerable?
  • Who will manage the appliance day to day, and are they on site?
  • Are you replacing an existing appliance, and is it still in support?
  • Do administrative or financial accounts currently require a second factor?

Ask AI what ARRIX does for Firewalls, Security Appliances & Identity Hardware — ARRIX Catalogue

Opens your assistant with the question ready. Gemini has no pre-filled link, so we copy the question to your clipboard first.