Firewall, WAF & NGF

Three layers,
one rule set

A firewall decides which connections are made at all. A web application firewall protects the application itself. A next generation firewall combines both and detects attacks inside permitted connections. We set up the layers, align the rule sets with one another and run them.

ISO 27001 based on BSI IT-GrundschutzData centres in Germany24/7/365 operation and support

Protection at the application level

Web application firewall

Diagram: web application firewall in front of the web application

Zero-day exploits, brute-force attacks, SQL injections, DoS attacks and other threats to your web application can be detected and fended off with our web application firewall (WAF). What matters is configuring the rule set individually: it has to take effect without disrupting production.

Beyond the OWASP Top 10, we make individual settings to counter new and unusual attack patterns as well. The WAF works in combination with the other protective layers – as part of a multi-level concept, not as a measure on its own.

Multi-layer protection

Next generation firewall

Attack tactics keep developing; effective protection therefore needs several layers.

Next generation firewalls (NGFW) go beyond conventional functions and come with built-in intrusion detection systems (IDS) and intrusion prevention systems (IPS). These detect attacks through traffic behaviour analysis, threat signatures and unusual activity. NGFWs inspect network traffic at application level and so improve the filtering of packet contents.

They include automatically updated virus and malware protection to reduce attack vectors. They restrict which programs can run and check permitted applications for vulnerabilities, hidden data breaches and risks from unknown applications. This reduces unnecessary traffic and makes better use of bandwidth.

With role-based access and extended policy control, NGFWs give fine-grained control over applications. Consistent data throughput means the protection stays the same regardless of how many protection services are enabled – with no loss of speed or connection quality.

Diagram: next generation firewall with built-in IDS and IPS

The difference

Detecting is not stopping

Intrusion detection (IDS) observes and reports. It compares traffic with threat signatures, evaluates behaviour patterns and raises an alert when something departs from the normal picture – without intervening itself.

Intrusion prevention (IPS) intervenes. It blocks the detected connection, drops the packets or blocks the source, depending on the rule set.

The two belong together, and both need upkeep: a rule set that is set too strictly blocks genuine traffic; one that is too lax lets attacks through. That is why the ongoing tuning is the real part of the work, not the installation.

In our next generation firewall, IDS and IPS are built in – there they detect attacks through traffic behaviour analysis, threat signatures and unusual activity.

Prices

What the managed firewall costs

Our managed firewall is based on OPNsense – virtual or on a dedicated appliance, as you choose. The business subscription is included; the Proofpoint subscription adds reputation and malware filters.

Managed firewall OPNsense

Virtual Fully managed virtual firewall incl. business subscription
€249.00 / month
Appliance Fully managed dedicated firewall incl. business subscription
€399.00 / month
Virtual, incl. Proofpoint Fully managed virtual firewall incl. business and Proofpoint subscription
€349.00 / month
Appliance, incl. Proofpoint Fully managed dedicated firewall incl. business and Proofpoint subscription
€549.00 / month

Setup and further protective layers

Installation / configuration Basic installation per firewall appliance
€199.00 one-off
Firewall cluster One-off basic installation per cluster
€349.00 one-off
Web application firewall Rule set to suit the application, beyond the OWASP Top 10
On request
Next generation firewall Multi-layer protection with built-in IDS/IPS
On request

All prices net, plus statutory VAT, as of January 2026. What makes sense in your case depends on throughput, applications and protection needs – we work that out in conversation.

Goes with it

The layers alongside

IDS & IPS

Attacks that run over permitted connections are detected and blocked by an intrusion detection and prevention system.

To IDS & IPS

DDoS protection

We filter out overload attacks before they reach your firewall – incident-based or continuously.

To DDoS protection

Load balancing

Our load balancing solutions bring load distribution and firewall protection together in one system.

To load balancing

Frequently asked questions about the managed firewall

What is a managed firewall?

A firewall that we set up, configure and run for you. You decide with us what should be permitted; we implement it, monitor operation, maintain the rules and react to faults. The systems are designed for high availability and are located in our data centres in Germany.

What is the difference between a firewall, a WAF and an NGF?

A classic firewall filters at network level (layer 3/4) – it decides which connections are made at all. A web application firewall protects the application itself and detects attacks such as SQL injection or brute-force attempts that run over permitted connections. A next generation firewall combines both and adds attack detection and prevention (IDS/IPS) as well as inspection of traffic at application level.

Which platform do you use?

For the managed firewall, OPNsense, either virtual or on a dedicated appliance: the business subscription is included, the Proofpoint subscription can be added, and for higher availability requirements we set up a cluster. The web application firewall and next generation firewall each run on their own systems in front — which ones, we discuss in conversation. The three take effect at different levels and do not replace one another.

Is a WAF enough on its own?

It covers the application level – but only that. Attacks on the network level and overload attacks get past it. That is why we combine the WAF with a firewall, attack detection and DDoS defence into a multi-level concept.

Who maintains the rule sets?

We do. The rule set is drawn up together with you at the start and maintained by us afterwards: updates, new signatures, adjustments to changes in your application. You pass change requests to us, and we implement them.

Can the firewall also protect systems that are not hosted with kyberio?

That depends on how your systems are connected. Tell us where they are today and how traffic reaches them – then we will look at whether and how a managed firewall can be put in front of them.

How do we find out about a detection?

In three ways, graded by urgency. Every detection first goes into our monitoring as an alert. Anything that calls for action is opened as a ticket and reported to you — it states what was detected and what we did. On top of that you receive a regular report on the detections in the period; it also shows what was not worth a report on its own but says something taken together. Within what time we intervene at which level is set out in your contract.

What response times do you commit to?

We monitor around the clock, every day of the year. How quickly we intervene and through which escalation stages is set out in your contract — a time we have not committed to is not a time we state here.

How quickly is a rule changed?

We monitor around the clock, every day of the year. How quickly we implement a change to the rule set and through which escalation stages is set out in your contract — a deadline we have not committed to is not a deadline we state here.

Satisfied customers

HornetsecurityIT-PHACONWOLFFAutoDoELAINE technologiesZEDALMAJA.cloudSDV SystemeAucotecPARATFP SignHyperspaceAttinaTutaElectronic Arts

Sovereignty

Paving the way for digital sovereignty

ISO 27001 based on BSI IT-Grundschutz, BSI-IGZ-0552-2023
BSI-IGZ-0552-2023 ISO 27001 based on BSI IT-Grundschutz Scope: all data centers and all cloud services Security concept
  • Owner-managed since 1997

    As an owner-managed operator with our own data centers, we make our decisions independently and are subject exclusively to German / EU law.

  • 100% made in Germany

    Our data center, product development, and customer support are all based in Germany for your digital sovereignty.

  • 24/7 Customer Support

    We are here for you: 24/7/365 customer support, in English and German

Let us find the right solution together

We take the time to understand what you need and to develop solutions that fit. We explain complicated technical matters clearly and precisely as we go. Get in touch with me directly and we will work it out.

  • We will get back to you as soon as we can.
  • No obligation, free of charge.

How we process your details is explained in our privacy notice.