Firewall, WAF & NGF
Three layers,
one rule set
A firewall decides which connections are made at all. A web application firewall protects the application itself. A next generation firewall combines both and detects attacks inside permitted connections. We set up the layers, align the rule sets with one another and run them.
Protection at the connection level
Managed firewall
Our high-availability managed firewall solutions (layer 3/4) protect against network outages and external access attempts. They are configured to your security requirements and work together with our intrusion detection systems, so that the network and application levels are secured together. Attack patterns not seen before can also be detected by analysing incoming and outgoing traffic.
Protection at the application level
Web application firewall
Zero-day exploits, brute-force attacks, SQL injections, DoS attacks and other threats to your web application can be detected and fended off with our web application firewall (WAF). What matters is configuring the rule set individually: it has to take effect without disrupting production.
Beyond the OWASP Top 10, we make individual settings to counter new and unusual attack patterns as well. The WAF works in combination with the other protective layers – as part of a multi-level concept, not as a measure on its own.
Multi-layer protection
Next generation firewall
Attack tactics keep developing; effective protection therefore needs several layers.
Next generation firewalls (NGFW) go beyond conventional functions and come with built-in intrusion detection systems (IDS) and intrusion prevention systems (IPS). These detect attacks through traffic behaviour analysis, threat signatures and unusual activity. NGFWs inspect network traffic at application level and so improve the filtering of packet contents.
They include automatically updated virus and malware protection to reduce attack vectors. They restrict which programs can run and check permitted applications for vulnerabilities, hidden data breaches and risks from unknown applications. This reduces unnecessary traffic and makes better use of bandwidth.
With role-based access and extended policy control, NGFWs give fine-grained control over applications. Consistent data throughput means the protection stays the same regardless of how many protection services are enabled – with no loss of speed or connection quality.
Intrusion detection and intrusion prevention
What IDS and IPS do
Secure your applications and systems with our individually configured intrusion detection systems (IDS). With rule sets tailored to you, our intrusion prevention system (IPS) detects and blocks anomalies such as port scans, WSDL scans and suspicious login attempts. So that detection fits your environment, we recommend embedding IDS and IPS in a multi-level security concept: together with DDoS protection, a web application firewall and next generation firewalling.
The difference
Detecting is not stopping
Intrusion detection (IDS) observes and reports. It compares traffic with threat signatures, evaluates behaviour patterns and raises an alert when something departs from the normal picture – without intervening itself.
Intrusion prevention (IPS) intervenes. It blocks the detected connection, drops the packets or blocks the source, depending on the rule set.
The two belong together, and both need upkeep: a rule set that is set too strictly blocks genuine traffic; one that is too lax lets attacks through. That is why the ongoing tuning is the real part of the work, not the installation.
In our next generation firewall, IDS and IPS are built in – there they detect attacks through traffic behaviour analysis, threat signatures and unusual activity.
Prices
What the managed firewall costs
Our managed firewall is based on OPNsense – virtual or on a dedicated appliance, as you choose. The business subscription is included; the Proofpoint subscription adds reputation and malware filters.
Managed firewall OPNsense
- Virtual Fully managed virtual firewall incl. business subscription
- €249.00 / month
- Appliance Fully managed dedicated firewall incl. business subscription
- €399.00 / month
- Virtual, incl. Proofpoint Fully managed virtual firewall incl. business and Proofpoint subscription
- €349.00 / month
- Appliance, incl. Proofpoint Fully managed dedicated firewall incl. business and Proofpoint subscription
- €549.00 / month
Setup and further protective layers
- Installation / configuration Basic installation per firewall appliance
- €199.00 one-off
- Firewall cluster One-off basic installation per cluster
- €349.00 one-off
- Web application firewall Rule set to suit the application, beyond the OWASP Top 10
- On request
- Next generation firewall Multi-layer protection with built-in IDS/IPS
- On request
All prices net, plus statutory VAT, as of January 2026. What makes sense in your case depends on throughput, applications and protection needs – we work that out in conversation.
Goes with it
The layers alongside
IDS & IPS
Attacks that run over permitted connections are detected and blocked by an intrusion detection and prevention system.
To IDS & IPSDDoS protection
We filter out overload attacks before they reach your firewall – incident-based or continuously.
To DDoS protectionLoad balancing
Our load balancing solutions bring load distribution and firewall protection together in one system.
To load balancingFrequently asked questions about the managed firewall
What is a managed firewall?
A firewall that we set up, configure and run for you. You decide with us what should be permitted; we implement it, monitor operation, maintain the rules and react to faults. The systems are designed for high availability and are located in our data centres in Germany.
What is the difference between a firewall, a WAF and an NGF?
A classic firewall filters at network level (layer 3/4) – it decides which connections are made at all. A web application firewall protects the application itself and detects attacks such as SQL injection or brute-force attempts that run over permitted connections. A next generation firewall combines both and adds attack detection and prevention (IDS/IPS) as well as inspection of traffic at application level.
Which platform do you use?
For the managed firewall, OPNsense, either virtual or on a dedicated appliance: the business subscription is included, the Proofpoint subscription can be added, and for higher availability requirements we set up a cluster. The web application firewall and next generation firewall each run on their own systems in front — which ones, we discuss in conversation. The three take effect at different levels and do not replace one another.
Is a WAF enough on its own?
It covers the application level – but only that. Attacks on the network level and overload attacks get past it. That is why we combine the WAF with a firewall, attack detection and DDoS defence into a multi-level concept.
Who maintains the rule sets?
We do. The rule set is drawn up together with you at the start and maintained by us afterwards: updates, new signatures, adjustments to changes in your application. You pass change requests to us, and we implement them.
Can the firewall also protect systems that are not hosted with kyberio?
That depends on how your systems are connected. Tell us where they are today and how traffic reaches them – then we will look at whether and how a managed firewall can be put in front of them.
How do we find out about a detection?
In three ways, graded by urgency. Every detection first goes into our monitoring as an alert. Anything that calls for action is opened as a ticket and reported to you — it states what was detected and what we did. On top of that you receive a regular report on the detections in the period; it also shows what was not worth a report on its own but says something taken together. Within what time we intervene at which level is set out in your contract.
What response times do you commit to?
We monitor around the clock, every day of the year. How quickly we intervene and through which escalation stages is set out in your contract — a time we have not committed to is not a time we state here.
How quickly is a rule changed?
We monitor around the clock, every day of the year. How quickly we implement a change to the rule set and through which escalation stages is set out in your contract — a deadline we have not committed to is not a deadline we state here.
Satisfied customers















Sovereignty
Paving the way for digital sovereignty
-
Owner-managed since 1997
As an owner-managed operator with our own data centers, we make our decisions independently and are subject exclusively to German / EU law.
-
100% made in Germany
Our data center, product development, and customer support are all based in Germany for your digital sovereignty.
-
24/7 Customer Support
We are here for you: 24/7/365 customer support, in English and German
Let us find the right solution together
We take the time to understand what you need and to develop solutions that fit. We explain complicated technical matters clearly and precisely as we go. Get in touch with me directly and we will work it out.
- We will get back to you as soon as we can.
- No obligation, free of charge.