ShieldGate Firewall features

A complete catalog of shipped capabilities—application gateway, WAF, traffic control, network firewall, and security operations.

Gateway

Reverse proxy & application gateway

Precise traffic topology and gateway authentication at the edge before requests reach your applications.

Hosts, clusters & routes

Model destinations, clusters, and routes with load balancing, session affinity, health checks, timeouts, and request transforms.

Gateway authentication

Protect upstreams with JWT validation or API key schemes at the edge before traffic reaches applications.

Header & path transforms

Rewrite, redirect, and shape requests consistently across environments without application changes.

Live configuration

Publish versioned config and push live updates to gateway nodes—no process restart required.

WAF

Policy engine & inspection

Policy-driven decisions with flexible modes and actions—never hardcoded security outcomes.

Policy modes

Run rules in Enforce, Detect, Simulate, or Test so you can validate coverage before blocking production traffic.

Rich actions

Allow, block, log, redirect, raise threat score, rate-limit, temporary or permanent ban, challenge, and CAPTCHA hooks.

Built-in inspectors

SQLi, XSS, path traversal, command injection, threat intelligence, and bot score inspectors out of the box.

Structured policies

Author structured policies that compile into fast runtime matchers for predictable performance.

Traffic control

Rate limits, lists, geo & bots

Shape abusive traffic and enforce geographic or identity-aware controls at the edge.

Rate limiting

Fixed window, sliding window, and token bucket algorithms with queue limits for abusive clients.

IP allow & block lists

Maintain allowlists and blocklists with temporary and permanent bans.

GeoIP rules

Country and ASN allow/block decisions for regional access policy.

Bot management

Detect or enforce bot scoring with challenge and CAPTCHA interstitial flows.

Intelligence

Threat intel & extensions

Extend ShieldGate with providers and webhooks without forking the core platform.

Threat intelligence sync

Ingest IP, CIDR, ASN, domain, and URL indicators; resolve conflicts by highest confidence.

Extensible plugins

Auth, WAF inspectors, threat intel, notifications, SIEM, challenge, IDS, and anomaly extension points.

Notifications

Channel-based alerts including webhook delivery for operational and security events.

Background enrichment

Jobs keep indicators, certificates, and enrichment pipelines current automatically.

Trust

Certificates & identity

TLS lifecycle and operator identity for multi-tenant environments.

Certificate management

Certificate upload, automated issuance, SNI bindings, renewal, and expiry monitoring.

Users, roles & permissions

Fine-grained RBAC across gateway, policy, intel, certificates, analytics, network, and tenancy surfaces.

API keys

Programmatic access for automation and integrations.

Config publish & rollback

Versioned configuration with one-click rollback to a prior known-good snapshot.

Visibility

Observability & SIEM

Know what the edge is doing—and export it to the tools your SOC already uses.

Analytics & live metrics

Security event rollups and live operational metrics for the operator dashboard.

Standards-based telemetry

Export metrics and traces with industry-standard observability protocols.

SIEM export

Pluggable SIEM channels for structured security event delivery.

Audit log

Immutable operator actions with export for compliance and investigation.

Network

Network firewall & appliance

Packet L2–L3 policy, VPN, and edge services—managed independently from application gateway config.

Interfaces, L2 & zones

VLANs, bridges, address inventory, interface statistics, and zone-aware topology for multi-appliance clusters.

Stateful firewall & NAT

Connection tracking with SNAT, DNAT, 1:1, and MASQUERADE—plus policy-based routing for traffic steering.

Routing & VPN

Static routes, ECMP, WireGuard, and IPSec VPN for secure site and remote connectivity.

Services, HA & WAN

DHCP and DNS, Active/Passive HA with session sync, OSPF/BGP, SD-WAN policies, and QoS.

Multi-appliance clusters

Appliance nodes with roles, heartbeat, capabilities, and coordinated config apply.

Independent network publish

Publish and roll back network config separately from application gateway policy.

Advanced

IDS, ZTNA, tunnel, SOC & anomaly

Security modules that extend ShieldGate beyond traditional WAF coverage.

IDS / IPS

Signature packs with Detect or Prevent modes on the application path.

Zero Trust Network Access

Applications and policies bound to routes with claims, groups, and optional client certificates.

Secure tunnel

Peer enrollment and authenticated connectivity for controlled access paths.

SOC / SOAR playbooks

Cases from critical events with notify, ban, and webhook automated responses.

Anomaly detection

Behavior analysis that raises threat scores when traffic exceeds baseline multiples.

Multi-tenant administration

Tenant isolation with platform-level administration across customers or environments.

See these capabilities in your environment

Request a walkthrough tailored to your apps, tenancy model, and compliance requirements.

Talk to us