Segmentation enforced, changes accountable.

Network firewalls and micro-segmentation delivered with our partners OPNsense, Sophos and Fortinet — every rule reviewed, every change reversible, every path explicit.

OPNsense · Sophos · FortinetPolicy as codeAudited changes
Capabilities

The rulebase, under control

Centralised control. Consistent enforcement. Smarter decisions, everywhere.

Per-network policyNorth-south rules at every network boundary.Zones with real edges
Micro-segmentationEast-west controls between workloads — breach containment by default.East-west under control
Change controlPeer-reviewed changes in planned windows, with rollback.
Every rule reviewed
Rulebase hygieneStale and shadowed rules found and retired on schedule.
Dead rules retired
Policy as codeRulebases live in your repository and deploy through review.
Firewalls in the pipeline
Dedicated capacityYour rulebase runs on capacity dedicated to your estate.
No noisy neighbours
Flow logs & evidenceEvery permitted and denied flow is recorded and queryable.
Segmentation you can prove
High-availability pairsActive-standby with sub-second state sync.
Failover without drops
Threat feeds appliedKnown-bad addresses blocked automatically, updated by the SOC.
Intel without effort
Application awarenessLayer-7 identification controls applications, not just ports.
Rules that match reality
Delivered with partners

Partnered with OPNsense, Sophos and Fortinet

Network firewalls are delivered on platforms from our security partners — deployed as dedicated instances inside your tenancy, managed as code and watched by the SOC and NOC around the clock.

OPNsenseTechnology partner
Open-source firewall · Policy as code
Open, inspectable, yours

Dedicated OPNsense instances with a fully open rulebase — every rule inspectable, exportable and driven as code through the API, with no per-feature licensing.

Open-source stack — no licence lock-in
Full API — rules live in your repository
Dedicated HA pairs per pool boundary
Best for policy-as-code teams and cost-conscious estates
SophosTechnology partner
NGFW · IPS · App control
Deep inspection, managed simply

Sophos Firewall brings IPS, TLS inspection and application control to the boundary, with reporting clear enough to hand straight to an auditor.

IPS and TLS inspection at the perimeter
Application and URL control per policy
Synchronized security with endpoint agents
Best for consolidated edge security with clear reporting
FortinetTechnology partner
FortiGate · Segmentation fabric
Enterprise fabric, zero-trust deep

FortiGate NGFWs enforce from the perimeter to east-west micro-segmentation — identity-aware policy at line rate for the largest regulated estates.

High-throughput NGFW in HA pairs
Micro-segmentation and identity-aware policy
Security-fabric integration with SOC monitoring
Best for large regulated estates and zero-trust programmes
CloudSouqThe YallaCloud marketplace
Explore the plans in CloudSouq
Perimeter, segmentation and zero-trust plans on all three platforms are listed in CloudSouq — compare inclusions, sizes and bundles, all inside your one flat fee.
Two ways to run it

You hold the rulebase, or we do

Both keep every change reviewed and reversible. The difference is who makes it.

Self-managed RulesYou hold the policyYour team writes and reviews policy through the console or as code, with history on every change.
Policy as code, versioned
Peer review before enforcement
Rollback in a single action
Best for:Teams with security engineers
Explore Self-managed Rules plans
OR
Managed FirewallWe hold the policySecurity Operations owns the rulebase, executes your change requests and reviews the policy set on a cycle.
Change requests executed and evidenced
Rule hygiene reviews, shadow rules removed
24/7 monitoring and response
Best when:Nobody dares touch the rules
Explore Managed Firewall plans
Who decides, who runs it

What each group gets from Firewalls

Four groups shape a cloud decision. Pick the one you belong to — the platform reads differently from each seat.

Blast radius is a design decision

Segmentation limits how far an incident can travel, which changes the shape of the risk conversation entirely.

GovernedSovereignPredictable

FAQs

Is the firewall dedicated to us?
Yes — your rulebase runs on capacity dedicated to your estate, not a shared multi-tenant policy set.
OPNsense, Sophos or Fortinet — which do we pick?
OPNsense when open policy-as-code and licence freedom matter most; Sophos for consolidated edge inspection with clean reporting; FortiGate for high-throughput segmentation and zero-trust programmes. Mixed estates are common — we run them under one operating standard.
Can we manage rules as code?
Yes. Policy is API-driven, so it can live in your repository and go through review like any other change.
How does segmentation avoid breaking apps?
We start in visibility mode, learn the real flows, then enforce — rather than guessing at policy on day one.
Do you remove old rules?
Under Managed Firewall, yes — hygiene reviews identify shadowed and unused rules and retire them with your approval.
Does this replace endpoint security?
No. Network policy limits movement; Endpoint Security watches what happens on the workload itself.
How is the flat fee different from public cloud pricing?
Everything inside the plan you opt for is included — no additional charge for the components that make it up. Public clouds meter each component on consumption, so the bill moves with usage. Here the plan is reserved for you and the figure you agreed is the figure you pay.
How do limits and quotas work?
Quotas are yours to shape — carve capacity per team or project and delegate inside it. Hard ceilings are a conversation, not a wall; the estate re-baselines at thresholds you approve.
Better together

Build more around every network boundary.

Connect Firewalls to the platform services that turn segmentation and policy into a complete security posture.

At the core
Firewalls

Network controls become a complete security plane when workloads, delivery, application defence and evidence work around them.

SegmentControlProtectObserve
One network security plane
WorkloadsSegmentationPolicyVisibilityEvidence
Noura
Noura — AI Cloud Experience Guide

Two ways Noura gets you moving

Choose the way that fits you best — Noura makes every step simple.

Not sure where to start?
Start the conversation

Describe the workload in plain language — Noura works out the tiers, sizes and protection with you.

Plain language input
Smart sizing & protection
No commitment. Just clarity.
Talk to Noura
Want to see it working?
Experience it in the marketplace

Explore CloudSouq experiences built on these services — see Firewalls working inside real solutions before you commit to anything.

Try real solutions
See it work in action
Commit with confidence
Explore CloudSouq
Noura is your guide at every stepfrom first question to final success.Intelligent
Guidance
Secure &
Trusted
Human
Simplicity