Skip to main content

Stateful Firewall

The 7G Fuse appliances feature a built-in, enterprise-grade firewall designed to provide robust protection, secure segmentation and intelligent traffic control across WAN, LAN and VPN networks. With stateful Layer 3 inspection and application-aware traffic filtering, 7G Fuse ensures that your network remains secure, controlled and optimised.

Zone-Based Segmentation

7G Fuse uses zone-based interface segregation to logically separate network traffic.


  • LAN Zone – All internal interfaces where users, devices, and internal services connect.
  • WAN Zone – All external interfaces, including wired, cellular, or VPN connections.

Traffic policies can be applied per zone:


  • INPUT – Controls traffic entering the zone. You can allow or block specific connections by default.
  • OUTPUT – Controls traffic leaving the zone, enabling restrictions on data going out to external networks.
  • FORWARD – Manages traffic passing between zones to ensure secure internal segmentation.

This approach prevents unauthorized lateral movement, isolates critical systems and provides granular security control.


Stateful Layer 3 Inspection
  • Monitors each network session to allow legitimate responses while blocking unsolicited traffic.
  • Maintains connection states in memory to efficiently handle ongoing traffic without inspecting every packet, optimizing performance.

Advanced Rule Management
  • Explicit port forwarding and NAT rules for precise traffic control.
  • Input/output rules configurable based on IP addresses, subnets, or ports.
  • Outbound rules allow blocking of specific traffic from internal networks to the Internet.

Application-Aware Firewall

7G Fuse goes beyond traditional firewalls by integrating application awareness:


  • Traffic Identification – Detects traffic by application type, URL, port, or IP address using Deep Packet Inspection (DPI).
  • Application Control – Block, allow, or prioritize traffic based on application type. Examples:
    • Prioritize CCTV, VoIP, or business-critical applications.
    • Block social media, P2P, streaming, or gaming traffic.
  • Flexible Routing Integration – Combine with Policy-Based Routing (PBR) to route specific applications through dedicated WAN links or WAN groups.

This provides granular control over network usage, ensuring critical applications always have optimal bandwidth while unwanted traffic is restricted.

Key Benefits:
  • Comprehensive Protection: Blocks unauthorized access, mitigates threats in real time, and secures sensitive data.
  • Flexible Control: Supports zone-based rules, port forwarding, NAT, and application-aware filtering.
  • Optimized Network Performance: Stateful inspection ensures legitimate traffic flows efficiently without unnecessary overhead.
  • Enhanced Security for Multi-WAN & VPNs: Protects both Internet-bound traffic and inter-branch communications.

Close Menu