Ubiquiti Enterprise Firewall Core (Image © PCMasters.de)
The hardware is based on 24 Neoverse N2 cores that provide the computing power required for distributed enterprise operations. This architecture enables the system to manage up to 10 million concurrent sessions and support up to 22,000 active devices. The focus on hyperscale-class computing power ensures that the firewall remains stable even with an enormous number of sessions and demanding security tasks.
Threat intelligence and SSL inspection
To cope with the speed of modern network threats, the Enterprise Firewall Core achieves a threat detection throughput of up to 79 Gbps. The system continuously inspects traffic against a database of tens of thousands of signatures, supported by real-time intelligence updates from Proofpoint via the Cybersecure Enterprise integration.
As encrypted traffic is widely used in enterprise environments, the platform provides full visibility through SSL inspection. The system can process encrypted traffic at speeds of up to 61 Gbps, ensuring that security policies are enforced and threats are identified in encrypted traffic streams without creating network bottlenecks.
SD-WAN and encrypted connectivity
The platform is designed to act as a central anchor for large-scale SD-WAN deployments. It supports more than 5,000 concurrent encrypted tunnels, including IPsec and WireGuard protocols. Aggregate IPsec throughput reaches 38 Gbps, enabling high-speed secure connectivity between global sites and distributed users.
Hardware redundancy and system resilience
Business continuity is ensured through multiple layers of hardware and software redundancy. The system utilizes VRRP-enabled shadow mode for rapid high-availability provisioning, while multi-chassis link aggregation and switch stacking improve resiliency at the core and edge of the network.
At the physical level, the device is designed for maximum uptime and features redundant power supplies and hot-swappable fans. Integrated management and console ports facilitate direct hardware maintenance and troubleshooting.
Central orchestration and identity control
Network management is centralized through the Site Manager platform, which provides a single interface for SD-WAN orchestration and policy management. To ensure that security policies remain consistent regardless of where a user connects, the system integrates with identity providers such as Entra, Google Workspace and LDAP. This identity-based framework allows administrators to enforce specific access controls based on user profiles across all connected locations.


