Fortinet, Palo Alto and our own Onyx Firewall — we size the appliance to your traffic and user count, supply it with official licensing, write the configuration ourselves and keep track of the renewal date for you.
The appliances that guard the edge of your network, plus the licensing, configuration and monitoring that actually make them work.
The main line of defence between your network and the internet — models from small office to data centre.
Connecting branches and remote staff to internal systems without exposing them to the internet.
A firewall with an expired licence does not protect anything, it just forwards traffic. Managing that subscription is our job.
A firewall on its own is not enough — without what sits around it you neither see an incident nor recover from it.
Official channel, official licensing. We size the appliance to the project instead of arriving with a fixed answer.
The FortiGate NGFW line — the firewall platform we deploy most often in Azerbaijan on feature-to-price grounds.
For larger organisations that need deep application-level control and have strict security requirements.
RouterOS-based network security and VPN gateways. Provides robust NAT, stateful firewall rules, and dependable multi-branch tunnels for budget-conscious projects.
Security within the same ecosystem for customers whose network is already built on Cisco.
ONYX's own hardware product: network protection, guest Wi-Fi, and a captive portal in one appliance for small and mid-size offices, without a heavy annual subscription burden. It is one of the options in our lineup — if it does not fit the project, we say so.
We supply Dell, HP and Lenovo for servers and Cisco and Mikrotik for network equipment — see the relevant categories.
Enterprise perimeter security platforms from Fortinet, Palo Alto, Cisco, and Mikrotik.
Desktop NGFW, FortiSP5 security processor, hardware acceleration, integrated SD-WAN
Designed for small offices, branches, and distributed corporate sites requiring web filtering and secure VPN.
1U Rackmount NGFW, 10G SFP+ ports, FortiSP5 security processor, hardware SSL inspection
Designed for mid-size networks requiring deep packet inspection (DPI), application control, and high-throughput IPSec.
High-throughput Enterprise NGFW, NP7 and CP9 processors, 10G/25G interfaces
Engineered for data centers, large enterprises, and continuous high-availability (HA) clusters.
Compact Enterprise NGFW, PAN-OS, App-ID and Content-ID architectures
Optimized for organizations of 20–100 users with rigorous security and audit requirements.
1U/2U Enterprise NGFW, dedicated control and data planes, WildFire
Designed for large enterprises demanding application-level visibility and automated zero-day threat prevention.
Compact desktop and 1U Rackmount NGFW, Cisco ASA / FTD software, Snort 3 IPS engine
Designed for corporate environments with existing Cisco infrastructure seeking unified threat management and centralized visibility.
Stateful packet filtering, RAW tables, hardware-accelerated IPSec and WireGuard
Budget-conscious solution for SMBs requiring robust site-to-site encrypted VPN and advanced NAT/routing rules.
Security appliances are sized based on encrypted traffic volumes and required inspection features.
Four steps from sizing the appliance to tracking its licence.
Link speed, user count, branch offices and whatever appliance is running today — we establish that first.
A model matched to your traffic and user count, plus the licence package. The quote lists the appliance and the one to three year subscription separately, so the annual cost is clear up front.
We prepare the configuration in advance and cut over outside business hours. Rules from the old appliance are reviewed, migrated and pruned rather than copied blindly.
We warn you 60 days before the subscription expires. On request the appliance goes onto a monthly support contract covering rule changes and monitoring.
Straight out of the box a firewall protects almost nothing — the value is in the configuration and the follow-up.
The appliance and its subscription are registered to your company through the official channel, so vendor support never turns into an argument about entitlement.
A firewall running default rules gives you very little. We build the rule set around your business processes, branches and user groups.
A subscription quietly lapsing is the most common gap we find. We keep the date in our own records and warn you well before it arrives.
Onyx Firewall is built by us, but it does not fit every project. If your requirements call for Fortinet or Palo Alto, that is what we quote.
What buyers ask us most often before ordering a firewall.
We evaluate encrypted traffic volume, concurrent user count, site-to-site VPN tunnels, and required inspection features (IPS, antivirus, web filtering). Based on these requirements, we recommend an appropriate platform from Fortinet, Palo Alto, or Cisco.
The appliance keeps forwarding traffic, but the security functions — IPS signatures, antivirus definitions, web filtering — stop updating. The box is still there while the protection quietly drains away. That is why we keep the expiry date in our own records and warn you 60 days ahead.
Not necessarily. We look at the model, the licence status and the configuration first. In practice the problem is often not the appliance but a rule set nobody ever tuned — and that is fixed without buying anything.
Fortinet delivers high throughput and a strong price-performance balance across distributed branches and enterprise campuses. Palo Alto Networks is engineered for corporate environments with strict security and audit requirements that need granular Layer 7 application inspection (App-ID) and automated zero-day threat analysis (WildFire).
Onyx Firewall is built for small and mid-size offices: protection, guest Wi-Fi and a captive portal in one appliance with minimal annual subscription cost. Fortinet offers broader functionality, certified security features and international vendor support. Where the requirements are strict or an audit is involved, we quote Fortinet.
For the rest of the project — server and network hardware.
Send us your user count and internet link speed and we will quote a matching appliance and licence package.