Network SecurityNX Series
FireEye Network Security is an effective cyber-defense solution designed to help organizations of all sizes minimize the risk of costly breaches by accurately detecting and immediately stopping advanced and evasive attacks hiding in Internet traffic. It enables the resolution of security alerts in minutes with concrete evidence, actionable intelligence and response workflow integrations. With FireEye Network Security, organizations are effectively protected against attacks that bypass traditional signature- and policy-based security solutions.
Seasoned security professionals know that indiscriminate detection and prevention is not good enough; organizations need to be able to quickly detect, prevent, respond to and share information about attacks to prevent serious data loss.
Modern attackers evade defenses with many techniques, including encrypted communications – both custom and standard SSL-based. The core Multi-Vector Virtual Execution™ (MVX) technology uses multi-stage detection to identify custom-encrypted threats. And with the add-on Secure Sockets Layer (SSL) Intercept appliance, you can increase your visibility into SSL traffic to detect and block encrypted attacks.

FireEye Network Security delivers threat protection to any number of your office sites with a wide range of form factor, deployment and performance options to align with your IT needs. You can choose between integrated or distributed deployment models:
- Integrated Network Security – standalone, all-in-one hardware appliance that uses the MVX service to secure a single Internet access point
- Distributed Network Security – Network Smart Nodes and shared MVX service that extends protection across an entire organization
- Network Smart Node – physical or virtual appliances deployed at Internet access points to identify and protect against suspicious activity
- MVX Smart Grid or FireEye Cloud MVX – on-premise or cloud-based MVX service that conducts further analyses to detect advanced attacks and make security teams more efficient
Network Security Essentials
For small to midsize organizations
FireEye Network Security Essentials is a starter-package designed to provide protection against advanced, targeted and evasive attacks for organizations who want to cost-effectively manage the risk of a breach. It enables you to:
- Accurately detect and immediately stop attacks that evade other security devices including file-based sandboxes
- Understand the alert with reliable execution evidence
- Proactively defend against threats with tactical intelligence from FireEye or a third party using the Structured Threat Information eXpression (STIX) format
- Deploy Network Security with integrated all-in-one hardware appliances or with a scalable and flexible cloud-based distributed model
- Future-proof your investment with an extensible, modular architecture
- Provide your Microsoft Windows and Apple OS X users with the same level of threat protection
- Achieve quick protection with machine-, attacker- and victim-based intelligence applied as updates to your defenses every 60 minutes
- Shorten the solution payback period by eliminating the operational cost of triaging alerts manually
Network Security
For midsize to large organizations
FireEye Network Security is designed for high-performance, pervasive and consistent protection against threats across your organization with integrated security workflow and actionable contextual intelligence. It enables you to:
- Accurately detect and immediately stop attacks that evade other security devices, including file-based sandboxes
- Understand and prioritize critical alerts with reliable execution evidence and contextual insights
- Proactively defend and investigate threats with tactical intelligence from FireEye or a third party using the Structured Threat Information eXpression (STIX) format as well as contextual and strategic threat intelligence
- Deploy Network Security with integrated all-in-one hardware appliances or with a scalable and flexible on-premise or cloud-based distributed model
- Future-proof your investment with an extensible, modular architecture
- Provide your Microsoft Windows and Apple OS X users with the same level of threat protection
- Achieve quick protection with machine-, attacker- and victim-based intelligence applied as updates to your defenses every 60 minutes
- Shorten the solution payback period by eliminating the operational cost of triaging alerts manually
- Integrate and automate your security workflow to easily prioritize, investigate and respond to alerts across different threat vectors
| Product Feature | Benefit | FireEye Network Security Essentials | FireEye Network Security |
|---|---|---|---|
| Detect advanced, targeted and evasive threats traditional security solutions miss | |||
| Signature-less threat detection (MVX service) Signature-less threat detection (MVX service) | Detects multi-flow, multi-stage, zero-day, polymorphic, ransomware and other advanced attacks Detects multi-flow, multi-stage, zero-day, polymorphic, ransomware and other advanced attacks |
|
|
| Real-time and retroactive detection Real-time and retroactive detection | Detects known and unknown threats in real time while also enabling back-in-time detection of threats Detects known and unknown threats in real time while also enabling back-in-time detection of threats |
|
|
| Multi-vector correlation Multi-vector correlation | Automates validation and blocking of attacks across multiple vectors Automates validation and blocking of attacks across multiple vectors | Cloud email and endpoint Cloud email and endpoint | Email (on-premise or cloud), file and endpoint Email (on-premise or cloud), file and endpoint |
| Multi-OS, multi-file and multi-application Support Multi-OS, multi-file and multi-application Support | Supports heterogeneous endpoint environments for a wide range of applications Supports heterogeneous endpoint environments for a wide range of applications |
|
|
| Hardened hypervisor Hardened hypervisor | Provides evasion proofing Provides evasion proofing |
|
|
| Rapidly respond and contain the impact of intrusions | |||
| Real-time inline blocking Real-time inline blocking | Immediately stops attacks Immediately stops attacks |
|
|
| Signature-based IPS Detection Signature-based IPS Detection | Automates and accelerates triaging of traditionally noisy alerts to eliminate overhead Automates and accelerates triaging of traditionally noisy alerts to eliminate overhead |
|
|
| Riskware Detection Riskware Detection | Categorizes critical and non-critical malware to prioritize response resources Categorizes critical and non-critical malware to prioritize response resources |
|
|
| Integrated security workflows Integrated security workflows | Pivots from detection to investigation and response Pivots from detection to investigation and response | Endpoint Forensics Endpoint Forensics |
Endpoint Forensics Enterprise Forensics Endpoint Forensics Enterprise Forensics |
| Actionable contextual intelligence Actionable contextual intelligence | Accelerates containment of advanced threat with in-depth information about the attack and attacker Accelerates containment of advanced threat with in-depth information about the attack and attacker |
|
|
| High availability (HA) High availability (HA) | Provides resilient defense Provides resilient defense |
|
|
| Continually adapt to the evolving threat landscape | |||
| Real-time threat intelligence sharing Real-time threat intelligence sharing | Globally-shares real evidence to immediately block previously unknown attacks and accelerate response Globally-shares real evidence to immediately block previously unknown attacks and accelerate response |
|
|
| Custom and third-party threat intelligence (STIX)* Custom and third-party threat intelligence (STIX)* | Allows ingestion of non-FireEye indicators into the intelligence-driven analytics engines Allows ingestion of non-FireEye indicators into the intelligence-driven analytics engines |
|
|
| Strategic threat intelligence Strategic threat intelligence | Enables a proactive assessment of threat landscape changes and empowers a lean-forward security posture Enables a proactive assessment of threat landscape changes and empowers a lean-forward security posture |
|
|
| Scale and remain flexible as the organization grows or the delivery mode of IT services changes | |||
| Supported bandwidths Supported bandwidths | 10 Mbps – 2 Gbps 10 Mbps – 2 Gbps | 10 Mbps – 8 Gbps 10 Mbps – 8 Gbps | |
| Supported users Supported users | 50 – 20,000 50 – 20,000 | 50 – 80,000 50 – 80,000 | |
| Supported NX Series Supported NX Series |
Integrated or Network Smart Node (cloud-only) Physical: NX 900 – NX 4420, NX 7500 Virtual: NX 1500V – NX 6500V Distributed mode: FireEye Cloud MVX only Integrated or Network Smart Node (cloud-only) Physical: NX 900 – NX 4420, NX 7500 Virtual: NX 1500V – NX 6500V Distributed mode: FireEye Cloud MVX only |
Integrated appliance or Network Smart Node Physical: NX 900 – NX 10550** Virtual: NX 1500V – NX 6500V Distributed mode: FireEye Cloud MVX or MVX Smart Grid MVX Smart Grid Physical: VX 5500, VX 12500 Integrated appliance or Network Smart Node Physical: NX 900 – NX 10550** Virtual: NX 1500V – NX 6500V Distributed mode: FireEye Cloud MVX or MVX Smart Grid MVX Smart Grid Physical: VX 5500, VX 12500 |
|
| MVX capabilities MVX capabilities |
|
|
|
| Supported form factors Supported form factors | Physical, virtual, cloud Physical, virtual, cloud | Physical, virtual, cloud Physical, virtual, cloud | |
| Deployment models Deployment models | Integrated and cloud-based distributed Integrated and cloud-based distributed | Integrated, on-premise and cloud-based distributed Integrated, on-premise and cloud-based distributed | |
| Cost-free integrated / distributed migration Cost-free integrated / distributed migration |
|
|
|
* Only supported on fourth-generation (NX x4xx) and newer appliances
configured in the integrated mode.
** All third-generation (NX
x3xx) and newer devices can be converted to Network Smart Nodes as
part of a distributed deployment.
"When it comes to detecting and preventing advanced attacks, the power of FireEye MVX technology has no competition."
- Wahid Hammami, Chief Information Officer
SSL Intercept
Protect against encrypted attacks by giving FireEye NX Series visibility into selected SSL traffic to detect and block exploits, malware, and callbacks hiding inside.
Forrester: The Total Economic Impact of FireEye Network Security
Learn how FireEye Network Security customers can expect a 152% ROI and payback on their initial investment in just 9.7 months.
Better Detection. Smarter Alerts. Faster Response.
An overview of how the FireEye Network and Email security products work better together, including a customer example.
Frost & Sullivan Network Security Sandbox Market Analysis
Research firm Frost & Sullivan recognizes FireEye as the market leader when it comes to "must have" network security.
Frost & Sullivan Advanced Malware Sandbox Market Analysis
Advanced malware uses evasion techniques to bypass traditional security methods. See how FireEye is the market leader in advanced malware sandbox detection technology.







