Network SecurityNX Series

Effective protection of network infrastructure, data and users against cyber breaches for organizations of all sizes

Cyber security is one of your top priorities. Your business operations depend on it. Your high-value assets warrant it. Your highly-regulated industry demands it.

Today’s cyber criminals are more sophisticated than ever. Your next-generation firewalls, antivirus (AV) software and Intrusion Prevention System (IPS) cannot detect today’s advanced, targeted and evasive threats. And they produce an unmanageable volume of alerts that leaves your security teams overwhelmed and your organization vulnerable.

You need a network security solution that:

  • Detects and stops threats traditional security products miss
  • Rapidly responds and contains the impact of incidents
  • Continually adapts to the evolving threat landscape
  • Scales and remains flexible as your organization grows or the delivery mode of IT services changes

Forrester Study: The Value of FireEye Network Security

Forrester utilized their TEI framework to identify the benefits, costs, flexibility and risks associated with an investment in FireEye Network Security (NX Series) products for a composite organization.

Download Now

Live Webinar: Why Today’s Changing Threat Landscape Requires Agile Security

November 9, 2016, 8:00 am PST
Presented by: Rob Westervelt, IDC, Research Manager, Security Products and Rajiv Raghunarayan, FireEye, Sr. Director, Product Marketing

Register Now

FireEye Network Security is an effective cyber-defense solution designed to help organizations of all sizes minimize the risk of costly breaches by accurately detecting and immediately stopping advanced and evasive attacks hiding in Internet traffic. It enables the resolution of security alerts in minutes with concrete evidence, actionable intelligence and response workflow integrations. With FireEye Network Security, organizations are effectively protected against attacks that bypass traditional signature- and policy-based security solutions.

Seasoned security professionals know that indiscriminate detection and prevention is not good enough; organizations need to be able to quickly detect, prevent, respond to and share information about attacks to prevent serious data loss.

Modern attackers evade defenses with many techniques, including encrypted communications – both custom and standard SSL-based. The core Multi-Vector Virtual Execution™ (MVX) technology uses multi-stage detection to identify custom-encrypted threats. And with the add-on Secure Sockets Layer (SSL) Intercept appliance, you can increase your visibility into SSL traffic to detect and block encrypted attacks.

nx-on-prem-distributed-architecture

FireEye Network Security delivers threat protection to any number of your office sites with a wide range of form factor, deployment and performance options to align with your IT needs. You can choose between integrated or distributed deployment models:

  • Integrated Network Security – standalone, all-in-one hardware appliance that uses the MVX service to secure a single Internet access point
  • Distributed Network Security – Network Smart Nodes and shared MVX service that extends protection across an entire organization
  • Network Smart Node – physical or virtual appliances deployed at Internet access points to identify and protect against suspicious activity
  • MVX Smart Grid or FireEye Cloud MVX – on-premise or cloud-based MVX service that conducts further analyses to detect advanced attacks and make security teams more efficient

Network Security Essentials

For small to midsize organizations

FireEye Network Security Essentials is a starter-package designed to provide protection against advanced, targeted and evasive attacks for organizations who want to cost-effectively manage the risk of a breach. It enables you to:

  • Accurately detect and immediately stop attacks that evade other security devices including file-based sandboxes
  • Understand the alert with reliable execution evidence
  • Proactively defend against threats with tactical intelligence from FireEye or a third party using the Structured Threat Information eXpression (STIX) format
  • Deploy Network Security with integrated all-in-one hardware appliances or with a scalable and flexible cloud-based distributed model
  • Future-proof your investment with an extensible, modular architecture
  • Provide your Microsoft Windows and Apple OS X users with the same level of threat protection
  • Achieve quick protection with machine-, attacker- and victim-based intelligence applied as updates to your defenses every 60 minutes
  • Shorten the solution payback period by eliminating the operational cost of triaging alerts manually

Network Security

For midsize to large organizations

FireEye Network Security is designed for high-performance, pervasive and consistent protection against threats across your organization with integrated security workflow and actionable contextual intelligence. It enables you to: 

  • Accurately detect and immediately stop attacks that evade other security devices, including file-based sandboxes
  • Understand and prioritize critical alerts with reliable execution evidence and contextual insights
  • Proactively defend and investigate threats with tactical intelligence from FireEye or a third party using the Structured Threat Information eXpression (STIX) format as well as contextual and strategic threat intelligence
  • Deploy Network Security with integrated all-in-one hardware appliances or with a scalable and flexible on-premise or cloud-based distributed model
  • Future-proof your investment with an extensible, modular architecture
  • Provide your Microsoft Windows and Apple OS X users with the same level of threat protection
  • Achieve quick protection with machine-, attacker- and victim-based intelligence applied as updates to your defenses every 60 minutes
  • Shorten the solution payback period by eliminating the operational cost of triaging alerts manually
  • Integrate and automate your security workflow to easily prioritize, investigate and respond to alerts across different threat vectors
Product Feature Benefit FireEye Network Security Essentials FireEye Network Security
Detect advanced, targeted and evasive threats traditional security solutions miss
Signature-less threat detection (MVX service) Signature-less threat detection (MVX service) Detects multi-flow, multi-stage, zero-day, polymorphic, ransomware and other advanced attacks Detects multi-flow, multi-stage, zero-day, polymorphic, ransomware and other advanced attacks
Real-time and retroactive detection Real-time and retroactive detection Detects known and unknown threats in real time while also enabling back-in-time detection of threats Detects known and unknown threats in real time while also enabling back-in-time detection of threats
Multi-vector correlation Multi-vector correlation Automates validation and blocking of attacks across multiple vectors Automates validation and blocking of attacks across multiple vectors Cloud email and endpoint Cloud email and endpoint Email (on-premise or cloud), file and endpoint Email (on-premise or cloud), file and endpoint
Multi-OS, multi-file and multi-application Support Multi-OS, multi-file and multi-application Support Supports heterogeneous endpoint environments for a wide range of applications Supports heterogeneous endpoint environments for a wide range of applications
Hardened hypervisor Hardened hypervisor Provides evasion proofing Provides evasion proofing
Rapidly respond and contain the impact of intrusions
Real-time inline blocking Real-time inline blocking Immediately stops attacks Immediately stops attacks
Signature-based IPS Detection Signature-based IPS Detection Automates and accelerates triaging of traditionally noisy alerts to eliminate overhead Automates and accelerates triaging of traditionally noisy alerts to eliminate overhead
Riskware Detection Riskware Detection Categorizes critical and non-critical malware to prioritize response resources Categorizes critical and non-critical malware to prioritize response resources
Integrated security workflows Integrated security workflows Pivots from detection to investigation and response Pivots from detection to investigation and response Endpoint Forensics Endpoint Forensics Endpoint Forensics
Enterprise Forensics
Endpoint Forensics
Enterprise Forensics
Actionable contextual intelligence Actionable contextual intelligence Accelerates containment of advanced threat with in-depth information about the attack and attacker Accelerates containment of advanced threat with in-depth information about the attack and attacker
High availability (HA) High availability (HA) Provides resilient defense Provides resilient defense
Continually adapt to the evolving threat landscape
Real-time threat intelligence sharing Real-time threat intelligence sharing Globally-shares real evidence to immediately block previously unknown attacks and accelerate response Globally-shares real evidence to immediately block previously unknown attacks and accelerate response
Custom and third-party threat intelligence (STIX)* Custom and third-party threat intelligence (STIX)* Allows ingestion of non-FireEye indicators into the intelligence-driven analytics engines Allows ingestion of non-FireEye indicators into the intelligence-driven analytics engines
Strategic threat intelligence Strategic threat intelligence Enables a proactive assessment of threat landscape changes and empowers a lean-forward security posture Enables a proactive assessment of threat landscape changes and empowers a lean-forward security posture
Scale and remain flexible as the organization grows or the delivery mode of IT services changes
Supported bandwidths Supported bandwidths 10 Mbps – 2 Gbps 10 Mbps – 2 Gbps 10 Mbps – 8 Gbps 10 Mbps – 8 Gbps
Supported users Supported users 50 – 20,000 50 – 20,000 50 – 80,000 50 – 80,000
Supported NX Series Supported NX Series Integrated or Network Smart Node (cloud-only)

Physical: NX 900 – NX 4420, NX 7500

Virtual: NX 1500V – NX 6500V

Distributed mode: FireEye Cloud MVX only
Integrated or Network Smart Node (cloud-only)

Physical: NX 900 – NX 4420, NX 7500

Virtual: NX 1500V – NX 6500V

Distributed mode: FireEye Cloud MVX only
Integrated appliance or Network Smart Node

Physical: NX 900 – NX 10550**

Virtual: NX 1500V – NX 6500V

Distributed mode: FireEye Cloud MVX or MVX Smart Grid

MVX Smart Grid
Physical: VX 5500, VX 12500
Integrated appliance or Network Smart Node

Physical: NX 900 – NX 10550**

Virtual: NX 1500V – NX 6500V

Distributed mode: FireEye Cloud MVX or MVX Smart Grid

MVX Smart Grid
Physical: VX 5500, VX 12500
MVX capabilities MVX capabilities
  • Integrated appliances
  • FireEye Cloud MVX
  • Integrated appliances
  • FireEye Cloud MVX
  • Integrated appliances
  • MVX Smart Grid
  • FireEye Cloud MVX
  • Integrated appliances
  • MVX Smart Grid
  • FireEye Cloud MVX
  • Supported form factors Supported form factors Physical, virtual, cloud Physical, virtual, cloud Physical, virtual, cloud Physical, virtual, cloud
    Deployment models Deployment models Integrated and cloud-based distributed Integrated and cloud-based distributed Integrated, on-premise and cloud-based distributed Integrated, on-premise and cloud-based distributed
    Cost-free integrated / distributed migration Cost-free integrated / distributed migration

    * Only supported on fourth-generation (NX x4xx) and newer appliances configured in the integrated mode.
    ** All third-generation (NX x3xx) and newer devices can be converted to Network Smart Nodes as part of a distributed deployment.

    "When it comes to detecting and preventing advanced attacks, the power of FireEye MVX technology has no competition."

    - Wahid Hammami, Chief Information Officer

    SSL Intercept

    Protect against encrypted attacks by giving FireEye NX Series visibility into selected SSL traffic to detect and block exploits, malware, and callbacks hiding inside.

    Learn More

    Forrester: The Total Economic Impact of FireEye Network Security

    Learn how FireEye Network Security customers can expect a 152% ROI and payback on their initial investment in just 9.7 months.

    Read the Study 

    Better Detection. Smarter Alerts. Faster Response.

    An overview of how the FireEye Network and Email security products work better together, including a customer example.

    Download Overview 

    Frost & Sullivan Network Security Sandbox Market Analysis

    Research firm Frost & Sullivan recognizes FireEye as the market leader when it comes to "must have" network security.

    Read the Excerpt 

    Frost & Sullivan Advanced Malware Sandbox Market Analysis

    Advanced malware uses evasion techniques to bypass traditional security methods. See how FireEye is the market leader in advanced malware sandbox detection technology.

    Read the excerpt