Skip to content
TRILOGY

Make every network boundary deliberate.

Build firewall and segmentation policies around the traffic your business needs. TRILOGY helps scope the architecture, review rules, implement agreed changes and test the allowed and blocked paths.

When this solution is relevant

  • Firewall refresh

    Size the replacement against inspected traffic and required security services.

  • Branch and data-center boundaries

    Separate zones while preserving documented application dependencies.

  • Encrypted traffic inspection

    Evaluate visibility, privacy and application compatibility before deployment.

  • Policy cleanup

    Review stale, broad or duplicate rules against ownership and actual use.

Technology options

Technology options to evaluate against your requirement. Product capabilities, editions and integrations are confirmed in the agreed configuration.

  • Check Point

    Check Point — Check Point Force — formerly Quantum Force

    • Next-generation firewall enforcement across supported deployment models
    • Cloud-delivered threat prevention through selected subscriptions
    • Central policy management and gateway sizing are defined for the environment
    Official product reference
  • Fortinet

    Fortinet — FortiGate + FortiManager

    • FortiGate combines firewall enforcement and network functions
    • Security processors support appliance-specific traffic processing
    • FortiManager centralizes policy across supported Fortinet deployments
    Official product reference
  • Palo Alto Networks

    Palo Alto Networks — Strata NGFW / Strata Cloud Manager

    • Application-aware firewall policy across supported environments
    • Hardware, virtual and cloud deployment options
    • Strata Cloud Manager or Panorama selected for the management model
    Official product reference
  • Cisco

    Cisco — Secure Firewall / Security Cloud Control

    • Firewall policy and threat defense for supported Cisco platforms
    • Cloud-delivered management through Security Cloud Control
    • Design distinguishes central management from traffic enforcement
  • HPE Juniper Networking

    HPE Juniper Networking — SRX / vSRX + Security Director

    • SRX combines network routing and firewall security
    • Physical and virtual firewall deployment options
    • Security Director management selected for cloud or on-premises requirements
  • Sophos

    Sophos — Sophos Firewall / XGS

    • XGS appliances use the Xstream architecture for firewall processing
    • Integrated networking and threat-prevention features
    • Management and related Sophos integrations are scoped by subscription

Names and trademarks belong to their owners.

What we verify

  • Policy validation

    Results for agreed permitted and denied application paths.

  • Capacity under inspection

    Observed throughput and resource use with the selected services enabled.

  • Failover behavior

    Interruption and session behavior observed during approved tests.

  • Rule accountability

    Rules with documented purpose, owner and review date.

How the technical work is scoped

01

Scope and architecture

Define the assets, integrations, ownership and acceptance criteria before selecting the configuration.

02

Implementation and change

Configure the agreed controls through an approved change plan, with rollback steps and assigned responsibilities.

03

Verification and handover

Test agreed scenarios, record exceptions and hand over the configuration, operating procedures and test evidence.

A pair of network appliances with patch cables in a rack

Technical scope in detail

Sizing beyond the headline

Datasheet firewall throughput is not a substitute for sizing with inspection enabled. Traffic mix, concurrent sessions and security subscriptions are included in the design. Acceptance tests use the agreed configuration.

Application-aware policy

Rules identify source, destination, application and business ownership where the platform supports them. Exceptions have a defined purpose. Tests verify essential application flows before obsolete rules are removed.

TLS inspection

Inspection scope accounts for certificates, privacy, exempt traffic and incompatible applications. A controlled pilot checks user and service impact. The handover identifies what remains encrypted and uninspected.

High availability

The design defines failure modes, connectivity and state synchronization. Approved tests observe failover and recovery behavior. Availability targets belong to the agreed architecture and service terms, not to an unsupported percentage on the webpage.

Logging and operations

Log sources, retention and integration are scoped with the monitoring owner. Test events confirm forwarding and useful context. Policy backups and change records form part of handover.

Licensing and sizing

Size the appliance or virtual instance with the intended inspection services enabled. Include security subscriptions, management, log storage, support and the required high-availability topology in the configuration.

What to share with us

Current topology and rules; traffic measurements; applications; subscriptions; availability requirements.

What you receive

  • Agreed scope and architecture

  • Selected configuration and integration record

  • Approved change and rollback plan

  • Test record and documented exceptions

  • Operating procedures and technical handover

Frequently asked questions

Is the fastest datasheet model the right choice?

Sizing depends on the required inspection services, session profile, traffic and growth assumptions.

Will segmentation block business applications?

Dependencies are mapped and tested before enforcement. The change plan defines exceptions and rollback.

Are all security services included?

No. Threat prevention, support, management and other subscriptions are reviewed in the bill of materials.

Discuss the requirement

Tell us what you need to protect, change or recover. We will use the details to define the next technical discussion.

Prefer to talk? Call +966591909277

We use the information you provide to respond to your request. Read our privacy notice for details.