CISO scoping
Perimeter, decryption exceptions, AD and SIEM integration.
2.5 Gbps · 2,500 IPs · TLS decryption proxy
Mid-range appliance for SMBs and mid-market companies: 2.5 Gbps throughput, up to 2,500 IPs, with IDS, IPS, NIDS, firewall and a certificate-based decryption proxy to inspect internal encrypted flows.
Mid-range appliance for SMBs and mid-market companies: 2.5 Gbps throughput, up to 2,500 IPs, with IDS, IPS, NIDS, firewall and a certificate-based decryption proxy to inspect internal encrypted flows.
SYLink Mini — 2.5 Gbps · 2,500 IPs · TLS decryption proxy.
SYLink Mini embarque un proxy TLS souverain capable de déchiffrer les flux HTTPS sortants et inter-applicatifs. La CA SYLink est poussée via GPO (Windows), MDM (macOS / mobile) ou Ansible (Linux). Le déchiffrement est sélectif : vous excluez les domaines bancaires, santé et personnels par classe de catégorie.
Le moteur IDS/IPS partage le pipeline avec le proxy, ce qui permet de détecter les charges malveillantes même cachées dans le trafic chiffré, sans repasser par un détour cloud. Tout reste dans la box : aucune copie de flux n'est exfiltrée.
Le SYLink Mini se positionne en cœur de SI ou en périmétrie sur les sites de taille intermédiaire (jusqu'à 2 500 IP). Inline avec votre WAN, il intègre NDR + sonde DPI dans un même appliance et publie ses logs vers votre SOC.
Guided rollout starting with CISO scoping, then install by your IT team or a SYLink partner. The critical step is rolling out the SYLink CA on endpoints — automated via GPO / MDM.
Perimeter, decryption exceptions, AD and SIEM integration.
Inserted as a gateway (between your router and the LAN) or as a transparent bridge.
Deploy the SYLink CA on endpoints via GPO / MDM / Ansible.
Activate IPS rules, exclude sensitive domains, monitor for 7 days.
Move from monitor-only to active blocking after calibration.
Perimeter, decryption exceptions, AD and SIEM integration.
Inserted as a gateway (between your router and the LAN) or as a transparent bridge.
Deploy the SYLink CA on endpoints via GPO / MDM / Ansible.
Activate IPS rules, exclude sensitive domains, monitor for 7 days.
Move from monitor-only to active blocking after calibration.
↓ Integration pipeline — step by step, from scoping to production ↓
Three times the SYLink Box capacity, sized for a multi-site SMB with internal servers.
Certificate-based decryption proxy (CA pushed to endpoints) — you see what travels in outbound HTTPS and between internal servers.
On-hardware configuration, no external cloud dependency for inline decisions.
Run several Minis from a single CISO console, with shared rules and centralized alerting.
| Throughput | 2,5 Gbps inspection complète |
| Capacity | Jusqu'à 2 500 IPs |
| Concurrent sessions | ~100 000 |
| Added latency | < 1 ms |
| Firewall | Stateful + application-aware |
| IDS / IPS / NIDS | Tous inclus, en série |
| Proxy déchiffrement | Par certificat (CA poussée via GPO / MDM) |
| Anti-malware | Sandbox cloud souveraine |
| Ports | 2× WAN 2.5G + 4× LAN 2.5G + 1× console |
| Form factor | Boîtier rack 1U (option desktop) |
| Power | AC 100-240 V, redondance optionnelle |
| SD-WAN client VPN | IPsec, WireGuard (site-à-site) |
| Topology | Mesh, hub-and-spoke, multi-hub |
| Débit VPN | Jusqu'à 1 Gbps chiffré |
| Remote-work usage | ⚠️ Utiliser SYLink VPN |
| Console | Portail SaaS ou on-premise |
| Directory | AD / LDAP / Entra ID |
| SIEM | Syslog, Splunk, QRadar, Elastic |
| API | REST + webhooks |
One Mini per site, central console, site-to-site VPN, OT/IT flow inspection.
Full visibility on outbound flows, court-admissible event logging.
Patient / medical IoT / staff segmentation, inspection of non-sensitive medical flows, HDS compliance.
Inspect outbound flows to detect exfiltration attempts, while leaving confidential client flows untouched (category exclusions).
30-minute guided demo, PoC on a pilot perimeter, support by our French teams based in Clermont-Ferrand, Marseille and Rennes.