Architecture review
SI mapping, insertion points, dependencies on existing EDR / SIEM / IAM.
10 Gbps · firewall + DPI + IDS / NIDS + IPS + Proxy · 10,000 IPs
High-performance all-in-one appliance for large organizations: NGFW firewall, DPI probe, IDS / NIDS, IPS and TLS decryption proxy combined into a single 1U unit. 10 Gbps SFP+ or RJ45, up to 10,000 IPs, native multi-VLAN, air-gap mode for sensitive zones. Deployable in series, active/passive cluster, or active/active.
High-performance all-in-one appliance for large organizations: NGFW firewall, DPI probe, IDS / NIDS, IPS and TLS decryption proxy combined into a single 1U unit. 10 Gbps SFP+ or RJ45, up to 10,000 IPs, native multi-VLAN, air-gap mode for sensitive zones. Deployable in series, active/passive cluster, or active/active.
SYLink Pro — 10 Gbps · firewall + DPI + IDS / NIDS + IPS + Proxy · 10,000 IPs.
SYLink Pro repose sur un OS dédié SYLinkOS (durci, lecture seule, secure boot), un pipeline de filtrage en C/Rust, et une accélération matérielle des fonctions cryptographiques (AES-NI, QAT). Le moteur de corrélation IA SYLink AI peut être hébergé en local pour qualifier les alertes sans latence.
L'architecture est modulaire : vous activez ou désactivez les modules (proxy TLS, IPS, threat intel, EDR sondes) selon votre politique. Chaque module est isolé en sandbox, ce qui permet une mise à jour différenciée sans toucher au cœur du firewall.
Le SYLink Pro est positionné en cœur de SI 10 G — il combine pare-feu, NDR et sonde DPI inline. Multi-VLAN, il filtre et inspecte simultanément le trafic Internet, OT et inter-sites.
Rollout led with your CISO and a SYLink architect. 30-day pilot PoC, then progressive cutover. MCO/MCS operated from France.
SI mapping, insertion points, dependencies on existing EDR / SIEM / IAM.
Deployed in monitor-only on a pilot perimeter, quality and coverage metrics.
Active/passive or active/active setup, failover testing.
Logs to SIEM, shared runbooks, escalation to UniSOC or your internal SOC.
Operational and security maintenance contract, recurring NATO / Armed Forces audits.
SI mapping, insertion points, dependencies on existing EDR / SIEM / IAM.
Deployed in monitor-only on a pilot perimeter, quality and coverage metrics.
Active/passive or active/active setup, failover testing.
Logs to SIEM, shared runbooks, escalation to UniSOC or your internal SOC.
Operational and security maintenance contract, recurring NATO / Armed Forces audits.
↓ Integration pipeline — step by step, from scoping to production ↓
Built for large perimeters (CAC40, government, critical operators): 10 Gbps SFP+ or RJ45, up to 10,000 supervised IPs.
No cloud callback required. Air-gap-zone compatible, classified environments (II 901, IGI 1300).
Active/passive or active/active with state sync. Transparent failover on hardware failure.
SIEM logs, runbooks, EDR-friendly. Connectors ready for Splunk, QRadar, Elastic, Sentinel and UniSOC.
| Débit en clair | 10 Gbps inspection complète (firewall + DPI + IDS/IPS + proxy) |
| Débit en SD-WAN chiffré | 5 Gbps en IPsec — l'overhead du chiffrement et de l'encapsulation IPsec consomme environ la moitié de la capacité brute du moteur |
| Capacity | Jusqu'à 10 000 IPs supervisées |
| Concurrent sessions | 1 M+ |
| VLANs | 4 094 max |
| Firewall | NGFW + application-aware + identity-based |
| IDS / IPS | Signatures + heuristique IA |
| Proxy TLS | Inclus, optionnel selon politique |
| SD-WAN client VPN | IPsec, WireGuard (site-à-site) |
| VPN télétravail | ⚠️ Utiliser SYLink VPN ou Protect |
| Ports | 8× SFP+ 10 G + 8× RJ45 10 G + 2× console + 2× management |
| Form factor | Rack 1U |
| Power | AC redondante hot-swap |
| Cooling | Ventilation contrôlée, mode silencieux |
| Targets | OTAN / Armées, II 901, IGI 1300, NIS2, LPM |
| PASSI | Format PASSI |
| Air-gap mode | Disponible |
| MCO / MCS | Inclus dans contrat régalien |
Replacing a foreign cyber layer on the critical perimeter, integrating with the existing SOC.
On-premise air-gap deployment, cleared MCO/MCS, II 901 / IGI 1300 compliance.
SI core, patient / medical IoT segmentation, real-time blocking, quarterly audit.
Hardened endpoints, EDR with no outbound telemetry, on-premise DPI for production.
30-minute guided demo, PoC on a pilot perimeter, support by our French teams based in Clermont-Ferrand, Marseille and Rennes.