New ยท Release 2026.04, Multi-tenant audit exports & SLA dashboards now live See changelog โ†’
Network security

Firewall visibility and rule management in one place

Bring multi-vendor firewall status, rules, and threat signals into the workspace with scheduled cache and log sync, so firewall state lives alongside the rest of IT operations.

Infronest security โ€” automatic blocking of malicious IPs with attack-type breakdown
Product proof

Already live in the product

Backed by app modules

Running in production today: multi-vendor firewall support with scheduled state and log sync.

Protected app route: /firewall
How it works

Built around real workflows

Highlights below describe capabilities already present in the protected app behind this page.

Multi-vendor firewall status
Rule and policy visibility
Threat and log signals
Scheduled cache and log sync
Workflow

What teams can do here

Step 1
Connect a firewall
Step 2
Review status and rules
Step 3
Track threat signals
Step 4
Keep logs in sync
How it works

How it works

01
Register a firewall
Add a firewall device โ€” Sophos, FortiGate or Palo Alto โ€” so its status and metadata live in the workspace alongside the rest of your IT operations.
02
Bring in logs and signals
Sophos connects over its API client; other vendors feed the platform over syslog, parsed into structured firewall logs, blocked-IP records, threat details and alerts.
03
Refresh on a schedule
A Celery task refreshes each firewall's cached view and aggregate stats on a short interval (about five minutes), so dashboards show recent state without polling the appliance on every page load.
04
Review rules and threats
See firewall rules and policies, blocked traffic, threat details and per-device stats in one place, and keep a whitelist of domains that should never be flagged.
Example

A worked example

Say a 300-user manufacturer runs a Sophos appliance at the head office and a FortiGate at the plant, and the two-person IT team is tired of checking two vendor consoles. The Sophos connects over its API; the FortiGate forwards syslog. Every five minutes or so the refresh task re-caches rules, blocked IPs and threat signals for both devices. When an intrusion alert fires at the plant, the on-duty engineer opens the threat detail in the same workspace where the servers and tickets already live, sees the source IP was blocked, and closes the loop without a second login.

In depth

Logs, rules and blocked traffic in one review surface

Once a firewall is feeding the platform, its raw output becomes structured records instead of console screens. Traffic events land as firewall logs with source, destination, protocol and the action the appliance took, so "what did the firewall actually do at 2am?" is a filterable query, not a scroll through a vendor UI. Rules and policies are listed with their status, giving reviewers a readable inventory of what the appliance currently enforces.

Blocked traffic gets its own treatment: each blocked IP is recorded with a threat level, so the block list reads as a ranked picture of what is probing your edge rather than an undifferentiated dump. Per-device statistics aggregate the volumes over time, which is what most audits and monthly reviews really need โ€” the shape of the traffic, not each individual packet.

Everything sits in the same workspace as server monitoring and network monitoring, which is the point: an engineer chasing an incident moves between the firewall view, the affected server and the open ticket without switching products.

In depth

Threats named by category, not just severity

Threat records carry a named category โ€” malware, ransomware, phishing, botnet, trojan, worm, spyware, adware, DDoS attack or brute force โ€” alongside a severity and a working status. That classification matters in practice: a brute-force burst against a VPN port and an adware callout from a user laptop are both "threats", but they demand different responses, and a category-labelled queue lets you route each to the right person immediately.

On top of the threat details, typed alerts (security threat, high bandwidth, DDoS, intrusion attempt, malware, policy violation) surface the conditions worth interrupting someone for. The whitelisted-domains list closes the loop on false positives: once a legitimate destination is whitelisted it stays out of future threat noise, so the queue tends to get quieter and more trustworthy as the deployment matures.

Each threat also carries a working status โ€” active, mitigated, resolved or false positive โ€” so triage has somewhere to land instead of an undated list. Combined with per-severity filtering, a small team can honestly say which of last month's threats were acted on, which were dismissed as false positives, and which are still open.

In depth

Getting data in: API for Sophos, syslog for everyone else

Sophos appliances connect through a direct API client, which pulls state without any change to your logging pipeline. FortiGate, Palo Alto and other appliances integrate the way network gear always has โ€” you point their syslog output at the platform's ingestion endpoint, and the parser turns those messages into the same structured logs, blocked-IP records and threat details the Sophos path produces. The setup effort is one forwarding rule on the appliance.

A scheduled task then refreshes each firewall's cached view and aggregate statistics on roughly a five-minute cycle. The cache is a deliberate design choice: dashboards load instantly and repeated page views never hammer the appliance's management plane, while the data stays recent enough for operational review. This is a monitoring layer by design โ€” the appliance remains the enforcement point, and nothing here pushes rule changes to it.

Each registered device also carries its own operational record: vendor type, connection protocol, an online/offline status and a monitoring state. For a team running several appliances across sites, that turns "is the branch firewall even reporting?" into a glance at the device list โ€” a silent appliance stands out as offline instead of being noticed only when its logs are missed during an investigation.

FAQ

Frequently asked questions

Which firewall vendors are supported?
The device model covers Sophos, Fortinet/FortiGate and Palo Alto Networks. Sophos has a direct API client; other vendors are ingested through syslog, which needs the syslog forwarding set up on the appliance.
Does this replace my firewall or push new rules to it?
No. It is a visibility and monitoring layer. It brings status, rules, blocked traffic and threat signals into the workspace for review โ€” the appliance remains your enforcement point.
How fresh is the firewall data?
A background task refreshes each firewall's cached data and aggregate statistics on a short cycle โ€” roughly every five minutes โ€” and log syncs run on their own schedule, so the dashboard reflects recent rather than stale state.
What do I need to configure to get logs in?
For non-API vendors you point the firewall's syslog output at the platform's syslog endpoint following the setup guide; the parser turns those messages into firewall logs, blocked IPs and threats.
Can I stop legitimate destinations being flagged?
Yes. A whitelisted-domains list lets you mark domains that should never be treated as threats, so known-good traffic stays out of the alert noise.
What kinds of alerts does the module raise?
Alerts are typed as security threat, high bandwidth, DDoS attack, intrusion attempt, malware detected or policy violation, each with a severity โ€” so you can triage by what the alert actually is rather than reading every message.
Can I monitor more than one firewall in the same workspace?
Yes. Each appliance is registered as its own device with its own status and per-device statistics, so a head office Sophos and a branch FortiGate sit side by side in one tenant view.

See also: Network monitoring ยท Network telemetry hub ยท Blog: Network monitoring tools ยท Blog: Network vulnerability assessment ยท Security & VAPT

Related

Explore connected offerings

One workspace for every firewall you run

Sophos over API, FortiGate and Palo Alto over syslog โ€” rules, blocked IPs, categorised threats and typed alerts refreshed on a five-minute cycle, next to the servers and tickets they affect.