Firewall ACT
Entry-point perimeter in a compact appliance running hardened Linux/BSD, built for networks of up to 50 hosts.
Service overview
Firewall ACT is ACT Tecnologia's entry-point perimeter solution, built on a hardened Linux/BSD operating system in a compact, silent appliance. It delivers stateful firewalling, advanced routing, VPN, and network segmentation at a reduced cost and power draw, suited for branches, offices, and network points that need secure connectivity without the complexity of an enterprise appliance. All configuration, monitoring, and response is handled by ACT's NOC.
Secure perimeter
Stateful firewall with zone-based policies, NAT, controlled port forwarding, and blocking by source, destination, and service.
Advanced routing
Static and dynamic routing (BGP, OSPF), 802.1Q VLANs, multiple WAN links, and load balancing.
VPN connectivity
Site-to-site tunnels and remote access via IPsec, OpenVPN, and WireGuard, with hub-and-spoke topology for access to networks behind CGNAT, provided the hub has a fixed IP.
Network and routing features
Layer 3 / Layer 4: routing and segmentation foundation to connect branches, isolate environments, and prioritize critical traffic. All features below are configured and versioned by ACT.
| Feature | Status | Description |
|---|---|---|
| Stateful firewall | Included | Session control by zone, source, destination, port, and protocol |
| NAT / Port forwarding | Included | SNAT, DNAT, and port mapping with audited rules |
| 802.1Q VLANs | Included | Network segmentation by department, environment, or trust level |
| Dynamic routing | Included | BGP and OSPF for multi-site topologies |
| Multiple WAN links | Included | Failover and load balancing across carriers, with configurable weights |
| QoS / Traffic shaping | Included | Policy-based VoIP and critical traffic prioritization |
| DHCP and DNS forwarding | Included | Address distribution and resolution with local cache |
Available features depend on appliance sizing and traffic profile.
Scope of coverage (layer 3/4)
Firewall ACT is a stateful network firewall (layers 3 and 4). Deep application inspection (layer 7) is covered by the FortiGate line. The table below makes the scope explicit.
| Capability | Layer | Firewall ACT |
|---|---|---|
| Stateful firewall (by port/protocol) | L3 / L4 | ✓ Covered |
| NAT, port forwarding, and routing | L3 / L4 | ✓ Covered |
| VLAN, VPN, QoS, and multi-WAN | L3 / L4 | ✓ Covered |
| IPS (intrusion prevention) | L7 | ✗ Not covered |
| Application control (App Control) | L7 | ✗ Not covered |
| Web filtering / content filtering by category | L7 | ✗ Not covered |
| Web proxy with caching | L7 | ✗ Not covered |
| Antivirus / anti-malware at the edge | L7 | ✗ Not covered |
| SSL/TLS inspection | L7 | ✗ Not covered |
| Anti-bot / C&C detection | L7 | ✗ Not covered |
| High availability in a redundant pair | N/A | ✗ Not covered |
For application inspection (layer 7) and high availability, FortiGate is the recommended solution. ACT sizes the right tier for each operation's needs.
VPN and remote access
Encrypted connectivity between sites and for remote users, supporting the three main tunnel technologies. ACT operates a hub-and-spoke topology to reach equipment behind CGNAT, which requires a fixed IP at the hub.
| Technology | Typical use | Characteristic |
|---|---|---|
| IPsec | Site-to-site | Tunnels interoperable with other vendors, market standard |
| OpenVPN | Remote access | Flexible, over TLS, traverses NAT and restrictive environments |
| WireGuard | High performance | Modern tunnel, low latency, and lower CPU overhead |
Technology choice depends on the client scenario and required interoperability. Tunnels provisioned and monitored by ACT.
Security and access control
Perimeter defense: Firewall ACT's protection combines edge traffic control, OS hardening, and administrative access governance, with logging and evidence for every change.
Traffic control
- Firewall policies by zone and interface
- Geo-blocking and IP reputation list blocking
- Egress filtering to contain unauthorized traffic
- Protection against scanning and flooding at the edge
- Versioned rules with change history
Administrative access
- Hardened operating system, reduced attack surface
- Management access restricted to ACT's VPN
- Key-based and individual credential authentication
- Logging of administrative sessions
- Security updates tracked by ACT
Management, monitoring, and automation
Centralized administration by ACT's NOC, with continuous Zabbix-based monitoring, proactive alerts, and versioned configuration; the client sees the health of the perimeter without operating the equipment.
Continuous monitoring
- Metric collection via Zabbix (CPU, memory, links, tunnels)
- Proactive alerts for link down and VPN failure
- Availability and bandwidth usage dashboards
- History for capacity and trend analysis
Managed operation
- Configuration as code, versioned and auditable
- Configuration backup before every change
- Fast restore in case of hardware failure
- Changes made in an agreed maintenance window
Specifications
| Form factor | Compact, fanless appliance for desktop or shallow rack |
| Power consumption | Typically low power draw (reference below 15 W) |
| Interfaces | Multiple Gigabit Ethernet ports for WAN, LAN, and DMZ |
| Operating system | Hardened Linux/BSD system, maintained and updated by ACT |
| Monitoring | Native Zabbix integration, 24x7 alerts |
| ACT support | Support via ACT's central desk, with SLA per contract (managed models) |
The perimeter ACT watches for you.
In managed models, ACT takes on end-to-end operation of Firewall ACT: configuration, VPN, monitoring, and response. Perimeter health stays visible to decision-makers, and changes only happen with evidence and backup.
Recommended use cases
Branches and offices
- Low-cost perimeter per site
- Site-to-site VPN with headquarters
- Segmentation by VLAN
Multi-site connectivity
- Dynamic routing between sites
- Failover between carriers
- Access to networks behind CGNAT (fixed IP at the hub)
Managed edge
- Replacement for carrier router
- Traffic control and visibility
- 24x7 monitoring by ACT
Want to know if Firewall ACT solves what your operation needs?
Talk to ACT and understand, with clarity, how this solution fits your environment.
Talk to ACT