01 · IDENTITY
The rule knows who is asking.
Firewall decisions use the same user and group as access policy. An IP allowlist without an identity is the old model.
- SSO / SCIM identity on the flow
- Group-aware exceptions
Firewall
One rule set across every site and cloud. IP lists, a simulator, and the same identity that already gates your apps. Enforced at your gateways.
How a rule decides
01 · IDENTITY
Firewall decisions use the same user and group as access policy. An IP allowlist without an identity is the old model.
02 · DESTINATION
L3/L4 rules cover CIDR, host and port. Use them for the paths that are not an application name yet.
03 · LISTS
Threat and allow lists attach to rules instead of being pasted into every site. Update a list once; every gateway sees it.
04 · SIMULATE
The rule simulator walks the same stages the gateway will: identity, destination, list, verdict. No guessing in production.
One rule set · every gateway
Firewall rules live on the same policy plane as web filtering and access. Identity, IP lists and a simulator travel with the rule, so a new gateway does not get a new spreadsheet.
Test before you trust
Pick a user, a device and a service, and watch the decision resolve stage by stage, from posture and device to access and egress, with the exact policy that matched. No guessing in production.
# simulate · who can reach what, and why user dana@acme.com device macbook-dana · managed service payments-api → posture ✓ pass # disk encryption · screen lock → device ✓ pass # managed · agent up to date → access ✓ allow # matched policy: eng-payments → egress orbit · eu-central # region pinned decision ALLOW
Plans
Security includes the identity-aware firewall from Business and above. Core keeps the network. No extra appliance to stand up.
For small teams getting started with zero trust access.
For growing teams who need more control and visibility.
For organizations with advanced security and compliance needs.
Full feature breakdown on the pricing page →
Better together
Security runs on the Pulse Network, and Network is included in every tier, including yours. The policy plane that enforces your traffic also routes it, with managed gateways, egress and DNS built in.