Ubiquiti News
Ubiquiti has taken the wraps off the Enterprise Firewall Core, a rack-mount security appliance that scales the Neoverse N2 architecture behind the Dream Machine Beast up into genuine enterprise territory. The Enterprise Firewall Core sits above everything else in the company’s gateway and console range, aimed at organisations running thousands of clients across multiple sites.
The headline is 24 Neoverse N2 cores, paired with throughput figures for threat detection, SSL inspection and IPsec that Ubiquiti says hold up under real security workloads rather than in a bare routing test.
As with the rest of the security stack, Ubiquiti is positioning this as licence-free: no per-seat or per-feature subscription for the firewall and threat protection capabilities themselves.
Ubiquiti’s stated capacity ceilings put this well outside prosumer or single-site SMB use. The platform is specified for up to 22,000 active devices and 10 million concurrent sessions, with the compute headroom to run advanced security services at the same time rather than trading one off against the other.
Threat detection runs against tens of thousands of signatures, with real-time intelligence updates supplied by Proofpoint under the Cybersecure Enterprise banner. Encrypted traffic is handled by full SSL inspection, which is the part that usually collapses performance on lesser hardware.
| Metric | Figure |
|---|---|
| Threat detection throughput | Up to 79 Gbps |
| Full SSL inspection throughput | Up to 61 Gbps |
| Aggregate IPsec throughput | Up to 38 Gbps |
| Concurrent IPsec/WireGuard tunnels | More than 5,000 |
| Active devices | Up to 22,000 |
| Concurrent sessions | Up to 10 million |
| CPU | 24 Neoverse N2 cores |
The tunnel and IPsec numbers point clearly at the intended role: hub for a large SD-WAN topology, terminating branch and remote-user connections back to a core site. Ubiquiti calls out support for more than 5,000 concurrent IPsec or WireGuard tunnels.
On the resiliency side, high availability is handled through VRRP-enabled Shadow Mode, with Multi-Chassis Link Aggregation at the core and switch stacking extending redundancy out to the edge. The hardware itself is specified with:
Multi-Chassis Link Aggregation and stacking only pay off if the rest of the fabric supports them, so this is a release that assumes a reasonably modern set of switches underneath it.
Management is centralised in Site Manager, which brings SD-WAN orchestration and policy enforcement for every location into one console. The more interesting part is identity integration: Entra, Google Workspace and LDAP can feed user identity into policy, so rules follow the person rather than the subnet they happen to land on.
For multi-site operators that is the practical difference between maintaining dozens of per-site rule sets and maintaining one policy framework. It also lines up with how most Australian organisations already handle identity, given how widespread Microsoft 365 and Google Workspace are here.
Let us be direct about the audience. This is not a product for a home lab or a ten-person office, and nobody running a Dream Machine at the edge of a small network needs to think about it. If you are terminating hundreds of branch tunnels or inspecting encrypted traffic for thousands of staff, it becomes relevant fast.
What we find genuinely notable is the licence-free positioning at this capacity. Competing appliances with comparable SSL inspection throughput typically arrive with annual subscriptions attached to threat feeds and SD-WAN orchestration, and over a five-year life those renewals often exceed the hardware cost. Removing that line item changes the shape of a tender response.
For integrators, the specification work is where the value sits. A core appliance of this class needs matching physical infrastructure — adequate rack space and airflow, high-speed optics between core and distribution, and clean power feeding the redundant supplies. Redundant PSUs protect against a supply failure, not against a mains event, so proper power protection still belongs in the design.
SMB IT teams should treat this as a signal rather than a shopping list. Ubiquiti pushing N2 compute up the range suggests the mid-market gear will keep inheriting security features that used to be reserved for far more expensive boxes. Ubiquiti has not published Australian pricing or availability for the Enterprise Firewall Core, so we would hold off on committing it to a budget until local supply is confirmed.
Read the full announcement at blog.ui.com.
The Enterprise Firewall Core is a rack-mount security appliance from Ubiquiti built around 24 Neoverse N2 cores. It is designed for large-scale enterprise networks, supporting up to 22,000 active devices and 10 million concurrent sessions while running advanced security services. It also acts as an SD-WAN hub, with support for more than 5,000 concurrent IPsec or WireGuard tunnels.
Ubiquiti states the Enterprise Firewall Core delivers up to 61 Gbps of full SSL inspection throughput. Threat detection is rated at up to 79 Gbps against tens of thousands of signatures, and aggregate IPsec throughput is listed at up to 38 Gbps. These are the figures published by Ubiquiti at announcement.
Ubiquiti is positioning the Enterprise Firewall Core as licence-free, meaning the firewall and threat protection capabilities do not carry separate subscription costs. Real-time threat intelligence is supplied through Proofpoint under the Cybersecure Enterprise offering. Ubiquiti has not detailed any additional commercial terms beyond that.
Ubiquiti has not announced an Australian release date or local pricing for the Enterprise Firewall Core. Availability for high-end enterprise hardware typically follows the global announcement by some months and can vary by region. Buyers planning a budget around it should wait for confirmed local supply.
The Enterprise Firewall Core supports VRRP-enabled Shadow Mode for rapid high-availability pairing, plus Multi-Chassis Link Aggregation at the core and switch stacking at the edge. On the hardware side it is specified with hot-swappable fans, redundant power supplies, and integrated management and console ports. The intent is to make failover straightforward to deploy rather than a bespoke engineering exercise.
No. The Enterprise Firewall Core is specified for up to 22,000 active devices and thousands of VPN tunnels, which is far beyond what a home network or a small single-site office would ever use. Smaller deployments are better served by UniFi cloud gateways and consoles sized to their client count.
Yes. The Enterprise Firewall Core is managed through Site Manager, which centralises SD-WAN orchestration and policy enforcement across every location in a single console. It integrates with Entra, Google Workspace and LDAP so that identity-aware policies follow users regardless of where they connect.
BUZY Networks stocks the full Ubiquiti range with a 2-year Advanced Replacement Warranty.