Athena NGFW (Next-Generation Firewall)

Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
8.0.85
{{sendMatomoQuery("Athena NGFW (Next-Generation Firewall)","Deployment Mode")}}

Deployment Mode

{{ $t('productDocDetail.updateTime') }}: 2026-01-06

The deployment mode refers to the operating mode set for the device. You can set the device to the routing mode, transparent mode, Virtual Wire mode, bypass mode, and blend mode. An appropriate deployment mode is the precondition for successfully connecting the device to the network and making it work.

Deployment Type

Scenario Description

Routing mode (Layer 3)

The device can be used as a routing device, which changes the network the most but can realize all the device's functions.

Transparent mode

(Layer 2)

The device can be regarded as a network cable with a filtering function. This mode is usually enabled when changing the original network topology is inconvenient. It can provide most of the device's functions by connecting it to the network seamlessly.

Virtual wire mode

This is another special type of transparent deployment, which does not need to check the MAC table and directly forwards it from the interface paired with the virtual network cable. The forwarding efficiency of the Virtual Wire is higher than that of the transparent mode.

Mirror mode

The device is connected to the mirror interface or HUB of the LAN switch, mirroring the data of LAN users and detecting the traffic through the mirrored data. There is no need to change the user's network environment at all, and it can avoid the risk of interrupting the user's network by the device. However, in this mode, the device only detects traffic and cannot block malicious traffic.

Mix mode

It mainly refers to layer 2 and layer 3 interfaces on the device, especially when the IP address of the Internet must be configured for DMZ's server cluster.

Table 4:Deployment Modes