Athena NGFW (Next-Generation Firewall)

Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
8.0.107
{{sendMatomoQuery("Athena NGFW (Next-Generation Firewall)","System Types")}}

System Types

{{ $t('productDocDetail.updateTime') }}: 2026-02-05

Athena NGFW supports two types of systems:

Public

The public system is a special default VSYS on Athena NGFW. It exists even if the VSYS feature is disabled. In this case, all settings specified by the administrator for Athena NGFW apply to the public system. After the VSYS feature is enabled, the public system inherits the existing settings on Athena NGFW.

The public system manages other VSYSs and provides services for communication between other VSYSs.

VSYS

A VSYS is a logical device that operates independently on Athena NGFW.

Athena NGFW ensures accurate forwarding, independent management, and isolation for each VSYS in the following ways:

Resource virtualization: The public system administrator can assign fixed system resources to each VSYS, including interfaces, VLANs, policies, and sessions, which are independently managed and used by the VSYS. Hence, other VSYSs will not be affected when one VSYS is busy.

Configuration virtualization: Each VSYS has its own VSYS administrator and configuration UI (CLI/Web). VSYS administrators can manage only the VSYS to which they belong, and the public system administrator can manage all VSYSs. This streamlines the management of multiple VSYSs and properly enables large-sized networking scenarios.

Routing virtualization: Each VSYS has its own routing tables, which are isolated from each other. This ensures proper communication even if the LANs of the VSYSs have the same IP ranges.

Switching virtualization: Each VSYS has its own MAC address tables and ARP tables, which are isolated from each other.

Log isolation: Each VSYS has its own log files and log display UIs.

Therefore, the administrator of each VSYS can use the VSYS as an exclusive device.