Athena NGFW (Next-Generation Firewall)

Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
8.0.107
{{sendMatomoQuery("Athena NGFW (Next-Generation Firewall)","Configuration Notes")}}

Configuration Notes

{{ $t('productDocDetail.updateTime') }}: 2026-04-29

Configuration Item (Athena NGFW)

Description

Traffic of Interest

- This is supported only in route mode.

- By default, IPv4 is enabled. This is equivalent to a case in which the peer/local IPv4 address is set to all zeros.

- IPv6 is enabled. This is equivalent to a case in which the peer/local IPv6 address is set to all zeros.

Peer Tunnel Interface

- This is supported only in route mode.

- If the referenced VPN tunnel interface is not shared with other IPsec VPN tunnels, we recommend that you leave this configuration item empty.

- You must enter the address of the peer tunnel interface if OSPF or BGP is used.

- When you need to specify the next hop for the static route or policy route, make sure that the next hop address is the same as the peer tunnel interface address of the IPsec VPN tunnel. Otherwise, business traffic may fail to be routed.

Encrypted Traffic

- The local and peer IP addresses in the encrypted traffic can be customized only in policy mode. You cannot customize the local and peer IP addresses in route mode. In addition, only two encrypted traffic entries are predefined: one using an all-0 IPv4 address and the other using an all-0 IPv6 address. By default, IPv4 is enabled, and the traffic to be actually encrypted is determined by the address specified in the traffic of interest.

- In policy mode, multiple local/peer IP addresses can be configured in the encrypted traffic. To be specific, a maximum of 16 * 16 addresses can be configured.