The model name tells you the maximum number of users supported: the XL25 handles 25, the XL20000 handles 20,000 users.
XLOG Firewall
From a 25-user branch office to a 20,000-user data center. The models differ in capacity and interfaces; the security, filtering, hotspot and logging modules are identical on every model and require no extra license.
Only the Capacity Differs: Every Module On, No Extra License Fee
Every model runs the same software. What you need to look at when deciding is how many users you will serve, how much traffic your line carries and whether you need a fiber interface. Nothing changes from model to model on the security, filtering, hotspot or logging side.
The total firewall processing capacity of the device.
The capacity reached with the next-generation firewall services, including IPS/IDS, switched on.
The SFP fiber port starts with the XL400, 10 Gbit SFP+ arrives with the XL600, and the XL2000 has four of them.
The figures apply to the XL25–XL2000 range. Performance and interface values for the XL5000, XL10000 and XL20000 are determined per project.
Branch and Small Office
A firewall and logging system offering solutions for small and medium-sized businesses.
6 Gbit Ethernet interfaces, no fiber port. 3,000–9,000 Mbps firewall, 750–2,250 Mbps NGFW.
Campus and Mid-Scale
Offers solutions for medium-sized businesses and organizations; delivers performance with high-end hardware.
The XL300 comes with 6 Gbit Ethernet; a fiber interface is added on the XL400 as SFP 1 Gbit and on the XL600 and XL1000 as SFP+ 10 Gbit.
Data Center and High End
A precise fit for large organizations and enterprises. Serves high bandwidth needs with 10 Gbit SFP+ ports.
The XL2000 has 8 Gbit Ethernet and 4 SFP+ 10 Gbit ports. Higher models are configured per project.
The capacity table for all 12 models
The model-by-model equivalent of the figures above is below. You can narrow the table with the segment filter and click a model name to reach all of its technical specifications.
| Model | Users | Firewall thr. | NGFW | Application thr. | Ethernet Ports | Fiber Ports | Brochure / Details |
|---|---|---|---|---|---|---|---|
| XLOG XL25 | 25 | 3,000 Mbps | 750 Mbps | 1,250 Mbps | 6 Gbit Ethernet | - | PDF Details |
| XLOG XL50 | 50 | 4,000 Mbps | 1,000 Mbps | 1,500 Mbps | 6 Gbit Ethernet | - | PDF Details |
| XLOG XL100 | 100 | 6,000 Mbps | 1,500 Mbps | 2,250 Mbps | 6 Gbit Ethernet | - | PDF Details |
| XLOG XL200 | 200 | 9,000 Mbps | 2,250 Mbps | 3,000 Mbps | 6 Gbit Ethernet | - | PDF Details |
| XLOG XL300 | 300 | 12,000 Mbps | 3,000 Mbps | 4,000 Mbps | 6 Gbit Ethernet | - | Details |
| XLOG XL400 | 400 | 14,000 Mbps | 3,500 Mbps | 5,000 Mbps | 6 Gbit Ethernet | 2 SFP 1Gbit | PDF Details |
| XLOG XL600 | 600 | 20,000 Mbps | 5,000 Mbps | 8,000 Mbps | 6 Gbit Ethernet | 2 SFP+ 10Gbit | PDF Details |
| XLOG XL1000 | 1,000 | 40,000 Mbps | 10,000 Mbps | 13,000 Mbps | 6 Gbit Ethernet | 2 SFP+ 10 Gbit | PDF Details |
| XLOG XL2000 | 2,000 | 70,000 Mbps | 16,000 Mbps | 21,000 Mbps | 8 Gbit Ethernet | 4 SFP+ 10 Gbit | PDF Details |
| XLOG XL5000 | 5,000 | Sorunuz | Sorunuz | Sorunuz | Sorunuz | Sorunuz | PDF Details |
| XLOG XL10000 | 10,000 | Sorunuz | Sorunuz | Sorunuz | Sorunuz | Sorunuz | PDF Details |
| XLOG XL20000 | 20,000 | Sorunuz | Sorunuz | Sorunuz | Sorunuz | Sorunuz | PDF Details |
The fields marked “On request” in the table belong to models whose configuration is determined per project. Talk to our sales team for the interface and performance values of those models.
Whatever the XL25 does, the XL20000 does the same
Every module on the device is active and requires no extra license. The values below apply to all 12 models; nothing is restricted on the smaller model.
Log records are signed automatically with a time stamp and kept signed on the device for two years. You can apply the security policies required by data protection law.
Security and Filtering
- Network Firewall
- Yes
- Website Filtering
- 70+ Categories
- Filter Database
- 4,900,000+ Sites
- HTTPS Filtering
- Yes
- Layer 2 / Layer 3 / Layer 7 Traffic Control
- Yes
- MAC-IP Binding
- Yes
- VPN
- Yes
- SSL VPN
- Yes
- WireGuard VPN
- Yes
- XLOG VPN Client
- Windows, Linux, Android, iOS
User Management
- Web Authorization / Hotspot
- Yes
- Turkish ID / SMS / LDAP / Hotel Integrations
- Yes
- VPN MFA (SMS, E-mail, Google Auth.)
- Yes
- Live User Monitoring
- Yes
- Per-User Download Quota
- Yes
- Per-User Speed Limit
- Yes
- Line Aggregation
- Yes
- Line Failover
- Yes
- Notification Options
- SMS, E-mail
Logging and Reporting
- On-Device Signed Logging Support
- Yes
- Log Retention Period
- 2 Years
- HTTPS Logging
- Yes
- SYSLOG
- Yes
- Syslog Collection (switch, router, server)
- Yes
- Reporting
- Yes
- Log Backup Support
- Yes
- Language Support
- Turkish, English
- Device
- Rack Type
XLOG Firewall Features
Pick a module from the list on the left and its details open on the right. Every module is active on every model and is managed from a web interface available in Turkish and English. Because all models use the same interface, changing model means nothing new to learn.
Firewall
- Opening, closing and forwarding ports is handled through the firewall.
- Port-based attacks from outside are blocked, keeping the system secure.
- Group-based rules can be created; the rules you choose apply to the groups you choose.
- With country-based blocking, IP blocks outside Türkiye, Azerbaijan and Iraq can be blocked in bulk with a single setting; specific IPs can be allowed when needed.
- Timed port opening: a port is opened for a set period and closes automatically.
- The IPs currently connected to a port can be viewed live.
- Port access triggers instant notification by SMS and e-mail.
Network Configuration
- Physical interfaces are defined as WAN, LAN or HA; addressing is done with a static IP, DHCP or PPPoE.
- VLAN, bridge and LAGG (link aggregation) virtual interfaces are created from the interface.
- Several interfaces can be grouped under one zone; because rules are written against the zone name, changing an interface does not break them.
- A gateway and a monitoring address are defined for each WAN; ordering multiple gateways sets up load balancing and redundancy.
- Static routing entries, MTU and DNS settings are managed on the same screen.
- With a Layer 2 tunnel interface, a remote branch joins the same broadcast domain as the central site.
IPS/IDS
- The intrusion detection system detects attacks arriving on the WAN and LAN interfaces; it runs in notification or blocking mode.
- Ready-made signatures and rules make management straightforward.
- Because the rules update automatically, attack conditions are tracked in real time.
- Under heavy traffic there is only a very small drop in throughput; it does not slow the network down.
- IPS/IDS signatures can be selected per profile to create blocking or warning conditions.
- Signature updates require no user intervention; the software stays current and keeps protecting.
Web Filtering
- A filter database of 70+ categories and 4,900,000+ sites is standard on every model.
- The blacklists ship on the device; no additional service is needed.
- Blacklist updates download automatically and require no user intervention; malicious software and illegal content addresses are blocked automatically.
HTTPS Filtering
- HTTPS/SSL pages can be blocked without installing a certificate on the computers.
- Wildcards (*.facebook.com) can be defined in the blacklists.
- Visits to HTTPS/SSL pages are logged per IP; the host names of the visited addresses are kept as well.
- Because no SSL certificate is used, no certificate error appears in the browser.
- Thanks to the dynamic database, sites that are not in the blacklist can be added to the lists by the user.
Hotspot
- The hotspot captive portal can be designed; a company logo or a welcome message can be published.
- Authentication methods: username and password, Turkish ID number, passport, SMS, LDAP/Active Directory, one-time password (voucher) and hotel/hospital software integrations; several methods can be used together in one zone.
- Integration with hotel management systems is available.
- For venues that want to charge for internet access, a timed billing module is available.
- After the hotspot login, users can be redirected automatically to any site you choose.
- The login and logout times of users who signed in can be listed.
- Currently active users and their quota usage can be listed.
- Privileged users can connect without seeing the hotspot page.
- One-time passwords can be created for guests.
- With thermal printer integration, the username and password can be handed over as a printed slip.
- The captive portal can be published in Turkish, English, German and Russian; the language is selected automatically from the browser setting. The privacy notice and the terms of use are defined separately for each language.
Speed Limiting
- Download and upload speed can be defined per user or per MAC address.
- A daily, weekly or monthly quota can be defined per user or per MAC address; when the quota is used up, access is cut off or dropped to a defined lower speed.
- Daily per-user and per-MAC quota usage is recorded and can be listed by date range.
- Devices generating excessive traffic are shown at the top of the list.
VPN / SSL VPN
- Site-to-site VPN is available; networks at remote sites can be joined to the central network.
- It interoperates with devices on the market that support IPsec VPN.
- Multi-subnet support is available; several VPN connections with different subnets can be established to the same IP.
- With SSL VPN, remote users can be joined to the corporate network in software.
- On MPLS networks it provides standalone management with no need for an additional DHCP or DNS server; installing only at the central site lets you manage every device from one point.
- With WireGuard support, a modern low-latency tunnel can be established.
- The XLOG VPN client connects from Windows, Linux, Android and iOS devices.
- VPN MFA: a second verification step is added with SMS, e-mail or Google Authenticator.
Line Aggregation
- Up to 5 internet lines can be combined on the system.
- It is a solution applied where the internet infrastructure is not fast enough.
- It works both as traffic steering and as line aggregation; both configurations are supported.
Line Failover
- When one of the internet lines in use is cut, internet continuity is maintained over the active lines.
- A monitoring address is defined for each line; when the address stops responding the line is considered down and traffic moves to the surviving lines.
- Which rule exits over which line can be chosen per rule; when the primary line returns, traffic falls back to its original layout.
Active–Passive (HA)
- Setup is done by defining an HA interface, the peer device IP and a shared key between the two devices.
- If the active device fails, the standby device takes over automatically; no manual intervention is needed on the network.
- The configuration is synchronized between the two devices; rules and profiles are not copied separately.
- The role of each device (MASTER/BACKUP) and the connection status are visible live in the panel.
Logging / Signing
- These logs can be reported in detail.
- Records are kept signed on the device for 2 years.
- Records can be searched by MAC address, source/destination IP, username, destination port, domain and date.
- Internet records can be downloaded to your computer by date.
- With the FTP backup feature, internet records can be copied to another device.
- Logins to the XLOG system are recorded.
SYSLOG
- Devices such as switches, routers and servers are defined as syslog sources; the records they send are collected on the device.
- The collected records can be searched by date range, source/destination address and port, user, rule and action fields.
- Records produced on XLOG are sent to an external SIEM or log server; you can choose which log types are forwarded.
- Internet records from other firewall brands are received over syslog and signed.
Application Filtering
- Allow or block rules are defined with a single click through ready-made application categories.
- Applications are listed in categories; permission is granted in bulk per category and, where needed, one application at a time.
- A specific application can be found with the search box and an exception defined for that application alone.
- Because the profile is bound to a firewall rule, the restriction is applied per user, per group or per time of day.
RADIUS MAC Filtering
- It works with managed switch integration on both Layer 2 and Layer 3 networks.
- Devices that join the network, or try to, can be tracked live.
- With SNMP and telnet support it collects ARP information from edge and core switches, adds the MAC address to log records on Layer 3 networks and provides signed logging.
- With Layer 2 filtering, clients trying to connect from the internal network join only with the system administrator's approval.
Every setting in one panel
Firewall rules, IPS/IDS profiles, user monitoring and records are all managed from the same web interface; you do not need to install a separate console or client software.
You Cannot Manage a Network You Cannot See
Preventing illegal traffic on your network is a headache, and trying to control it without knowing what your users are doing on that network is nothing but wasted time.
You may know that your users reach sites and applications you would rather they did not during working hours, and generate excessive traffic, yet be unable to stop it.
You need simple, powerful security that makes the network easier to control, saves you time and makes it easier to manage. The XLOG Network Security and Logging System UTM Firewall delivers that and more.
The questions technical teams ask most
No. Every module on the device is active and requires no extra license. The only things that differ between models are user capacity, firewall/NGFW/application throughput and the network interfaces.
Log records are signed automatically with a time stamp and kept signed on the device for 2 years. With the FTP backup feature the records can also be copied to another device.
No. HTTPS/SSL pages can be blocked without installing a certificate on the computers; because no SSL certificate is used, no certificate error appears in the browser either. Wildcards such as *.facebook.com can be defined in the blacklists.
Up to 5 internet lines can be combined on the system. The device works both as traffic steering and as line aggregation; when one of the lines is cut, internet continuity is maintained over the active lines.
With High Availability support, an Active-Passive setup engages automatically on a physical device failure and the standby device takes over.
The performance and interface configuration of these models is determined per project. If you share your user count and line capacity, our sales team will work out the right configuration.
Assess your network with XLOG
Let us review your user count and line capacity together, and recommend the model that matches your scale.