Solution — One Device

One Device, Full Management

Firewall, hotspot, logging and 802.1x. The four are not separate boxes but modules running in the same XLOG Firewall chassis: the device admitted to the network, the guest verified at the captive portal, the rule applied and the record signed all come together in one place.

Four Jobs

Four jobs, one chassis

A network is expected to do four things every day: admit the device to the network, identify the user, filter traffic by rule and by content, and keep a record of what happened. On the XLOG Firewall these four do not run as separate products wired together but as modules in the same chassis. The four headings below are the backbone of this page.

01
FIREWALL

Filters traffic at rule and content level

Port management, attack blocking and content filtering are all defined on the same device. A rule is written for a group; any session that falls into that group is subject to the same rule, whether it is a corporate device admitted through 802.1x or a guest verified at the hotspot.

Opening, closing and forwarding ports; port-based attacks from outside are blocked.
Group-based rules are created; the rules you choose apply to the groups you choose.
IPs outside Türkiye are blocked by default; even if a rule is written incorrectly, the system blocks them automatically.
Timed port opening prevents ports left open by mistake; SMS and e-mail notifications are sent on port access.
IPS/IDS inspects the content of every packet before it enters the network; it is kept current with a dynamic signature database.
Web filtering works with a database of 70+ categories and 4,900,000+ sites, and HTTPS filtering works without a certificate or a proxy.
02
HOTSPOT

Identifies the guest at the captive portal

No separate hotspot hardware is placed for the guest network; the module runs on the firewall and is present on all 12 firewall models. The verified guest joins the same rule and logging regime as a corporate user.

Three main authentication methods: ID number, username and password, and SMS integration.
Verification can be done with LDAP, hotel management programs and third-party software.
The captive portal is designed with the organization's logo and message; users can be redirected to any address after login.
One-time passwords are generated for guests; they can be handed over as a printed slip with thermal printer integration.
Currently active users, quota usage and login/logout times can be listed.
A timed billing module is available for venues that charge for internet access.
03
LOGGING

Signs the record and keeps it on the device itself

No separate log server or signing service is installed for your access records. The records are saved on your own systems and retained for two years; the device does that on itself.

Every log record saved on the system is signed with a time stamp and stored on the device.
Records are kept signed on the device itself for two years.
Reports can be searched by MAC address, source and destination IP, username, destination port, domain and date.
Visits to HTTPS pages are recorded per IP together with the host name of the address visited.
Records can be copied to another device with FTP backup and downloaded to a computer by date range.
Internet logs from other firewall brands can also be signed through syslog signing.
04
802.1X

Filters the device before it joins the network

The admission decision is made at the edge, on the managed switch; a device that is not approved never enters the network. 802.1x MAC control was developed in 2020 and the RADIUS MAC filtering R&D was completed the same year; 802.1X RADIUS dynamic VLAN assignment was added in 2022.

Works with managed switch integration on both Layer 2 and Layer 3 networks.
Client devices can be blocked or filtered at the edge, before they join the network.
With 802.1X RADIUS dynamic VLAN assignment, an approved device is directed to the relevant VLAN.
Devices that join the network, or try to, can be tracked live.
With Layer 2 filtering, clients trying to connect from the internal network join with the administrator's approval.
With SNMP and telnet support, ARP information is collected from edge and core switches; the MAC address is written into the log records as well.
4 functions
Firewall, hotspot, logging and 802.1x in the same chassis
12 models
The same module set across the entire Firewall family
2 years
Signed record retention on the device itself
No extra license
Every module is active; no per-module license is purchased
Working Together

The four form a single chain on the same device

The corporate device admitted through 802.1x and the guest verified at the hotspot captive portal are both subject to the same firewall rules; the traffic of both is recorded on the same device, signed with a time stamp. There is no separate server, no separate console and no device-to-device pairing for the handovers in between.

The flow of four functions on a single device The XLOG Firewall is shown inside a dashed frame. The device is first admitted to the network through 802.1x MAC control on a managed switch, then the guest user is verified at the hotspot captive portal, and the traffic then passes through the firewall, IPS/IDS and content filtering rules to reach the internet. The record of all three stages is signed on the same device with a time stamp and kept for two years. XLOG FIREWALL — ONE DEVICE 01 — NETWORK ADMISSION 802.1x MAC control through managed switch integration 02 — VERIFICATION Hotspot portal ID number · username and password · SMS 03 — RULE AND FILTER Firewall IPS/IDS, web, HTTPS and application filter, quota Internet Rule-bound egress 04 — RECORD Logging and signing Signed with a time stamp; kept for two years with MAC address, username, source and destination IP, domain and time.
On Layer 3 networks, XLOG collects ARP information from edge and core switches with SNMP and telnet support; that way the device identity from the first step is written into the final record as a MAC address.

From admission to verification

A device that passes 802.1x MAC control joins the network; the user is still unknown. The guest device lands on the captive portal and is verified with an ID number, a username and password, or SMS. Both steps are defined on the same device.

From verification to rule

The verified session is bound to a group-based firewall rule, to the web, HTTPS and application filters, and to a per-user or per-MAC quota and speed limit. No separate policy server is kept for guests and corporate users.

From rule to record

The record of the traffic is signed on the same device with a time stamp. On Layer 3 networks, thanks to the ARP information collected from the switches, the MAC address is written into the record as well; the device identity from the first step carries through to the final record.

What Is in the Box

The module set the four rest on

Every heading on the firewall, hotspot, logging and 802.1x side comes from the module set below. None of the modules is optional; they ship with the device and are switched on. You do not need to place an order or enter a new key to start using a module.

Firewall

Opening, closing and forwarding ports; blocking port-based attacks, group-based rules.

IPS/IDS

Packet content is inspected before it enters the network; threats are stopped and the dynamic signature database is updated.

Web Filtering

Blocking unwanted sites with the blacklists that ship on the device.

HTTPS Filtering

Blocking or allowing HTTPS addresses without a certificate or a proxy.

Hotspot

Guest access verified with Turkish ID, SMS, LDAP, hotel software and third-party software.

Speed Limiting

Per-user or per-MAC download/upload speed and quota definition, preventing excessive traffic.

Interface Management

Management from a web interface available in Turkish and English.

Automatic Updates

The software updates itself; malicious and illegal content addresses are blocked automatically.

VPN / SSL VPN

Joining branches with site-to-site VPN, remote user access with SSL VPN.

Line Aggregation

Combining multiple internet lines and using them as a single line.

Line Failover

Internet continuity over the active lines when one of them is cut.

Logging / Signing

Records signed with a time stamp and stored on the device.

Application Filtering

Allowing or blocking applications through ready-made application categories.

RADIUS MAC Filtering

Blocking or filtering clients at the edge through managed switch integration.

General Extras

Management with no extra DHCP/DNS server, SNMP/telnet switch integration, FTP backup, HA support.

Model Selection

The four do not change with the model

The firewall, the hotspot, logging and edge control are identical across all 12 models of the Firewall family. There is no “which function do I give up” question when choosing a model; you only look at how many users and how much traffic you will serve.

Unchanging
The same on every model
Network firewall, IPS/IDS and Layer 2/Layer 3/Layer 7 traffic control Website filtering: 70+ categories, a database of 4,900,000+ sites HTTPS filtering and HTTPS logging Web authorization / hotspot with Turkish ID, SMS, LDAP and hotel integrations RADIUS MAC filtering and managed switch integration On-device signed logging, 2-year retention, log backup VPN and SSL VPN, line aggregation and line failover Per-user quota and speed limits, MAC-IP binding, live user monitoring
Changing
What differs by model
Number of users
25 – 20,000
Firewall throughput
3,000 – 70,000 Mbps
NGFW throughput
750 – 16,000 Mbps
Application throughput
1,250 – 21,000 Mbps
Ethernet ports
6 – 8 Gbit
Fiber ports
None – 4x SFP+ 10 Gbit

The performance and interface configuration of the XL5000, XL10000 and XL20000 is determined per project.

Bring the four jobs onto one device

Tell us which boxes handle your firewall, your guest network, your log records and your network admission control today; let us work out the configuration that covers all of them together.

Request a demo