Next-generation firewalls
Palo Alto NGFW: App-ID, User-ID, threat prevention and TLS inspection – physical, virtual or as a service.
- PA-Series & VM-Series
- Advanced Threat Prevention
- Advanced URL Filtering
- WildFire
- DNS Security
Network and IT-security solutions with Palo Alto Networks – the market leader for next-generation firewalls. Protection is delivered from European data centres – for Zero Trust and European digital sovereignty.
We cover four areas of network security from a single provider: Palo Alto next-generation firewalls with App-ID, User-ID, threat prevention and TLS inspection; Zero Trust with micro-segmentation, ZTNA and identity-based policies; managed security delivered from European data centres; and network architecture from IPv4/IPv6 design and policy-based routing to cross-site connectivity.
Palo Alto NGFW: App-ID, User-ID, threat prevention and TLS inspection – physical, virtual or as a service.
Micro-segmentation, secure access (ZTNA) and consistent least-privilege policies.
Cloud-delivered protection from European data centres – operated and monitored.
Design and implementation of complex network structures – from IPv4/IPv6 and policy-based routing to cross-site, enterprise-wide connectivity.
We build on Palo Alto Networks, the market leader for next-generation firewalls, and work primarily with its portfolio: PA-Series and VM-Series firewalls, Panorama for central firewall management, Prisma Access for SASE, Cortex XDR, Threat Prevention, WildFire, DNS Security, the Precision AI Security Bundle, Secure Internet Edge and Secure Network Segmentation.
We protect our own platform with the same Palo Alto technology we deploy for customers: Palo Alto firewalls protect the Nokkela services in the group, from nokkela-it-concept.gmbh to nokkela.systems, with protection and analysis functions delivered from European data centres. Perimeter firewall, segmentation and workload form one coherent protection concept.
From the perimeter firewall through segmentation to the workload – one coherent protection concept.
Protection and analysis functions from EU data centres – GDPR-compliant.
We stand behind three things in network security. We work consistently with the market-leading technology of Palo Alto Networks; we have protection functions delivered from EU data centres, GDPR-compliant and oriented towards the NIS2 directive; and we provide network, firewall and operations from a single provider, together with our infrastructure and cloud services.
Palo Alto Networks – consistently leading technology, no compromises.
Protection functions from EU data centres, GDPR- and NIS2-oriented.
Network, firewall and operations from a single provider – together with infrastructure & cloud.
Below are the questions we are asked most often about this area. Each answer is written to stand on its own, so it stays correct when quoted alone.
A next-generation firewall classifies traffic by application, user and content rather than only by port and IP address. On the Palo Alto NGFWs that nokkela.network deploys, App-ID identifies the actual application behind a connection, User-ID ties a session to a directory identity, and TLS inspection makes encrypted traffic visible to Threat Prevention. Rules then read as "this user group may use this application" instead of port numbers.
nokkela.network deploys Palo Alto next-generation firewalls physically, virtually or as a service, and the choice follows where the traffic is. A PA-Series appliance suits an on-site perimeter or a data-centre edge; the VM-Series runs inside a virtualisation or cloud environment where no hardware belongs; Prisma Access (SASE) covers distributed users and sites. Panorama keeps the rule base consistent across them. We recommend the mix after looking at your topology.
Zero Trust means no connection is trusted because of its network location; nokkela.network implements it through micro-segmentation, identity-based policies and least privilege. In practice we start by making traffic visible with App-ID and User-ID, group systems into segments by function and data class, then replace broad any-any rules with per-segment policies. Remote access moves from a flat VPN to ZTNA, where each session is authorised per application. This can be approached in stages.
The protection functions that nokkela.network uses – Advanced Threat Prevention, Advanced URL Filtering, WildFire and DNS Security – are delivered from European data centres, so analysis stays in Europe rather than crossing to a US region. The firewalls themselves sit at your perimeter or in your virtualisation environment. Where a managed setup is used, monitoring and updates run from the EU as well, and processing follows GDPR.
No – a Palo Alto firewall does not make an organisation NIS2-compliant, because NIS2 is an EU directive transposed into national law, not a product feature or a certification anyone can hold. nokkela.network works NIS2-oriented: segmentation, logging, monitoring, patch and update handling and incident response are set up so that the technical requirements can be approached. The organisational and reporting duties remain with your management.
Managed security from nokkela.network means we operate and monitor the protection ourselves: the cloud-delivered protection functions come from European data centres, and we handle monitoring, signature and software updates and incident response. 24/7 monitoring is available and is agreed individually with each customer. Scope, escalation paths and response times are set out in the concept before implementation starts.
Yes – nokkela.network designs and implements network structures across sites, including dual-stack IPv4 and IPv6 addressing, policy-based routing and enterprise-wide connectivity between locations. The design is drawn up together with the security concept, so segments, routing and firewall zones fit each other instead of being retrofitted. Where a site network already exists, we document the current state first and then plan the target picture with you.
We start with a free initial consultation of up to 30 minutes – whether the topic is a new firewall, a Zero-Trust project, managed security or a network design. Tell us your situation through the form or by email at contact@nokkela-it-concept.com, and we usually reply within one business day. Your data is never shared with third parties.
nokkela.network – a service of Nokkela-IT-Concept GmbH
Email: contact@nokkela-it-concept.com
Part of the group: Nokkela-IT-Concept