Why Neurowall?

Why teams choose Neurowall.

A simple comparison of what Neurowall offers, how it is priced, and how it differs from other firewall options.

Quick view
AWS Network Firewall
Cloud service with usage-based pricing.
VyOS
Subscription model with no per-device fees.
pfSense
Open source with paid support options.
FortiGate
Enterprise firewall with quote-based pricing.
Comparison

The short version: why Neurowall.

If you want a firewall that runs on standard Linux, is easy to price, and avoids appliance lock-in, Neurowall is built for that.

Dimension AWS Network Firewall FortiGate pfSense VyOS Neurowall
Pricing model Usage-based cloud pricing. Quote-based appliance pricing. Free core edition, paid support. Subscription with no per-device fee. Flat per-node pricing.
Deployment fit AWS-first environments. Appliance or VM deployments. Physical or virtual deployments. Cloud, bare metal, and edge. Standard Linux across cloud, on-prem, and edge.
Operational style AWS-managed. Vendor platform. Community-driven. Automation-friendly. Simple, API-first, Linux-native.
Best for AWS-only teams. Large enterprises. Labs and small teams. Routing-first teams. Teams that want a modern, Linux-native network security platform without hardware lock-in.
Performance & Scale

Built to stay fast under load.

Neurowall has been benchmarked across throughput, rule scaling, packet-rate stress, and flood conditions. The useful buyer story is not just headline speed, but how predictably performance changes as policies grow and traffic gets ugly.

14.8Gbps
XDP firewall throughput measured with 10,000 rules at a 20 Gbps offered traffic rate.
375K
Security policies tested across blocklists, allowlists, and mixed firewall rules.
~1.27M
Observed XDP packet rate during the 20 Gbps firewall-rule test.
~96K
Packets per second during the uncapped SYN flood test, with the system remaining responsive.
The more useful buyer story is that the XDP rule profile stayed flat as rules increased from 0 to 10,000. That fixed-path cost is real, but the rule-count scaling itself is predictable.
Benchmark summary

One-page results.

Metric Tested Result
Transport baseline at 20 Gbps offered rate19.99 Gbps
XDP prefilter15.06 Gbps
XDP firewall, 10K rules12 Gbps
XDP + DDoS + 10K rules12 Gbps
XDP packet rate during 20 Gbps firewall test~1.27 Mpps
Largest policy configuration tested375,000 policies
SYN flood generated in 375K-policy test~96K PPS
ICMP flood generated in 375K-policy test~83K PPS
Throughput profile

The XDP path has a fixed cost.

At a 20 Gbps offered rate, the rule-count scaling stayed essentially flat. The more visible cost is the XDP path itself, not the difference between 0 and 10,000 rules inside that path.

Configuration Throughput vs baseline
Transport baseline19.99 Gbps
nftables raw, 10K IP rules20.00 Gbps~0%
XDP prefilter only15.06 Gbps-24.7%
XDP + rules, 0 rules14.76 Gbps-26.2%
XDP + rules, 10K rules14.82 Gbps-25.9%
XDP + DDoS + rules, 013.04 Gbps-34.8%
XDP + DDoS + rules, 10K rules13.01 Gbps-34.9%
Rule-set composition

What was actually loaded.

Policy type Count
IP blocklist entries250,000
IP allowlist entries100,000
Mixed 3/4/5-tuple firewall rules25,000
Total policies loaded375,000
System behavior

Resource use at 375K rules.

Test Approx. Generated Rate System Idle Neurowall Process CPU Memory
375K policies, idle 89.18% 14.29% 773 MB
SYN flood ~96K PPS 74.52% 23.34% 754 MB
ICMP flood ~83K PPS 80.51% 17.86% 744 MB
XDP share

What the kernel path carried.

Condition System idle Neurowall CPU RSS XDP/NAPI CPU share
Idle 89.18% 14.29% 773 MB 0.04%
~96K PPS SYN flood 74.52% 23.34% 754 MB 14.25%
~83K PPS ICMP flood 80.51% 17.86% 744 MB 12.00%
At a glance

What stands out quickly.

AWS Network Firewall

Good if you want AWS-native firewalling and don’t mind usage-based billing.

FortiGate

A mature enterprise option, usually bought through quotes or bundles.

pfSense

Great for flexible firewalling, especially if you prefer open source.

VyOS

Strong for routing and automation with a subscription model.

Bottom line

Simple pricing. Simple deployment.

Neurowall is the choice when you want predictable pricing and a firewall that runs on the Linux infrastructure you already have.

AWS Network Firewall
Variable

Usage-based pricing can be harder to predict.

  • Best for AWS-native deployments.
  • Costs rise with traffic.
FortiGate
Quote-based

Usually priced by appliance, VM bundle, or support package.

  • Best for large enterprise buyers.
  • Requires sales engagement.
pfSense
Free + paid support

Good when you want open-source flexibility.

  • Strong community adoption.
  • Pricing depends on support needs.
Feature fit

What each platform offers.

Short version: Neurowall is built for Linux-native gateway deployments with simple, predictable pricing.

Capability AWS Network Firewall FortiGate pfSense VyOS Neurowall
Firewalling Yes, managed cloud firewall for VPC traffic. Yes, next-gen firewall platform. Yes, stateful firewall on FreeBSD. Yes, nftables-based firewalling. Yes, Linux-native network security platform with eBPF/XDP fast path.
VPN Not the core product focus. Available in the FortiGate ecosystem. Included. Included. Included where needed for branch and edge deployments.
DDoS protection Managed protection is available as part of the service and threat-defense options. Included through Fortinet security services and subscriptions. Usually handled by separate tooling or packages. Typically paired with external controls or custom policy. Built in, with packet-level filtering and attack mitigation.
Threat intel feeds Available through managed AWS rule groups and partner integrations. Included through Fortinet security services and subscriptions. Usually handled by separate tooling or plugins. Usually integrated through the operating model and external tooling. Built in, with multi-source threat intelligence feeds.
L7 controls Advanced inspection is available as an add-on capability. Available through NGFW application controls and security services. Available via firewall rules and related packages. Available through policy and routing features, depending on deployment. Built in, including domain-level blocking and application-aware controls.
Deployment model AWS-only service. Appliance or VM, often vendor ecosystem oriented. Physical or virtual firewall/router. Cloud, bare metal, and virtualized Linux deployments. Standard Linux infrastructure across cloud, on-prem, edge, and Kubernetes ingress.
Management AWS console / IaC / cloud networking constructs. Vendor UI, APIs, and security management stack. Web UI, CLI, and community workflows. CLI-first with APIs and automation support. REST, gRPC, CLI, and built-in web UI.
Next step

Want a simpler firewall choice?