- Description
- Specifications
25G Enterprise Firewall with 12.5 Gbps IDS/IPS, Real-Time SSL Decryption, Shadow Mode Failover, and 5,000+ Client Capacity
The Ubiquiti Enterprise Fortress Gateway (EFG) is the flagship security gateway for UniFi deployments running 500+ devices and 5,000+ concurrent clients behind a single perimeter. It delivers 12.5 Gbps of routing with active IDS/IPS inspection (95,000+ signatures), real-time SSL/TLS decryption on 10,000 concurrent sessions, and 25G SFP28 WAN capacity. Dual hot-swappable 150W CRPS power supplies and Shadow Mode VRRP failover keep the gateway online through hardware failures.
The EFG sits at the top of the UniFi gateway lineup as a true enterprise firewall with stateful Layer 7 inspection, zone-based filtering, BGP and OSPF dynamic routing, multi-WAN load balancing across up to 5 WAN interfaces, and license-free SD-WAN with WireGuard at 980 Mbps single-tunnel throughput. Managed from the same UniFi Network console as every switch, AP, and camera in the deployment.
Where the Enterprise Fortress Gateway Fits
- Enterprise campuses and multi-site organizations running 500+ UniFi devices that need a perimeter firewall with 12.5 Gbps IDS/IPS, SSL inspection, and 25G WAN capacity without per-seat or per-feature licensing fees
- MSPs and integrators replacing Cisco Meraki or Fortinet where recurring firewall license fees are eliminated by moving to UniFi while retaining enterprise security features including SSL decryption, dynamic routing, and high availability
- Government and NDAA-required deployments that need a certified enterprise gateway with redundant hot-swap power supplies, Shadow Mode failover, and full audit-ready security inspection
What the Enterprise Fortress Gateway Delivers
- 12.5 Gbps IDS/IPS with SSL inspection: Active intrusion prevention with 95,000+ CyberSecure Enterprise signatures. SSL/TLS decryption inspects 10,000 concurrent encrypted sessions in real time, preventing threats from hiding inside HTTPS traffic.
- 25G SFP28 WAN with multi-WAN support: Two 25G SFP28, two 10G SFP+, and two 2.5 GbE RJ45 ports. Up to 5 WAN interfaces configurable for load balancing, ISP redundancy, or service separation. 1 million concurrent sessions.
- Shadow Mode high availability: VRRP-based failover keeps a second EFG in hot standby. Combined with dual hot-swappable 150W CRPS power supplies, the gateway maintains uptime through both power and unit failures.
- BGP, OSPF, and full VPN suite: Dynamic routing makes the EFG a real core gateway for campus and multi-site architectures. WireGuard (980 Mbps), OpenVPN, IPsec, L2TP, Teleport, and Identity Endpoint VPN all included with no licensing.
- 1U rack mount with 18-core processor: ARM v8.2 at 2 GHz with 16 GB RAM in a 1U chassis (442 x 44 x 325 mm). 1.3-inch front touchscreen shows throughput, IPS events, and system health. NDAA compliant.
