Security

Hardened for the LAN edge.

One authenticated management portal on the LAN. Change controls stay off desk reach. Firewall and IDS sit in the traffic path.

Secure operations console

Access

LAN portal. Locked-down controls.

Operators use an encrypted console on the office LAN. WAN, bandwidth, firewall, VPN, alerts, and backup changes are not open services for every desk.

  • Login rate-limited per source
  • Authenticator MFA for admin roles
  • Factory password must change first
Hardened appliance ports

Perimeter

Profiles that match production

Balanced for first production rollout. Strict for hardened offices. Anti-spoof protects the WAN while configured ISP gateways still answer.

  • IDS alert mode is the safe start
  • Prevention is opt-in with confirm
  • Diagnostic targets are allowlisted

Security Posture

PROTECTED or HARDEN, in real time.

The console grades real checks. It is not a static marketing badge.

Core path

  • Sticky multi-WAN fabric up
  • Firewall policy active
  • IDS running with EDGE rules
  • Portal accounts in place
  • Change controls not LAN-exposed
  • LAN and WAN roles assigned
  • Admin MFA enrolled

Hardening extras

  • Portal limited to LAN
  • Strict firewall profile
  • Quiet WAN ICMP posture
  • Anti-spoof enabled
  • DNS sinkhole present
  • MAC allowlist when ready

Honesty

No deep-inspection theatre.

AE-200 does not sell sandbox AV or cloud web-filter categories. The product is perimeter, sticky path, and operable MFA.

Specs

Inclusions and outs, plainly.