Firewall rules, per gateway and per user

Firewall rules in QS-WAN are written two ways, attached to a gateway or attached to a user, and they reach the gateways in real time instead of waiting for a maintenance window. Your gateways, your VLANs and your certificates stay exactly where they are, and nothing gets unracked to make room.

The Network
Your network, and the rules that decide what reaches what
What it is

Two scopes, two timings, and no maintenance window in either of them

A firewall rule in QS-WAN is a rule set with an owner, and there are two kinds of owner. A rule set attached to a gateway covers what that gateway serves, which is the right shape when the rule is about a site, a branch or a piece of infrastructure. A rule set attached to a user follows the person instead of the place, so someone connecting from a hotel on Tuesday and from the office on Thursday keeps the same rule both times. The timings matter as much as the scopes: rules are applied to the gateways in real time, so the gap between deciding something and it being true on the network is short enough to sit and watch, and they’re reapplied every time a device reconnects. That second one is the quiet part. A laptop that’s been shut for a week comes back on the current rules, not the ones it left with.

Gateway Vlan Sdwan
One scope is the gateway, and the segments sitting behind it

Cybersecurity in action

This is Monday at 08:40, the week’s first wave of laptops coming back online across every gateway you run, each one picking up the rules you wrote on Thursday rather than the ones it went to sleep with.

Mission Control
Every gateway on one screen, on the morning everything reconnects at once
Benefits

Same two scopes. One person wants them fast, the other wants them written down.

The person running the network wants a change that’s live before the coffee goes cold. The person signing for it wants to point at a screen when an auditor asks which rule is running where. Both get it from the same place.

For the network

No maintenance window

Rules are applied to the gateways in real time, so a change doesn’t queue up behind a Saturday night. You make the decision and then you watch it be true, which is not how most people remember changing a firewall.

The laptop in the back of a car can't dodge it

Every reconnection reapplies the rules. Anything that only enforces at the moment you press save has a hole shaped exactly like the machine that spent the month in a bag, and reconnection closes it without anyone chasing the device.

Two scopes, one console

The rule about the branch and the rule about the person live in the same place, in the same shape. You’re not keeping a second rule set in step with the first by memory, which is the job nobody ever writes on a timesheet.

For the business

"Which rule is live, right now?" stops being a research project

In a lot of networks the honest answer is that someone has to go and look. Here it’s a screen, and the difference shows up in an audit rather than in a meeting.

Drift stops being a policy you fund

Two rule sets that agree on the day they’re written start disagreeing the day after, and the cost of that is invisible until it isn’t. One set of scopes means the network keeps agreeing with the document describing it.

Nothing new on the invoice

This runs on the gateways, profiles and segments you already have. No appliance to rack, no second product, no equipment leaving the building.

Three steps, and the only human being in the first one is pressing Connect

Here’s what actually has to happen for a firewall rule to mean something on a device that isn’t in your building. Watch how little of it involves you phoning anyone.

Step 1

A laptop that's been shut since last Tuesday opens in an airport

The person hits Connect in the QNova Client, and the tunnel comes up. That’s the whole of their job: there’s no rule list on the endpoint to approve, nothing to review, and nothing to switch off on a bad afternoon. The rules go back on with the connection, so the device that missed everything you did last week comes back on the current set rather than the one it remembers. If the tunnel doesn’t come up, the client keeps a live log per profile and a notification history of connection outcomes, so the person can tell you something specific instead of “the internet’s broken”.

Client Secure Connection
One button on the device. The rules come back on with the tunnel
Security Dashboard
The same reconnection, with the context the device never had
Step 2

You already know, and nobody had to call you

The same reconnection shows up on your side with the context the laptop never had. QS-WAN carries a VPN device inventory that drills down into activity per user, and a security events feed you can filter by severity and status, so what’s connecting across the estate is something you read rather than something you’re told. The person in the airport knows their tunnel came up. You know which profile it was, which gateway took it, and what rule set it landed on.

Step 3

You pick the scope, and the scope is the whole decision

This part is yours alone, and it’s one question: is this rule about a place or about a person? If the branch office has no business reaching the finance systems, the rule goes on the gateway and covers everyone it serves. If it’s one contractor who should only ever reach one system, the rule goes on the user profile and follows them to the hotel, the office and their sister’s kitchen. Either way it’s applied in real time, and you didn’t visit a single desk to do it.

Vpn Profiles
The other scope, attached to the person instead of the postcode
Specifications
LayerWhat you already haveWhat comes inDoes it move?
[…][…][…]No
[…][…][…]No
[…][…][…]No
Comparison
Replace

Mostly it replaces work that nobody was ever able to show you.

Add the layer

Everything else stays exactly where it is and keeps doing its own job.

Integrations and dependencies

Qs-Wan Gateway (Required)

The gateway is the enforcement point, so a rule applies wherever the connection is terminated, in the office or not.

Tower Connection (The One That Can Block You)

With a gateway’s Tower Connection off, a rule change saves and the intent is recorded, but it isn’t pushed. It converges when the gateway is reachable again, and the console tells you the difference.

User Profiles And Device Certificates (Required For Per-User Rules)

A per-user rule needs a profile to attach to. One profile can carry several devices, each with its own certificate, across several gateways.

Qnova Client (Nothing To Configure)

No rule list and no local setting. Reconnection is what reapplies the rules, and connection outcomes are kept in the client’s own log and notification history.

Proof

100%

of communications encrypted, always with post-quantum cryptography, including the establishment of the tunnels themselves.

10

Portuguese startups were named most promising for 2025 by EU-Startups on 17 February 2025, and QuantumNova was one of them.

2023

is the year QuantumNova was founded, which makes three full years of it in 2026.

Credentials

Tell us the rule you're least sure is still running.

Name one rule you’d have to go and check before swearing to it, and say whether it’s really about a place or about a person. We’ll show you both scopes in a console, applied in real time on a network shaped like yours, and you’ll see what reconnection does to a device that missed the last three changes.

Frequently Asked Questions

Firewall rules in QS-WAN decide what a connection is allowed to reach once it’s inside, and they’re written with one of two owners: a gateway or a user. Gateway rules cover what that gateway serves, which suits anything about a site or a branch. User rules follow the person, so the rule is the same from a hotel as it is from a desk.

The scope, and that’s the whole difference. A gateway rule is about a place and applies to everything that gateway serves; a user rule is about a person and travels with them. If you can’t decide which one a rule needs, ask whether it would still be true if the person moved to another city.

No. Rules are applied to the gateways in real time, so a change doesn’t wait for a scheduled slot or a service restart. That’s the part people find hardest to believe, mostly because of every other firewall they’ve ever touched.

It comes back on the current rules. Rules are reapplied every time a device reconnects, so a laptop that spent a fortnight in a bag picks up what changed while it was away instead of keeping the access it had in March. You don’t have to chase the device or wait for someone to bring it in.

Not necessarily, and this is worth knowing before an audit rather than during one. The database is the authority for what you configured, and propagation out to gateways is best effort, so a saved rule proves the intent was recorded. A gateway with Tower Connection off converges when it’s reachable again, and the console shows you that difference instead of a green tick it hasn’t earned.

Still unsure
Next

network access control

Access control decides what gets in at all. Firewall rules decide what it’s allowed to reach afterwards.

security policy management

The rules that live on the device itself, like USB ports and protection settings, travel in a different vehicle: a signed company policy.

microsegmentation

VLANs, LANs and the edges between them are the objects your rules point at, so it helps if they’re drawn the way you actually work.

Tell us the rule you're least sure is still running.

Name one rule you’d have to go and check before swearing to it, and say whether it’s really about a place or about a person. We’ll show you both scopes in a console, applied in real time on a network shaped like yours, and you’ll see what reconnection does to a device that missed the last three changes.

Resources

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top