Extend your firewall. Protect your distributed WAN.

An executive marketing brochure and architecture brief for distributed enterprises: enhancing an existing next-generation firewall environment across MPLS and 4G/5G branch connectivity, while adding an encrypted WAN overlay that carries the same policy wherever the traffic travels.

LAYERED SECURITY ARCHITECTURE

Bridging enterprise firewalls and resilient multi-path WANs.

Provider MPLS links and high-speed 4G/5G cellular connections provide raw physical connectivity. Lira-VPN provides the cryptographic overlay, and your next-generation firewall enforces inspection and policy. Each layer keeps its own responsibility — that is what makes the design portable across carriers and transports.

LAYER 3 · Security visibility & response Correlated telemetry · SIEM · SOC · incident response network + identity + endpoint events in one investigation LAYER 2 · Secure & resilient WAN transport Lira-VPN encrypted multi-path WAN overlay carrier-independent tunnels · failover · least-privilege segmentation LAYER 1 · Security enforcement — your existing NGFW Firewall · IDS/IPS · application control · content filtering the authority for enterprise security policy and inspection Carrier MPLSprivate circuit Broadband / Internetmulti-ISP 4G / 5G cellularresilient second path THE UNDERLAY CHANGES · THE POLICY DOES NOT
Physical connectivity at the bottom, the encrypted overlay in the middle, enforcement and response above it — each layer independent of the carrier beneath it.
LAYER 1 · ENFORCEMENT

Retain and leverage your existing next-generation firewall

Your existing NGFW remains the authority for enterprise security inspection and policy rules.

  • Stateful firewalling and deep packet inspection
  • Intrusion detection and prevention (IDS / IPS)
  • Application control, protocol analysis and sandboxing
  • Content, URL and web threat filtering
  • Centralised internet access and outbound egress control
  • Threat prevention, anti-virus and anti-malware
  • Compliance logging, audit trails and event dispatch
LAYER 2 · TRANSPORT

Lira-VPN encrypted multi-path WAN overlay

An agile cryptographic overlay across legacy MPLS and high-speed 4G/5G.

  • Carrier-independent encrypted inter-site tunnel mesh
  • Automatic path failover between MPLS and 4G/5G
  • Confidentiality across public and private links
  • Policy enforcement that does not lapse during transport shifts
  • Granular branch-to-branch least-privilege segmentation
  • High-frequency tunnel health probing and rapid recovery
  • Real-time network and tunnel telemetry
LAYER 3 · VISIBILITY

Correlated telemetry across network, identity and SIEM/SOC

Isolated packet metrics become high-context cyber-resilience intelligence.

  • Firewall security logs correlated with transport telemetry
  • Real-time link degradation, latency and packet-loss alerting
  • Integration with enterprise SIEM, SOAR and managed SOC
  • Identity-aware access control with existing directory services and MFA
  • Endpoint detection and response context binding
  • Centralised DNS security and malicious-domain interception
  • Automated incident triage and root-cause determination

ARCHITECTURAL BREAKDOWN

Four places the architectural gap usually appears.

Where enterprise security controls and wide-area network transport most often fail to meet — and how the overlay closes each gap.

01

Why encrypt carrier MPLS traffic?

MPLS provides private transport SLAs, but private transport must never be equated with cryptographic confidentiality. Unencrypted MPLS remains exposed to carrier misconfiguration, provider infrastructure compromise and traffic interception.

“MPLS provides transport quality; Lira-VPN provides the cryptographic overlay.”

02

4G/5G failover without a bypass

Cellular connectivity crosses operator cores and the public Internet. The overlay ensures that failover to cellular routes through encrypted tunnels into the same inspection stack, preventing uncontrolled Internet breakouts at the branch.

The physical carrier changes. The security policy, inspection and logging do not.

03

Least-privilege branch segmentation

Branches should not be flat extensions of the head-office LAN. Segmentation across user, server, management, IoT and guest zones confines a branch incident locally instead of letting it move laterally across the enterprise.

Branch-to-branch communication is blocked by default and permitted on documented business need.

04

Correlated telemetry for SIEM / SOC

Tunnel health, jitter, packet loss and failover notifications are streamed into existing SIEM or SOC tooling, so transport degradation can be correlated with application response and firewall event logs.

Distinguish an application fault from a transport change in seconds, not hours.

How this relates to the rest of the site

The commercial summary of these ideas — what the overlay adds and what it preserves — is set out on the secure WAN overlay page. The packet-level design sits on the architecture page, and Lira-VPN’s place in the wider security stack on the security page.

CAPABILITY COMPARISON

Existing foundation versus recommended enhancement.

What an enterprise typically has today, and what changes when the overlay is introduced. Nothing in the left-hand column is removed.

AreaCapabilityExisting foundationRecommended enhancement
SecurityNext-generation firewallExisting NGFW platformRetain it and optimise policy rules across all WAN paths
IDS / IPS threat detectionCentralised NGFW IDS/IPSExtend inspection coverage to 4G/5G failover and inter-branch traffic
Content & web filteringHead-office appliancePreserve filtering policy during branch failover; prevent uncontrolled breakout
NetworkMPLS transportCarrier MPLS (unencrypted)Retain the transport SLA while adding the encrypted overlay
4G/5G connectivityAd-hoc backup / internet linkFully integrate it into the encrypted, policy-enforced WAN overlay
Inter-site encryptionVariable / inconsistentConsistent enterprise-grade encryption across all transport paths
Failover architectureManual or route flappingAutomated, health-checked failover with no lapse in security posture
OperationsBranch segmentationFlat branch LANsMicro-segmented zones: users, servers, management, IoT, guests
Branch-to-branch trustUnrestricted lateral reachExplicit, business-driven least-privilege access rules only
Telemetry & monitoringSiloed link up/down checksCorrelated WAN telemetry and firewall events in one dashboard
Incident responseFragmented troubleshootingWAN context integrated into SIEM/SOC workflows

Reproduced from the Lira-VPN enterprise cyber-resilience brochure (PDF). Recommendations describe a target design to be agreed for each environment — they are not claims about any specific deployment.

DELIVERY PLAN

Five stages, from validation to continuous improvement.

A phased approach designed for real branches: pilot with representative sites, onboard the rest in phases, integrate telemetry, then keep testing the design.

Stage 01Weeks 1 – 2

Architecture validation

Audit the existing WAN topology, firewall zones, routing tables and critical business applications so the target design aligns with live operations instead of disrupting them.

  • Current-state network and security topology map
  • Policy gap analysis across transports
  • Target overlay and segmentation specification
Stage 02Weeks 3 – 4

Controlled pilot deployment

Deploy the overlay across two or three representative branches — one high-volume MPLS site, one site that relies on cellular backup and one business-critical location.

  • Pilot gateways installed and dual-homed
  • Failover and recovery testing under load
  • Pilot acceptance sign-off
Stage 03Weeks 5 – 8

Progressive branch rollout

Phased migration of the remaining sites using documented runbooks and controlled cutover windows, verifying routing at each step and confirming that policy remains intact during transport changes.

  • Phased branch gateway commissioning
  • Per-site rollback procedures documented
  • Branch micro-segmentation implemented
Stage 04Weeks 9 – 10

Security & operations integration

Connect overlay telemetry into central firewall logging, SIEM/SOC platforms, directory services and monitoring consoles, so VPN, firewall and monitoring data tell one story.

  • Event forwarding and alert rules configured
  • Unified NOC / SOC operations dashboards
  • Incident-response runbooks updated
Stage 05Ongoing

Continuous cyber-resilience improvement

Quarterly resilience validation, recovery simulations, policy audits and architecture roadmap refinement — resilience treated as an operating discipline rather than a one-off project.

  • Quarterly WAN resilience and failover drills
  • Annual architecture review and capacity planning
  • Proactive advisory and optimisation reports

RACI GOVERNANCE

Who is responsible, accountable, consulted and informed.

Roles are agreed at the start of an engagement so that a WAN event, a policy change or an incident never lands in an undefined gap. A/R = accountable and responsible · C = consulted · I = informed.

ActivityClient ITSecurity teamLira-VPN teamWAN provider
Next-generation firewall managementA / RA / RCI
Carrier MPLS circuitsCICA / R
4G/5G backup servicesCIA / RA / R
Lira-VPN overlay meshCCA / RI
Core enterprise routingA / RCCC
Security policy enforcementA / RA / RCI
Branch micro-segmentationA / RA / RCI
WAN & telemetry monitoringA / RA / RCC
Security incident responseCA / RCC
WAN degradation incidentsA / RCA / RA / R
Configuration backupsA / RCCI
Resilience & failover drillsA / RA / RA / RC

SECURITY PRINCIPLES

Ten principles that govern the design.

The rules the architecture is held to — useful when reviewing any proposed change to the network.

Preserve existing investmentDo not replace an existing security capability unless there is a demonstrated business or technical gap.
Defence in depthNo single security control is sufficient; security is layered at transport, perimeter and endpoint.
Least-privilege accessOnly documented, business-justified communication is allowed between sites and network segments.
Secure by defaultNew branches, tunnels and network paths start isolated and controlled until they are validated.
Consistent security during failoverA failure of the primary transport must never compromise, bypass or degrade security inspection.
Pervasive visibilityAll network and security events — from tunnel flaps to firewall drops — are observable and correlated.
Granular segmentationA compromise in one branch or segment must never automatically grant enterprise-wide reach.
Cryptographic confidentialitySensitive enterprise traffic is encrypted across both private carrier links and public cellular networks.
Guaranteed recoverabilityNetwork and security configurations are auditable, versioned, backed up and rapidly recoverable.
Continuous improvementSecurity and resilience are an ongoing operational discipline, not a one-off project.

EXECUTIVE MARKETING BROCHURE & ARCHITECTURE BRIEF

Lira-VPN enterprise network security & cyber-resilience

The brochure version of this brief: value proposition, three-layer architecture, architectural deep dives, capability comparison, investment-protection scope, delivery roadmap, RACI governance and the ten security principles.

Download opens the PDF directly · no sign-up required · links are omitted in the PDF.

Download brief (PDF)

Also available: secure WAN overlay brochure · all resources.