Extend your firewall. Protect your distributed WAN.
An executive marketing brochure and architecture brief for distributed enterprises: enhancing an existing next-generation firewall environment across MPLS and 4G/5G branch connectivity, while adding an encrypted WAN overlay that carries the same policy wherever the traffic travels.
LAYERED SECURITY ARCHITECTURE
Bridging enterprise firewalls and resilient multi-path WANs.
Provider MPLS links and high-speed 4G/5G cellular connections provide raw physical connectivity. Lira-VPN provides the cryptographic overlay, and your next-generation firewall enforces inspection and policy. Each layer keeps its own responsibility — that is what makes the design portable across carriers and transports.
Retain and leverage your existing next-generation firewall
Your existing NGFW remains the authority for enterprise security inspection and policy rules.
- Stateful firewalling and deep packet inspection
- Intrusion detection and prevention (IDS / IPS)
- Application control, protocol analysis and sandboxing
- Content, URL and web threat filtering
- Centralised internet access and outbound egress control
- Threat prevention, anti-virus and anti-malware
- Compliance logging, audit trails and event dispatch
Lira-VPN encrypted multi-path WAN overlay
An agile cryptographic overlay across legacy MPLS and high-speed 4G/5G.
- Carrier-independent encrypted inter-site tunnel mesh
- Automatic path failover between MPLS and 4G/5G
- Confidentiality across public and private links
- Policy enforcement that does not lapse during transport shifts
- Granular branch-to-branch least-privilege segmentation
- High-frequency tunnel health probing and rapid recovery
- Real-time network and tunnel telemetry
Correlated telemetry across network, identity and SIEM/SOC
Isolated packet metrics become high-context cyber-resilience intelligence.
- Firewall security logs correlated with transport telemetry
- Real-time link degradation, latency and packet-loss alerting
- Integration with enterprise SIEM, SOAR and managed SOC
- Identity-aware access control with existing directory services and MFA
- Endpoint detection and response context binding
- Centralised DNS security and malicious-domain interception
- Automated incident triage and root-cause determination
ARCHITECTURAL BREAKDOWN
Four places the architectural gap usually appears.
Where enterprise security controls and wide-area network transport most often fail to meet — and how the overlay closes each gap.
Why encrypt carrier MPLS traffic?
MPLS provides private transport SLAs, but private transport must never be equated with cryptographic confidentiality. Unencrypted MPLS remains exposed to carrier misconfiguration, provider infrastructure compromise and traffic interception.
“MPLS provides transport quality; Lira-VPN provides the cryptographic overlay.”
4G/5G failover without a bypass
Cellular connectivity crosses operator cores and the public Internet. The overlay ensures that failover to cellular routes through encrypted tunnels into the same inspection stack, preventing uncontrolled Internet breakouts at the branch.
The physical carrier changes. The security policy, inspection and logging do not.
Least-privilege branch segmentation
Branches should not be flat extensions of the head-office LAN. Segmentation across user, server, management, IoT and guest zones confines a branch incident locally instead of letting it move laterally across the enterprise.
Branch-to-branch communication is blocked by default and permitted on documented business need.
Correlated telemetry for SIEM / SOC
Tunnel health, jitter, packet loss and failover notifications are streamed into existing SIEM or SOC tooling, so transport degradation can be correlated with application response and firewall event logs.
Distinguish an application fault from a transport change in seconds, not hours.
How this relates to the rest of the site
The commercial summary of these ideas — what the overlay adds and what it preserves — is set out on the secure WAN overlay page. The packet-level design sits on the architecture page, and Lira-VPN’s place in the wider security stack on the security page.
CAPABILITY COMPARISON
Existing foundation versus recommended enhancement.
What an enterprise typically has today, and what changes when the overlay is introduced. Nothing in the left-hand column is removed.
| Area | Capability | Existing foundation | Recommended enhancement |
|---|---|---|---|
| Security | Next-generation firewall | Existing NGFW platform | Retain it and optimise policy rules across all WAN paths |
| IDS / IPS threat detection | Centralised NGFW IDS/IPS | Extend inspection coverage to 4G/5G failover and inter-branch traffic | |
| Content & web filtering | Head-office appliance | Preserve filtering policy during branch failover; prevent uncontrolled breakout | |
| Network | MPLS transport | Carrier MPLS (unencrypted) | Retain the transport SLA while adding the encrypted overlay |
| 4G/5G connectivity | Ad-hoc backup / internet link | Fully integrate it into the encrypted, policy-enforced WAN overlay | |
| Inter-site encryption | Variable / inconsistent | Consistent enterprise-grade encryption across all transport paths | |
| Failover architecture | Manual or route flapping | Automated, health-checked failover with no lapse in security posture | |
| Operations | Branch segmentation | Flat branch LANs | Micro-segmented zones: users, servers, management, IoT, guests |
| Branch-to-branch trust | Unrestricted lateral reach | Explicit, business-driven least-privilege access rules only | |
| Telemetry & monitoring | Siloed link up/down checks | Correlated WAN telemetry and firewall events in one dashboard | |
| Incident response | Fragmented troubleshooting | WAN context integrated into SIEM/SOC workflows |
Reproduced from the Lira-VPN enterprise cyber-resilience brochure (PDF). Recommendations describe a target design to be agreed for each environment — they are not claims about any specific deployment.
DELIVERY PLAN
Five stages, from validation to continuous improvement.
A phased approach designed for real branches: pilot with representative sites, onboard the rest in phases, integrate telemetry, then keep testing the design.
Architecture validation
Audit the existing WAN topology, firewall zones, routing tables and critical business applications so the target design aligns with live operations instead of disrupting them.
- Current-state network and security topology map
- Policy gap analysis across transports
- Target overlay and segmentation specification
Controlled pilot deployment
Deploy the overlay across two or three representative branches — one high-volume MPLS site, one site that relies on cellular backup and one business-critical location.
- Pilot gateways installed and dual-homed
- Failover and recovery testing under load
- Pilot acceptance sign-off
Progressive branch rollout
Phased migration of the remaining sites using documented runbooks and controlled cutover windows, verifying routing at each step and confirming that policy remains intact during transport changes.
- Phased branch gateway commissioning
- Per-site rollback procedures documented
- Branch micro-segmentation implemented
Security & operations integration
Connect overlay telemetry into central firewall logging, SIEM/SOC platforms, directory services and monitoring consoles, so VPN, firewall and monitoring data tell one story.
- Event forwarding and alert rules configured
- Unified NOC / SOC operations dashboards
- Incident-response runbooks updated
Continuous cyber-resilience improvement
Quarterly resilience validation, recovery simulations, policy audits and architecture roadmap refinement — resilience treated as an operating discipline rather than a one-off project.
- Quarterly WAN resilience and failover drills
- Annual architecture review and capacity planning
- Proactive advisory and optimisation reports
RACI GOVERNANCE
Who is responsible, accountable, consulted and informed.
Roles are agreed at the start of an engagement so that a WAN event, a policy change or an incident never lands in an undefined gap. A/R = accountable and responsible · C = consulted · I = informed.
| Activity | Client IT | Security team | Lira-VPN team | WAN provider |
|---|---|---|---|---|
| Next-generation firewall management | A / R | A / R | C | I |
| Carrier MPLS circuits | C | I | C | A / R |
| 4G/5G backup services | C | I | A / R | A / R |
| Lira-VPN overlay mesh | C | C | A / R | I |
| Core enterprise routing | A / R | C | C | C |
| Security policy enforcement | A / R | A / R | C | I |
| Branch micro-segmentation | A / R | A / R | C | I |
| WAN & telemetry monitoring | A / R | A / R | C | C |
| Security incident response | C | A / R | C | C |
| WAN degradation incidents | A / R | C | A / R | A / R |
| Configuration backups | A / R | C | C | I |
| Resilience & failover drills | A / R | A / R | A / R | C |
SECURITY PRINCIPLES
Ten principles that govern the design.
The rules the architecture is held to — useful when reviewing any proposed change to the network.
EXECUTIVE MARKETING BROCHURE & ARCHITECTURE BRIEF
Lira-VPN enterprise network security & cyber-resilience
The brochure version of this brief: value proposition, three-layer architecture, architectural deep dives, capability comparison, investment-protection scope, delivery roadmap, RACI governance and the ten security principles.
Download opens the PDF directly · no sign-up required · links are omitted in the PDF.
Also available: secure WAN overlay brochure · all resources.