← Back to all products

Ruijie Enterprise Network Stack
Two Ruijie lines. One Ruijie Cloud. AGH delivery.

The Ruijie enterprise network stack combines two product lines under Ruijie Cloud — the RG-WALL 1600 enterprise NGFW with AI-driven threat detection, and the Cybrey Cloud line of L3/L2+ switches, cloud-managed firewalls, routers, and Wi-Fi 7 access points. AGH is the Solution Provider for Hong Kong and APAC, delivering and integrating both lines under a single Ruijie Cloud tenant so the perimeter, the access fabric, and the wireless layer are configured and audited together.

8-in-1
IPS · AV · URL · App · WAF · SD-WAN · TI · AI
24,000+
TianMu Lab IPS rules, weekly updates
Wi-Fi 7
RG-CAP series (Cybrey Cloud)
HK + APAC
AGH solution-provider delivery
Ruijie Cybrey Cloud product family — cloud-managed switches (RG-CS series), firewalls (RG-CF series), routers (RG-CR series), and Wi-Fi 7 access points (RG-CAP series), centrally orchestrated under Ruijie Cloud

Ruijie RG-WALL is a partner product — AGH is the Solution Provider

The Ruijie RG-WALL Next-Generation Firewall series is developed, owned, and maintained by Ruijie Networks (锐捷网络), a leading Chinese enterprise networking vendor listed on the Shenzhen Stock Exchange. AGH is the Solution Provider for Hong Kong and APAC, with responsibility for sales, deployment, first-line technical support, and customer success in this territory. All product specifications, capabilities, performance figures, and technical claims on this page are based on material provided by Ruijie Networks and are reproduced with the vendor's consent. The product is sold under Ruijie's trademark; references to “Ruijie” and “RG-WALL” are to the vendor's product line. AGH does not develop, manufacture, or maintain the underlying technology, and the AI-driven detection engine, TianMu Lab IPS library, and BrightCloud / Kaspersky / Google threat-intelligence integrations are proprietary assets of Ruijie Networks and their respective suppliers.

Stacked appliances, stale signatures, and unknown threats at the perimeter

Most enterprise perimeters still run a stack of point appliances: a firewall, a separate IPS, a separate URL filter, a separate sandbox, a separate DDoS scrubber, and a separate management console for each. The result is high CapEx on hardware, high OpEx on policy maintenance, and — most importantly — delayed signal. New attack patterns are spotted by one box but not propagated to the others for days. And >50% of modern attacks use private protocols or low-and-slow behaviour that signature-based detection cannot catch.

50%+
Of intrusions use private-protocol C&C channels

Private C&C channels use keys the defender does not have, so static-rule engines — IPS, AV, threat-intel matching — cannot inspect them. Behavioural AI is the only practical defence.

4+
Separate appliances for the same perimeter

Firewall + IPS + URL filter + WAF + DDoS scrubber — five racks, five licences, five policy surfaces. Each new attack type means another appliance and another console.

3 days
Mean-time-to-triage per alert, current stacks

Analysts spend 3 days per event moving evidence between consoles, correlating timestamps by hand, and writing triage notes that nobody re-reads. Consolidated telemetry and AI-assisted triage compress this to hours.

weekly
Stale threat-intel updates in legacy stacks

Most legacy URL / TI feeds refresh weekly or monthly. Adversaries rotate domains and IPs hourly. The Ruijie stack pulls from BrightCloud and other clouds with hourly updates, and ingests Google and Kaspersky streams on a continuous basis.

Layered detection on a single appliance

The RG-WALL inspects every packet through three coordinated layers — signature-based detection, multi-source threat-intelligence correlation, and AI behaviour analysis. The three layers share a context and a logging pipeline; one event that scores positive at one layer is enriched by the others. Operations are centralised through Ruijie Cloud; devices self-organise into SON-managed groups that share topology, configuration, and policy updates automatically.

L1
Signature detection

TianMu Lab IPS library with 24,000+ rules across 90+ categories — weekly cadence, the fastest in the industry per vendor benchmarks. Covers known CVEs, exploit kits, worm patterns, and botnet C&C list updates.

L2
Multi-source threat intelligence

BrightCloud (URL & app categorisation — the top-1 vendor cited by leading security vendors and cloud providers), Kaspersky, and Google feeds, combined with Ruijie's own aggregated TI stream. Hourly updates versus the weekly or monthly cadence of legacy stacks.

L3
AI behaviour engine

A built-in AI engine combining One-Class SVM, Isolation Forest, VAE, LSTM, and Open Set Recognition. Detects private-protocol C&C channels, slow brute-force on SSH / RDP, WebShell drop-ins, HTTP / DNS / ICMP tunnels, HTTPS callbacks, rebound shells, and domain-fronting — patterns that signature rules cannot match.

OPS
Cloud-native operations

Ruijie Cloud delivers a single pane for topology, alerting, policy simulation, and AI-assisted troubleshooting. Self-Organizing Network (SON) propagates configuration across the entire estate; SSL VPN for up to 500–1000 concurrent remote users is included lifetime-free.

All-in-one security · Multi-source intelligence · AI-driven detection

The Ruijie RG-WALL stack is built around three design principles — consolidate what can be consolidated, fuse intelligence from multiple top-tier feeds, and add a behaviour layer that does not depend on signatures. Each pillar addresses a specific failure mode of legacy perimeters.

PILLAR 1 · ALL-IN-ONE
Consolidated stack, programmable silicon

One appliance carries IPS, antivirus, URL filtering, application control, built-in WAF, and SSL decryption. The WAF engine has both rule and semantic engines out of the box — covering the OWASP Top 10 web attacks without a second appliance. Underneath the network stack, a programmable chip delivers sustained throughput even when all threat engines run together — no more “throughput drops when you turn on the security”.

PILLAR 2 · MULTI-SOURCE INTELLIGENCE
Three independent feeds, hourly updates

BrightCloud provides URL / application categorisation — billions of URLs, millions of apps, with AI-adapted training that boosts detection on minority-language traffic. Kaspersky and Google feeds contribute malware and phishing intelligence. Ruijie's own TI layer aggregates all three plus the vendor's own honeypot-derived signals. The combined coverage closes the gap when any one feed is delayed.

PILLAR 3 · AI BEHAVIOUR ENGINE
Unknown-threat detection built-in

Behavioural models — One-Class SVM, Isolation Forest, VAE, LSTM, Open Set Recognition — watch connection patterns, protocol anomalies, and timing characteristics. The engine flags private-protocol C&C channels where signature rules have nothing to match, low-and-slow brute force on SSH and RDP, WebShell drop-ins, encrypted-tunnel exfiltration, and HTTPS callbacks to attacker-controlled infrastructure. Detection surfaces with confidence scoring, not just a binary hit/miss.

Two SKUs for mid-size to large-enterprise perimeters

The RG-WALL 1600 series are the enterprise-flagship SKUs of the Ruijie NGFW line. Both run the full software stack — IPS, antivirus, threat-intel correlation, URL / app control, built-in WAF, SD-WAN — with the same policy surface and the same Ruijie Cloud orchestration. SKU choice is driven by site throughput requirement and by the number of SSL VPN tunnels you need.

RG-WALL 1600-Z3200-S
Mid-size enterprise · branch aggregation

10 Gbps threat-protection throughput. 8 × 1G Base-T, 1 × 1G SFP, 1 × 10G SFP+. 500 lifetime-free SSL VPN tunnels. Cloud-managed. Routing, NAT, VPN, and the full security stack are enabled by a single licence tier.

RG-WALL 1600-Z5100-S
Large enterprise · regional headquarters

15 Gbps threat-protection throughput. 8 × 1G Base-T, 2 × 1G SFP, 4 × 10G SFP+. 500+ SSL VPN tunnels with headroom for surge. Same single-licence enablement as the Z3200-S; the choice is interface density and headroom.

Wi-Fi 7 ceiling, wallplate, and outdoor APs — all cloud-managed

The Ruijie Cybrey Cloud wireless line covers the full enterprise footprint with Wi-Fi 7 and Wi-Fi 6 access points — ceiling-mount for high-density offices and classrooms, wallplate for in-room coverage in hotels and hospitals, IP-rated outdoor for courtyards and perimeter — and the RG-CNC access controllers that anchor multi-site deployments. All managed from the same Ruijie Cloud surface as the firewall and switch lines, so the wireless layer, the perimeter, and the access fabric are configured and audited together.

RG-CAP73Max-I
Wi-Fi 7 high-density ceiling AP (flagship)

Tri-radio Wi-Fi 7 ceiling AP for the highest-density offices, lecture halls, and conference spaces. Multi-gigabit PoE uplink, BSS coloring across all bands, MU-MIMO, and the full 802.11be feature set. Roaming, band steering, and airtime fairness are coordinated at the Ruijie Cloud controller layer so a dense deployment behaves like one fabric.

RG-CAP72-I · RG-CAP62-I
Wi-Fi 7 / Wi-Fi 6 indoor ceiling APs (mid-tier)

Mid-tier dual-radio ceiling APs for branch and standard-density office deployments. RG-CAP72-I delivers the full Wi-Fi 7 feature set; RG-CAP62-I provides a cost-effective Wi-Fi 6 path for sites not yet on Wi-Fi 7. Both are managed from the same Ruijie Cloud surface and share policy with the higher-tier RG-CAP73Max-I.

RG-CAP73-O · RG-CAP72-WP
Outdoor + wallplate APs (Wi-Fi 7)

RG-CAP73-O is the IP-rated Wi-Fi 7 outdoor AP for courtyards, parking decks, and perimeter fencing; pairs with the directional RG-ANT90-T6 / RG-ANT30-T2 / RG-ANT30-D2 antennas for long-range coverage. RG-CAP72-WP is the Wi-Fi 7 wallplate AP that drops into in-room boxes for hotels, hospitals, and MTUs where each room needs its own SSID.

RG-CNC105 · RG-CNC312 · RG-CNC312E
Cybrey Cloud wireless controllers

On-premises or co-located wireless controllers — RG-CNC105 for small sites, RG-CNC312 for mid-size, RG-CNC312E for high-density or multi-tenant deployments. Centralize fast roaming (802.11r/k/v), per-user and per-AP isolation, rogue-AP detection, and orchestrate with Ruijie Cloud for multi-site visibility. The wireless controller is the bridge that lets the firewall, switch, and wireless lines share one management fabric.

Switches, cloud-managed firewalls, and routers — under one Ruijie Cloud

The Ruijie Cybrey Cloud line goes beyond wireless — it covers the L3 / L2+ switches that form the access fabric, the RG-CF cloud-managed firewall line for site and branch deployments, and the RG-CR router line for SD-WAN edges and aggregation. Together with the RG-WALL enterprise NGFW and the RG-CAP Wi-Fi 7 access points, this is the full enterprise network — managed, monitored, and orchestrated from a single Ruijie Cloud tenant.

RG-CS87 · RG-CS85 · RG-CS63 · RG-CS62 · RG-CS61
Cybrey Cloud switches (L3 + L2+ stack)

Full enterprise switch line under Ruijie Cloud — RG-CS87 and RG-CS85 for L3 aggregation, RG-CS63 and RG-CS62 for L3 access, RG-CS61 for L2+ access. All managed from the same Ruijie Cloud surface as the firewall and wireless lines. Stacking, MLAG, and Ruijie SON propagate topology, configuration, and policy updates across the access fabric automatically.

RG-CF50XS · RG-CF30XS · RG-CF10S
Cybrey Cloud firewalls (branch + site)

Cloud-managed firewall line for site and branch deployments — distinct from the on-prem RG-WALL 1600 enterprise NGFW. RG-CF50XS for mid-size sites, RG-CF30XS for branch aggregation, RG-CF10S for small branches. Same Ruijie Cloud management surface, same multi-source threat-intel feeds, but a smaller form factor and licence tier optimised for distributed sites that don't need full data-centre NGFW throughput.

RG-CR5016XS · RG-CR2010XS · RG-CR0510XS
Cybrey Cloud routers (SD-WAN edge)

Enterprise router line for SD-WAN edges and aggregation. RG-CR5016XS for headquarters-grade aggregation, RG-CR2010XS for regional sites, RG-CR0510XS for branch SD-WAN edges. All run SON-managed under Ruijie Cloud with the same policy surface as the firewall and switch lines — IPsec / SD-WAN overlay, BGP, QoS, and per-application routing are configured in one place and propagated automatically.

Ruijie Cloud · SON · SD-WAN
Single-pane management for the whole stack

Ruijie Cloud is the orchestrator for all four product lines — RG-WALL firewalls, RG-CF branch firewalls, RG-CS switches, RG-CAP APs, RG-CNC controllers, and RG-CR routers share one tenant. Self-Organizing Network (SON) propagates configuration across the estate; SD-WAN overlays, AI-assisted troubleshooting, and per-site policy are configured once and applied everywhere. This is what lets AGH deliver the full Ruijie stack as a single managed service across HK + APAC.

Solution Provider — sales, deployment, and first-line support across HK + APAC
covering the full Ruijie network stack — switches, APs, NAC, firewalls

AGH's role as the Solution Provider covers the full customer journey — pre-sales scoping, deployment and integration, first-line technical support, and ongoing customer success. The Ruijie product line is broader than the firewall alone: it includes the full enterprise network stack — access / aggregation switches, Wi-Fi 6 / Wi-Fi 7 access points, on-premises NAC (RG-OCE), and the Ruijie Cloud orchestrator — which means we can deliver and integrate the firewall into an end-to-end Ruijie-managed estate when that's the right answer.

For enterprises consolidating their stack — replacing a multi-vendor perimeter with a Ruijie-managed network — the AGH × Ruijie delivery model means one provider, one delivery contract, one support contract, and a single bilingual delivery team.

What AGH delivers
  • Site survey & sizing — throughput, interfaces, link aggregation
  • Pilot deployment — single site, single rule pack, single TI tier
  • Production rollout — multi-site, with policy templates and SON enrollment
  • Stack consolidation — integrating switches, APs, NAC under one Ruijie Cloud tenant
  • Bilingual rule configuration (EN / SC / TC)
  • Integration with existing observability stack (SIEM / SOAR / log shipping)
  • First-line technical support (L1) — AGH
  • Vendor escalation (L2 / L3) — Ruijie Networks
  • Quarterly capacity & policy review

Ready to consolidate the perimeter?

30 minutes with our team. We'll review your current stack, throughput profile, and integration points — and propose a phased deployment that lands the firewall in production without disrupting what's already working. No commitment.

Book a Discovery Call