The Ruijie enterprise network stack combines two product lines under Ruijie Cloud — the RG-WALL 1600 enterprise NGFW with AI-driven threat detection, and the Cybrey Cloud line of L3/L2+ switches, cloud-managed firewalls, routers, and Wi-Fi 7 access points. AGH is the Solution Provider for Hong Kong and APAC, delivering and integrating both lines under a single Ruijie Cloud tenant so the perimeter, the access fabric, and the wireless layer are configured and audited together.
Most enterprise perimeters still run a stack of point appliances: a firewall, a separate IPS, a separate URL filter, a separate sandbox, a separate DDoS scrubber, and a separate management console for each. The result is high CapEx on hardware, high OpEx on policy maintenance, and — most importantly — delayed signal. New attack patterns are spotted by one box but not propagated to the others for days. And >50% of modern attacks use private protocols or low-and-slow behaviour that signature-based detection cannot catch.
Private C&C channels use keys the defender does not have, so static-rule engines — IPS, AV, threat-intel matching — cannot inspect them. Behavioural AI is the only practical defence.
Firewall + IPS + URL filter + WAF + DDoS scrubber — five racks, five licences, five policy surfaces. Each new attack type means another appliance and another console.
Analysts spend 3 days per event moving evidence between consoles, correlating timestamps by hand, and writing triage notes that nobody re-reads. Consolidated telemetry and AI-assisted triage compress this to hours.
Most legacy URL / TI feeds refresh weekly or monthly. Adversaries rotate domains and IPs hourly. The Ruijie stack pulls from BrightCloud and other clouds with hourly updates, and ingests Google and Kaspersky streams on a continuous basis.
The RG-WALL inspects every packet through three coordinated layers — signature-based detection, multi-source threat-intelligence correlation, and AI behaviour analysis. The three layers share a context and a logging pipeline; one event that scores positive at one layer is enriched by the others. Operations are centralised through Ruijie Cloud; devices self-organise into SON-managed groups that share topology, configuration, and policy updates automatically.
TianMu Lab IPS library with 24,000+ rules across 90+ categories — weekly cadence, the fastest in the industry per vendor benchmarks. Covers known CVEs, exploit kits, worm patterns, and botnet C&C list updates.
BrightCloud (URL & app categorisation — the top-1 vendor cited by leading security vendors and cloud providers), Kaspersky, and Google feeds, combined with Ruijie's own aggregated TI stream. Hourly updates versus the weekly or monthly cadence of legacy stacks.
A built-in AI engine combining One-Class SVM, Isolation Forest, VAE, LSTM, and Open Set Recognition. Detects private-protocol C&C channels, slow brute-force on SSH / RDP, WebShell drop-ins, HTTP / DNS / ICMP tunnels, HTTPS callbacks, rebound shells, and domain-fronting — patterns that signature rules cannot match.
Ruijie Cloud delivers a single pane for topology, alerting, policy simulation, and AI-assisted troubleshooting. Self-Organizing Network (SON) propagates configuration across the entire estate; SSL VPN for up to 500–1000 concurrent remote users is included lifetime-free.
The Ruijie RG-WALL stack is built around three design principles — consolidate what can be consolidated, fuse intelligence from multiple top-tier feeds, and add a behaviour layer that does not depend on signatures. Each pillar addresses a specific failure mode of legacy perimeters.
One appliance carries IPS, antivirus, URL filtering, application control, built-in WAF, and SSL decryption. The WAF engine has both rule and semantic engines out of the box — covering the OWASP Top 10 web attacks without a second appliance. Underneath the network stack, a programmable chip delivers sustained throughput even when all threat engines run together — no more “throughput drops when you turn on the security”.
BrightCloud provides URL / application categorisation — billions of URLs, millions of apps, with AI-adapted training that boosts detection on minority-language traffic. Kaspersky and Google feeds contribute malware and phishing intelligence. Ruijie's own TI layer aggregates all three plus the vendor's own honeypot-derived signals. The combined coverage closes the gap when any one feed is delayed.
Behavioural models — One-Class SVM, Isolation Forest, VAE, LSTM, Open Set Recognition — watch connection patterns, protocol anomalies, and timing characteristics. The engine flags private-protocol C&C channels where signature rules have nothing to match, low-and-slow brute force on SSH and RDP, WebShell drop-ins, encrypted-tunnel exfiltration, and HTTPS callbacks to attacker-controlled infrastructure. Detection surfaces with confidence scoring, not just a binary hit/miss.
The RG-WALL 1600 series are the enterprise-flagship SKUs of the Ruijie NGFW line. Both run the full software stack — IPS, antivirus, threat-intel correlation, URL / app control, built-in WAF, SD-WAN — with the same policy surface and the same Ruijie Cloud orchestration. SKU choice is driven by site throughput requirement and by the number of SSL VPN tunnels you need.
10 Gbps threat-protection throughput. 8 × 1G Base-T, 1 × 1G SFP, 1 × 10G SFP+. 500 lifetime-free SSL VPN tunnels. Cloud-managed. Routing, NAT, VPN, and the full security stack are enabled by a single licence tier.
15 Gbps threat-protection throughput. 8 × 1G Base-T, 2 × 1G SFP, 4 × 10G SFP+. 500+ SSL VPN tunnels with headroom for surge. Same single-licence enablement as the Z3200-S; the choice is interface density and headroom.
The Ruijie Cybrey Cloud wireless line covers the full enterprise footprint with Wi-Fi 7 and Wi-Fi 6 access points — ceiling-mount for high-density offices and classrooms, wallplate for in-room coverage in hotels and hospitals, IP-rated outdoor for courtyards and perimeter — and the RG-CNC access controllers that anchor multi-site deployments. All managed from the same Ruijie Cloud surface as the firewall and switch lines, so the wireless layer, the perimeter, and the access fabric are configured and audited together.
Tri-radio Wi-Fi 7 ceiling AP for the highest-density offices, lecture halls, and conference spaces. Multi-gigabit PoE uplink, BSS coloring across all bands, MU-MIMO, and the full 802.11be feature set. Roaming, band steering, and airtime fairness are coordinated at the Ruijie Cloud controller layer so a dense deployment behaves like one fabric.
Mid-tier dual-radio ceiling APs for branch and standard-density office deployments. RG-CAP72-I delivers the full Wi-Fi 7 feature set; RG-CAP62-I provides a cost-effective Wi-Fi 6 path for sites not yet on Wi-Fi 7. Both are managed from the same Ruijie Cloud surface and share policy with the higher-tier RG-CAP73Max-I.
RG-CAP73-O is the IP-rated Wi-Fi 7 outdoor AP for courtyards, parking decks, and perimeter fencing; pairs with the directional RG-ANT90-T6 / RG-ANT30-T2 / RG-ANT30-D2 antennas for long-range coverage. RG-CAP72-WP is the Wi-Fi 7 wallplate AP that drops into in-room boxes for hotels, hospitals, and MTUs where each room needs its own SSID.
On-premises or co-located wireless controllers — RG-CNC105 for small sites, RG-CNC312 for mid-size, RG-CNC312E for high-density or multi-tenant deployments. Centralize fast roaming (802.11r/k/v), per-user and per-AP isolation, rogue-AP detection, and orchestrate with Ruijie Cloud for multi-site visibility. The wireless controller is the bridge that lets the firewall, switch, and wireless lines share one management fabric.
The Ruijie Cybrey Cloud line goes beyond wireless — it covers the L3 / L2+ switches that form the access fabric, the RG-CF cloud-managed firewall line for site and branch deployments, and the RG-CR router line for SD-WAN edges and aggregation. Together with the RG-WALL enterprise NGFW and the RG-CAP Wi-Fi 7 access points, this is the full enterprise network — managed, monitored, and orchestrated from a single Ruijie Cloud tenant.
Full enterprise switch line under Ruijie Cloud — RG-CS87 and RG-CS85 for L3 aggregation, RG-CS63 and RG-CS62 for L3 access, RG-CS61 for L2+ access. All managed from the same Ruijie Cloud surface as the firewall and wireless lines. Stacking, MLAG, and Ruijie SON propagate topology, configuration, and policy updates across the access fabric automatically.
Cloud-managed firewall line for site and branch deployments — distinct from the on-prem RG-WALL 1600 enterprise NGFW. RG-CF50XS for mid-size sites, RG-CF30XS for branch aggregation, RG-CF10S for small branches. Same Ruijie Cloud management surface, same multi-source threat-intel feeds, but a smaller form factor and licence tier optimised for distributed sites that don't need full data-centre NGFW throughput.
Enterprise router line for SD-WAN edges and aggregation. RG-CR5016XS for headquarters-grade aggregation, RG-CR2010XS for regional sites, RG-CR0510XS for branch SD-WAN edges. All run SON-managed under Ruijie Cloud with the same policy surface as the firewall and switch lines — IPsec / SD-WAN overlay, BGP, QoS, and per-application routing are configured in one place and propagated automatically.
Ruijie Cloud is the orchestrator for all four product lines — RG-WALL firewalls, RG-CF branch firewalls, RG-CS switches, RG-CAP APs, RG-CNC controllers, and RG-CR routers share one tenant. Self-Organizing Network (SON) propagates configuration across the estate; SD-WAN overlays, AI-assisted troubleshooting, and per-site policy are configured once and applied everywhere. This is what lets AGH deliver the full Ruijie stack as a single managed service across HK + APAC.
AGH's role as the Solution Provider covers the full customer journey — pre-sales scoping, deployment and integration, first-line technical support, and ongoing customer success. The Ruijie product line is broader than the firewall alone: it includes the full enterprise network stack — access / aggregation switches, Wi-Fi 6 / Wi-Fi 7 access points, on-premises NAC (RG-OCE), and the Ruijie Cloud orchestrator — which means we can deliver and integrate the firewall into an end-to-end Ruijie-managed estate when that's the right answer.
For enterprises consolidating their stack — replacing a multi-vendor perimeter with a Ruijie-managed network — the AGH × Ruijie delivery model means one provider, one delivery contract, one support contract, and a single bilingual delivery team.
30 minutes with our team. We'll review your current stack, throughput profile, and integration points — and propose a phased deployment that lands the firewall in production without disrupting what's already working. No commitment.
Book a Discovery Call