LOGIC TELECOM
Tech worldJuly 26, 20262 min read

Kaspersky NGFW 1.2 adds virtual contexts and resilient routing

Kaspersky has released a major NGFW 1.2 update. We examine virtual contexts, routing, resilience and the checks required in an enterprise pilot.

A next-generation firewall segmenting an enterprise network and redundant routes
Contents

Kaspersky announced NGFW 1.2 on 8 July 2026, describing it as the product’s largest update since launch. The release expands network segmentation, routing, change control and resilience monitoring.

Confirmed changes

Virtual Security System contexts allow independent logical instances with their own policies and routing tables to run on one physical appliance. Other additions include policy-based routing, a pre-commit configuration diff, IP SLA tracking with a backup static route, site-to-site IPsec VPN using IKEv2, anti-spoofing and SNMP monitoring for clusters and BGP/OSPF neighbours.

Kaspersky reports up to 140 Gbit/s in NGFW mode on its largest KX-3500 appliance, more than 6,000 detected applications and support for 100,000 firewall rules. These are vendor figures and need validation against the customer’s packet sizes, encrypted traffic and enabled security functions.

Logical separation has shared dependencies

Virtual contexts separate policy and routing, but they still share a physical platform. A pilot should test resource allocation, noisy-neighbour behaviour, administrator boundaries, configuration backup, platform updates and cluster failover.

Where physical separation or different protection classes are mandatory, one appliance may remain unsuitable regardless of the number of contexts.

Test the operating process

Change review should connect every rule to a service and owner, identify overly broad access, require peer review, validate metrics after deployment and preserve a tested rollback.

The pilot should cover throughput and latency with the required inspection, cluster and provider failover, session-table pressure, configuration rollback, SIEM export, monitoring integration, upgrade behaviour and false positives.

Registry and certification status should be checked against the applicable requirements at procurement time.

Conclusion

NGFW 1.2 addresses relevant enterprise operations: logical separation, resilient routing, VPN, change audit and routing-protocol monitoring. Suitability still depends on a pilot with real policies and traffic.

Zero Trust architecture explains why access should be granted to individual resources rather than an entire internal network. SLIs and SLOs provide a way to measure network-service reliability.

Source: Kaspersky’s official announcement dated 8 July 2026.

Primary source: Kaspersky: Kaspersky NGFW 1.2 update

SecurityInfrastructureResilience

Read also