Are multiple machines required to implement BorderWare?
No. BorderWare is implemented on a single IBM-compatible machine. The firewall is intended to be used as a stand-alone system. BorderWare incorporates separate kernel-level packet-filters on each interface which means it does not need external packet-filtering capabilities to be implemented by wrapping packet-filtering routers around it. The common firewall network setup, with an internal and external router and application servers running on a bastion host in the middle, can be replaced with a single BorderWare machine.