This paper presents the architecture of information security systems for enterprise software-defined networks. Its main advantages are unified network configuration and monitoring, flexibility, efficient hardware use, total check of network traffic. The architecture has been implemented as a firewall. Our firewall algorithm was tested by the Mininet simulator. The results of network performance evaluation have confirmed the firewall efficiency by delays and bandwidth.