Feature suite

Everything required to run a secure, programmable edge.

Feature coverage spans routing, firewalling, VPN, identity, services, and observability.

Highlights at a glance

  • REST API with 100+ endpoints.
  • nftables-based firewall + NAT automation.
  • WireGuard + IPSec lifecycle orchestration.
  • Built-in Web UI for day-two operations.

Security and policy

Define zones, policies, and traffic shaping through a unified manager.

Firewall

Zone-based policies

Stateful filtering, inter-zone rules, and customizable actions.

NAT

SNAT, DNAT, and one-to-one

Full NAT lifecycle with persistence and API control.

Protection

DDoS mitigation

Rate limiting, connection tracking, and attack testing toolkit.

QoS

Traffic shaping

Interface-based QoS profiles with persistence.

Routing and WAN

Manage complex topologies with static, dynamic, and multi-WAN capabilities.

Static & dynamic routing

Static route management plus FRR-driven BGP/OSPF integration.

Multi-WAN orchestration

Health checks, failover, and weighted load balancing.

High availability

VRRP and conntrack synchronization with persistence.

Services and identity

Deliver critical network services from a single control plane.

DNS & DDNS

Forwarding, dynamic updates, and config history tracking.

DHCP + Relay

Pool management, reservations, and relay configuration APIs.

RADIUS support

Centralized authentication, accounting, and health checks.

VPN operations

WireGuard and IPSec tunnels with key management.