One firewall, the whole stack.

DYNOBLE combines a kernel datapath with an intelligent control plane — everything from packet filtering to global threat intelligence in a single console.

eBPF/XDP datapath

Line-rate packet filtering with aya-based eBPF. Run native XDP or TC ingress and keep the hot path in the kernel — userspace only handles detection, blocking, and intelligence.

Live traffic & analytics

Real-time traffic stats, rate history, and top SYN sources with historical charts. Understand exactly what is hitting your box, and when.

SSH brute-force protection

Failed logins become automatic blocks with escalation, whitelists, and a live event feed. Attackers get stopped at the packet level before they reach sshd.

Postfix & mail-log analysis

SASL brute-force detection and connect/disconnect tracking straight from the mail server log — no extra agent, no log shipper.

GeoIP & ASN intelligence

Per-service country allow/deny lists and ASN blocklists using fast local MMDB lookups, with optional rich IP enrichment.

Global reputation sharing

A shared community ban list with provenance, trust weighting, and adaptive thresholds. Every firewall contributes; every firewall learns.

Outbound detection

SNI/Host attribution of suspicious outbound connections with per-site quarantine and false-positive learning — stop data exfiltration at the source.

Backup & restore

S3-compatible snapshot backup and restore of the full firewall state, so a rebuild is minutes, not a weekend.

Kernel

eBPF programs filter packets at the interface — native XDP or TC ingress, with per-CPU counters and a full blocklist trie.

Control

A daemon manages maps, watches logs, scores attacks, and syncs the blocklist to the datapath in real time.

Intelligence

GeoIP, ASN, and a shared global reputation feed — what one firewall learns, the whole fleet enforces.

See DYNOBLE on your servers

Tell us about your setup and we'll help you get DYNOBLE running.

Contact us