eBPF/XDP datapath
Line-rate filtering with aya-based eBPF — native XDP or TC ingress, with a full blocklist trie and per-CPU counters.
The inline eBPF/XDP firewall for your core servers. A full kernel datapath, an intelligent control plane, and everything you need to protect a production box.
Everything runs in one daemon, on one box — no agents, no telemetry pipeline.
Line-rate filtering with aya-based eBPF — native XDP or TC ingress, with a full blocklist trie and per-CPU counters.
Real-time stats, rate history, and top SYN sources with historical charts — know exactly what is hitting your box.
Failed logins become automatic blocks with escalation, whitelists, and a live event feed — stopped before they reach sshd.
SASL brute-force detection and connect/disconnect tracking straight from the mail server log.
Per-service country allow/deny lists and ASN blocklists with fast local MMDB lookups, plus optional rich IP enrichment.
Contributes to and enforces a shared community ban list with provenance, trust weighting, and adaptive thresholds.
From the first packet to a fleet-wide ban, in four steps.
Ingress traffic reaches the NIC and the eBPF program — no userspace hop on the hot path.
The datapath checks the blocklist trie and per-service rules in the kernel.
The daemon watches SSH, mail, and web logs and scores attackers in real time.
New blocks are pushed to the datapath immediately and shared with your fleet.
Ubuntu 24.04+ recommended · kernel 5.10+
Full eBPF build flow supported
WAL persistence — no external database
The Firewall ships today. Edge — lightweight protection for the rest of your fleet — is on the roadmap.