Product · Firewall

DYNOBLE Firewall

The inline eBPF/XDP firewall for your core servers. A full kernel datapath, an intelligent control plane, and everything you need to protect a production box.

What the Firewall does

Everything runs in one daemon, on one box — no agents, no telemetry pipeline.

eBPF/XDP datapath

Line-rate filtering with aya-based eBPF — native XDP or TC ingress, with a full blocklist trie and per-CPU counters.

Live traffic & analytics

Real-time stats, rate history, and top SYN sources with historical charts — know exactly what is hitting your box.

SSH brute-force protection

Failed logins become automatic blocks with escalation, whitelists, and a live event feed — stopped before they reach sshd.

Postfix & mail-log analysis

SASL brute-force detection and connect/disconnect tracking straight from the mail server log.

GeoIP & ASN intelligence

Per-service country allow/deny lists and ASN blocklists with fast local MMDB lookups, plus optional rich IP enrichment.

Global reputation sharing

Contributes to and enforces a shared community ban list with provenance, trust weighting, and adaptive thresholds.

How a block happens

From the first packet to a fleet-wide ban, in four steps.

Packet hits the interface

Ingress traffic reaches the NIC and the eBPF program — no userspace hop on the hot path.

eBPF filters at line rate

The datapath checks the blocklist trie and per-service rules in the kernel.

Userspace scores & learns

The daemon watches SSH, mail, and web logs and scores attackers in real time.

Blocks sync back

New blocks are pushed to the datapath immediately and shared with your fleet.

Under the hood

Linux

Ubuntu 24.04+ recommended · kernel 5.10+

x86_64

Full eBPF build flow supported

SQLite

WAL persistence — no external database

Protect your main box

The Firewall ships today. Edge — lightweight protection for the rest of your fleet — is on the roadmap.