| Filtering | Stateful nftables filtering; 6 rule actions (allow, block, reject, log, nat, redirect); 7 NAT types; alias groups (IP range, ASN, MAC, domain) |
| Threat prevention | Suricata IDS/IPS with live event consumption, nDPI application identification and DPI, threat-intelligence feeds |
| Content control | URL filtering, TLS inspection via managed MITM CA |
| VPN | WireGuard, IPsec/IKEv2 (strongSwan), OpenVPN, SSL-VPN portal |
| Routing & WAN | Multi-WAN, SD-WAN path policies and probes, BGP and OSPF (FRR) |
| Network services | DNS (Unbound), DHCP (Kea), traffic shaping (tc), WiFi controller (hostapd/CAPWAP), VoIP SBC (Kamailio/rtpengine), captive portal (FreeRADIUS) |
| Deploy pipeline | Database-compiled policy, atomic transactional nftables load, dry-run and rollback, GitOps config sync |
| Resilience | High availability (keepalived + conntrackd session sync), carrier-grade MEF OAM/CFM |
| Multi-vendor | Read-only monitoring and drift detection for OPNsense, Cisco, Fortinet, Palo Alto, Juniper, MikroTik and more |
| Databases | PostgreSQL 16 (79 migrations), Redis 7 |
| API | ~120 route modules across L3–L7 domains |
| Multi-tenancy | Organisation → tenant → sub-tenant; application-enforced isolation; per-tenant envelope-encrypted secrets |
| Host requirements | Linux host with nftables and elevated network capabilities (it manages the host datapath directly) |
| Backend stack | TypeScript on Node.js, Express, PostgreSQL, Redis, BullMQ workers |
| Frontend stack | React 18 with TypeScript, Vite, Redux Toolkit, Tailwind CSS, Leaflet maps, Monaco editor |
| Deployment | Bare metal, Docker Compose, Kubernetes (Helm), cloud VMs, virtual environments, air-gapped |