Sign in to the console.
First run? If no users exist, the first sign-in bootstraps an admin.
central manager · firewall + reverse-proxy WAF + streams + DNS
These bans are delivered to every agent on check-in and enforced in each agent's nftables. Removing one un-blocks it fleet-wide on the next check-in.
| IP / CIDR | Reason | Expires | Added |
|---|
Every agent's samples on one timeline. Agents do not share sample timestamps, so points are bucketed before they are summed — adding them raw would chart check-in jitter rather than traffic.
Busiest first. Open a host to see only its traffic, its rules and its bans.
| Agent | Address | WAF inspected | WAF blocked | Connections | FW dropped |
|---|
Every agent reports the addresses it has banned. This is the fleet roll-up: one row per address, showing which hosts independently found it. An address several edges banned on their own is a far stronger signal than one a single host saw once — those are the right candidates to promote to the Global Blocklist.
| Address | Country | Network | Hosts | Found by | Why | Hold |
|---|
Ban volume alone only says a host is noisy. Paired with the domains that host actually serves, it says what is under attack. Only here counts addresses no other host has seen — that separates a campaign aimed at this host from the internet background noise every edge sees.
| Host | Address | Bans | Permanent | Only here | Domains served | Top reasons |
|---|
Every question the fleet answered, and every zone transfer in both directions. Kept in a ring separate from the security event log, so ordinary query volume can never push a sinkhole or a refused transfer out of the record. Outbound rows are the AXFR an agent performs as a secondary, pulling a zone from its primary every refresh cycle — in this estate those are the transfers that actually happen, and they were invisible until now because only inbound transfer requests were ever recorded.
| When | Dir | Agent | Peer | Name | Type | Proto | Rcode | Recs | Flags | Kind |
|---|
| User | Role | Status | Security |
|---|
Roles: viewer reads · operator pushes blocks/config · admin manages users & settings. You cannot delete yourself or the last enabled admin.
Must match the console's public domain exactly for passkeys to work.
Outbound email for password-reset links (STARTTLS, port 587).
Turn a directory group into a hub role. While the switch below is off nothing changes — the stored role keeps governing, exactly as today. You can fill this in and use Test before committing to it.
Leaving “no rule matches” blank denies the login. That is deliberate: a user whose groups you have not accounted for should not quietly inherit a role.
| Group (name or full DN) | Role |
|---|
Read group membership straight from the domain. The service account only needs read access — this never writes to the directory. Ships switched off; use Test lookup to prove the filter and the rules against the real directory before activating.
Country, owning network (ASN) and enclosing netblock for every address in the console. Looked up locally from a database the hub holds, so no address is ever sent to a third party and nothing tips off the source you are investigating.
For a hub with no outbound access. Take dbip-country-lite-YYYY-MM.mmdb.gz and dbip-asn-lite-YYYY-MM.mmdb.gz from db-ip.com and upload each here; either the .gz or the unpacked .mmdb is accepted.
IP geolocation by DB-IP, used under CC BY 4.0.
Set your email to receive password-reset links.
| Session | Started |
|---|
Agent-wide WAF. These regex rules and auto-block thresholds apply to every request this host proxies. For rules scoped to a single site (host-routed overlays), use the Domains & App-WAF sub-tab.
| Domain | Avg ms | p95 ms | Samples | Status |
|---|
This is where an agent becomes a real reverse proxy. Each row maps one host (the Host: header a browser sends, e.g. app.example.com) to the upstream it should be proxied to (e.g. http://10.0.0.5:8000). One WAF listener can front many sites this way — the host header picks the backend, exactly like nginx server blocks or Pangolin resources.
The same host also selects an optional app-WAF overlay: extra rules that run in addition to the global ruleset, only for that site (different apps have different L7 weak spots). Clean requests are forwarded to that host's upstream; malicious ones get a 403 and can trip the firewall. A host with no upstream falls back to the agent's default [waf].upstream.
Point the public DNS record for each host at the agent's edge IP (see the guide → DNS setup). Agent-discovered domains appear here automatically; add, route, and protect more below. Non-HTTP services (mail, databases) are routed on the Streams tab.
| Host | App label | Upstream (backend) | Notes | Domain Rules |
|---|
Declare which host/domain accepts which traffic type — this ties the Proxy, Streams, and DNS tabs together so the operator states intent (e.g. app.example.com = http-proxy, mail.example.com = L4-stream, ns1.example.com = dns). Inventory + intent; enforcement lives on the respective tab.
| Host / domain | Traffic type | Note |
|---|
Not everything is HTTP. The stream proxy forwards raw TCP/UDP ports to a backend, so an agent protects mail (SMTP 25/587, SMTPS 465, IMAP 143, IMAPS 993, POP3 110/995), databases, or game servers the same way the WAF protects web apps. Banned source IPs are dropped at L3 by nftables before they reach the listener; a per-IP connection-rate limit bans floods on top of that.
These routes are hub-managed per agent and applied live — the selected agent rebinds its listeners on its next check-in, no restart. For TLS services many names share one port via SNI passthrough (add a server_name); the proxy peeks the ClientHello (never terminating TLS) and dials the matching backend.
| Name | Proto | Listen (ip:port) | Upstream (host:port) | SNI → upstream | Max conns/min |
|---|
Bind failures (privileged port, port in use) are logged by the agent and skip that route only. Ports < 1024 need the agent to run as root / with CAP_NET_BIND_SERVICE.
| Time | Actor | Action | Target | Detail |
|---|
Pick a platform. The installer/snippet comes with your hub URL and a valid enrollment token baked in, so a fresh agent auto-registers on first start.