Axonwall 1.0 Release • Pure Linux 6.12 LTS & nftables Engine

The Next-Generation Open Source Firewall Built on Linux

Replace legacy BSD packet filters and accidental admin lockouts. Axonwall delivers line-rate multi-core performance, Junos-style commit-confirm with automated rollback, and a reactive Next.js 16 console.

100 Gbps
Wire-Speed nftables
60s
Commit-Confirm Rollback
0ms
CAKE Bufferbloat Latency
100%
Open Source Core
https://axonwall.internal/firewall
Commit-Confirm: 00:48 auto-rollback
TABLE INET AXONWALL
28,450 pkts/s
0 dropped packets on LAN
SMART QOS (CAKE)
A+ Bufferbloat Grade
DiffServ Prioritization Active
SURICATA IDS/IPS
NFQUEUE Fail-Open
Zero downtime on reload
# nft -f /etc/axonwall/candidate.nft (atomic transaction)
table inet axonwall {
  chain forward { type filter hook forward priority 0; policy drop; }
  chain postrouting { type nat hook postrouting priority srcnat; oifname "eth0" masquerade; }
}
✓ Atomic transaction completed in 1.4ms. Commit-confirm timer armed.
The Linux Advantage

Why We Left FreeBSD Behind

For 20 years, open-source firewalls relied on FreeBSD. But today, the modern internet runs on Linux. Here is why Axonwall is the definitive architectural upgrade.

nftables Line-Rate

FreeBSD pf locks on single cores under heavy NAT loads. Linux nftables scales across all CPU cores with lockless flow tables and multi-queue RSS.

Commit-Confirm Rollback

No more fear of applying rules remotely. If a mistake cuts your connection, the Go daemon automatically reverts to the last-known-good atomic bundle within 60 seconds.

Kernel DCO VPN

WireGuard runs natively in the Linux kernel, and OpenVPN 2.6 uses kernel Data Channel Offload (ovpn-dco), eliminating user-space context switches for line-rate encryption.

Cloud-Native & Hybrid

Axonwall manages strictly table inet axonwall without touching Docker or Kubernetes tables. Deploy on Bare Metal, VM, Docker, or Kubernetes CNF pods.

Enterprise Feature Set

Full OPNsense Parity, Built for 2026

Every critical security service—from ISC Kea DHCP to FRRouting BGP and Suricata IDS—re-architected for Linux.

Suricata IDS/IPS (Fail-Open)

Integrated NFQUEUE fail-open bypass. If Suricata restarts or crashes under DDoS load, packet flow bypasses the queue rather than severing all network connectivity.

Smart QoS (CAKE + IFB)

Linux CAKE queue discipline with automatic DiffServ DSCP prioritization, TCP ACK filtering, and IFB virtual ingress shaping. Eliminates latency during full downloads.

CrowdSec & Dynamic Feeds

CrowdSec LAPI bouncer directly binds attacker IPs to native nftables interval sets with zero ruleset reload. Dynamic URL table feeds, GeoIP, and ASN blocking.

High Availability (VRRP + State Sync)

Keepalived VRRP active/standby virtual routers combined with Conntrackd FTFW UDP state replication. Zero dropped sessions on failover.

FRRouting (BGP / OSPF / BFD)

Production-grade enterprise dynamic routing powered by FRR. Full IPv4 and IPv6 BGP multi-homing with BFD sub-second link failure detection.

VictoriaMetrics Telemetry

Embedded high-resolution time series engine and NetFlow/IPFIX flow analyzer. Identify top bandwidth talkers and destination ports in real time.

Turnkey Systems

Pre-Configured Hardware Appliances

Factory burned-in, pre-loaded with Axonwall OS, and tested for maximum thermal reliability. Ships globally with next-day advance hardware replacement.

Branch & Home Lab

Axonwall Edge 10

$499

Silent, fanless aluminum chassis for home labs, branch offices, and edge deployments.

  • ✓ Quad-Core Intel x86 (Fanless)
  • ✓ 4x 2.5GbE RJ-45 (Intel i226)
  • ✓ 2x 10GbE SFP+ Ports
  • ✓ 16GB DDR5 RAM + 128GB NVMe
  • ✓ 2.5 Gbps WireGuard Throughput
Cellular Failover

Axonwall Edge 20-5G

$899

Integrated 5G Sub-6 modem with dual SIM redundancy for retail and mobile edge.

  • ✓ Octa-Core ARM64 / x86
  • ✓ Dual SIM 5G Sub-6 + GNSS
  • ✓ 4x 2.5GbE + 2x 10GbE SFP+
  • ✓ 802.3at PoE Power Input
  • ✓ Out-of-band management
Most Popular

Axonwall Rack 100

$1,699

1U rackmount appliance for medium enterprises, schools, and central headquarters.

  • ✓ Intel Xeon D 8-Core / 16-Thread
  • ✓ 8x 2.5GbE + 4x 10GbE SFP+
  • ✓ 32GB ECC RAM (expandable to 128GB)
  • ✓ Dual Redundant 300W PSUs
  • ✓ 10 Gbps WireGuard & IMIX NAT
Datacenter HA Pair

Axonwall Core HA

$7,999

Turnkey active/standby dual 1U HA pair with 100GbE QSFP28 and sub-second failover.

  • ✓ 2x 1U Clustered Appliances
  • ✓ AMD EPYC 16-Core / 32-Thread
  • ✓ 4x 25GbE SFP28 + 2x 100GbE QSFP28
  • ✓ Conntrackd 100GbE DAC Link
  • ✓ Dedicated IPMI / BMC management
Transparent Pricing

Software Editions & Enterprise Support

100% open source community edition for everyone, with certified long-term support and commercial threat feeds for mission-critical enterprise deployments.

Community Edition

For homelabs, developers, and self-supported small deployments.

$0 / forever
  • ✓ 100% Free & Open Source Core
  • ✓ Bi-weekly rolling release cycle
  • ✓ Full nftables, WireGuard, and IPsec
  • ✓ OpenLDAP and ISC Kea DHCP
  • ✓ Community Forum Support
Download Community ISO
Recommended for Production

Business Edition

Hardened, validated release channel for commercial environments.

$249 / appliance / year
  • ✓ Everything in Community, plus:
  • ✓ Hardened Quarterly LTS update stream
  • ✓ Automated hardware regression QA
  • ✓ Commercial Threat Intelligence Feeds
  • ✓ MaxMind GeoIP2 + CrowdSec CTI
  • ✓ Encrypted Cloud Config Vault

Enterprise SLA Support

24/7 mission-critical response for enterprise and government clusters.

$1,499 / node / year
  • ✓ Everything in Business Edition, plus:
  • ✓ 24x7x365 Emergency Phone & Ticket SLA
  • ✓ 2-hour response time guarantee
  • ✓ Named Technical Account Manager (TAM)
  • ✓ Architecture review & migration service
  • ✓ Next-business-day hardware advance swap

Migrate from OPNsense or pfSense in 30 Seconds

Our built-in migration engine parses your existing config.xml backup and automatically translates interface mappings, aliases, firewall rules, NAT port forwards, and DHCP subnets to Linux nftables.

Frequently Asked Questions

Why did you build Axonwall on Linux instead of FreeBSD?

Linux provides modern hardware drivers on day one (including 5G cellular, Wi-Fi 7, and 100GbE NICs), multi-core scalability via nftables and eBPF, and native support for running inside Docker and Kubernetes. FreeBSD packet filtering (pf) suffers from lock contention under heavy symmetrical traffic.

Can I install Axonwall on my own PC or server?

Yes. Axonwall Community Edition runs on any standard 64-bit x86 or ARM64 computer. We provide bootable UEFI ISO images, Debian 13 packages (.deb), Docker Compose templates, and Proxmox/KVM virtual machine images.

How does Commit-Confirm prevent lockouts?

When you apply a new ruleset, Axonwall loads it into the Linux kernel and arms a 60-second confirmation timer. If your session remains connected and you click "Confirm", the configuration is permanently stored. If your rule severed connectivity, the timer expires and the daemon automatically rolls back to the previous working bundle.