Replace legacy BSD packet filters and accidental admin lockouts. Axonwall delivers line-rate multi-core performance, Junos-style commit-confirm with automated rollback, and a reactive Next.js 16 console.
For 20 years, open-source firewalls relied on FreeBSD. But today, the modern internet runs on Linux. Here is why Axonwall is the definitive architectural upgrade.
FreeBSD pf locks on single cores under heavy NAT loads. Linux nftables scales across all CPU cores with lockless flow tables and multi-queue RSS.
No more fear of applying rules remotely. If a mistake cuts your connection, the Go daemon automatically reverts to the last-known-good atomic bundle within 60 seconds.
WireGuard runs natively in the Linux kernel, and OpenVPN 2.6 uses kernel Data Channel Offload (ovpn-dco), eliminating user-space context switches for line-rate encryption.
Axonwall manages strictly table inet axonwall without touching Docker or Kubernetes tables. Deploy on Bare Metal, VM, Docker, or Kubernetes CNF pods.
Every critical security service—from ISC Kea DHCP to FRRouting BGP and Suricata IDS—re-architected for Linux.
Integrated NFQUEUE fail-open bypass. If Suricata restarts or crashes under DDoS load, packet flow bypasses the queue rather than severing all network connectivity.
Linux CAKE queue discipline with automatic DiffServ DSCP prioritization, TCP ACK filtering, and IFB virtual ingress shaping. Eliminates latency during full downloads.
CrowdSec LAPI bouncer directly binds attacker IPs to native nftables interval sets with zero ruleset reload. Dynamic URL table feeds, GeoIP, and ASN blocking.
Keepalived VRRP active/standby virtual routers combined with Conntrackd FTFW UDP state replication. Zero dropped sessions on failover.
Production-grade enterprise dynamic routing powered by FRR. Full IPv4 and IPv6 BGP multi-homing with BFD sub-second link failure detection.
Embedded high-resolution time series engine and NetFlow/IPFIX flow analyzer. Identify top bandwidth talkers and destination ports in real time.
Factory burned-in, pre-loaded with Axonwall OS, and tested for maximum thermal reliability. Ships globally with next-day advance hardware replacement.
Silent, fanless aluminum chassis for home labs, branch offices, and edge deployments.
Integrated 5G Sub-6 modem with dual SIM redundancy for retail and mobile edge.
1U rackmount appliance for medium enterprises, schools, and central headquarters.
Turnkey active/standby dual 1U HA pair with 100GbE QSFP28 and sub-second failover.
100% open source community edition for everyone, with certified long-term support and commercial threat feeds for mission-critical enterprise deployments.
For homelabs, developers, and self-supported small deployments.
Hardened, validated release channel for commercial environments.
24/7 mission-critical response for enterprise and government clusters.
Our built-in migration engine parses your existing config.xml backup and automatically translates interface mappings, aliases, firewall rules, NAT port forwards, and DHCP subnets to Linux nftables.
Linux provides modern hardware drivers on day one (including 5G cellular, Wi-Fi 7, and 100GbE NICs), multi-core scalability via nftables and eBPF, and native support for running inside Docker and Kubernetes. FreeBSD packet filtering (pf) suffers from lock contention under heavy symmetrical traffic.
Yes. Axonwall Community Edition runs on any standard 64-bit x86 or ARM64 computer. We provide bootable UEFI ISO images, Debian 13 packages (.deb), Docker Compose templates, and Proxmox/KVM virtual machine images.
When you apply a new ruleset, Axonwall loads it into the Linux kernel and arms a 60-second confirmation timer. If your session remains connected and you click "Confirm", the configuration is permanently stored. If your rule severed connectivity, the timer expires and the daemon automatically rolls back to the previous working bundle.