Platform Everything below goes through the same pipeline: validate, apply live, write atomically, record a revision — with drift detection watching the result.
Structured rules, inline NAT, tables, a live state browser, brute-force auto-ban, anti-lockout built in.
OSPF and BGP with a real policy engine, peer groups, TCP-MD5, zero-downtime key rotation, a route-leak gate.
WireGuard with a full key lifecycle, IPsec (IKEv2 and manual), GRE, VXLAN, EtherIP and gif.
Multi-WAN failover on real health probes, PPPoE, IPv6 end to end, VLANs and bridges.
DHCP with live leases, DNS with DNS-over-TLS and DNSSEC, block-lists, managed NTP.
CARP with safe preemption windows, pfsync, authenticated configuration sync.
Users, roles and MFA, a tamper-evident audit trail, two-step updates, alerting, diagnostics.
Signed, optionally encrypted bundles, dry-run import, a rehearsed console-only restore.