Features

What it manages, and what it refuses to do

Firewall, routing, VPN, services, high availability and the operations around them — all through one pipeline: validate, apply live, write atomically, record a revision. Anything not yet shipped is badged. Every line on this page traces to evidence in the source tree.

The safety model

Cross-cutting. Every domain below inherits it.

Firewall (PF)

A real rule model, not a text box over pf.conf.

Dynamic routing — OSPF & BGP

Depth most firewall interfaces never expose.

VPN & tunnels

WireGuard, IPsec and the tunnel family.

Resilient edge

Multi-WAN, PPPoE, IPv6, VLANs and bridges.

Network services

DHCP, DNS and time.

High availability

CARP, pfsync and configuration sync.

Day-2 operations

Users, audit, updates, alerts, diagnostics.

Backup & recovery

Signed bundles and a rehearsed restore.

The safety model

A firewall is the one machine where a bad change locks you out. These guarantees exist for that reason, and every domain on this page inherits them.

  • Validated, atomic, revisioned. every apply is checked first, applied live, written atomically, and recorded as a revision you can browse and roll back.
  • Commit-confirmed windows. changes that could cut you off — firewall rules, tunnels, WireGuard, CARP — revert automatically unless you confirm they worked.
  • Drift detection, and drift alerts. every domain continuously compares configured intent against live state, shows you the difference, and raises an alert.
  • Boot safety. an unconfirmed configuration never boots live, and a bad firewall marker falls back to the last known-good ruleset rather than failing open.
  • Unattended repair. a headless box repairs its filesystems at boot instead of stopping at a single-user prompt — one command to enable on the software edition, pre-applied on the image edition.
  • Idempotent operations. mutating operations carry idempotency keys, so a nervous retry can never double-apply.

Firewall (PF)

Structured PF management — a real rule model, not a text box over pf.conf.

  • Structured rules. inline NAT (nat-to, rdr-to, binat-to), macros, tables, and policy-based routing with route-to / reply-to.
  • Live state browser. search live states and tracked sources as they stream, and kill individual states surgically.
  • Abuse resistance. TCP syncookies, per-source connection caps, and brute-force auto-ban backed by overload tables.
  • You stay in. anti-lockout and default-deny baselines are built into every ruleset the system writes.
  • Safe applies. rulesets apply inside commit-confirmed windows — if the new rules cut you off, they revert on their own.
The firewall rule editor showing structured PF rules with block/pass actions, macros, a blocklist table, and keep-state flags, plus a commit-confirmed apply banner.
Structured PF rules with macros and tables — validated with pfctl before every apply, applied inside a self-reverting window.
The live firewall state and source browser, listing active connections with protocol, source and destination, searchable, with the ability to kill individual states.
The live state browser — search active connections and kill individual states surgically.

Dynamic routing — OSPF & BGP

Both protocols driven from one canonical model, with depth most firewall interfaces never expose. This is the part network engineers notice first.

  • Full OSPF surface. redistribution with cross-daemon collision gating, per-interface timers, stub areas with inherited defaults, SPF tuning, and CARP-aware demotion.
  • Zero-downtime key rotation. rotate OSPF MD5 authentication keys through multi-key rings without dropping adjacencies.
  • A real BGP policy engine. prefix and AS sets, import/export filters, communities — and a transit-leak gate that refuses configurations that would leak routes between peers.
  • Built for more than three peers. peer groups and dynamic-peer templates that accept whole CIDR ranges.
  • Session protection. per-neighbour timers, multihop and TTL security, TCP-MD5, and per-address-family announce control for IPv4 and IPv6.
  • Live visibility. OSPF neighbour and BGP session status straight from the routing daemons.

VPN & tunnels

Site-to-site and remote access on the primitives OpenBSD does best.

  • WireGuard, properly. the full key lifecycle including per-peer preshared keys, minimal-diff peer reconciliation, and drift detection.
  • IPsec. IKEv2 via iked plus manual keying, with the firewall passes for the encrypted path managed for you.
  • Tunnels. GRE, EtherGRE, VXLAN, EtherIP and gif interfaces, under the same reversible apply model as everything else.

Resilient edge

Built for real ISP connections and imperfect uplinks.

  • Multi-WAN failover. gateway health probes catch the dead-but-link-up uplink that static routing misses, fail over, and alert you.
  • PPPoE WAN. PAP/CHAP credentials held in the secret store, MSS clamping handled.
  • IPv6 end to end. SLAAC, DHCPv6 prefix delegation, and router advertisements — with drift detection that understands dynamic v6 addressing.
  • Layer-2 flexibility. VLANs, bridges and virtual ethernet, with display names and per-interface settings.

Network services

The services every LAN needs, managed from the same interface.

  • DHCP server. pools and static reservations, a live lease view, and one-click make-static from any active lease.
  • DNS. Unbound with DNS-over-TLS upstreams, DNSSEC, local zones and records, block-domains, and per-subnet access control.
  • Time. managed NTP and timezone handling.

High availability

Two boxes, one address — and no drive to the office at 3 a.m.

  • CARP virtual IPs. master/backup roles with safe preemption windows, so a takeover can never strand you.
  • State synchronisation. pfsync keeps established connections alive across a failover.
  • Configuration sync. authenticated, certificate-pinned config replication between peers.

Day-2 operations

The unglamorous features that decide whether a firewall is operable for years.

  • Users, roles, MFA. granular role-based access, per-user TOTP with recovery codes, and hard anti-lockout protections.
  • Session and lockout policy. session lifetime and lockout thresholds are administrator policy, not constants.
  • A tamper-evident audit trail. every privileged action is recorded with its actor, integrity-tagged, verified on a schedule, mirrored to syslog, and verifiable off the box with a tool we provide to auditors.
  • Revisions & rollback. every apply records who changed what and when; browse the history and roll back.
  • Two-step updates. an off-by-default update check that sends nothing about your box; stage and verify now, apply in your window with an automatic snapshot.
  • Alerting. delivery to TLS syslog and authenticated webhooks, with sensible rules seeded on.
  • Diagnostics. read-only packet capture, private-subnet ping sweeps and port checks, ARP/NDP views, and live connection-log streaming.
  • Support without a web session. a one-command redacted support bundle, a support role with its own MFA rule, and root-console break-glass for a lost admin or a lockout.
  • A root console, with a manual page. status, confirm and cancel, updates, backup and recovery — from the console when the web tier is the thing you are debugging.
  • Kernel tunables. curated network sysctls with a safety gate on the ones that can take you offline.
The system health dashboard: live CPU, memory and disk usage, firewall state count, per-interrupt NIC rates, uptime, OpenBSD version and time-sync status.
Live system health — CPU, memory, disk, firewall states and time sync, refreshed continuously.
The diagnostics page with tools for packet capture, subnet ping sweeps, port checks and reachability tests, plus a history of previous runs.
On-box diagnostics — capture, sweep, port and reachability checks, with run history.

Backup & recovery

Configuration you can carry out of a fire — and trust on the way back in.

  • Export & restore. full-configuration export, validated dry-run imports, and revision history for per-domain content rollback.
  • Signed & encrypted bundles. cryptographically signed, optionally encrypted backups with role-gated import — verifiable on a different box.
  • Disaster recovery. a runbook and a console-only restore path to rebuild a router without the web tier, rehearsed across two boxes.
Try it

See it on your own hardware this afternoon.

Download the signed package, install it on a stock OpenBSD system, and manage the router from a browser within the hour. Or skip the build and pre-order an appliance.