NuajProtect

The NuajBridge appliance · Powered by NuajProtect · Now in beta

NuajBridge

Plug it in.
Attacks stop here.

NuajBridge sits invisibly in front of your network and filters attacks out of your traffic before they ever arrive — no IP address, no reconfiguration, nothing for an attacker to find. Always-current global threat intelligence plus live detection of floods, scanners and repeat offenders, enforced inline at line rate. The 2.5-Gigabit model is in beta today; larger ones are in qualification and development.

Invisible inline protection Line rate · 2.5G in beta Zero-config setup

Join the beta free — and stay free for a full year after general availability, with priority access to every NuajBridge as it ships.

Live Operations Dashboard

NuajProtect Dashboard — Real-time threat map showing blocked attacks worldwide
Up to 100G
Line-rate filtering
Global
Threat intelligence
Zero
Config to deploy
NuajProtect Intelligence — Threats blocked by country with flag indicators

Live visibility across every protected location — blocked threats, where they came from, and what was stopped.

The NuajBridge appliance

The simplest way to protect
an entire network.

Place NuajBridge between your internet connection and your network. It filters out attacks inline and forwards only clean traffic — with nothing to install on your servers and nothing to redesign.

Invisible

Nothing to attack

NuajBridge has no address on the network it protects. It can't be scanned, logged into, or targeted — it simply sits in the path and removes hostile traffic.

Effortless

Set up in minutes

Scan a code to claim it, place it inline, and you're protected. No network changes, no rule writing, no firewall to replace.

Fast

Inline, not in the way

Every packet is filtered at line rate in the kernel's earliest packet path — no userspace proxy, no extra routing hop, nothing reassembled on the way through. Accepted traffic is forwarded, not inspected twice.

Always current

Protected against today's threats

NuajBridge is continuously updated with global threat intelligence from the NuajProtect network, so it blocks new attack sources as they emerge — automatically.

Resilient

Designed to never get in the way

If anything ever goes wrong, your traffic keeps flowing. NuajBridge is engineered so that protection never becomes an outage.

Included

NuajProtect in the box

Every NuajBridge ships with a NuajProtect subscription included — global threat intelligence, the live dashboard, and updates. Up to three years, depending on the model.

The lineup

One appliance family.
2.5 Gigabit today.

Filtering every packet inline, at line rate, is hard — and it gets harder the faster the link. NuajBridge is one architecture across the range, so the protection is identical at every size. What differs is availability: the table below says exactly which models you can have now and which are still ahead of us.

NuajBridge 2.5G 10G 25G 100G 400G
Best for The entry point — balanced cost and performance Growing sites Core & multi-tenant High-capacity sites Carrier & backbone
Link speeds it serves 2.5G · 1G 10G · 2.5G · 1G 25G · 10G · 2.5G · 1G 100G and below (target) 400G and below (target)
Banlist held in the engine 1M IPv4 · 256K IPv6 4M IPv4 · 1M IPv6 4M IPv4 · 1M IPv6 30M IPv4 · 4M IPv6 30M IPv4 · 4M IPv6
Form factor Compact desktop Rackmount Rackmount Rackmount Rackmount
Power supply Single Single Single Dual, redundant Dual, redundant
Availability Beta now In qualification In qualification In development Design-partner project
Every defence, on every model — no feature is held back for a bigger box
Global threat intelligence
Flood & DDoS protection
Invisible inline filtering
Application-aware detection
Live dashboard & alerts
Included NuajProtect subscription
In the box 1 year 3 years 3 years 3 years 3 years

Throughput classes are indicative and depend on traffic profile and policy. Every figure on this page — throughput, capacity, block counts — is what a particular configuration achieved under a particular traffic mix. Yours will differ. Treat them as the shape of the thing, not a guarantee; we will size a deployment with you rather than have you infer it from a table. Every model runs the same engine and every defence layer — nothing is withheld to sell an upgrade. What a larger model buys you is capacity the hardware genuinely provides: more traffic, and a bigger banlist held in memory at once. Only the 2.5G model is available today, in beta. The other models are at earlier stages and are shown so you can see where the family is going — they are not offers, and we do not date them. The 400-Gigabit XXL is work we would take on with a design partner who needs carrier-scale filtering — if that's you, let's talk.

Next on the roadmap: line-rate filtering to 100 Gigabit, then high-availability pairs — active–standby failover for a single inline point. And it's designed to scale out: a bridge on each of your redundant routed paths, managed as one fleet.

How it works

Every connection,
checked before it lands.

Each piece of incoming traffic is weighed against a live picture of global attack activity — and the threats are removed before they reach you. The whole network learns from every attack any one part of it sees.

1

Known threats, blocked

Millions of known malicious sources — botnets, scanners, and active attack infrastructure — are stopped before they ever reach your services.

2

New attacks, caught

When a new source starts behaving badly, it's identified and blocked — and shared across your network so the next location is already protected.

3

Floods, absorbed

Flood Shield soaks up traffic surges and denial-of-service attempts, keeping your services online and responsive while the attack is shed at the edge.

4

Regions, controlled

Choose which parts of the world can reach which services — and quietly turn away traffic from places you don't do business with.

5

Probing, stopped

Gatekeeper watches for the patterns of an attack in progress — scans, break-in attempts, and abuse — and shuts the source out automatically.

6

Trusted, untouched

The people and systems you trust keep clean, predictable access — protection stays invisible to the traffic that belongs.

No slowdown
Filtering at full speed
Always on
Continuous protection
Millions
Of threats tracked

Already have servers or routers?

Start with the gear
you already run.

NuajBridge is the flagship — the full inline engine, filtering whole networks at line rate. When you just need to protect a single box, the same NuajProtect intelligence also runs as software on the servers and routers you already own. A fast way to get protected today, with a clear path up to NuajBridge when you need the full-speed engine.

On your Linux servers

Protect an exposed server directly, with nothing extra in the network path. NuajProtect installs in minutes and blocks hostile traffic right at the server, before it reaches your applications.

  • Works on all major Linux distributions
  • Lightweight — no measurable overhead
  • Protect the server, or forward and protect other services
  • Managed from the same dashboard as your appliances

On your MikroTik routers

Turn a MikroTik you already run into a protected edge. Scan a code to connect it, and NuajProtect keeps it loaded with current global threat intelligence — essential blocking, no replacement firewall required.

  • Essential threat-intelligence blocking
  • Simple code-scan onboarding
  • Stays up to date automatically
  • Step up to NuajBridge for full line-rate filtering

Want turnkey, whole-network protection with nothing to install? That's NuajBridge.

Network Architecture

NuajProtect can protect individual servers, routers, remote services, and entire network edges from the same central policy system.

NuajProtect Network Architecture

Types and modes

Three things to deploy.
Six ways to place them.

Two separate decisions. What runs the protection — a Linux binary, your MikroTik router, or a NuajBridge appliance. And where it sits relative to the traffic it protects. Not every pairing is possible, and the ones that aren't are listed as unavailable rather than quietly dropped at setup.

Type · software

Linux agent

A single static binary under systemd. It picks the fastest enforcement the kernel offers — XDP/eBPF where available, nftables or iptables+ipset where it isn't — so an older box still gets kernel drops rather than nothing.

  • Applications on the host can report attackers directly
  • Break-glass API on 127.0.0.1
  • Signature-checked self-upgrade

Type · no install

MikroTik RouterOS

No binary and nothing to install: a generated script installs managed rule chains and address lists on the router you already own. Enforcement is RouterOS' own firewall, so it inherits that hardware's limits — and its strengths.

  • RouterOS 7.13+
  • IPv4 and IPv6 address lists
  • Scripts stay current automatically

Type · appliance

NuajBridge

The full engine on purpose-built hardware, filtering a whole network at line rate. It carries the parts that only exist when we control the box: native-driver XDP, sealed port roles, and inline placement with no address for an attacker to reach.

  • Protects gear that can't run an agent
  • Native XDP on both tiers
  • Zero-touch enrolment

Sentry — protect this machine

The protection runs on the thing it defends. Traffic to and from that host is filtered in its own kernel, and software on the host can hand the agent an attacker it spotted at the application layer. The default for servers and VMs.

Relay — protect what's behind it

A forwarding gateway cleans traffic on its way to services that never see the raw Internet. Traffic reaches them directly or through a tunnel — GRE, WireGuard, or IPsec — so the protected addresses need not be exposed at all.

Bridge — invisible in the path

Two ports, no IP address on the data path, transparent to everything either side of it. Nothing has to be readdressed to deploy it, and there is no management surface in the traffic path for an attacker to find.

Linux agent MikroTik NuajBridge
Where it can sit
Sentry — protects itself Yes Yes
Relay — protects downstream Yes Yes
Bridge — transparent inline Yes Yes
How it enforces
Kernel-level drop XDP/eBPF RouterOS firewall XDP, native driver
Fallback on older kernels nftables · iptables+ipset
Line-rate whole-network filtering Per host To the router's limits Yes
Defence layers
Allowlist · blocklist · banlist · country Yes Yes Yes
Gatekeeper trap ports Yes Yes Yes
Flood protection Adaptive + fixed limits Fixed limits, IPv4 Adaptive + fixed limits
IPv6 Yes Yes Yes
Running it
Keeps filtering if the server is unreachable Yes Yes Yes
Apps on the host can report attackers Yes Yes
Stays current Signed self-upgrade Managed script sync Signed self-upgrade

A dash means the pairing is not supported. Relay is not supported on RouterOS — the rules NuajProtect installs there filter the forward chain, so a MikroTik covers downstream devices in Sentry or Bridge mode. Sentry is not supported on a NuajBridge: its data path carries no IP address of its own. Bridge is not supported on a Linux agent; transparent inline filtering runs on the appliance, on hardware whose NICs and kernel are known. The pairings are enforced when an endpoint is created.

The comparison

More protection,
for less.

Most security products solve only part of the problem — and charge extra for the rest. NuajProtect includes the threat intelligence, attack detection, flood protection, and management other vendors sell as add-ons.

It isn't another box to rip-and-replace. NuajProtect protects what you already run — and gives you a purpose-built appliance when you want one.

NuajProtect CrowdSec FortiGate pfSense+ Firewalla Untangle
Annual Cost (5 endpoints) $1,490/yr $1,860+/yr $5,500+ yr1 $645+/yr $1,395 once ~$500/yr
Threat Intelligence
Curated IP Blocklist 10M+ capacity, included +$900/mo +$500/yr manual DIY ~100K ~100K
Global Community Banlist included community
Threat Scoring included +$49/mo FortiGuard basic
Real-Time Feed Updates instant hourly real-time manual real-time daily
Protects MikroTik Routers
Flood Shield (DDoS) Protection
Line-Speed Filtering appliance & Linux appliance-dependent
Auto-Mitigation global ban bouncers hardware alert only basic IPS
Threat filtering throughput multi-Gbps software limited 700 Mbps 1 Gbps 500 Mbps 500 Mbps
Management
Cloud Dashboard desktop + mobile free +$$/yr mobile app yes
Live Threat Map
Analytics included basic +$3K/yr limited reports
Multi-Site (unlimited) included +$31/node +$5K/yr MSP app limited
Hardware Security
30s Device Revocation yes mobile app
Auto Token Rotation ✦ 7-day auto
Data Sovereignty
SaaS / Cloud yes yes yes yes
Self-Hosted available local appliance only local appliance only
Air-Gapped Capable yes yes

Comparison based on publicly available information and typical deployment assumptions as of May 2026. Pricing, features, hardware requirements, throughput, and licensing terms vary by vendor, region, device model, and deployment size.

The difference

Built for the people who keep
networks running.

Managed service providers, ISPs, hosting companies, and data centers — operators protecting real networks, servers, customer sites, and exposed infrastructure, not a lab. One dashboard, every site, consistent protection everywhere.

Performance

Filtering, not a bottleneck

Attacks are removed at line rate, whether you run the appliance or the software — in the kernel, with no proxy to reassemble your traffic and no proprietary firewall hardware to buy into.

Fits what you have

Works with your gear

Protect your existing servers and routers as they are. Add an appliance where you want turnkey, whole-network coverage. One dashboard for all of it.

Visibility

See everything, in one place

A single live dashboard shows what was blocked, where it came from, and which locations were targeted — across every server, router, and appliance you protect.

Scalability

Grows with you

Start with one server or one appliance, then expand across sites and customers under the same account — no re-platforming as you scale.

Defense

The whole network learns

When one location spots a new attacker, every other location is protected from it — so an attack on one becomes immunity for all.

Coverage

Protect anything

Servers, routers, and whole networks — all from one central dashboard, with consistent protection everywhere.

Built-In Security

Shared protection,
without shared risk.

The network learns from every attack any one location sees — while each location stays fully under your control, auditable, and instantly revocable.

Communications

Encrypted end to end

Every protected location has its own unique identity and talks to the platform over encrypted, outbound-only connections. There are no open management ports for an attacker to reach.

Authentication

Multi-Factor Authentication

TOTP authenticator apps, WebAuthn/passkeys, SMS codes, and email verification — four MFA methods built in. Not a paid add-on.

Access Control

Role-Based Permissions

Six granular roles from Account User to Super Admin. Control exactly who can view, operate, or administer each tenant — across your entire organization.

Notifications

Real-Time Alerts

Configurable email and SMS notifications for attacks, a protected location going offline, and security incidents. Know instantly when something needs attention.

Integration

Your apps can fight back

Your own applications can report the abuse only they can see — failed logins, scraping, suspicious activity — and NuajProtect turns those signals into network-wide blocking.

Flexibility

Policy Profiles

Apply standard protection profiles or customize policy per endpoint, site, customer, or deployment mode.

Software pricing

Everything included.
No hidden add-ons.

Threat intelligence, the live dashboard, attack detection, flood protection, analytics, and central management — all included. The things other vendors charge extra for come standard.

Pricing is per protected endpoint — a server, a router, or an appliance — and is what your account moves to after the free beta and its first year post-GA. Every NuajBridge comes with NuajProtect included (1 year on the 2.5G model, 3 years on 10G and above).

The beta offer

Join now and it's free — and it stays free for a full year after we reach general availability, plus priority access to every NuajBridge as it ships.

Join the beta — free
Monthly Annual Save 16%

Shield

Evaluation · 1 endpoint

Free

forever

  • 1 protected endpoint
  • Basic threat feed
  • 1-day activity history
  • Dashboard access
  • Community support
Get Started

Guard

Small business · 5 endpoints

$149

/month

  • 5 protected endpoints
  • Global threat intelligence
  • 7-day activity history
  • Attack & intrusion detection
  • Flood & DDoS protection
  • Protects servers & routers
  • Alerts and API access
Join the beta — free

Fortress

Multi-site · 25 endpoints

$549

/month

  • Everything in Guard
  • 25 protected endpoints
  • Multi-site management
  • Advanced analytics
  • Customer/site grouping
  • Priority support
Contact Sales

Citadel

Operators · 100 endpoints

$1,799

/month

  • Everything in Fortress
  • 100 protected endpoints
  • Advanced onboarding
  • SLA with priority escalation
Contact Sales
Contact Sales

Data sovereignty

Your data,
on your terms.

Prefer to keep everything in-house? NuajProtect can run fully self-hosted — including isolated and air-gapped environments — so your policy, logs, and threat data never leave your control. Talk to us about self-hosted →

Get started

Stop the attacks.
Keep control.

Reserve a NuajBridge for turnkey, whole-network protection — or start free in software on a single server. Everything you protect lives in one account.

Built by operators

The people who built it
run networks for a living.

NuajProtect came out of day-to-day operations, not a product roadmap. The same team runs a Canadian data center and the networks inside it — which is where every assumption in this product gets tested before a customer ever sees it.

Where it runs

Halton Data Center

Canadian colocation, cloud, and managed infrastructure. NuajProtect defends these networks in production — the first deployment was our own, and it stays that way with every release.

Visit HaltonDC

What we run alongside it

Nexaplane

The other platform Nuaj ships: Proxmox turned into a multi-tenant cloud with billing and self-service. Same engineering team, same bias toward operators who need control rather than another dashboard.

See Nexaplane

What Nuaj ships

Two platforms. One operating base.

Nuaj is not an agency, and it is not a catalogue. We ship two platforms — NuajProtect for edge security and Nexaplane for cloud orchestration — and we run the data center, networks, and AI systems underneath them. That operating work is why the platforms are built the way they are; it is not a separate list of things to sell you.

NuajProtect
Edge security
Nexaplane
Cloud orchestration