The NuajBridge appliance · Powered by NuajProtect · Now in beta
Plug it in.
Attacks stop here.
NuajBridge sits invisibly in front of your network and filters attacks out of your traffic before they ever arrive — no IP address, no reconfiguration, nothing for an attacker to find. Always-current global threat intelligence plus live detection of floods, scanners and repeat offenders, enforced inline at line rate. The 2.5-Gigabit model is in beta today; larger ones are in qualification and development.
Join the beta free — and stay free for a full year after general availability, with priority access to every NuajBridge as it ships.
Live Operations Dashboard
Live visibility across every protected location — blocked threats, where they came from, and what was stopped.
The NuajBridge appliance
The simplest way to protect
an entire
network.
Place NuajBridge between your internet connection and your network. It filters out attacks inline and forwards only clean traffic — with nothing to install on your servers and nothing to redesign.
Invisible
Nothing to attack
NuajBridge has no address on the network it protects. It can't be scanned, logged into, or targeted — it simply sits in the path and removes hostile traffic.
Effortless
Set up in minutes
Scan a code to claim it, place it inline, and you're protected. No network changes, no rule writing, no firewall to replace.
Fast
Inline, not in the way
Every packet is filtered at line rate in the kernel's earliest packet path — no userspace proxy, no extra routing hop, nothing reassembled on the way through. Accepted traffic is forwarded, not inspected twice.
Always current
Protected against today's threats
NuajBridge is continuously updated with global threat intelligence from the NuajProtect network, so it blocks new attack sources as they emerge — automatically.
Resilient
Designed to never get in the way
If anything ever goes wrong, your traffic keeps flowing. NuajBridge is engineered so that protection never becomes an outage.
Included
NuajProtect in the box
Every NuajBridge ships with a NuajProtect subscription included — global threat intelligence, the live dashboard, and updates. Up to three years, depending on the model.
The lineup
One appliance family.
2.5 Gigabit
today.
Filtering every packet inline, at line rate, is hard — and it gets harder the faster the link. NuajBridge is one architecture across the range, so the protection is identical at every size. What differs is availability: the table below says exactly which models you can have now and which are still ahead of us.
| NuajBridge | 2.5G | 10G | 25G | 100G | 400G |
|---|---|---|---|---|---|
| Best for | The entry point — balanced cost and performance | Growing sites | Core & multi-tenant | High-capacity sites | Carrier & backbone |
| Link speeds it serves | 2.5G · 1G | 10G · 2.5G · 1G | 25G · 10G · 2.5G · 1G | 100G and below (target) | 400G and below (target) |
| Banlist held in the engine | 1M IPv4 · 256K IPv6 | 4M IPv4 · 1M IPv6 | 4M IPv4 · 1M IPv6 | 30M IPv4 · 4M IPv6 | 30M IPv4 · 4M IPv6 |
| Form factor | Compact desktop | Rackmount | Rackmount | Rackmount | Rackmount |
| Power supply | Single | Single | Single | Dual, redundant | Dual, redundant |
| Availability | Beta now | In qualification | In qualification | In development | Design-partner project |
| Every defence, on every model — no feature is held back for a bigger box | |||||
| Global threat intelligence | ✔ | ✔ | ✔ | ✔ | ✔ |
| Flood & DDoS protection | ✔ | ✔ | ✔ | ✔ | ✔ |
| Invisible inline filtering | ✔ | ✔ | ✔ | ✔ | ✔ |
| Application-aware detection | ✔ | ✔ | ✔ | ✔ | ✔ |
| Live dashboard & alerts | ✔ | ✔ | ✔ | ✔ | ✔ |
| Included NuajProtect subscription | |||||
| In the box | 1 year | 3 years | 3 years | 3 years | 3 years |
Throughput classes are indicative and depend on traffic profile and policy. Every figure on this page — throughput, capacity, block counts — is what a particular configuration achieved under a particular traffic mix. Yours will differ. Treat them as the shape of the thing, not a guarantee; we will size a deployment with you rather than have you infer it from a table. Every model runs the same engine and every defence layer — nothing is withheld to sell an upgrade. What a larger model buys you is capacity the hardware genuinely provides: more traffic, and a bigger banlist held in memory at once. Only the 2.5G model is available today, in beta. The other models are at earlier stages and are shown so you can see where the family is going — they are not offers, and we do not date them. The 400-Gigabit XXL is work we would take on with a design partner who needs carrier-scale filtering — if that's you, let's talk.
Next on the roadmap: line-rate filtering to 100 Gigabit, then high-availability pairs — active–standby failover for a single inline point. And it's designed to scale out: a bridge on each of your redundant routed paths, managed as one fleet.
How it works
Every connection,
checked before it
lands.
Each piece of incoming traffic is weighed against a live picture of global attack activity — and the threats are removed before they reach you. The whole network learns from every attack any one part of it sees.
Known threats, blocked
Millions of known malicious sources — botnets, scanners, and active attack infrastructure — are stopped before they ever reach your services.
New attacks, caught
When a new source starts behaving badly, it's identified and blocked — and shared across your network so the next location is already protected.
Floods, absorbed
Flood Shield soaks up traffic surges and denial-of-service attempts, keeping your services online and responsive while the attack is shed at the edge.
Regions, controlled
Choose which parts of the world can reach which services — and quietly turn away traffic from places you don't do business with.
Probing, stopped
Gatekeeper watches for the patterns of an attack in progress — scans, break-in attempts, and abuse — and shuts the source out automatically.
Trusted, untouched
The people and systems you trust keep clean, predictable access — protection stays invisible to the traffic that belongs.
Already have servers or routers?
Start with the gear
you already run.
NuajBridge is the flagship — the full inline engine, filtering whole networks at line rate. When you just need to protect a single box, the same NuajProtect intelligence also runs as software on the servers and routers you already own. A fast way to get protected today, with a clear path up to NuajBridge when you need the full-speed engine.
On your Linux servers
Protect an exposed server directly, with nothing extra in the network path. NuajProtect installs in minutes and blocks hostile traffic right at the server, before it reaches your applications.
- Works on all major Linux distributions
- Lightweight — no measurable overhead
- Protect the server, or forward and protect other services
- Managed from the same dashboard as your appliances
On your MikroTik routers
Turn a MikroTik you already run into a protected edge. Scan a code to connect it, and NuajProtect keeps it loaded with current global threat intelligence — essential blocking, no replacement firewall required.
- Essential threat-intelligence blocking
- Simple code-scan onboarding
- Stays up to date automatically
- Step up to NuajBridge for full line-rate filtering
Want turnkey, whole-network protection with nothing to install? That's NuajBridge.
Network Architecture
NuajProtect can protect individual servers, routers, remote services, and entire network edges from the same central policy system.
Types and modes
Three things to deploy.
Six ways to place
them.
Two separate decisions. What runs the protection — a Linux binary, your MikroTik router, or a NuajBridge appliance. And where it sits relative to the traffic it protects. Not every pairing is possible, and the ones that aren't are listed as unavailable rather than quietly dropped at setup.
Type · software
Linux agent
A single static binary under systemd. It picks the fastest enforcement the kernel offers — XDP/eBPF where available, nftables or iptables+ipset where it isn't — so an older box still gets kernel drops rather than nothing.
- Applications on the host can report attackers directly
- Break-glass API on 127.0.0.1
- Signature-checked self-upgrade
Type · no install
MikroTik RouterOS
No binary and nothing to install: a generated script installs managed rule chains and address lists on the router you already own. Enforcement is RouterOS' own firewall, so it inherits that hardware's limits — and its strengths.
- RouterOS 7.13+
- IPv4 and IPv6 address lists
- Scripts stay current automatically
Type · appliance
NuajBridge
The full engine on purpose-built hardware, filtering a whole network at line rate. It carries the parts that only exist when we control the box: native-driver XDP, sealed port roles, and inline placement with no address for an attacker to reach.
- Protects gear that can't run an agent
- Native XDP on both tiers
- Zero-touch enrolment
Sentry — protect this machine
The protection runs on the thing it defends. Traffic to and from that host is filtered in its own kernel, and software on the host can hand the agent an attacker it spotted at the application layer. The default for servers and VMs.
Relay — protect what's behind it
A forwarding gateway cleans traffic on its way to services that never see the raw Internet. Traffic reaches them directly or through a tunnel — GRE, WireGuard, or IPsec — so the protected addresses need not be exposed at all.
Bridge — invisible in the path
Two ports, no IP address on the data path, transparent to everything either side of it. Nothing has to be readdressed to deploy it, and there is no management surface in the traffic path for an attacker to find.
| Linux agent | MikroTik | NuajBridge | |
|---|---|---|---|
| Where it can sit | |||
| Sentry — protects itself | Yes | Yes | — |
| Relay — protects downstream | Yes | — | Yes |
| Bridge — transparent inline | — | Yes | Yes |
| How it enforces | |||
| Kernel-level drop | XDP/eBPF | RouterOS firewall | XDP, native driver |
| Fallback on older kernels | nftables · iptables+ipset | — | — |
| Line-rate whole-network filtering | Per host | To the router's limits | Yes |
| Defence layers | |||
| Allowlist · blocklist · banlist · country | Yes | Yes | Yes |
| Gatekeeper trap ports | Yes | Yes | Yes |
| Flood protection | Adaptive + fixed limits | Fixed limits, IPv4 | Adaptive + fixed limits |
| IPv6 | Yes | Yes | Yes |
| Running it | |||
| Keeps filtering if the server is unreachable | Yes | Yes | Yes |
| Apps on the host can report attackers | Yes | — | Yes |
| Stays current | Signed self-upgrade | Managed script sync | Signed self-upgrade |
A dash means the pairing is not supported. Relay is not supported on RouterOS — the rules NuajProtect installs there filter the forward chain, so a MikroTik covers downstream devices in Sentry or Bridge mode. Sentry is not supported on a NuajBridge: its data path carries no IP address of its own. Bridge is not supported on a Linux agent; transparent inline filtering runs on the appliance, on hardware whose NICs and kernel are known. The pairings are enforced when an endpoint is created.
The comparison
More protection,
for less.
Most security products solve only part of the problem — and charge extra for the rest. NuajProtect includes the threat intelligence, attack detection, flood protection, and management other vendors sell as add-ons.
It isn't another box to rip-and-replace. NuajProtect protects what you already run — and gives you a purpose-built appliance when you want one.
| NuajProtect | CrowdSec | FortiGate | pfSense+ | Firewalla | Untangle | |
|---|---|---|---|---|---|---|
| Annual Cost (5 endpoints) | $1,490/yr | $1,860+/yr | $5,500+ yr1 | $645+/yr | $1,395 once | ~$500/yr |
| Threat Intelligence | ||||||
| Curated IP Blocklist | 10M+ capacity, included | +$900/mo | +$500/yr | manual DIY | ~100K | ~100K |
| Global Community Banlist | included | community | — | — | — | — |
| Threat Scoring | included | +$49/mo | FortiGuard | — | basic | — |
| Real-Time Feed Updates | instant | hourly | real-time | manual | real-time | daily |
| Protects MikroTik Routers | ✔ | — | — | — | — | — |
| Flood Shield (DDoS) Protection | ||||||
| Line-Speed Filtering | appliance & Linux | — | appliance-dependent | — | — | — |
| Auto-Mitigation | global ban | bouncers | hardware | — | alert only | basic IPS |
| Threat filtering throughput | multi-Gbps | software limited | 700 Mbps | 1 Gbps | 500 Mbps | 500 Mbps |
| Management | ||||||
| Cloud Dashboard | desktop + mobile | free | +$$/yr | — | mobile app | yes |
| Live Threat Map | ✔ | — | — | — | — | — |
| Analytics | included | basic | +$3K/yr | — | limited | reports |
| Multi-Site (unlimited) | included | +$31/node | +$5K/yr | — | MSP app | limited |
| Hardware Security | ||||||
| 30s Device Revocation | ✔ | — | yes | — | mobile app | — |
| Auto Token Rotation | ✦ 7-day auto | — | — | — | — | — |
| Data Sovereignty | ||||||
| SaaS / Cloud | yes | yes | yes | — | — | yes |
| Self-Hosted | available | — | — | local appliance only | local appliance only | — |
| Air-Gapped Capable | yes | — | — | yes | — | — |
Comparison based on publicly available information and typical deployment assumptions as of May 2026. Pricing, features, hardware requirements, throughput, and licensing terms vary by vendor, region, device model, and deployment size.
The difference
Built for the people who keep
networks
running.
Managed service providers, ISPs, hosting companies, and data centers — operators protecting real networks, servers, customer sites, and exposed infrastructure, not a lab. One dashboard, every site, consistent protection everywhere.
Performance
Filtering, not a bottleneck
Attacks are removed at line rate, whether you run the appliance or the software — in the kernel, with no proxy to reassemble your traffic and no proprietary firewall hardware to buy into.
Fits what you have
Works with your gear
Protect your existing servers and routers as they are. Add an appliance where you want turnkey, whole-network coverage. One dashboard for all of it.
Visibility
See everything, in one place
A single live dashboard shows what was blocked, where it came from, and which locations were targeted — across every server, router, and appliance you protect.
Scalability
Grows with you
Start with one server or one appliance, then expand across sites and customers under the same account — no re-platforming as you scale.
Defense
The whole network learns
When one location spots a new attacker, every other location is protected from it — so an attack on one becomes immunity for all.
Coverage
Protect anything
Servers, routers, and whole networks — all from one central dashboard, with consistent protection everywhere.
Built-In Security
Shared protection,
without shared
risk.
The network learns from every attack any one location sees — while each location stays fully under your control, auditable, and instantly revocable.
Communications
Encrypted end to end
Every protected location has its own unique identity and talks to the platform over encrypted, outbound-only connections. There are no open management ports for an attacker to reach.
Authentication
Multi-Factor Authentication
TOTP authenticator apps, WebAuthn/passkeys, SMS codes, and email verification — four MFA methods built in. Not a paid add-on.
Access Control
Role-Based Permissions
Six granular roles from Account User to Super Admin. Control exactly who can view, operate, or administer each tenant — across your entire organization.
Notifications
Real-Time Alerts
Configurable email and SMS notifications for attacks, a protected location going offline, and security incidents. Know instantly when something needs attention.
Integration
Your apps can fight back
Your own applications can report the abuse only they can see — failed logins, scraping, suspicious activity — and NuajProtect turns those signals into network-wide blocking.
Flexibility
Policy Profiles
Apply standard protection profiles or customize policy per endpoint, site, customer, or deployment mode.
Software pricing
Everything included.
No hidden
add-ons.
Threat intelligence, the live dashboard, attack detection, flood protection, analytics, and central management — all included. The things other vendors charge extra for come standard.
Pricing is per protected endpoint — a server, a router, or an appliance — and is what your account moves to after the free beta and its first year post-GA. Every NuajBridge comes with NuajProtect included (1 year on the 2.5G model, 3 years on 10G and above).
The beta offer
Join now and it's free — and it stays free for a full year after we reach general availability, plus priority access to every NuajBridge as it ships.
Join the beta — freeShield
Evaluation · 1 endpoint
Free
forever
- 1 protected endpoint
- Basic threat feed
- 1-day activity history
- Dashboard access
- Community support
Guard
Small business · 5 endpoints
$149
/month
- 5 protected endpoints
- Global threat intelligence
- 7-day activity history
- Attack & intrusion detection
- Flood & DDoS protection
- Protects servers & routers
- Alerts and API access
Fortress
Multi-site · 25 endpoints
$549
/month
- Everything in Guard
- 25 protected endpoints
- Multi-site management
- Advanced analytics
- Customer/site grouping
- Priority support
Citadel
Operators · 100 endpoints
$1,799
/month
- Everything in Fortress
- 100 protected endpoints
- Advanced onboarding
- SLA with priority escalation
Data sovereignty
Your data,
on your terms.
Prefer to keep everything in-house? NuajProtect can run fully self-hosted — including isolated and air-gapped environments — so your policy, logs, and threat data never leave your control. Talk to us about self-hosted →
Get started
Stop the attacks.
Keep control.
Reserve a NuajBridge for turnkey, whole-network protection — or start free in software on a single server. Everything you protect lives in one account.
Built by operators
The people who built it
run networks for a living.
NuajProtect came out of day-to-day operations, not a product roadmap. The same team runs a Canadian data center and the networks inside it — which is where every assumption in this product gets tested before a customer ever sees it.
Where it runs
Halton Data Center
Canadian colocation, cloud, and managed infrastructure. NuajProtect defends these networks in production — the first deployment was our own, and it stays that way with every release.
Visit HaltonDCWhat we run alongside it
Nexaplane
The other platform Nuaj ships: Proxmox turned into a multi-tenant cloud with billing and self-service. Same engineering team, same bias toward operators who need control rather than another dashboard.
See Nexaplane