Beyond the flagship network security, DDoS protection, and L7 domain blocking capabilities, Neurowall includes the following out of the box.
Pulls indicators from abuse.ch, AlienVault OTX, AbuseIPDB, and compatible sources. IP indicators push directly into the kernel blocklist. URL extraction pipeline parses raw feed URLs into domain blocks. Redis-backed caching survives restarts. Integrity-check API flags null-epoch rows, expired leaks, and allow-field anomalies.
Admin (full access), Operator (rules + policy, own password), Viewer (read-only). Every state-changing operation is written to an immutable audit log with user identity and timestamp. Config hot-reload applies TI settings, feed parameters, and sidecar config live — no restart, no traffic interruption.
Leader election via etcd with ~2–3 s failover. Rules, threats, and config replicate to all cluster members via etcd watches. If etcd becomes unavailable, each node continues independently with its last-known state. Standalone mode is fully supported — no cluster required.
Metrics cover request latency, rule/threat counts, eBPF packet totals, DDoS counters, Redis hit rates, HA events, TI URL ingestion, DNS sink sync, Vaanvil webhook events, and more. Pre-built Grafana dashboards and SSE endpoints for real-time stats streaming to ops dashboards.
Static route lifecycle management for controlled pathing. Masquerading/NAT with POSTROUTING rule management. Port forwarding provisioning via the firewall UI. WireGuard VPN peer management and config for site-to-site or admin access into protected networks.
Each UDP packet is scored by payload size and service type — DNS, NTP, Memcached, and others. Sources accumulating excessive cost scores are rate-limited before they can amplify against a target. Thresholds are configurable per service profile.