nEdge Lite
Lightweight Layer-7 Traffic Control for Every Network Segment
nEdge Lite is a high-performance, netfilter-based Deep Packet Inspection and policy enforcement Layer-7 firewall and probe for Linux. It sits inline and identifies applications and protocols in real time using nDPI. It can be used to enforce fine-grained pass/drop/rate policies, all while streaming live flow data into ntopng for centralized visibility and management.
nEdge Lite supports two deployment modes:
Bridge Mode Transparent Layer-2 deployment between two network segments (e.g. LAN/WAN, or two VLANs). Ideal for inserting inspection between an existing switch and router without touching the rest of the topology.
Router Mode Protects traffic on one interface, or runs as the filtering layer of a Linux router/gateway alongside standard IP forwarding and NAT.
nEdge Lite vs nEdge
nEdge Lite is not a replacement for nEdge, it’s a complementary, lighter-weight tool. nEdge is a full-featured perimeter gateway appliance with its own web GUI, bandwidth shaping, multi-WAN failover, and captive portal/authentication, built for a single chokepoint like an office or hotel’s Internet edge. nEdge Lite is a headless, netfilter-native application designed to be deployed repeatedly, at every segment, VLAN, or branch that needs Layer-7 enforcement, with all visibility and policy management centralized in ntopng rather than in a per-box GUI. nEdge Lite also provides more flexibility when integrating with pre-existing netfilter-based configurations and appliances.
Make Every Segment of Your Network Enforceable
Modern networks aren’t just protected at the perimeter anymore. Traffic needs to be inspected and controlled between VLANs, in front of IoT devices, at branch offices, and across guest networks. nEdge Lite is built to be dropped into any of those points: it’s a single lightweight binary, driven by JSON policy or by ntopng, that turns any Linux box with a couple of NICs into an application-aware enforcement point.
- See the application, not just the port. nDPI-powered detection identifies hundreds of protocols and applications, including inside encrypted traffic via ETA and behavioral heuristics.
- Enforce policy where the traffic actually is. Deploy as many instances as you have segments, all reporting to one ntopng
- No disruption, no black box. Transparent bridge or router deployment, connection-tracked verdicts, hot-reloadable rules.
nEdge Lite is built on nDPI, the same detection engine used across ntop’s product line, to identify traffic by application and category, not just port number. It recognizes services like Facebook, YouTube, Netflix, Zoom, BitTorrent, and thousands
more, and can flag protocols even when they’re encrypted, using behavioral analysis.
Traffic is matched against JSON-defined policies that combine multiple criteria:
- Protocols: e.g. block BitTorrent, allow SSH
- Categories: Social Networks, Streaming, Gaming, File Sharing, VPN, Remote Access, and more
- Countries and continents: GeoIP-based geographic restrictions
- ASN: block or allow entire provider networks by Autonomous System Number
- Pools: apply different policies to different IP ranges or MAC addresses (e.g. "Guest WiFi" vs "Executive Devices"), with policy inheritance
Layer-7 Deep Packet Inspection and Policy-Based Filtering
Native Netfilter Architecture
nEdge Lite plugs directly into the Linux kernel’s netfilter framework via NFQUEUE: iptables rules hand undecided packets to nEdge Lite, which inspects them, calls nDPI, evaluates policy, and returns a verdict. Once a flow is classified, the decision is written to the conntrack, so the kernel enforces it for the rest of the connection without round-tripping every packet back to userspace.
Policies resolve to a simple marker (pass, drop, etc.), applied at the connection level so every packet in a flow is treated consistently. Labels are also supported, to provide visibility on the application protocol at the kernel level by setting it directly into the conntrack entry.
Multiple netfilter queues can be load-balanced and CPU-pinned for multi-gigabit throughput.
nEdge Lite exports flow data to ntopng in real time over ZeroMQ (compact TLV or human-readable JSON, optionally CURVE-encrypted), so every flow it inspects (including peers, protocol, application, bytes, verdict) shows up live in ntopng’s dashboards, historical views, and alerts.
Policies can be also configured and pushed back from ntopng: define pools and policies in ntopng’s web UI and they propagate to every connected nEdge Lite instance automatically, no restart required. Any number of nEdge Lite agents, on any number of hosts, can report into a single ntopng.
Centralized Visibility with ntopng
at a glance
Key Features
- Layer-7 application and protocol detection via nDPI (450+ protocols), including heuristic detection in encrypted traffic
- Protocol, category, country, continent, and ASN-based policy rules
- Pool-based policy assignment by IP range or MAC address, with policy inheritance
- Bridge mode and single-interface/router mode, with IPv4 and IPv6 support
- Multi-queue, CPU-fanned-out packet processing for multi-gigabit throughput
- Hash-based flow tracking with automatic idle-flow purging
- Hot policy reload via SIGHUP or live push from ntopng: zero-downtime updates
- Real-time flow export to ntopng over ZeroMQ, with optional CURVE encryption
- Multiple instances, on multiple hosts, fanning into a single ntopng for centralized management
- Runs as a lightweight, headless Linux daemon: no dedicated appliance or GUI required on the enforcement node itself
Ideal for Every Environment
Use Cases
Enterprise Traffic Enforcement
Block unauthorized applications, social media, P2P file sharing, cryptocurrency mining, gaming and streaming, while keeping business-critical traffic flowing, enforced directly at the network edge or branch office.
Network Micro-Segmentation
Deploy nEdge Lite between VLANs or subnets in a data center or cloud environment to control East-West traffic, enforce application-level policy between security zones, and monitor inter-service communication that a traditional firewall never sees.
Distributed Guest / IoT / Segment Policy
Because instances are lightweight and fan into one ntopng, nEdge Lite is well suited to environments with many enforcement points and one management console: guest Wi-Fi, IoT device networks, school labs, or branch offices, each with its own pool and policy but a single pane of glass.
Specifications
Tech Specs
- Linux (netfilter, NFQUEUE, conntrack)
- Centralized policy management via the ntopng web UI
- Flow export and policy push via ZMQ
- CURVE encryption
- JSON policy files (with SIGHUP hot-reload)
- Ethernet
- IPv4/IPv6
- TCP/UDP/ICMP
- 450+ Layer-7 application protocols supported by nDPI
Subject to the EULA terms.
