nEdge Lite

Lightweight Layer-7 Traffic Control for Every Network Segment

nEdge Lite is a high-performance, netfilter-based Deep Packet Inspection and policy enforcement Layer-7 firewall and probe for Linux. It sits inline and identifies applications and protocols in real time using nDPI. It can be used to enforce fine-grained pass/drop/rate policies, all while streaming live flow data into ntopng for centralized visibility and management.

nEdge Lite supports two deployment modes:

Bridge Mode Transparent Layer-2 deployment between two network segments (e.g. LAN/WAN, or two VLANs). Ideal for inserting inspection between an existing switch and router without touching the rest of the topology.

Router Mode Protects traffic on one interface, or runs as the filtering layer of a Linux router/gateway alongside standard IP forwarding and NAT.

nedge-lite-inline
nEdge Lite vs nEdge

nEdge Lite is not a replacement for nEdge, it’s a complementary, lighter-weight tool. nEdge is a full-featured perimeter gateway appliance with its own web GUI, bandwidth shaping, multi-WAN failover, and captive portal/authentication, built for a single chokepoint like an office or hotel’s Internet edge. nEdge Lite is a headless, netfilter-native application designed to be deployed repeatedly, at every segment, VLAN, or branch that needs Layer-7 enforcement, with all visibility and policy management centralized in ntopng rather than in a per-box GUI. nEdge Lite also provides more flexibility when integrating with pre-existing netfilter-based configurations and appliances.

Make Every Segment of Your Network Enforceable

Modern networks aren’t just protected at the perimeter anymore. Traffic needs to be inspected and controlled between VLANs, in front of IoT devices, at branch offices, and across guest networks. nEdge Lite is built to be dropped into any of those points: it’s a single lightweight binary, driven by JSON policy or by ntopng, that turns any Linux box with a couple of NICs into an application-aware enforcement point.

nEdge Lite is built on nDPI, the same detection engine used across ntop’s product line, to identify traffic by application and category, not just port number. It recognizes services like Facebook, YouTube, Netflix, Zoom, BitTorrent, and thousands
more, and can flag protocols even when they’re encrypted, using behavioral analysis.

Traffic is matched against JSON-defined policies that combine multiple criteria:

Layer-7 Deep Packet Inspection and Policy-Based Filtering
Native Netfilter Architecture

nEdge Lite plugs directly into the Linux kernel’s netfilter framework via NFQUEUE: iptables rules hand undecided packets to nEdge Lite, which inspects them, calls nDPI, evaluates policy, and returns a verdict. Once a flow is classified, the decision is written to the conntrack, so the kernel enforces it for the rest of the connection without round-tripping every packet back to userspace.

Policies resolve to a simple marker (pass, drop, etc.), applied at the connection level so every packet in a flow is treated consistently. Labels are also supported, to provide visibility on the application protocol at the kernel level by setting it directly into the conntrack entry.

Multiple netfilter queues can be load-balanced and CPU-pinned for multi-gigabit throughput.

nEdge Lite exports flow data to ntopng in real time over ZeroMQ (compact TLV or human-readable JSON, optionally CURVE-encrypted), so every flow it inspects (including peers, protocol, application, bytes, verdict) shows up live in ntopng’s dashboards, historical views, and alerts.

Policies can be also configured and pushed back from ntopng: define pools and policies in ntopng’s web UI and they propagate to every connected nEdge Lite instance automatically, no restart required. Any number of nEdge Lite agents, on any number of hosts, can report into a single ntopng.

Centralized Visibility with ntopng
at a glance

Key Features

Ideal for Every Environment

Use Cases

Enterprise Traffic Enforcement

Block unauthorized applications, social media, P2P file sharing, cryptocurrency mining, gaming and streaming, while keeping business-critical traffic flowing, enforced directly at the network edge or branch office.

Deploy nEdge Lite between VLANs or subnets in a data center or cloud environment to control East-West traffic, enforce application-level policy between security zones, and monitor inter-service communication that a traditional firewall never sees.

Because instances are lightweight and fan into one ntopng, nEdge Lite is well suited to environments with many enforcement points and one management console: guest Wi-Fi, IoT device networks, school labs, or branch offices, each with its own pool and policy but a single pane of glass.

Specifications

Tech Specs

Subject to the EULA terms.

models

Choose Your Model

Did you already install the software?

Coming Soon
  • Fully integrated with netfilter
  • Layer-7 detection with nDPI
  • Geolocation support (MMDB)
  • Small/medium networks
Buy