# Drop hostile traffic in the kernel fast path.

NuajProtect is centralized edge threat protection that runs on your own Linux boxes and MikroTik routers.
XDP acceleration when hardware supports it, nftables fallback when it does not. Curated threat feeds.
Gatekeeper heuristic detection. No vendor-locked appliance required.

3M+
Curated threat entries  
XDP  
Kernel fast-path drops  
4  
Protection paths  
$9  
Per endpoint / mo

## Your infrastructure. Centralized policy.

No proprietary hardware in the data path. NuajProtect agents run on your Linux servers and MikroTik routers, pulling policy from NuajProtect Central (SaaS or self-hosted).

## What actually runs. No magic. No black boxes.

### Linux agent

**Protects applications directly on the server.**
- **No separate appliance** — runs on the server itself. Your applications can report threats that only they can see, and the agent blocks offenders in the kernel instantly.
- **XDP/eBPF fast path** — drops hostile IPs before they hit the network stack. Hash map for IPv4, LPM trie for IPv6 subnets.
- **nftables fallback** — automatic when NIC or kernel does not support XDP. Same policy, same feeds.
- **Gatekeeper heuristics** — detects scanning, brute-force, and abuse patterns. Shares detections across all endpoints.
- **Per-IP rate limiting** — sliding window counters in the XDP data path for Flood mitigation without userspace overhead.

### MikroTik agent

**RouterOS native integration.**
- **Address-list sync** — incremental DSV-based updates chunked to fit RouterOS memory limits (3300 entries / 64KB).
- **Sentry, Relay, and Bridge** — all three deployment modes supported on RouterOS 7.13+.
- **Firewall rule injection** — policy-driven feed selection with blocklist, threat feed, GeoIP, and Flood lists.
- **QR onboarding** — scan, paste token, done. No manual firewall configuration.

### Threat feeds
3M+ entries from curated sources. Blocklist, GeoIP (/24 precision), threat intel, and Gatekeeper detections.

### Supported platforms
Ubuntu, Debian, RHEL/Rocky/Alma, Fedora (x86_64 + ARM64). MikroTik RouterOS 7.13+.

### Deployment modes
Sentry (direct endpoint), Relay (forwarding proxy), Bridge (transparent inline). Mix and match per endpoint.

### On-prem option
Self-hosted NuajProtect Central with perpetual license. Full data sovereignty. Air-gapped operation supported.

## Honest take
NuajProtect is not a next-gen firewall. It is not a SIEM. It does one thing well: block known-bad and heuristically-detected traffic at the edge before it reaches your services.

If you run Linux servers or MikroTik routers and want centralized threat protection without buying a Fortinet/Palo Alto/Sophos appliance for every site — this is what NuajProtect does.

## Pricing

### SaaS or self-hosted. No seat tax. No surprise renewals.

**Shield (SaaS)**  
$9  
per endpoint / mo

**Guard (On-Prem)**  
$4,900  
5 endpoints · perpetual

**Fortress**  
$12,500  
25 endpoints · perpetual

**Sovereign**  
$75K  
unlimited · perpetual

All tiers include full product, threat feeds, and updates. On-prem includes Nuaj Blocklist server at Sovereign tier.
