Every feature, one platform
The complete Cenvero Stratum capability set — from high-performance networking and the zero-trust firewall to NAT, failover IPs, BGP and gateway HA.
-
High-Performance Networking
- In-kernel packet processing Traffic is filtered and forwarded in the kernel fast path, before it touches user space.
- Source-IP blocklist Block traffic from specific addresses right at the network edge, each with an optional expiry.
- MAC & VLAN lockdown Lock every port to approved hardware addresses and VLANs.
- Zero-downtime reloads Change networking rules without dropping a single connection.
-
IP Address Management
- Address pools IPv4 and IPv6 pools with automatic dual-stack assignment and release.
- Conflict detection Overlapping or already-used addresses are rejected before they cause problems.
- Per-tenant address space Separate address ranges for each tenant.
- Full visibility See every lease and allocation at a glance.
-
DHCP & DNS
- DHCP server Hand out addresses per network with automatic renew and expiry, plus flood protection.
- Authoritative DNS Run your own zones and records — A, AAAA, CNAME and more.
- Split answers Give internal and external clients different DNS answers.
- Filtering & caching Sinkhole unwanted domains, sign responses, cache, and forward upstream.
-
Routing & NAT
- Static & policy routing Programmable routing tables with policy-based rules.
- Outbound NAT Lets tenant traffic reach the internet from shared addresses.
- Inbound port forwarding Expose internal services to the outside with port forwards.
- Dual-stack support IPv4 and IPv6 routing and NAT, including NAT66, side by side.
- Shared public IP Source-NAT masquerade lets many private tenants share a single public address to reach the internet.
- Hairpin NAT Reach an internal service through its own public address from inside the same network.
- NAT64 IPv6-only clients can reach IPv4-only services through the gateway.
- Ping through the gateway Tenants can ping hosts on the internet, with replies tracked back to the right sender.
- Live rule management Add, list and remove rules while everything keeps running.
-
Overlay Networks
- VXLAN overlays Stretch a single Layer-2 network across hosts and racks over your existing IP fabric.
- Tenant isolation Each overlay carries its own segment so tenants never see each other’s traffic.
- Spans the whole cluster Workloads on different physical hosts share one virtual network as if they were side by side.
- In-kernel encapsulation Overlay packets are wrapped and unwrapped in the kernel datapath.
- Geneve tunnels Standards-based Geneve overlay tunnels can run alongside VXLAN for flexible encapsulation.
- Virtual routing & forwarding Separate routing tables per VRF keep overlapping tenant networks isolated.
-
Anti-Spoofing
- IP-to-MAC binding Every port is locked to its approved address pair, so nobody can impersonate another host.
- ARP protection Forged ARP replies are dropped at the edge, stopping man-in-the-middle attacks.
- IPv6 NDP guard Neighbour-discovery spoofing on IPv6 is blocked the same way as ARP on IPv4.
- Enforced in the datapath Anti-spoof checks run inline on every packet, not as an afterthought.
- IPv6 RA-guard Rogue router advertisements from tenant ports are dropped, stopping gateway hijacking.
- DHCP snooping Tenant ports can never pose as the address server, for both DHCP and DHCPv6.
-
Connection Tracking
- Stateful inspection Only packets belonging to a known, allowed connection are let through.
- Automatic return traffic Replies to outbound flows are recognised and admitted without extra rules.
- Flow table Active connections are tracked across the datapath with automatic ageing.
- Backs the firewall & NAT The same connection state powers stateful firewalling and address translation.
-
Failover & Floating IPs
- Portable IPs Assign movable IPs to any host in the cluster.
- Automatic failover A floating IP moves to a healthy host the moment one fails.
- Instant takeover Traffic reroutes to the new host within milliseconds.
- Cluster-wide ownership Which host owns each IP is replicated across the whole cluster.
-
BGP Edge Routing
- Advertise your networks Peer with upstream routers and announce your VM networks.
- Smart path selection The best route to each destination is chosen automatically.
- Route filtering Control exactly which routes you import and export.
- Resilient peering Lossless restarts and sub-second detection of neighbour failures.
- RPKI origin validation Received routes are checked against signed RPKI data, and invalid origins are rejected.
- EVPN address family Exchange MAC and VTEP reachability for the VXLAN overlay as BGP routes.
-
Gateway High Availability
- Redundant gateways A standby gateway takes over automatically if the active one fails.
- Fast failure detection A dedicated heartbeat spots failures in under a second.
- Failover & failback Automatic failover, with operator-controlled failback when you choose.
- One owner per IP Exactly one gateway owns each virtual IP at any moment.
-
Zero-Trust Firewall
- Layered policy Rules from network-wide down to a single VM, evaluated by priority.
- Default-deny Nothing passes unless you allow it, with stateful connection tracking throughout.
- Rich matching Match on address, network, port, protocol, hardware address or domain.
- Scheduled rules Turn rules on and off by day and time.
- Domain-based rules Allow or block by domain name, kept in sync automatically.
- Conflict detection Overlapping or contradictory rules are caught before they apply.
- Presets & batch apply Web, database, mail and game-server presets applied all at once.
- Hardware binding Bind ports to specific devices, hard or soft.
- Per-source connection limits Cap how many connections any single source can open, blocking abusers automatically.
-
Intrusion Detection
- Traffic anomaly detection Suspicious traffic patterns are spotted as packets flow through the platform.
- Early threat signal Get alerted to probing and abnormal behaviour before it becomes an incident.
- Works with the firewall Detection sits alongside the zero-trust firewall for layered defence.
- Tied into alerting Detections surface through the same alerting and event stream as everything else.
-
Load Balancing
- Virtual IPs High-speed load balancing spread across your backends.
- Balancing algorithms Round-robin, least-connections, weighted and source-hash.
- Stable backend selection Consistent hashing keeps each client on the same backend.
- Health checks Unhealthy backends are removed automatically, with fast return paths.
- Layer-7 HTTP balancing Route HTTP traffic by host and path, with optional TLS termination at the balancer.
-
Bandwidth & Usage
- Bandwidth limits Per-VM upload and download limits, shared pools and burst allowances.
- Monthly quotas Usage caps that reset automatically each month.
- Usage-based billing Byte and packet accounting with 95th-percentile calculation.
- Flow records & export Per-connection stats with CSV and JSON export.
-
Clustering & Virtual Networks
- Virtual networks Isolated networks that span every host in the cluster.
- Resilient cluster state Leader election and replicated state keep the cluster consistent.
- Everything replicated Addresses, blocklists, peers, floating IPs and tenants stay in sync cluster-wide.
- Compute & gateway nodes Run a node as a VM host or as a traffic gateway.
-
Multi-Tenancy & Isolation
- Tenant management Create tenants with their own quotas and usage tracking.
- Scoped API keys Generate, validate, expire and revoke keys per tenant.
- Private networks Isolated networks with controlled membership.
- Container networking Attach containers to the same managed networks, firewall and address pools as VMs.
- Workload portability The same networking model applies whether a workload is a VM or a container.
-
Interfaces & Hardware
- Network-card management Physical network cards are detected and given stable names.
- Link bonding Combine multiple links for redundancy or more throughput.
- Consistent packet sizes Matching packet sizes across bonded links and virtual networks.
- Tamper protection Changes to managed interfaces made outside the platform are detected and reconciled back to their intended configuration.
- Interface lockdown An optional kernel-level guard blocks out-of-band deletion of managed interfaces in real time.
- Optional hardware offload Where the network card supports it, packet processing can offload to hardware, while software stays the default.
-
Observability
- Metrics & dashboards Prometheus-compatible metrics for your dashboards and alerting.
- Alerting Threshold alerts with actions, cooldown and history.
- Live events A real-time event stream across the whole system.
- Audit log A structured record of every management action.
- Event webhooks Push signed event notifications to your own endpoints, each carrying an HMAC signature.
-
Platform & Lifecycle
- Backup & restore Full and config backups with schedules and retention.
- Self-update Signed, pull-based updates the agent verifies against its baked-in publisher key before applying.
- Self-healing Automatic checks and repair for disk, memory, database and networking.
- Always-on supervision An independent watchdog restarts the platform if it ever stalls.
-
Account TLS & Private CA
- Per-account certificate authority Each account gets its own private CA, so certificates from one account never trust another.
- Automatic node certificates Nodes are issued signed leaf certificates the moment they activate — no manual key wrangling.
- Auto-trust Every node automatically trusts its own account CA, so internal traffic is encrypted out of the box.
- Automatic renewal Certificates renew themselves before they expire, with no downtime or operator action.
- Domain-change re-signing Change a node’s domain and a fresh certificate is issued and rolled out automatically.
-
Plugins & Developer Program
- Signed plugins Extend the platform with plugins that are cryptographically signed and verified before they run.
- Built-in store Discover and install plugins from a built-in store right inside the platform.
- Developer program Approved developers receive their own signing certificates to build and publish plugins.
- Publish to the marketplace Ship your plugin to other operators through the marketplace.
- Revocation A signed revocation list instantly disables any compromised or withdrawn plugin.
-
Security
- Signed end-to-end Configs, licenses, plugins and binaries are all cryptographically signed.
- Brute-force protection Repeated failed logins are locked out.
- Request validation Body-size and content-type limits on every API.
- Anti-tampering Time-drift and clock-spoofing checks keep the platform honest even offline.
-
Single Sign-On
- SAML 2.0 sign-on Your team can sign in through any SAML identity provider, kept off until an admin turns it on.
- OpenID Connect sign-on Sign in through any OpenID Connect provider, with new accounts created as plain customers.
- Role-based access Scope operator accounts to admin, operator, billing or read-only roles.
-
Licensing & Activation
- Hardware-bound licences Each licence is tied to the machine it runs on and cannot be copied elsewhere.
- Per-machine activation Activate node by node, with each activation recorded against your licence.
- Silent auto-renewal Licences renew quietly in the background so coverage never lapses.
- Key regeneration Roll a node’s key when you need to, without losing its activation.
- Guided onboarding New nodes pull their full configuration on first contact and are ready in minutes.
- Revocation A signed revocation list lets you retire a licence instantly across the fleet.
-
Billing & Wallet
- Plans & billing cycles Choose a plan and a monthly, quarterly, semi-annual or annual cycle.
- Account wallet Keep a balance on file to cover renewals and new orders.
- Automatic renewal payments Renewals are paid from your wallet automatically, with an invoice issued ahead of time.
- Discount coupons Apply percentage or fixed-amount coupon codes at checkout.
- PDF invoices Every paid order generates a downloadable, numbered PDF invoice.
- Order & proof workflow Place an order, submit payment proof, and get your licence once it’s verified.
-
APIs, CLI & Onboarding
- Full API access REST, gRPC, WebSocket and a local control socket.
- Command-line control Manage every feature from one command-line tool.
- Scriptable activation License-gated install + activation that drops straight into automation.
- Bulk operations Create many firewall rules or DNS records in a single API request.
High-Performance Networking
In-kernel packet processing
Traffic is filtered and forwarded in the kernel fast path, before it touches user space.
Source-IP blocklist
Block traffic from specific addresses right at the network edge, each with an optional expiry.
MAC & VLAN lockdown
Lock every port to approved hardware addresses and VLANs.
Zero-downtime reloads
Change networking rules without dropping a single connection.
IP Address Management
Address pools
IPv4 and IPv6 pools with automatic dual-stack assignment and release.
Conflict detection
Overlapping or already-used addresses are rejected before they cause problems.
Per-tenant address space
Separate address ranges for each tenant.
Full visibility
See every lease and allocation at a glance.
DHCP & DNS
DHCP server
Hand out addresses per network with automatic renew and expiry, plus flood protection.
Authoritative DNS
Run your own zones and records — A, AAAA, CNAME and more.
Split answers
Give internal and external clients different DNS answers.
Filtering & caching
Sinkhole unwanted domains, sign responses, cache, and forward upstream.
Routing & NAT
Static & policy routing
Programmable routing tables with policy-based rules.
Outbound NAT
Lets tenant traffic reach the internet from shared addresses.
Inbound port forwarding
Expose internal services to the outside with port forwards.
Dual-stack support
IPv4 and IPv6 routing and NAT, including NAT66, side by side.
Shared public IP
Source-NAT masquerade lets many private tenants share a single public address to reach the internet.
Hairpin NAT
Reach an internal service through its own public address from inside the same network.
NAT64
IPv6-only clients can reach IPv4-only services through the gateway.
Ping through the gateway
Tenants can ping hosts on the internet, with replies tracked back to the right sender.
Live rule management
Add, list and remove rules while everything keeps running.
Overlay Networks
VXLAN overlays
Stretch a single Layer-2 network across hosts and racks over your existing IP fabric.
Tenant isolation
Each overlay carries its own segment so tenants never see each other’s traffic.
Spans the whole cluster
Workloads on different physical hosts share one virtual network as if they were side by side.
In-kernel encapsulation
Overlay packets are wrapped and unwrapped in the kernel datapath.
Geneve tunnels
Standards-based Geneve overlay tunnels can run alongside VXLAN for flexible encapsulation.
Virtual routing & forwarding
Separate routing tables per VRF keep overlapping tenant networks isolated.
Anti-Spoofing
IP-to-MAC binding
Every port is locked to its approved address pair, so nobody can impersonate another host.
ARP protection
Forged ARP replies are dropped at the edge, stopping man-in-the-middle attacks.
IPv6 NDP guard
Neighbour-discovery spoofing on IPv6 is blocked the same way as ARP on IPv4.
Enforced in the datapath
Anti-spoof checks run inline on every packet, not as an afterthought.
IPv6 RA-guard
Rogue router advertisements from tenant ports are dropped, stopping gateway hijacking.
DHCP snooping
Tenant ports can never pose as the address server, for both DHCP and DHCPv6.
Connection Tracking
Stateful inspection
Only packets belonging to a known, allowed connection are let through.
Automatic return traffic
Replies to outbound flows are recognised and admitted without extra rules.
Flow table
Active connections are tracked across the datapath with automatic ageing.
Backs the firewall & NAT
The same connection state powers stateful firewalling and address translation.
Failover & Floating IPs
Portable IPs
Assign movable IPs to any host in the cluster.
Automatic failover
A floating IP moves to a healthy host the moment one fails.
Instant takeover
Traffic reroutes to the new host within milliseconds.
Cluster-wide ownership
Which host owns each IP is replicated across the whole cluster.
BGP Edge Routing
Advertise your networks
Peer with upstream routers and announce your VM networks.
Smart path selection
The best route to each destination is chosen automatically.
Route filtering
Control exactly which routes you import and export.
Resilient peering
Lossless restarts and sub-second detection of neighbour failures.
RPKI origin validation
Received routes are checked against signed RPKI data, and invalid origins are rejected.
EVPN address family
Exchange MAC and VTEP reachability for the VXLAN overlay as BGP routes.
Gateway High Availability
Redundant gateways
A standby gateway takes over automatically if the active one fails.
Fast failure detection
A dedicated heartbeat spots failures in under a second.
Failover & failback
Automatic failover, with operator-controlled failback when you choose.
One owner per IP
Exactly one gateway owns each virtual IP at any moment.
Zero-Trust Firewall
Layered policy
Rules from network-wide down to a single VM, evaluated by priority.
Default-deny
Nothing passes unless you allow it, with stateful connection tracking throughout.
Rich matching
Match on address, network, port, protocol, hardware address or domain.
Scheduled rules
Turn rules on and off by day and time.
Domain-based rules
Allow or block by domain name, kept in sync automatically.
Conflict detection
Overlapping or contradictory rules are caught before they apply.
Presets & batch apply
Web, database, mail and game-server presets applied all at once.
Hardware binding
Bind ports to specific devices, hard or soft.
Per-source connection limits
Cap how many connections any single source can open, blocking abusers automatically.
Intrusion Detection
Traffic anomaly detection
Suspicious traffic patterns are spotted as packets flow through the platform.
Early threat signal
Get alerted to probing and abnormal behaviour before it becomes an incident.
Works with the firewall
Detection sits alongside the zero-trust firewall for layered defence.
Tied into alerting
Detections surface through the same alerting and event stream as everything else.
Load Balancing
Virtual IPs
High-speed load balancing spread across your backends.
Balancing algorithms
Round-robin, least-connections, weighted and source-hash.
Stable backend selection
Consistent hashing keeps each client on the same backend.
Health checks
Unhealthy backends are removed automatically, with fast return paths.
Layer-7 HTTP balancing
Route HTTP traffic by host and path, with optional TLS termination at the balancer.
Bandwidth & Usage
Bandwidth limits
Per-VM upload and download limits, shared pools and burst allowances.
Monthly quotas
Usage caps that reset automatically each month.
Usage-based billing
Byte and packet accounting with 95th-percentile calculation.
Flow records & export
Per-connection stats with CSV and JSON export.
Clustering & Virtual Networks
Virtual networks
Isolated networks that span every host in the cluster.
Resilient cluster state
Leader election and replicated state keep the cluster consistent.
Everything replicated
Addresses, blocklists, peers, floating IPs and tenants stay in sync cluster-wide.
Compute & gateway nodes
Run a node as a VM host or as a traffic gateway.
Multi-Tenancy & Isolation
Tenant management
Create tenants with their own quotas and usage tracking.
Scoped API keys
Generate, validate, expire and revoke keys per tenant.
Private networks
Isolated networks with controlled membership.
Container networking
Attach containers to the same managed networks, firewall and address pools as VMs.
Workload portability
The same networking model applies whether a workload is a VM or a container.
Interfaces & Hardware
Network-card management
Physical network cards are detected and given stable names.
Link bonding
Combine multiple links for redundancy or more throughput.
Consistent packet sizes
Matching packet sizes across bonded links and virtual networks.
Tamper protection
Changes to managed interfaces made outside the platform are detected and reconciled back to their intended configuration.
Interface lockdown
An optional kernel-level guard blocks out-of-band deletion of managed interfaces in real time.
Optional hardware offload
Where the network card supports it, packet processing can offload to hardware, while software stays the default.
Observability
Metrics & dashboards
Prometheus-compatible metrics for your dashboards and alerting.
Alerting
Threshold alerts with actions, cooldown and history.
Live events
A real-time event stream across the whole system.
Audit log
A structured record of every management action.
Event webhooks
Push signed event notifications to your own endpoints, each carrying an HMAC signature.
Platform & Lifecycle
Backup & restore
Full and config backups with schedules and retention.
Self-update
Signed, pull-based updates the agent verifies against its baked-in publisher key before applying.
Self-healing
Automatic checks and repair for disk, memory, database and networking.
Always-on supervision
An independent watchdog restarts the platform if it ever stalls.
Account TLS & Private CA
Per-account certificate authority
Each account gets its own private CA, so certificates from one account never trust another.
Automatic node certificates
Nodes are issued signed leaf certificates the moment they activate — no manual key wrangling.
Auto-trust
Every node automatically trusts its own account CA, so internal traffic is encrypted out of the box.
Automatic renewal
Certificates renew themselves before they expire, with no downtime or operator action.
Domain-change re-signing
Change a node’s domain and a fresh certificate is issued and rolled out automatically.
Plugins & Developer Program
Signed plugins
Extend the platform with plugins that are cryptographically signed and verified before they run.
Built-in store
Discover and install plugins from a built-in store right inside the platform.
Developer program
Approved developers receive their own signing certificates to build and publish plugins.
Publish to the marketplace
Ship your plugin to other operators through the marketplace.
Revocation
A signed revocation list instantly disables any compromised or withdrawn plugin.
Security
Signed end-to-end
Configs, licenses, plugins and binaries are all cryptographically signed.
Brute-force protection
Repeated failed logins are locked out.
Request validation
Body-size and content-type limits on every API.
Anti-tampering
Time-drift and clock-spoofing checks keep the platform honest even offline.
Single Sign-On
SAML 2.0 sign-on
Your team can sign in through any SAML identity provider, kept off until an admin turns it on.
OpenID Connect sign-on
Sign in through any OpenID Connect provider, with new accounts created as plain customers.
Role-based access
Scope operator accounts to admin, operator, billing or read-only roles.
Licensing & Activation
Hardware-bound licences
Each licence is tied to the machine it runs on and cannot be copied elsewhere.
Per-machine activation
Activate node by node, with each activation recorded against your licence.
Silent auto-renewal
Licences renew quietly in the background so coverage never lapses.
Key regeneration
Roll a node’s key when you need to, without losing its activation.
Guided onboarding
New nodes pull their full configuration on first contact and are ready in minutes.
Revocation
A signed revocation list lets you retire a licence instantly across the fleet.
Billing & Wallet
Plans & billing cycles
Choose a plan and a monthly, quarterly, semi-annual or annual cycle.
Account wallet
Keep a balance on file to cover renewals and new orders.
Automatic renewal payments
Renewals are paid from your wallet automatically, with an invoice issued ahead of time.
Discount coupons
Apply percentage or fixed-amount coupon codes at checkout.
PDF invoices
Every paid order generates a downloadable, numbered PDF invoice.
Order & proof workflow
Place an order, submit payment proof, and get your licence once it’s verified.
APIs, CLI & Onboarding
Full API access
REST, gRPC, WebSocket and a local control socket.
Command-line control
Manage every feature from one command-line tool.
Scriptable activation
License-gated install + activation that drops straight into automation.
Bulk operations
Create many firewall rules or DNS records in a single API request.