Secure the protocols at the core of your network.
Axiom places an inline reverse proxy in front of your SMB file shares and a resilient DNS security node inside your network, with centralized policy, reputation, telemetry, and offline-ready operation.
No agent on endpoints Ubuntu and Debian Air-gap capable Cluster-ready data plane
# Run the signed installer from the Axiom release package
$ chmod +x axiom-installer.sh
$ sudo ./axiom-installer.sh
✓ Role selected: management
✓ Configuration written to /etc/axiom/axiom.toml
✓ axiom.service enabled and started
✓ Management UI ready on :8443
$ ▋
Self-hosted control plane
Cluster-managed data plane
Offline license activation
No endpoint deployment
Protect file traffic and DNS. Operate both from one console.
Axiom separates the management plane from the SMB and DNS data planes. Start with one node per role, then add cluster-managed replicas as capacity and availability requirements grow.
Reverse Proxy for SMB
Sit Axiom between your users and your file server. The SMB Node transparently proxies SMB2/SMB3 traffic and inspects file write streams before forwarding them. Firewall policy can then restrict the real file server so clients reach it only through Axiom.
- Transparent SMB2/SMB3 reverse proxy
- Streaming SHA-256 and MD5 calculation
- Signatures, archive, entropy, and reputation policy
- Per-transfer evidence and security events
DNS Security Gateway
The DNS Node receives internal queries, applies local policy, caches approved answers, serves local records, and forwards permitted requests to the upstream resolvers you choose.
- UDP and TCP forwarding on port 53
- Allow, monitor, and block domain rules
- Optional administrator-managed threat feeds
- Local A/AAAA records and response caching
- Customizable air-gap-ready HTTP block page
Inline SMB inspection
Inspect SMB create, write, and close flows while data is relayed between clients and file servers.
Streaming reputation
Calculate SHA-256 and MD5 without buffering whole files, then apply policy-driven hash verdicts.
DNS policy enforcement
Allow, monitor, or block domains using local rules and administrator-selected threat feeds.
Local DNS and caching
Serve local A/AAAA records, cache safe answers, and forward approved queries to configured upstream resolvers.
Branded DNS block page
Explain HTTP policy blocks with an air-gap-ready page, custom logo, color, support link, and multilingual UTF-8 text.
Verified policy delivery
Push encrypted, authenticated policy updates from Management and confirm which nodes applied them.
Unified operations
Review node health, SMB transfer evidence, DNS activity, policy events, and support diagnostics in one console.
Cluster-managed scale
Enroll additional SMB or DNS nodes from a shared service template and track health, drift, and synchronization centrally.
Secure replica enrollment
Protect cluster joins with an Argon2-secured password, then issue a unique revocable credential to every replica.
3
Production server roles
2
Protected network protocols
0
Endpoint agents required
1
Central management plane
A distributed system, simple to operate.
Axiom is built from independent nodes you deploy on your own Debian-based Linux. Management controls policy and cluster state; data-plane nodes enforce close to the traffic they protect.
Management Node
The control plane. Registers nodes, manages policy, pushes encrypted updates, and presents unified telemetry.
SMB Node
The reverse-proxy data plane that secures SMB traffic between your users and file servers.
DNS Node
The forwarding and caching data plane that evaluates DNS queries before using configured upstream resolvers.
Cluster Groups
Optional SMB or DNS groups that share service settings, policy, reputation, and operational health without copying host-specific NIC configuration.
Control plane
Management Node
Registers nodes, distributes encrypted policy updates, receives telemetry, and provides the administrative console.
Data plane
SMB Nodes
One or more inline SMB2/SMB3 proxies, with shared service policy and host-specific listener addressing.
Data plane
DNS Nodes
One or more forwarding and caching resolvers with synchronized local records, policy, and upstream settings.
Add replicas without rebuilding configuration.
Create an SMB or DNS cluster from a healthy source node, then enroll replicas through the standard installer. Management remains the control-plane source of truth.
Seed from a live node
Capture SMB backend routes or DNS upstream, cache, and timeout settings from an enrolled source node.
Enroll securely
Use the cluster name and join password once. Every accepted replica receives its own revocable node credential.
Keep policy consistent
Track shared service-template drift and synchronize policy, reputation, and delivery acknowledgements from Management.
Choose the traffic HA layer
Publish multiple DNS nodes to clients, or place SMB nodes behind an external TCP/445 VIP with session affinity.
Cluster membership synchronizes Axiom configuration; it does not create or control an external VIP. Existing data-plane nodes continue with their last installed local configuration and policy during a temporary Management outage.
From zero to protected in three steps
Deploy your nodes
Install Axiom on any Debian-based Linux with a single command. Nodes register securely to your Management Node.
Route your traffic
Point users at the SMB Node in front of your file server, and delegate DNS to the Axiom DNS Node.
Enforce policy at the edge
Define policy centrally, confirm delivery to each node, and review the evidence produced by SMB and DNS traffic.
Put enterprise security at the edge of your business.
See how Axiom protects SMB file services and DNS in a deployment walkthrough with our team.