Edge security platform

Secure the protocols at the core of your network.

Axiom places an inline reverse proxy in front of your SMB file shares and a resilient DNS security node inside your network, with centralized policy, reputation, telemetry, and offline-ready operation.

No agent on endpoints Ubuntu and Debian Air-gap capable Cluster-ready data plane

root@axiom-mgmt: ~

# Run the signed installer from the Axiom release package

$ chmod +x axiom-installer.sh

$ sudo ./axiom-installer.sh

✓ Role selected: management

✓ Configuration written to /etc/axiom/axiom.toml

✓ axiom.service enabled and started

✓ Management UI ready on :8443

$

Self-hosted control plane

Cluster-managed data plane

Offline license activation

No endpoint deployment

The platform

Protect file traffic and DNS. Operate both from one console.

Axiom separates the management plane from the SMB and DNS data planes. Start with one node per role, then add cluster-managed replicas as capacity and availability requirements grow.

Reverse Proxy for SMB

Sit Axiom between your users and your file server. The SMB Node transparently proxies SMB2/SMB3 traffic and inspects file write streams before forwarding them. Firewall policy can then restrict the real file server so clients reach it only through Axiom.

  • Transparent SMB2/SMB3 reverse proxy
  • Streaming SHA-256 and MD5 calculation
  • Signatures, archive, entropy, and reputation policy
  • Per-transfer evidence and security events

DNS Security Gateway

The DNS Node receives internal queries, applies local policy, caches approved answers, serves local records, and forwards permitted requests to the upstream resolvers you choose.

  • UDP and TCP forwarding on port 53
  • Allow, monitor, and block domain rules
  • Optional administrator-managed threat feeds
  • Local A/AAAA records and response caching
  • Customizable air-gap-ready HTTP block page

Inline SMB inspection

Inspect SMB create, write, and close flows while data is relayed between clients and file servers.

Streaming reputation

Calculate SHA-256 and MD5 without buffering whole files, then apply policy-driven hash verdicts.

DNS policy enforcement

Allow, monitor, or block domains using local rules and administrator-selected threat feeds.

Local DNS and caching

Serve local A/AAAA records, cache safe answers, and forward approved queries to configured upstream resolvers.

Branded DNS block page

Explain HTTP policy blocks with an air-gap-ready page, custom logo, color, support link, and multilingual UTF-8 text.

Verified policy delivery

Push encrypted, authenticated policy updates from Management and confirm which nodes applied them.

Unified operations

Review node health, SMB transfer evidence, DNS activity, policy events, and support diagnostics in one console.

Cluster-managed scale

Enroll additional SMB or DNS nodes from a shared service template and track health, drift, and synchronization centrally.

Secure replica enrollment

Protect cluster joins with an Argon2-secured password, then issue a unique revocable credential to every replica.

3

Production server roles

2

Protected network protocols

0

Endpoint agents required

1

Central management plane

Node architecture

A distributed system, simple to operate.

Axiom is built from independent nodes you deploy on your own Debian-based Linux. Management controls policy and cluster state; data-plane nodes enforce close to the traffic they protect.

  • Management Node

    The control plane. Registers nodes, manages policy, pushes encrypted updates, and presents unified telemetry.

  • SMB Node

    The reverse-proxy data plane that secures SMB traffic between your users and file servers.

  • DNS Node

    The forwarding and caching data plane that evaluates DNS queries before using configured upstream resolvers.

  • Cluster Groups

    Optional SMB or DNS groups that share service settings, policy, reputation, and operational health without copying host-specific NIC configuration.

Control plane

Management Node

Registers nodes, distributes encrypted policy updates, receives telemetry, and provides the administrative console.

role

Data plane

SMB Nodes

One or more inline SMB2/SMB3 proxies, with shared service policy and host-specific listener addressing.

role

Data plane

DNS Nodes

One or more forwarding and caching resolvers with synchronized local records, policy, and upstream settings.

Optional cluster groups coordinate source nodes and replicas through Management
Runs on any Debian-based Linux · Deployed as systemd-managed nodes
Cluster-managed scale

Add replicas without rebuilding configuration.

Create an SMB or DNS cluster from a healthy source node, then enroll replicas through the standard installer. Management remains the control-plane source of truth.

Read the cluster deployment guide
01

Seed from a live node

Capture SMB backend routes or DNS upstream, cache, and timeout settings from an enrolled source node.

02

Enroll securely

Use the cluster name and join password once. Every accepted replica receives its own revocable node credential.

03

Keep policy consistent

Track shared service-template drift and synchronize policy, reputation, and delivery acknowledgements from Management.

04

Choose the traffic HA layer

Publish multiple DNS nodes to clients, or place SMB nodes behind an external TCP/445 VIP with session affinity.

Cluster membership synchronizes Axiom configuration; it does not create or control an external VIP. Existing data-plane nodes continue with their last installed local configuration and policy during a temporary Management outage.

How it works

From zero to protected in three steps

01

Deploy your nodes

Install Axiom on any Debian-based Linux with a single command. Nodes register securely to your Management Node.

02

Route your traffic

Point users at the SMB Node in front of your file server, and delegate DNS to the Axiom DNS Node.

03

Enforce policy at the edge

Define policy centrally, confirm delivery to each node, and review the evidence produced by SMB and DNS traffic.

Put enterprise security at the edge of your business.

See how Axiom protects SMB file services and DNS in a deployment walkthrough with our team.