Linux moves packets. CyberGuard decides. An inline gateway between the internet and the office network — every forwarded packet allowed or dropped by the CyberGuard Decision Engine, not by nftables business rules.
Fail-closed: if nothing explicitly allows a packet, it is dropped
Zones: WAN, LAN, DMZ, GUEST, ADMIN, VPN — traffic must go through the box
Inline gateway. Every forwarded packet is allowed or dropped by the CyberGuard Decision Engine — not by nftables business rules. If the engine is not running, forwarding is dropped. Traffic does not leak through.
Fail-closed by default
If nothing explicitly allows a packet, it is dropped. Guest Wi‑Fi cannot reach LAN, DMZ, ADMIN, or VPN. Internet SSH (22) and Remote Desktop (3389) stay closed. Established return traffic for a flow we already allowed still passes.
IPS, intel, then policy
Scan, brute-force, exploit, and sweep detectors auto-block the source for 10 minutes. HIGH and CRITICAL threat-intel hits drop even if a zone rule would allow. Application labels detect and log — they do not block unless you ask.
Where it sits
Internet → ISP modem → CyberGuard WAN
CyberGuard LAN → office switch / Wi‑Fi AP
Phones, PCs, printers → that switch
Two NICs (or VLANs). Do not plug CyberGuard into the office LAN as just another PC. Traffic that does not pass through the box is not protected.
Decision pipeline
TCP connection-state check
IPS (scan / brute-force / exploit / sweep)
Threat intelligence + risk
Session table (return traffic we already allowed)
Application label (SNI / Host / port)
Zone + rule policy (priority, first match)
Rate limit → ALLOW / LOG / DROP + JSON event
What default policy allows
From
To
Meaning
LAN
Internet
Employees may browse
GUEST
Internet
Visitors browse only
LAN
DMZ / VPN
Office may reach servers and tunnels
VPN
LAN
Remote staff may reach the office
ADMIN
FIREWALL
On-site management of the box
What default policy blocks
Rule
Blocks
CG-SSH-BLOCK
Internet → office SSH (port 22)
Remote Desktop
Internet → office RDP (port 3389)
CG-GUEST-ISOLATE
Guest Wi‑Fi → LAN, DMZ, ADMIN, VPN
CG-DMZ-ISOLATE
Servers may not initiate to employees
CG-DEFAULT
Everything else (default DROP)
What it is
A userspace firewall appliance for on-site monthly clients
Inline between the internet and the client network
Zones for employees, guests, servers, VPN, and management
One verdict from policy, intel, IPS, and application labels
What it is not (yet)
Not a 24/7 SOC, MDR, or breach warranty
Not a Windows desktop agent or a consumer one-click install
Does not see traffic that bypasses the box
Does not learn “normal business hours” yet (Phase 7 / v1.0)
No full file inspection or app ID when there is no SNI
Included with monthly protection
Not sold as a standalone box
The CyberGuard Firewall ships with Guardian and Diamond. We image it, place it inline, and include it in the refundable hardware deposit — you do not buy the appliance from the shop.
No. This is not a consumer one-click product. Diamond Bright images Core v0.7 and sets it up on site (or guided remote). You do not compile software or write nftables.
Does this replace my monthly CyberGuard plan?
No. Guardian ($197/mo) includes the appliance — See it + Block it. Essential ($98) is visibility only and does not include a firewall. Diamond ($350) includes the box and we manage it. The appliance is not sold separately.
Does it block YouTube or Microsoft 365?
Not by default. Core v0.7 names apps from TLS SNI, HTTP Host, or well-known ports (Office 365, streaming, cloud storage, RDP) and detects and logs. We change the rule to DROP only if you ask.
What if the engine stops?
Fail-closed. systemd restarts the service in about two seconds. While it is down, forwarding is dropped — traffic does not leak through. The box does not protect devices that bypass it.
What version is shipping?
CyberGuard Firewall Core v0.7 (12 August 2026): sessions and TCP state, zones, WireGuard management, threat-intel lookup, IPS (scan / brute / exploit / sweep), and application labels. Learning “normal business hours” (v1.0) is not shipped.
CyberGuard Firewall™ is a managed appliance product of Diamond Bright LLC.
It does not guarantee prevention of all cyberattacks, compromises, or losses.
Not a 24/7 SOC. Authorized configuration only on networks you own or control.