Core v0.7 · Linux inline gateway · fail-closed

CyberGuard Firewall™

Linux moves packets. CyberGuard decides. An inline gateway between the internet and the office network — every forwarded packet allowed or dropped by the CyberGuard Decision Engine, not by nftables business rules.

  • Fail-closed: if nothing explicitly allows a packet, it is dropped
  • Zones: WAN, LAN, DMZ, GUEST, ADMIN, VPN — traffic must go through the box
  • IPS (scan / brute / exploit / sweep) + HIGH/CRITICAL threat-intel drops
  • Diamond Bright sets it up on site — not a consumer one-click install
CyberGuard Firewall™ appliance — compact Linux firewall with Ethernet ports

Linux moves packets. CyberGuard decides.

Inline gateway. Every forwarded packet is allowed or dropped by the CyberGuard Decision Engine — not by nftables business rules. If the engine is not running, forwarding is dropped. Traffic does not leak through.

Fail-closed by default

If nothing explicitly allows a packet, it is dropped. Guest Wi‑Fi cannot reach LAN, DMZ, ADMIN, or VPN. Internet SSH (22) and Remote Desktop (3389) stay closed. Established return traffic for a flow we already allowed still passes.

IPS, intel, then policy

Scan, brute-force, exploit, and sweep detectors auto-block the source for 10 minutes. HIGH and CRITICAL threat-intel hits drop even if a zone rule would allow. Application labels detect and log — they do not block unless you ask.

Where it sits

Internet → ISP modem → CyberGuard WAN CyberGuard LAN → office switch / Wi‑Fi AP Phones, PCs, printers → that switch

Two NICs (or VLANs). Do not plug CyberGuard into the office LAN as just another PC. Traffic that does not pass through the box is not protected.

Decision pipeline

  1. TCP connection-state check
  2. IPS (scan / brute-force / exploit / sweep)
  3. Threat intelligence + risk
  4. Session table (return traffic we already allowed)
  5. Application label (SNI / Host / port)
  6. Zone + rule policy (priority, first match)
  7. Rate limit → ALLOW / LOG / DROP + JSON event

What default policy allows

FromToMeaning
LANInternetEmployees may browse
GUESTInternetVisitors browse only
LANDMZ / VPNOffice may reach servers and tunnels
VPNLANRemote staff may reach the office
ADMINFIREWALLOn-site management of the box

What default policy blocks

RuleBlocks
CG-SSH-BLOCKInternet → office SSH (port 22)
Remote DesktopInternet → office RDP (port 3389)
CG-GUEST-ISOLATEGuest Wi‑Fi → LAN, DMZ, ADMIN, VPN
CG-DMZ-ISOLATEServers may not initiate to employees
CG-DEFAULTEverything else (default DROP)

What it is

  • A userspace firewall appliance for on-site monthly clients
  • Inline between the internet and the client network
  • Zones for employees, guests, servers, VPN, and management
  • One verdict from policy, intel, IPS, and application labels

What it is not (yet)

  • Not a 24/7 SOC, MDR, or breach warranty
  • Not a Windows desktop agent or a consumer one-click install
  • Does not see traffic that bypasses the box
  • Does not learn “normal business hours” yet (Phase 7 / v1.0)
  • No full file inspection or app ID when there is no SNI

Included with monthly protection

Not sold as a standalone box

The CyberGuard Firewall ships with Guardian and Diamond. We image it, place it inline, and include it in the refundable hardware deposit — you do not buy the appliance from the shop.

Do I install Linux or compile the firewall?

No. This is not a consumer one-click product. Diamond Bright images Core v0.7 and sets it up on site (or guided remote). You do not compile software or write nftables.

Does this replace my monthly CyberGuard plan?

No. Guardian ($197/mo) includes the appliance — See it + Block it. Essential ($98) is visibility only and does not include a firewall. Diamond ($350) includes the box and we manage it. The appliance is not sold separately.

Does it block YouTube or Microsoft 365?

Not by default. Core v0.7 names apps from TLS SNI, HTTP Host, or well-known ports (Office 365, streaming, cloud storage, RDP) and detects and logs. We change the rule to DROP only if you ask.

What if the engine stops?

Fail-closed. systemd restarts the service in about two seconds. While it is down, forwarding is dropped — traffic does not leak through. The box does not protect devices that bypass it.

What version is shipping?

CyberGuard Firewall Core v0.7 (12 August 2026): sessions and TCP state, zones, WireGuard management, threat-intel lookup, IPS (scan / brute / exploit / sweep), and application labels. Learning “normal business hours” (v1.0) is not shipped.

CyberGuard Firewall™ is a managed appliance product of Diamond Bright LLC. It does not guarantee prevention of all cyberattacks, compromises, or losses. Not a 24/7 SOC. Authorized configuration only on networks you own or control.