Files
Nexus-Guard-Suite/docs/portfolio/features.md
T
datadunia 4eea268ec5 refactor: merge setup.sh into update.sh for seamless first-run
- update.sh now auto-generates .env from .env.example if missing
- Generates random JWT/SALT keys on first run
- Existing .env is never overwritten
- Deleted redundant setup.sh
- Updated all documentation references
2026-06-26 17:23:52 +07:00

291 lines
7.0 KiB
Markdown

# Features
NexusGuard provides enterprise-grade SD-WAN capabilities with a focus on security, automation, and ease of use.
## Zero-Trust Security
### No Public Registration
The `/auth/register` endpoint is locked. Admin accounts can only be created via CLI:
```bash
# Docker
docker exec -it nexus-guard-suite-server-core-1 ./server-core \
-create-admin -user admin -pass "SecurePassword123!"
# Native
sudo /usr/local/bin/nexusguard-server \
-create-admin -user admin -pass "SecurePassword123!"
```
**Why?** Eliminates the attack surface of open registration. No bots, no brute force, no unauthorized accounts.
### Encrypted Provisioning
Agent provisioning uses AES-256-GCM encryption:
1. Agent sends registration token + hardware ID (HWID)
2. Server generates WireGuard config
3. Config encrypted with AES-256-GCM before transmission
4. Agent decrypts in memory, never touches disk
**Why?** WireGuard keys are sensitive. Encryption in transit prevents interception even on compromised networks.
### Memory-Injected Tunnels
WireGuard configuration is injected directly into the kernel via `IpcSet`:
```
Traditional: Config file → /etc/wireguard/wg0.conf → wg-quick up wg0
NexusGuard: Config bytes → IpcSet() → Tunnel active (no files)
```
**Benefits:**
- No config files to steal
- No lingering configs after disconnect
- Multiple agents can run without conflicts
- Clean uninstall = kill process
### Hardware ID Binding
Each agent is bound to its hardware via HWID:
- **Linux:** `/sys/class/dmi/id/product_uuid` or CPU serial
- **Windows:** DMI product UUID
- **macOS:** IOPlatformSerialNumber
HWID is included in provisioning request. Server validates before issuing config.
## Multi-Node Support
### Geographic Scaling
Deploy WireGuard servers across multiple regions:
```
Node 1 (Singapore): 10.172.21.0/24
Node 2 (Frankfurt): 10.172.22.0/24
Node 3 (Virginia): 10.172.23.0/24
```
Each node has its own:
- IP pool (CIDR)
- Interface address
- Peer defaults (DNS, MTU, Keepalive)
- Endpoint (IP/Domain + Port)
### Centralized IPAM
IP Address Management is centralized in the database:
1. Admin defines IP pool per node (e.g., `10.172.21.0/24`)
2. When device is created, server allocates next available IP
3. IP is reserved in database (no duplicates)
4. IP is released when device is deleted
**Why?** Prevents IP conflicts across nodes. Enables static IP assignment for critical devices.
### Per-Node Defaults
Each node can have different peer defaults:
| Setting | Node 1 (SG) | Node 2 (DE) |
|---------|-------------|-------------|
| DNS | `1.1.1.1` | `8.8.8.8` |
| MTU | 1420 | 1280 |
| Keepalive | 25s | 0s |
| AllowedIPs | `10.172.21.0/24` | `0.0.0.0/0` |
Devices inherit from their node, with per-device overrides available.
## Real-Time Firewall
### nftables Integration
NexusGuard manages Linux nftables directly:
```bash
# What NexusGuard creates in the kernel
table ip nexusguard {
set peers_v4 {
type ipv4_addr
elements = { 10.172.21.2, 10.172.21.3, ... }
}
chain forward {
type filter hook forward priority 0; policy accept;
ip daddr @peers_v4 accept
ip saddr @peers_v4 accept
drop
}
}
```
### Per-Peer Rules
Each device can have custom firewall rules:
- **Allow/Block IP ranges** — `192.168.1.0/24`, `10.0.0.1`
- **Port filtering** — TCP/UDP port ranges
- **Direction control** — Inbound, outbound, or both
Changes are synced to kernel instantly — no restart required.
### Default SSH Provisioning
New peers automatically get SSH access (port 22):
```go
// Automatically added on peer creation
AddFirewallRule(peerIP, "0.0.0.0/0", 22, "tcp", "allow")
```
**Why?** Ensures remote access isn't accidentally locked out.
## Cross-Platform Agent
### Linux — Systemd Daemon
```bash
# Automated install
sudo ./install_agent.sh \
--server-url "https://api.yourdomain.com" \
--token "REG_TOKEN"
# Verify
sudo systemctl status sys-bridge.service
```
Features:
- Runs as root (required for WireGuard)
- Auto-restart on failure
- Journal logging
- Config at `~/.config/nexusguard/nexusguard.conf`
### Windows — System Tray + Service
System tray application with service management:
| Menu Item | Action |
|-----------|--------|
| Status | Shows Connected/Disconnected |
| IP | Shows internal VPN IP |
| Connect | Start tunnel |
| Disconnect | Stop tunnel |
| Install as Service | Register Windows service |
| Start on Boot | Toggle auto-start |
### macOS — System Tray
System tray application (no service support):
- Config at `~/Library/Application Support/NexusGuard/nexusguard.conf`
- Logs at `~/Library/Logs/NexusGuard/`
### Self-Healing
All platforms implement exponential backoff:
```
Failure 1: Wait 30s, retry
Failure 2: Wait 60s, retry
Failure 3: Wait 120s, retry
...
Failure N: Wait 300s (max), retry
```
Network drops are handled gracefully — tunnel stays alive, agent reconnects in background.
## Dashboard
### Glassmorphism Design
Futuristic UI with glass-like transparency:
- Backdrop blur effects
- Semi-transparent panels
- Gradient accents
- Smooth animations
### Live Telemetry
Device health polled every 10 seconds:
```
┌─────────────────────────────────────────┐
│ Device: server-01 │
│ Status: ● Online │
│ IP: 10.172.21.2 │
│ Last Handshake: 15s ago │
│ Uptime: 3d 14h 22m │
└─────────────────────────────────────────┘
```
### QR Code Setup
Generate QR codes for mobile WireGuard clients:
1. Create device in Dashboard
2. Click "Show QR Code"
3. Scan with WireGuard app on iOS/Android
4. Tunnel ready — no manual config
### Share Links
Time-limited config sharing:
1. Click "Generate Share Link"
2. Set expiration (1h, 24h, 7d)
3. Share URL with recipient
4. Recipient downloads `.conf` file
5. Link expires automatically
## Deployment Flexibility
### Docker (Recommended)
```bash
git clone https://git.datadunia.com/nexusguard/Nexus-Guard-Suite.git
cd Nexus-Guard-Suite
bash update.sh
```
One command to start everything. Auto-migration on first boot.
### Native Install
For servers without Docker:
```bash
sudo bash nexusguard-install.sh
```
Creates systemd service, nginx config, PostgreSQL database.
### Development Mode
Hot-reload for both backend and frontend:
```bash
# Terminal 1: Backend
cd apps/server-core
go run -tags dev .
# Terminal 2: Frontend
cd apps/dashboard-ui
npm run dev
```
Auto-migration on startup. No Docker required.
## Comparison
| Feature | NexusGuard | Traditional VPN | Commercial SD-WAN |
|---------|------------|-----------------|-------------------|
| Zero-trust | ✅ | ❌ | ✅ |
| Fileless tunnel | ✅ | ❌ | ❌ |
| Multi-platform agent | ✅ | Partial | ✅ |
| Real-time firewall | ✅ | ❌ | ✅ |
| Self-hosted | ✅ | ✅ | ❌ |
| Open source | ✅ | ✅ | ❌ |
| Cost | Free | Free | $$$$ |