7.0 KiB
Features
NexusGuard provides enterprise-grade SD-WAN capabilities with a focus on security, automation, and ease of use.
Zero-Trust Security
No Public Registration
The /auth/register endpoint is locked. Admin accounts can only be created via CLI:
# Docker
docker exec -it nexus-guard-suite-server-core-1 ./server-core \
-create-admin -user admin -pass "SecurePassword123!"
# Native
sudo /usr/local/bin/nexusguard-server \
-create-admin -user admin -pass "SecurePassword123!"
Why? Eliminates the attack surface of open registration. No bots, no brute force, no unauthorized accounts.
Encrypted Provisioning
Agent provisioning uses AES-256-GCM encryption:
- Agent sends registration token + hardware ID (HWID)
- Server generates WireGuard config
- Config encrypted with AES-256-GCM before transmission
- Agent decrypts in memory, never touches disk
Why? WireGuard keys are sensitive. Encryption in transit prevents interception even on compromised networks.
Memory-Injected Tunnels
WireGuard configuration is injected directly into the kernel via IpcSet:
Traditional: Config file → /etc/wireguard/wg0.conf → wg-quick up wg0
NexusGuard: Config bytes → IpcSet() → Tunnel active (no files)
Benefits:
- No config files to steal
- No lingering configs after disconnect
- Multiple agents can run without conflicts
- Clean uninstall = kill process
Hardware ID Binding
Each agent is bound to its hardware via HWID:
- Linux:
/sys/class/dmi/id/product_uuidor CPU serial - Windows: DMI product UUID
- macOS: IOPlatformSerialNumber
HWID is included in provisioning request. Server validates before issuing config.
Multi-Node Support
Geographic Scaling
Deploy WireGuard servers across multiple regions:
Node 1 (Singapore): 10.172.21.0/24
Node 2 (Frankfurt): 10.172.22.0/24
Node 3 (Virginia): 10.172.23.0/24
Each node has its own:
- IP pool (CIDR)
- Interface address
- Peer defaults (DNS, MTU, Keepalive)
- Endpoint (IP/Domain + Port)
Centralized IPAM
IP Address Management is centralized in the database:
- Admin defines IP pool per node (e.g.,
10.172.21.0/24) - When device is created, server allocates next available IP
- IP is reserved in database (no duplicates)
- IP is released when device is deleted
Why? Prevents IP conflicts across nodes. Enables static IP assignment for critical devices.
Per-Node Defaults
Each node can have different peer defaults:
| Setting | Node 1 (SG) | Node 2 (DE) |
|---|---|---|
| DNS | 1.1.1.1 |
8.8.8.8 |
| MTU | 1420 | 1280 |
| Keepalive | 25s | 0s |
| AllowedIPs | 10.172.21.0/24 |
0.0.0.0/0 |
Devices inherit from their node, with per-device overrides available.
Real-Time Firewall
nftables Integration
NexusGuard manages Linux nftables directly:
# What NexusGuard creates in the kernel
table ip nexusguard {
set peers_v4 {
type ipv4_addr
elements = { 10.172.21.2, 10.172.21.3, ... }
}
chain forward {
type filter hook forward priority 0; policy accept;
ip daddr @peers_v4 accept
ip saddr @peers_v4 accept
drop
}
}
Per-Peer Rules
Each device can have custom firewall rules:
- Allow/Block IP ranges —
192.168.1.0/24,10.0.0.1 - Port filtering — TCP/UDP port ranges
- Direction control — Inbound, outbound, or both
Changes are synced to kernel instantly — no restart required.
Default SSH Provisioning
New peers automatically get SSH access (port 22):
// Automatically added on peer creation
AddFirewallRule(peerIP, "0.0.0.0/0", 22, "tcp", "allow")
Why? Ensures remote access isn't accidentally locked out.
Cross-Platform Agent
Linux — Systemd Daemon
# Automated install
sudo ./install_agent.sh \
--server-url "https://api.yourdomain.com" \
--token "REG_TOKEN"
# Verify
sudo systemctl status sys-bridge.service
Features:
- Runs as root (required for WireGuard)
- Auto-restart on failure
- Journal logging
- Config at
~/.config/nexusguard/nexusguard.conf
Windows — System Tray + Service
System tray application with service management:
| Menu Item | Action |
|---|---|
| Status | Shows Connected/Disconnected |
| IP | Shows internal VPN IP |
| Connect | Start tunnel |
| Disconnect | Stop tunnel |
| Install as Service | Register Windows service |
| Start on Boot | Toggle auto-start |
macOS — System Tray
System tray application (no service support):
- Config at
~/Library/Application Support/NexusGuard/nexusguard.conf - Logs at
~/Library/Logs/NexusGuard/
Self-Healing
All platforms implement exponential backoff:
Failure 1: Wait 30s, retry
Failure 2: Wait 60s, retry
Failure 3: Wait 120s, retry
...
Failure N: Wait 300s (max), retry
Network drops are handled gracefully — tunnel stays alive, agent reconnects in background.
Dashboard
Glassmorphism Design
Futuristic UI with glass-like transparency:
- Backdrop blur effects
- Semi-transparent panels
- Gradient accents
- Smooth animations
Live Telemetry
Device health polled every 10 seconds:
┌─────────────────────────────────────────┐
│ Device: server-01 │
│ Status: ● Online │
│ IP: 10.172.21.2 │
│ Last Handshake: 15s ago │
│ Uptime: 3d 14h 22m │
└─────────────────────────────────────────┘
QR Code Setup
Generate QR codes for mobile WireGuard clients:
- Create device in Dashboard
- Click "Show QR Code"
- Scan with WireGuard app on iOS/Android
- Tunnel ready — no manual config
Share Links
Time-limited config sharing:
- Click "Generate Share Link"
- Set expiration (1h, 24h, 7d)
- Share URL with recipient
- Recipient downloads
.conffile - Link expires automatically
Deployment Flexibility
Docker (Recommended)
git clone https://git.datadunia.com/nexusguard/Nexus-Guard-Suite.git
cd Nexus-Guard-Suite
./setup.sh
bash update.sh
One command to start everything. Auto-migration on first boot.
Native Install
For servers without Docker:
sudo bash nexusguard-install.sh
Creates systemd service, nginx config, PostgreSQL database.
Development Mode
Hot-reload for both backend and frontend:
# Terminal 1: Backend
cd apps/server-core
go run -tags dev .
# Terminal 2: Frontend
cd apps/dashboard-ui
npm run dev
Auto-migration on startup. No Docker required.
Comparison
| Feature | NexusGuard | Traditional VPN | Commercial SD-WAN |
|---|---|---|---|
| Zero-trust | ✅ | ❌ | ✅ |
| Fileless tunnel | ✅ | ❌ | ❌ |
| Multi-platform agent | ✅ | Partial | ✅ |
| Real-time firewall | ✅ | ❌ | ✅ |
| Self-hosted | ✅ | ✅ | ❌ |
| Open source | ✅ | ✅ | ❌ |
| Cost | Free | Free | |