NTPSense InetGateway is a firewall, multi-WAN router, and self-hosted site-to-site VPN mesh — engineered on FreeBSD from a Rust daemon up, for teams who'd rather own their edge than rent it.
Every subsystem is either kernel-native FreeBSD or a purpose-built daemon — nothing bolted on.
ntpsense-configd governs pf, Kea DHCP, WireGuard, and Squid through a single Unix-socket control plane — no shelling out to fragile scripts under load.
Full-mesh site-to-site connectivity over Headscale + WireGuard — your keys, your coordination server, no third-party relay in the trust path.
Dedicated and shared/NAT uplinks are treated differently by design — mesh, DNS, and sync traffic prefer your real IP link automatically.
Multi-zone segmentation out of the box, with Role-based interface assignment enforced at the firewall layer, not just labeled in a UI.
Local caching proxy with categorized blocklists, bandwidth accounting, and authentication — first-match-wins ACL ordering done correctly.
Runs on commodity Atom, N-series, and Core-class boards — no proprietary silicon required to get started, a clear upgrade path when you need one.
Start where your network actually is today — the same daemon and mesh design carries forward as you grow.
Home office to multi-branch — the segment NTPSense is built and validated for right now.
Multi-site organizations needing centralized policy and higher throughput per unit.
NFV/vCPE-class deployment — the gap to close is named, not hidden.
Pick a tier, get an ISO, and be filtering traffic in under an hour.