FreeBSD-native · built from scratch · no third-party VPN dependency

The gateway appliance that owns
every packet from WAN to zone.

NTPSense InetGateway is a firewall, multi-WAN router, and self-hosted site-to-site VPN mesh — engineered on FreeBSD from a Rust daemon up, for teams who'd rather own their edge than rent it.

LIVE TOPOLOGY — MULTI-ZONE GATEWAY
WAN1 dedicated · fiber WAN2 dedicated · fiber WAN3 shared · failover NTPSense pf · Kea · WireGuard Site Mesh VPN LAN1 office network DMZ public services GUESTNET isolated wifi Branch Site mesh peer, via VPN
FreeBSD 14.3
kernel-native pf, wg(4), no shim layers
Rust
core daemon — memory-safe, single static binary
0
third-party VPN relay dependency
SMB → Telco
one architecture, three market tiers
Architecture

Built as an appliance, not a distro repackaged.

Every subsystem is either kernel-native FreeBSD or a purpose-built daemon — nothing bolted on.

01 · CONTROL PLANE

Rust daemon, one socket

ntpsense-configd governs pf, Kea DHCP, WireGuard, and Squid through a single Unix-socket control plane — no shelling out to fragile scripts under load.

02 · MESH VPN

Site Mesh VPN, self-hosted

Full-mesh site-to-site connectivity over Headscale + WireGuard — your keys, your coordination server, no third-party relay in the trust path.

03 · MULTI-WAN

Failover that knows the difference

Dedicated and shared/NAT uplinks are treated differently by design — mesh, DNS, and sync traffic prefer your real IP link automatically.

04 · ZONES

WAN / LAN / DMZ / GUESTNET

Multi-zone segmentation out of the box, with Role-based interface assignment enforced at the firewall layer, not just labeled in a UI.

05 · PROXY

Squid, with real category filtering

Local caching proxy with categorized blocklists, bandwidth accounting, and authentication — first-match-wins ACL ordering done correctly.

06 · HARDWARE

x86 you can actually source

Runs on commodity Atom, N-series, and Core-class boards — no proprietary silicon required to get started, a clear upgrade path when you need one.

Where it runs

One architecture. Three points of scale.

Start where your network actually is today — the same daemon and mesh design carries forward as you grow.

DEPLOY TODAY

SMB & Branch Office

Home office to multi-branch — the segment NTPSense is built and validated for right now.

  • 6-port multi-zone gateway, single unit
  • Site Mesh VPN across branch + HQ
  • Dedicated/shared WAN-aware failover
ROADMAP — NEAR TERM

Enterprise

Multi-site organizations needing centralized policy and higher throughput per unit.

  • Xeon-D class hardware ceiling
  • Centralized multi-site management
  • SD-WAN path selection
ROADMAP — CHARTED

Telco & Carrier Edge

NFV/vCPE-class deployment — the gap to close is named, not hidden.

  • DPDK/VPP packet-path evaluation
  • 25G/100G port ceiling
  • Carrier-grade redundancy

See it running on your own hardware.

Pick a tier, get an ISO, and be filtering traffic in under an hour.

Get Started →