Network, policy and visibility. Under control.
Firewall, site VPNs, intrusion prevention and application control. Argos makes your network rules explicit.
Zone firewall, VLANs and port publication
Argos separates networks into trust zones and defines which communications are allowed between them. It manages access rules, port publishing, address translation and blocklists. Physical interfaces and virtual networks distinguish offices, operational devices and exposed services.
Firewall changes with confirmation
Firewall rules are applied together while preserving the previous configuration. Administrators have 60 seconds to confirm: cancellation or timeout restores the saved rules. Defined management access is protected against accidental lockout. This protection covers firewall rules, not every interface or service change.
Multi-WAN with reachability checks
Uplinks have default routes ordered by metric. An optional ICMP probe runs through the uplink device: after three consecutive failures the route is withdrawn and restored on the first success. Policy routing maps destinations to per-uplink tables. No session-continuity or bandwidth-bonding guarantee is published.
VPN and protected site connectivity
Argos connects sites and remote networks through encrypted VPN tunnels. Configuration covers key or certificate authentication, reachable networks and remote gateway settings. Checks detect overlaps between local networks and active tunnels. Compatibility and continuity need to be verified with actual devices and connections.
QoS: ingress and egress bandwidth classes
Bandwidth management sets priorities and limits for incoming and outgoing traffic on each interface. Classes can define a guaranteed allocation and a maximum rate. Classification uses service ports: it does not automatically prioritize applications recognized by traffic analysis. Request limits are also available for published services.
DNS protection and domain controls
DNS protection filters requests using blocklists organized by category, with exceptions for allowed domains and subdomains. You can choose upstream resolution services or use direct resolution. Configuration is checked before it is applied.
Intrusion prevention and traffic observation
The DPI tier applies inline prevention in selected zones to flows allowed by policy. Flows are marked so subsequent packets and replies also return to the inspection engine. The advanced tier adds passive observation, authentication events, DNS anomalies, periodic communications and host inventory. The management baseline remains outside inspection.
Encrypted content and analytical limits
Argos does not decrypt TLS. It analyzes available metadata, TLS/QUIC JA4 client fingerprints and application signals; traffic with insufficient signals remains unclassified. When the inline engine is unavailable the queue allows traffic through. Passive observation does not issue blocking verdicts. Coverage depends on selected zones, protocols and loaded signatures.
DPI tier requirements
Traffic analysis requires at least 2 cores, 2 GiB RAM and 20 GB disk; the advanced level requires at least 4 cores, 4 GiB and 40 GB, plus required components. These are activation thresholds, not throughput guarantees. Interface count and speed depend on hardware; verify sizing against expected traffic.
Application visibility and control
The console classifies applications using documented names and addresses, showing per-zone volumes and the unclassified share. Zone policies can allow, block or block and report categories and applications. Per-client detail stays disabled until an administrator enables it; metadata handling requires attention to privacy.
Network services and web publishing
Alongside DNS and VLANs, Argos manages DHCP server or relay on internal interfaces and a reverse proxy for publishing web services with names and certificates. Networks, zones and exposed services are explicit administrator choices. Publishing a service remains separate from authorizing console access.
Partner remote management
Connecting to Citadel lets an approved partner administer the appliance through a dedicated tunnel and verified sessions. This is full administrative access that must be granted deliberately. Disconnecting closes the link and revokes its keys; it does not create a high-availability cluster.
These capabilities are documented in the source; they are not hardware certifications, benchmarks or availability guarantees. Verify configuration and workload during assessment.
Documented capabilities
Application visibility and control
The console classifies applications using documented names and addresses, showing per-zone volumes and the unclassified share.
DNS protection and domain controls
DNS lists are downloaded, deduplicated and grouped by category.
Intrusion prevention and traffic observation
Intrusion prevention and traffic observation in selected zones.
Zone firewall, VLANs and port publication
Access rules, trust zones and controlled service publishing.
VPN and protected site connectivity
Encrypted connections between sites and remote networks, with defined access.
Multi-WAN with reachability checks
Uplinks have default routes ordered by metric.
Partner remote management
Connecting to Citadel lets an approved partner administer the appliance through a dedicated tunnel and verified sessions.
QoS: ingress and egress bandwidth classes
The tc HTB engine applies per-interface classes with guaranteed rates, optional ceilings and bursts.
Control starts with a conversation.
Tell us about your infrastructure. Let’s start with what you actually need.
Talk to an engineer