Faster and lighter
We used to build a webfilter based on a web proxy. But it may cause a serious latency problem in your network. Your web traffic needs to go through one point in your network that is your webfilter and it becomes a bottle neck. So we go for another approach. It is DNS Filtering. NxFilter is a DNS filter. Since it uses a light weight DNS protocol there is no need to have your network traffic going through anywhere. You get no latency problem with NxFilter.
Boosting up your internet speed
Our users are surprised when they see how much NxFilter improved their Internet connection speed. NxFilter has its own cache for DNS lookup. Suppose in your network, everybody uses Google public DNS server. Their DNS queries need to be sent to a DNS server on the Internet and they need to wait for the response from it. But if you run NxFilter in your network, it keeps a cache for the DNS response from its upstream DNS server and your users don’t need to wait for the response from the Internet.
Even though it is faster and lighter to be compared to the traditional web proxy based filtering, DNS Filtering had its own limit in the past. It didn’t support authentication. This is natural as DNS protocol doesn’t have any authentication scheme. It was the biggest obstacle for a DNS filter to be employed in a real world enterprise environment. However, NxFilter supports authentication based on IP and password and it also supports the single sign-on with Active Directory.
You just need to set up your DHCP server to make NxFilter to be the DNS server for your network. Then your users will use NxFilter as their DNS server and they will be under filtering. Forcing filtering to your users is also possible. You can block outgoing UDP/53 except from NxFilter. In that way, NxFilter becomes the only DNS server your users can use.
NxFilter can handle several thousand users easily. It has been proven by many users since we released its first version in 2013. It has built-in clustering for load balancing and you can add up to 4 nodes to your cluster. Some of our users reported that they are serving more than 30,000 users in their site with one cluster of NxFilter.
In reality, these malwares and botnet programs are network server/client programs by themselves. Naturally, they are heavily relying on DNS protocol. NxFilter is capable of detecting and blocking malware and botnet based on DNS packet inspection.
NxFilter provides a remote filtering client software that is NxClient for filtering the Internet activity of your off-site or mobile workers.
NxFilter provides Application Control through its agent that is NxClient. With this feature, you can block UltraSurf, Tor, uTorrent, Skype, Minecraft and other applications you want to block.
* NxClient is a remote user filtering agent for NxFilter.
Content filtering by NxClassifier
NxFilter does Content Filtering with its built-in website classification engine that is NxClassifier. With NxClassifier, you can classify a website into a certain category based on its contents. This means that you can block almost every website you want to block even if it is a new website which is not known to people yet.