Why NxFilter

Faster and lighter

Many people still uses a traditional webfilter based on an HTTP proxy for their filtering needs. This approach may cause a serious latency problem in your network. Your web traffic needs to go through one point in your network that is your webfilter and it becomes a bottle neck in your network. But there is another approach. It is a DNS filtering and NxFilter is a DNS filter. Since it uses a light weight DNS protocol there is no need to have your traffic going through somewhere. You get no latency problem with NxFilter.

Boosting up your internet speed

Our users are surprised when they see how much NxFilter improved their Internet connection speed. NxFilter has its own cache for DNS lookup. Suppose in your network, everybody uses Google public DNS server. Their DNS queries need to be sent to a DNS server on the Internet and they need to wait for the response from it. But if you run NxFilter in your network, it keeps a cache for the DNS response from its upstream DNS server and your users don’t need to wait for the response from the Internet.

Authentication

Even though it is faster and lighter to be compared to the traditional web proxy based filtering, DNS filtering had its own limit in the past. It didn’t support authentication. This is natural as DNS protocol doesn’t have any authentication scheme. It was the biggest obstacle for a DNS filter to be employed in a real world enterprise environment. However, NxFilter supports authentication based on IP and password and it also supports the single sign-on with Active Directory.

Easy deployment

You just need to set up your DHCP server to make NxFilter to be the only DNS server for your network. Then your users will use NxFilter as their DNS server and they will be under filtering. Forcing filtering to your users is also possible. You can block outgoing UDP/53 except from NxFilter. In that way, NxFilter becomes the only DNS server your users can use.

Scalibility

NxFilter can handle several thousand users easily. It has been proven by many users since we released its first version in 2013. It has built-in clustering for load balancing and you can add up to 4 nodes to your cluster. Some of our users reported that they are serving more than 30,000 users in their site with one cluster of NxFilter.

Malware/botnet detection

In reality, these malwares and botnet programs are network server/client programs by themselves. Naturally, they are heavily relying on DNS protocol. NxFilter is capable of detecting and blocking malware and botnet based on DNS packet inspection.

Remote filtering

NxFilter provides a remote filtering client software that is NxClient for filtering the Internet activity of your off-site or mobile workers.

Application control

NxFilter provides Application Control through its agent that is NxClient. With this feature, you can block UltraSurf, Tor, uTorrent, Skype, Minecraft and other applications you want to block.

* NxClient is a remote user filtering agent for NxFilter.

Content filtering by NxClassifier

NxFilter does Content Filtering with its built-in website classification engine that is NxClassifier. With NxClassifier, you can classify a website into a certain category based on its contents. This means that you can block almost every website you want to block even if it is a new website which is not known to people yet.

Flag Counter