Enforce.
Filter. Control.
— EnforceGate vX: Self-Hosted Secure Web Gateway for Linux
EnforceGate vX secures your network with URL filtering, access control, and automated threat blocking — deployed as a self-hosted virtual appliance on your existing infrastructure. No proprietary hardware, no per-seat fees, no cloud dependency. Managed from the CLI and automated via REST API.
How EnforceGate vX
processes your traffic.
It runs on commodity x86-64 hardware — self-hosted on your own infrastructure, no proprietary appliances required.
Everything you need
to secure your network.
URL filtering, access control, threat blocking, and audit logging — in a single self-hosted appliance. Operated from the CLI, automated via the REST API, and built to integrate with your existing stack.
Deploy the appliance,
own the CLI.
Runs on VMware vSphere, Hyper-V, Linux KVM, or Docker. All operations are performed through
egctl.
--signature EnforceGate-vX-2026.01.0380beta1-docker-x64.tar.bz2.sig \
--certificate-identity security@exosys.ch \
--certificate-oidc-issuer https://accounts.exosys.ch
docker-compose.yml, and a default configuration.-C /srv/enforcegate --strip-components=1
do docker load -i "$f"; done
Plain-text rules.
Instant enforcement.
Policies are simple .acls files living in
/opt/enforcegate/etc/rules.d/.
Name them with a numeric prefix — lower numbers win. One
cgacls policy reload and they're live.
http and https.
90-denyurlshort file — explicit allows always take priority.
10-allow*.acls rule is always evaluated before a
90-deny*.acls rule —
making override behaviour explicit and auditable.
EnforceGate operates deny-all by default: anything not explicitly permitted is blocked.
Pick the right build
for your infrastructure.
EnforceGate vX ships in three editions — from a lightweight single-node deployment for small teams to a multi-node cluster with threat intelligence feeds for large-scale environments.
|
Lite
Tech Savvy Users
|
Standard
Recommended
|
Enterprise
Enterprise Features
|
|
|---|---|---|---|
| filtering | |||
| HTTP/HTTPS URL filtering | ✓ | ✓ | ✓ |
| ACL rules | 1,000 | 10,000 | 100,000 |
| Policy management | Basic | Full | Full |
| Squid connector | ✓ | ✓ | ✓ |
| network access control (NAC) | |||
| Captive portal | ✓ | ✓ | ✓ |
| Active Directory | ✕ | ✕ | ✓ |
| LDAP | ✕ | ✕ | ✓ |
| RADIUS | ✕ | ✕ | ✓ |
| management | |||
| CLI | ✓ | ✓ | ✓ |
| Web GUI | ✕ | ✓ | ✓ |
| REST API | ✓ | ✓ | ✓ |
| deployment | |||
| Node topology | Single | Single | Multi-node |
| Hypervisors | Docker | Docker · VMware · Hyper-V · KVM | Docker · VMware · Hyper-V · KVM |
| Throughput | 10 Gbps+†1 | 10 Gbps+†1 | 10 Gbps+†1 |
| Hardware | x86_64 | x86_64 | x86_64 |
| security | |||
| Threat intelligence feeds | ✕ | ✓ | ✓ |
| Zero-day feed | ✕ | ✕ | ✓ |
| SIEM export | ✕ | ✕ | ✓ |
| support | |||
| Support tier | Community†2 | Standard | Priority + SLA |
| pricing — annual subscription | |||
| Annual license†3 | USD 199 / yr | USD 495 / yr | |
| †1 Throughput depends on hardware specifications, hypervisor configuration, and network topology. Actual performance may vary by installation. | |||
| †2 Community support is provided through a shared support space where users can ask questions, share configurations, and help each other. No response time is guaranteed, however this space is actively monitored by the Exosys development team. | |||
| †3 Prices are for an annual subscription license. The software is fully operational throughout the active subscription period. Once the subscription expires, the product can no longer be used. | |||
Get early access
to EnforceGate vX.
Open to IT and security teams of all sizes — from solo sysadmins to enterprise engineering teams. If you manage network security, EnforceGate vX is built for you. Register and we'll send an invite when your slot opens.
when your invite is ready.
Your network.
Your rules.
Self-hosted. No proprietary hardware. No per-seat fees. Full audit trail from day one.