Nacxwan
Router
Performance, Security,
and Centralized Management
The Nacxwan Router is a next-generation network appliance, available in both physical and virtual form, designed for single or multisite environments and secure remote work. As part of Nacxwan’s 100% VPN-based architecture, it integrates advanced routing, traffic management, and security features — all fully managed via the NetworkManager cloud platform.
Designed for optimal connectivity, it efficiently connects your sites, cloud infrastructures and remote users. It supports dynamic routing protocols. It integrates Nacxwan SD-WAN technology and traffic prioritisation for latency-sensitive services such as VoIP and video conferencing.
With NetworkManager, configurations are deployed in real time to each device, enabling:
- Centralized orchestration of security policies
- Automated deployment of VPN clients (desktop and mobile)
- Unified management of mobile VPN licenses
- Continuous monitoring with alerts and detailed reporting
Robust, scalable, and easy to manage, the Nacxwan Router ensures business continuity and secure communications across hybrid and distributed IT environments.
Nacxwan CyberVigilance – Smart Security for a Safer Network
Nacxwan offers a comprehensive network security solution based on IDS/IPS technologies combined with anti-malware analysis.
The IDS/IPS system (Intrusion Detection and Prevention) is at the core of the CyberVigilance solution. It detects and blocks any unauthorised attempts to access your nacxwan private network, including all associated local networks.
Constantly active, it monitors network traffic in real time, leveraging historical internet activity data and deep learning mechanisms. Any abnormal behaviour is identified immediately.
Integrated directly into the Nacxwan router, which handles all internet traffic, the CyberVigilance solution provides enhanced protection. It effectively complements the EDR security tools already deployed on user workstations.
IDS – IPS
The Intrusion Detection System (IDS) monitors traffic across the nacxwan private network, identifying abnormal or malicious behaviour through behavioural analysis and threat signatures.
The Intrusion Prevention System (IPS) acts in real time to block unauthorised or suspicious traffic from the internet, while generating alerts for further investigation.
Together, they deliver proactive threat detection and mitigation at network level.
Anti-Malware
The Anti-Malware module analyses outbound web traffic to block access to domains known for hosting malware, phishing, or command-and-control activity.
It leverages a threat database updated daily, providing up-to-date protection and reinforcing endpoint defences.
FireWall
The Firewall enforces security policies by filtering traffic based on IP, port, and protocol. It ensures that only authorised flows are allowed into or out of the local area network.
All other traffic is automatically blocked, reducing the external attack surface.
Web Filtering
Web Filtering restricts access to websites based on categorisation, blocking high-risk or non-compliant content (e.g. terrorism, hate speech, adult content).
It supports policy enforcement per user or group, helping maintain security and regulatory compliance.
Application Filtering
Application Filtering controls communications based on protocols and services such as music streaming (Spotify, Deezer), video downloads, online gaming, or internet TV/radio.
Traffic is allowed or blocked according to predefined security policies.
Application Qos
Application QoS prioritises traffic by type and criticality — for example, real-time services (VoIP, video conferencing) or business-critical flows.
This ensures bandwidth is allocated where it matters most.
Multi-Line
The Multi-Line feature manages both primary and backup connections integrated into your VPNRouter.
It is activated when multiple links are available at the Office site, ensuring service continuity.
SD-Wan
The SD-WAN function dynamically optimises traffic distribution across all VPNRouter connections.
It adjusts in real time according to available bandwidth and measured latency, delivering improved performance and resilience.
High Availability
High Availability is enabled when a backup VPNRouter is deployed at the office.
In case of failure of the primary VPNRouter, the backup unit automatically takes over to ensure uninterrupted service.
Performance Monitoring
The Performance module continuously tests access to a predefined set of resources.
This allows for rapid diagnostics in the event of service degradation or network issues.
Hardware and Virtual Platforms for nacxwan Software: Scalable Deployment from Edge to Cloud
Qualified Hardware Platforms for Nacxwan firmware
To ensure optimal performance, stability and full compatibility with Nacxwan distributions, the following hardware appliances have been officially qualified to host Nacxwan firmware


Lanner 1510A
Compact and Reliable Security Appliance
Designed for edge deployments, the Lanner 1510A offers a compact form factor with industrial-grade reliability. Equipped with multi-core processing, advanced I/O interfaces, and fanless operation, it provides a robust foundation for running nacxwan firmware in demanding on-prem environments.
- Fanless and compact for silent operation
- Intel® atom with high efficiency
- 6 x 1GbE LAN ports
- Ideal for branch offices and remote sites
- Fully compatible with Nacxwan’s firmware and OS distribution
- Supports full Nacxwan feature set, including CyberVigilance and SD-WAN
VpN protocol
up
(Mbits/s)
down
(Mbits/s)
average
nts 3.8 no thread
224
175
199,5
nts 3.8 thread
276
167
221,5
nts 3.8 perf
323
179
251
Ipsec v1 aes256
459
231
345
Ipsec v1 aes256 (device)
358
209
283,5
nts = Nacxwan Tunnelling System




Axiomtek NA350C
Versatile and Scalable Performance
The Axiomtek NA350C is a flexible network appliance designed for small to medium-sized infrastructures. With modular connectivity and solid performance, it is well-suited for hosting nacxwan solutions requiring reliable throughput and future scalability.
- Fanless and compact for silent operation
- Intel® atom with high efficiency
- 3 x 2,5GbE LAN ports + 4 x 1GbE
- Ideal for branch offices and remote sites
- Fully compatible with Nacxwan’s firmware and OS distribution
- Supports full Nacxwan feature set, including CyberVigilance and SD-WAN
VpN protocol
up
(Mbits/s)
down
(Mbits/s)
average
nts 3.8 no thread
260
359
304,5
nts 3.8 thread
304
405
354,5
nts 3.8 perf
361
393
377
Ipsec v1 aes256
458
325
391,5
Ipsec v1 aes256 (device)
525
306
415,5
nts = Nacxwan Tunnelling System
Nacxwan Virtual Edition: Compatible with for AWS, Azure and VMware Environments
The Nacxwan Virtual Edition is a fully featured virtual appliance that delivers the same capabilities as the physical nacxwan platforms. It is qualified for deployment on VMware, Microsoft Azure, and AWS, ensuring seamless integration within existing virtualised or cloud infrastructures.
This version includes the full nacxwan network services, VpnClient for desktop & mobile, monitoring, and centralised management tools.
It is particularly well-suited for cloud-native environments, hybrid architectures, or organisations seeking a flexible, scalable, and consistent solution, regardless of the deployment model.