Network access & policy platform

Control access and network policy from one place.

Manage firewall rules, bandwidth, VLANs, DHCP, and device access across every site. URUFI applies policy directly on your Linux gateways.

The model

Access, policy, edge.

Three questions decide how every client is treated. URUFI answers all three in one system.

ACCESS

Who can connect

An account, device, plan, trial, PIN, or certificate becomes an authorization with an expiry time.

POLICY

What that connection can do

Firewall rules, bandwidth tiers, VLAN membership, and addressing move together as one versioned change.

EDGE

Where policy is enforced

The Linux gateway in the traffic path applies the change, verifies the result, and keeps enforcing it on its own.

The product

Real screens from the URUFI console.

One console, two areas: network operations, and the business side that grants access.

URUFI console Networks page listing client networks with VLAN, subnet, DHCP pool, and per-gateway convergence status

Networks and convergence

VLANs, addressing, DHCP, MTU, and whether the requested revision reached the gateway.

URUFI console Service classes page showing bandwidth tiers linked to firewall policy

Service classes

Reusable upload and download tiers, joined to the firewall policy that travels with them.

URUFI console business dashboard showing subscriber access states, plans, and PIN inventory

Subscribers and access plans

Active access, paid accounts, trials, and unredeemed PINs — without network configuration in view.

URUFI console branding editor with a live preview of the captive access portal

Captive branding

Per-organization logo, colours, wording, and support details, previewed before publishing.

Read the operator documentation
Platform

Four things URUFI controls.

Each pillar is a complete area of the platform, not a single feature.

Access

Decide who reaches the network and for how long. Authorization ends when the entitlement does.

Covers
  • Accounts
  • Devices
  • Certificates
  • PINs
  • Trials
  • RADIUS
  • Expiry

Network

Define how each site is addressed and segmented, and keep those settings reviewable in one place.

Covers
  • VLANs
  • Addressing
  • DHCP
  • DNS
  • MTU
  • Gateways
  • Sites

Policy

Build firewall and bandwidth policy once as reusable objects, then apply them wherever they belong.

Covers
  • Firewall
  • Bandwidth
  • Service classes
  • Access rules

Edge

The Edge Agent checks each change against local conditions before it touches the kernel, and the site keeps running if the platform goes away.

Covers
  • Linux enforcement
  • Validation
  • Durable state
  • Convergence
  • Outage continuity
Explore platform capabilities
How it works

Define, deliver, enforce.

  1. 01

    Define

    Author network, access, and security policy centrally in the console.

  2. 02

    Deliver

    URUFI sends the desired state to the gateway that owns the site, over an authenticated channel.

  3. 03

    Enforce

    The Edge Agent validates it, applies it as one transaction, and reports the exact revision it now runs.

Client traffic never traverses the URUFI control plane. The Linux gateway forwards it locally, so a platform outage cannot interrupt a site that is already configured.

Explore the architecture
Why URUFI

One policy model instead of disconnected tools.

URUFI did not invent DHCP, firewalling, shaping, or certificate identity. The difference is that identity, access rights, addressing, policy, and enforcement stop living in seven systems that never quite agree — an identity store, a RADIUS server, a firewall config, a DHCP server, a shaping script, a captive portal, and a customer database.

URUFISeparate tools
Access decisions Identity and entitlement become authorization at the gateway Accounts and network rules live in different systems
Network setup VLAN, DHCP, gateway, DNS, and MTU move in one revision Settings split across devices and services
Firewall policy Authored once, enforced by nftables at each site A separate appliance, or rules edited site by site
Bandwidth Reusable service classes tied to entitlement Rate limits disconnected from customer state
Change confidence Pending, applied, or failed with the reason Configuration is sent without end-to-end confirmation
Team boundaries Network and business permissions separated inside one console Commercial and technical access mixed together
Deployment

URUFI Cloud, or your own infrastructure.

Both modes use the same Edge Agent and the same console. Only the location of the central services changes.

Managed cloud

URUFI Cloud

We operate and update the central platform. You manage sites and policy.

  • No central servers to maintain
  • Add sites and organizations as you grow
  • Managed updates for central services
Self-hosted

Your servers, your data location

Run the central platform inside your own infrastructure when placement matters.

  • You choose where services and data run
  • Signed licensing verifies without a permanent connection
  • Same Edge Agent, same operational model
Use cases

More than guest Wi-Fi.

Access can arrive through an access point, a wired port, or a VLAN. URUFI owns the decision and the policy behind it either way.

MSP and ISP fleets

Run many customer organizations and edge locations from one console with isolated data.

Firewall as a managed service

Protect customer sites centrally without shipping another proprietary appliance to every location.

Segmented branch networks

Keep VLANs, DHCP, gateways, DNS, and MTU in one configuration your team can review.

See all use cases
Pricing

Start with one gateway.

Run VLANs, DHCP, firewall rules, bandwidth, and access expiry on your own hardware before you scale.

$39 / month · one cloud-managed edge
Self-hosted from $299 / monthCompare plansCreate account
FAQ

Four questions worth answering first.

Is URUFI a Wi-Fi management system?

No. URUFI manages network access and policy. Wi-Fi and captive access are one access environment it supports, alongside firewall rules, bandwidth control, VLANs, DHCP, wired clients, and per-device identity.

Do we need to replace our switches or access points?

No. URUFI runs on the Linux gateway in the traffic path and manages access and policy there. Your existing switches, access points, and wireless controllers keep operating as they do now.

What happens if the central platform becomes unavailable?

The site keeps running its last validated configuration. Unexpired leases, firewall rules, bandwidth policy, and existing authorizations continue, and the Edge Agent reconnects on its own. New changes and new captive sessions wait for the connection to return — nothing is deleted.

Can URUFI be self-hosted?

Yes. The central platform can run on your own infrastructure, verified by a signed licence that does not need a permanent connection, using the same Edge Agent and console as URUFI Cloud.

Get started

Bring access and network policy under one control plane.

Start on one gateway, or talk to us about a multi-site deployment first.