Platform

Everything URUFI manages, in four areas.

Access, network, policy, and edge enforcement — with the capabilities that belong to each and what the platform guarantees about them.

Access

Who reaches the network, and until when.

Every form of access resolves to one authorization with an owner and an expiry time.

Available today

Access lifecycle

Grant access by account, device, plan, trial, PIN, or certificate, and end it automatically when the entitlement expires.

Per-device identity

Issue individual EAP-TLS credentials and revoke one device without changing a password the whole site depends on.

Built-in RADIUS

Authenticate devices against the platform's own RADIUS service instead of maintaining a separate server.

Branded access portal

Use phone verification, controlled trials, plans, and PINs when public or paid access is part of the service.

Network

How each site is addressed and segmented.

A site's logical networks are one reviewable configuration, separate from the physical topology the gateway approves locally.

VLANs and networks

Manage native and tagged networks, access, hybrid, and trunk modes, gateway addresses, MTU, and allowed VLANs.

DHCP at the edge

Manage address pools, DNS, and lease times per network, with leases that survive a gateway restart — no separate DHCP server.

Multi-organization operation

Keep each organization's data and permissions isolated while operating the whole fleet from one console.

Policy

What a connection is allowed to do.

Firewall and bandwidth policy are reusable objects, so the same intent applies identically at every site that uses it.

Central firewall policy

Author ordered open, captive, authorized, blocked, and custom rules once. Each gateway enforces them with Linux nftables.

Bandwidth service classes

Build reusable upload and download tiers, then attach them to plans, devices, organizations, or sites.

Edge

Where policy actually takes effect.

The gateway decides what is locally safe to apply, and it — not the platform — is what client traffic passes through.

Convergence you can read

See whether a change is pending, applied, or failed, with the boundary that rejected it — VLAN permission, subnet overlap, active leases, or an unavailable interface.

Local validation

Central intent cannot rename the physical LAN or WAN, bypass the site's VLAN allow-list, or adopt an interface the gateway does not own.

Continuity without the platform

The gateway restores its last validated configuration, leases, and authorization state at boot and keeps enforcing them while the platform is unreachable.

FAQ

Questions about scope and requirements.

Does it work with wired networks and VLANs?

Yes. Access applies to an untagged LAN, a VLAN, a wired port, or traffic arriving through an access point.

What does each site need?

A Linux gateway connected to WAN and LAN, running the URUFI Edge Agent with the system permissions required for VLAN, DHCP, nftables, RADIUS, and bandwidth control.

Can we manage multiple customers from one platform?

Yes. Each organization's data, permissions, and policies stay separate while you operate every site from one console.