All plans run on Linux infrastructure you already own. No proprietary hardware, no per-packet fees.
Self-hosted. Core network security for individuals and small teams. No license fee.
Typical customers: developers, homelabs, product evaluation
For: homelabs, evaluation, learning, small deployments
Scale: single gateway, lab environments
Community plus threat intelligence, QoS, backups, and standard operational controls.
Typical customers: SaaS companies, hosting providers, MSPs
For: SMBs, SaaS platforms, MSPs, production deployments
Scale: production gateways, cloud deployments
Business plus governance, multi-site management, and enterprise operations.
Typical customers: banks, healthcare, government, telecom
For: large organizations, regulated industries, multi-site deployments
Scale: multiple gateways, multi-site, HA clusters
Gateway deployments for branch, edge, and on-prem use. Hardware and deployment requirements may apply.
Typical customers: branch offices, on-prem gateway teams, edge deployments
For: branch offices, dedicated on-prem gateways
Scale: branch office, single-site hardware gateway
Neurowall runs on the Linux infrastructure you already operate — cloud VM, bare metal, or existing gateway hardware. There's no proprietary appliance to buy, no hardware refresh cycle, and no per-GB or per-attack charges. Cloud firewall services often combine a subscription with usage-based traffic pricing; Neurowall's cost is flat per node, whether you're passing 1 Gbps or getting hit with a DDoS attack.
| Traditional / cloud firewall | Neurowall |
|---|---|
| Proprietary appliance or vendor VM image | Standard Linux server you already run |
| Hardware refresh cycles | No hardware to refresh |
| Usage-based or per-GB traffic charges | Flat price per node, regardless of traffic |
| Costs spike during DDoS/burst events | No per-attack or per-packet fees |
| Complex, tiered licensing | Simple per-node subscription |
| Vendor lock-in to appliance ecosystem | Deploy anywhere Linux runs — cloud, bare metal, edge |
| Feature | Community | Business | Enterprise | Gateway |
|---|---|---|---|---|
| Goal | Evaluate Neurowall | Secure production workloads | Protect mission-critical infrastructure | Secure branch, edge, or on-prem gateways |
| Price | Free | $99 / node / mo | $299 / node / mo | $499 / node / mo |
| Network Security | ||||
| eBPF/XDP firewall | ✓ | ✓ | ✓ | ✓ |
| nftables firewall | ✓ | ✓ | ✓ | ✓ |
| L7 firewall (Vaanvil) | ✓ | ✓ | ✓ | ✓ |
| DNS sinkhole | ✓ | ✓ | ✓ | ✓ |
| DNS local resolver | ✓ | ✓ | ✓ | ✓ |
| DDoS protection | ✓ | ✓ | ✓ | Add-on |
| Threat intelligence | – | ✓ | ✓ | ✓ |
| Custom threat feeds | – | – | ✓ | Add-on |
| Networking & Gateway | ||||
| Multi-WAN | ✓ | ✓ | ✓ | ✓ |
| WAN failover | ✓ | ✓ | ✓ | ✓ |
| QoS / traffic shaping | – | ✓ | ✓ | ✓ |
| VLAN / advanced routing | – | – | – | ✓ |
| DHCP / NAT | – | – | – | ✓ |
| VPN gateway | – | – | – | ✓ |
| Offline operation | – | – | – | ✓ |
| Management & Operations | ||||
| CLI | ✓ | ✓ | ✓ | ✓ |
| API access | – | ✓ | ✓ | ✓ |
| Backups | – | ✓ | ✓ | ✓ |
| Telemetry / monitoring | – | ✓ | ✓ | ✓ |
| Zero-touch provisioning | – | – | ✓ | ✓ |
| Multi-site fleet management | – | – | ✓ | ✓ |
| HA clustering | – | – | ✓ | ✓ |
| Disaster recovery | – | – | ✓ | ✓ |
| Identity & Access | ||||
| RBAC | Admin only | ✓ | ✓ | ✓ |
| SSO + MFA | – | – | ✓ | – |
| SCIM / provisioning | – | – | ✓ | – |
| Service accounts | – | – | ✓ | – |
| Granular API permissions | – | – | ✓ | – |
| Approval workflows | – | – | ✓ | – |
| Audit & Compliance | ||||
| Audit logs | ✓ | ✓ | ✓ | ✓ |
| Audit log retention | Limited | Standard | Extended | Standard |
| Tamper-proof / immutable audit logs | – | – | ✓ | ✓ |
| Audit export | – | ✓ | ✓ | Add-on |
| SIEM integration | – | – | ✓ | Add-on |
| Support & Service | ||||
| Response-time SLA | – | – | ✓ | ✓ |
| Enterprise support | – | – | ✓ | ✓ |
| Limitation | Max 3 nodes | – | Minimum contracts apply | – |
| Question | Answer |
|---|---|
| How is pricing calculated? | Per node, per month (or per year for Gateway). A node is one Linux instance running Neurowall. |
| Is there a free version? | Yes — Community is free, self-hosted, limited to 3 nodes. No license required. |
| Can I upgrade later? | Yes. You can move from Community to Business, Enterprise, or Gateway as your deployment grows. |
| Can I migrate from Community? | Yes. Community installs use the same Linux-native foundation, so the upgrade path is a plan change rather than a platform migration. |
| What happens during a DDoS attack — do costs spike? | No. Pricing is flat per node. There are no per-packet, per-event, or burst fees. |
| Do you charge per GB transferred? | No. Neurowall does not bill on traffic volume, packet count, or attack bursts. |
| Can I deploy on-premises? | Yes. Neurowall runs on standard Linux hardware, including dedicated on-prem gateways and data center servers. |
| Can I deploy in AWS? | Yes. Neurowall can run on AWS Linux instances just like other cloud VMs. |
| Can I deploy in Azure? | Yes. Neurowall can run on Azure Linux instances and other standard cloud infrastructure. |
| Are volume discounts available? | Yes, for Enterprise and Gateway plans. Contact us to discuss your deployment size. |
| What support is included? | Community and Business are self-serve. Enterprise includes direct support. Gateway support is available as an add-on service. |