Office hours: Monday to Friday, 8:00 – 17:00
RLW Technology RLW Technology IT Solutions Simplified Get in touch 068 920 9065

Home  /  DN-Guard

DNGUARD

A layer 7 firewall, built in house and run from South Africa

Low cost, proudly South African, and designed for every environment from a single mobile phone to a school, office or corporate network. DN-Guard is a product of RLW Technology.

How DN-Guard handles a query Your device DN-Guard checks it Blocked Safe site loads

Every query is checked before it leaves your network — malicious domains never load, safe ones pass straight through.

What it does

All it takes is one unpatched system, one malicious link or one malicious file for an attacker to get into your network, encrypt your files and deploy ransomware. Most of those attempts start with a domain name.

DN-Guard filters at the DNS layer. Every lookup a device makes is checked against our blocklists and rules before the connection is allowed, so the request never reaches the harmful destination in the first place. It runs at layer 7, which means it can act on what the traffic actually is rather than just which port it arrived on.

The side effect customers notice first is speed: filtering out advertising, tracking and junk traffic frees up the line you are already paying for.

What it blocks

  • Malware domains
  • Phishing attacks
  • DDoS traffic
  • Adult content
  • Advertising and trackers
  • Pop-up windows
  • Categories you choose
  • Anything you blacklist

Built for homes, schools, SMEs and corporate environments — covering a whole network or a single mobile device.

Two ways to run it

Hosted in our environment, or on hardware in your own comms cabinet. The filtering is identical; the difference is where it sits and how much control you keep locally.

Hosted

Best for mobile devices, homes and smaller sites
  • Nothing to install on site
  • Devices connect over DNS-over-HTTPS or DNS-over-TLS
  • Mobile devices point at our hosted address
  • Runs across five data centres in South Africa and the UK
  • Automatic fallback DNS if a data centre or line fails
  • Certificates renewed automatically every 90 days

On site

Best for offices, schools and multi-user networks
  • Deployed on a Red Hat VM or a supplied Mikrotik unit
  • Per-device blocking and filter rules
  • Per-device reporting and HTTPS rules
  • Local login for your own staff to manage
  • Client-controlled block and unblock
  • Built-in DHCP for networks up to 200 addresses
  • Small form factor, or repurpose hardware you already own

What it did on a real site

We ran a four-week proof of concept for a security firm in Gauteng with 50 office staff. Before installation they were struggling to stream live CCTV from client sites despite plenty of ISP bandwidth, and transferring files inside the business was slow. DN-Guard was installed onto the main router and firewall.

  • 27 millionDNS queries processed
  • 570 000requests blocked by filters
  • 167malware and phishing attempts blocked
  • 629adult websites blocked
  • 32%increase in bandwidth speed
  • 0company functions lost to the change

The client ended the proof of concept on a faster network, able to perform all company requirements without failure.

You keep the controls

The management portal shows usage for a single device or for the whole network, and generates reports you can hand to a manager or a parent. Category filters are changed from the same place — once the unit is configured, there is nothing else to set up.

You can whitelist or blacklist any domain your organisation considers inappropriate or against company policy. On the on-site option, those rules can apply to specific people rather than everyone.

We allow a 15 day learning period at the start so the rules can be tuned to how your site actually uses the internet, instead of blocking something people need on day one.

Updates and support

  • 3 secondsTypical downtime while an update applies.
  • 9 MBTypical update size, depending on new features.
  • Tested firstEvery release runs in our own environment before it reaches a client site.
  • One clickSites connect to our Red Hat Ansible tower for deployment and fault checking.

Technical specification

For the IT manager who wants to know exactly what they are pointing their network at.

  • PlatformVMware ESXi, Red Hat Enterprise Server, containerised for scaling
  • ProtocolsDNS-over-TLS, DNS-over-HTTPS, DNSCrypt and DNS-over-QUIC, as client or server
  • FilteringLayer 7 content rules, CNAME resolution, HTTPS filtering and scanning, compiled hosts blocklists, pop-up blocking
  • ScalingCompute increases automatically once resources reach 80%
  • BackupsEvery 15 minutes, spread across five nodes
  • RedundancyFive data centres across South Africa and the UK, with fallback DNS
  • FootprintRuns on small hardware on site without losing performance or features

Try it on your own network

We will scope a proof of concept for your site and show you the numbers at the end of it.