dnxOS

  • flexible management, advanced diagnostics
  • centralized configuration
  • secure data transmission, role‑based access
  • for industrial and enterprise infrastructure

dnxOS — Operating System for Donyx Routers.

Optimized for industrial and corporate infrastructure, dnxOS delivers flexible management, advanced diagnostics, centralized configuration, and secure data transmission. dnxOS enables complex device configuration management, secure network operations, scaling and segmentation, performance and quality of service (QoS) assurance, as well as integration and diagnostics within a unified system.

The web interface and CLI are fully synchronized, sharing the same logic and command structure. Unified CLI commands come with context-sensitive hints, reducing errors and eliminating the need for deep Linux knowledge. Any change made in the web UI is instantly reflected in the console, and vice versa, ensuring configuration integrity. Key router parameters (CPU load, memory usage, interface status) are displayed in real time on the main dashboard. Modified but unapplied settings are visually highlighted, providing complete control and faster troubleshooting.

The modular architecture stores configuration in a human-readable text format, allowing manual editing and transfer across different Donyx device series while maintaining command compatibility across updates. Changes are first applied in RAM and only saved after a successful health check; an accidental lockout can be resolved by rebooting to the last working configuration.

A flexible user and permission system supports role‑based access to both web UI and CLI, with granular restrictions per section. Custom software integration is simplified via manifest files – no manual layout coding is required, and new sections appear instantly in both interfaces.

Advanced networking features include hardware‑accelerated encryption, support for tunnels (IPSec, GRE, OpenVPN, WireGuard, L2TP, PPTP, EoIP) with server modes for L2TP, PPTP, and OpenVPN.

Redundancy protocols (STP, RSTP, MSTP) ensure uninterrupted operation for critical services. Enhanced VLAN support enables secure traffic separation.

Wi‑Fi 802.11s mesh provides multiple SSIDs and dynamic client segmentation.

Built‑in diagnostics include ping, arping, traceroute, sniffer, pinger, journal, keepalive for GRE, SNMP polling, and Zabbix integration. QoS prioritizes VoIP, video conferencing, and latency‑sensitive applications. A built‑in certificate authority generates and manages TLS certificates without third‑party tools. dnxOS is available for x86 hardware (servers, PCs, virtual machines), supporting high‑load scenarios such as large tunnel aggregates or 1+ Gbit/s Ethernet.

dnxOS is built for those who value control, security, and stable business operations.

Tunneling

OpenVPN: Ability to run one server and multiple clients simultaneously.

Encryption: Client – AES-128-CBC, AES-192-CBC, AES-256-CBC; Server – AES-128-CBC, AES-128-GCM, AES-192-CBC, AES-192-GCM, AES-256-CBC, AES-256-GCM

IPsec: IKEv1, IKEv2.

Encryption: Client – AES-128, AES-192, AES-256; Server – AES-128, AES-128, AES-192, AES-192, AES-256, AES-256

GRE: GRE TUN (Layer 3)

EoIP: MikroTik RouterOS protocol based on GRE RFC 1701

PPTP, L2TP: Server and Client mode support for L2TPv2, L2TPv3

Wireguard: WireGuard tunnels and peers

DMVPN: Client mode operation, additional IP Security encryption

Network Functions

Routing: Static

Network protocols: PPP, PPPoE, DHCP, TCP, UDP, ARP, IPv4, ICMP, HTTP, HTTPS, TLS, SSL

Connection Monitoring: Ping Reboot, Periodic Reboot, LCP and ICMP for link tracking

Firewall: Port forwarding, ZONE-based rules, pre-configured firewall rules, custom rules, NAT

DHCP: Static and dynamic IP address allocation

Network Backup: VRRP; Wired, Mobile or WiFi WAN. Supports automatic failover to an alternative connection (Automatic Failover)

Network Services: DHCP Server, NTP, DNS, SSH, SNMP

Security Features

Authentication: Pre-shared key, digital certificates, X.509 certificates

Attack prevention: DDOS prevention (SYN flood protection, SSH attack prevention, HTTP/HTTPS attack prevention), port scan prevention (SYN-FIN, SYN-RST, X-mas, NULL flags, FIN scan attacks)

VLAN: Port and tag based VLAN separation

Access control: WiFi access control (MAC address filter)

Monitoring & Management

UI: WEB UI access via HTTP/HTTPS, CLI access via SSH, status, setup and configuration, firmware update, system log

SSH: SSH (v1, v2)

SNMP: SNMP (v2c, v3)

Zabbix: Zabbix Agent (requires manual package installation)

Wi-Fi

Wireless mode: Access Point (AP), Station (STA), Station Bridge (STA WDS mode allows interface to be bridged)

Wi-Fi security:

  • WPA/WPA2-Enterprise-PEAP, WPA/WPA2-PSK, AES-CCMP, TKIP, Auto Cipher modes
  • SAE

Wi-Fi users: Up to 100 simultaneous connections

SSID: SSID stealth mode, access control list MAC address

Your order

No items.

Place an order