

Edge SMB reverse proxy, DNS security nodes, clusters, and offline licensing.
Overview
Axiom is an on-premises security platform for organizations that want enforcement and operational evidence in the SMB and DNS paths without installing an agent
Production quickstart
A production Axiom deployment uses three separate Ubuntu or Debian servers: 1. **Management Server** - Web UI, node registry, policy control plane, reputation d
Architecture and server roles
The Management Server is the only role administrators need to browse directly. It stores policy and reputation data, registers data-plane nodes, receives teleme
Production prerequisites
- Ubuntu or Debian family Linux with `systemd` - x86-64 Linux for the current release package - Root or `sudo` access during installation - Static IPv4 addressi
Install the Management Server
Configure a static IP, hostname, time synchronization, and the firewall rules listed in Network requirements. Transfer the verified `axiom-installer.sh` to the
Install the SMB Proxy Node
The SMB node needs a stable client-facing IP and reachability to the real file server. Clients will connect to the Axiom IP, not the file-server IP. Plan firewa
Install the DNS Security Node
Axiom can sit between endpoints and upstream resolvers, or between an internal DNS/DC server and its upstream resolvers. In an Active Directory environment, end
Cluster deployment and high availability
An Axiom cluster is a Management-controlled group of nodes with the same data-plane role. An SMB cluster contains one source SMB node and one or more SMB replic
DNS block page configuration
Overview When DNS policy blocks a domain, Axiom can return a controlled IPv4 address and serve a branded explanation page from the DNS node. The Managemen
Network and firewall requirements
| Source | Destination | Protocol/port | Purpose | | --- | --- | --- | --- | | Administrators | Management Server | TCP 8443 | Web UI and node report/config end
Offline licensing
Axiom license activation is designed for restricted networks. The Management Server creates a machine-bound activation request and verifies the signed response
Upgrades, repair, backup, and removal
At minimum, preserve: Use permissions that protect enrollment tokens, directory bind credentials, TLS private keys, license state, audit logs, and reputation da
Security hardening checklist
- Use HTTPS with a certificate issued by a trusted internal or public CA. - Restrict TCP 8443 to approved administrator networks and enrolled node IPs. - Use a
Deployment validation checklist
- [ ] Web UI is reachable only from approved networks. - [ ] HTTPS certificate is trusted and matches the Management URL. - [ ] Local administrator login succee
Troubleshooting
Confirm the process is running, the configured IP exists on the selected NIC, and no other process owns the required port. 1. Verify `/etc/axiom/axiom.toml` con
Customer portal guide
Open `/portal` on the Axiom website and use the email address assigned by Axiom staff or your organization's portal owner. Change a temporary password immediate