FreeZero Client SetupWire-Speed ForwardingQUIC & HTTP/3 ReadyGeoIP Policy Routing

PulseGate

Transparent Traffic Filter & Smart Gateway Protection

A transparent traffic filter and gateway protection program designed for OpenWrt and Linux routers. Protect all LAN devices without installing client software or certificates. Features native TLS and QUIC (HTTP/3) traffic inspection, encrypted DNS anti-bypass, and GeoIP with SOCKS5 policy routing. Validated streams flow at native wire speed, paired with a real-time web console for seamless, high-performance network security.

http://192.168.1.1:8088
Protection & Routing Active
PulseGate Transparent Traffic Filter & Smart Gateway Protection

Key Advantages

Why Choose PulseGate

Engineered specifically for modern routers and Linux gateways, combining transparent filtering, modern encryption inspection, DNS enforcement, and smart policy routing.

Zero-Touch Client Protection

Deploy on your router or gateway. All connected phones, PCs, smart TVs, and IoT appliances are protected automatically without installing client apps, plugins, or certificates.

Modern Encrypted Traffic Inspection

Native deep handshake inspection for both TCP TLS and modern UDP QUIC (HTTP/3) traffic, featuring ECH (Encrypted Client Hello) awareness and precision filtering.

Encrypted DNS Enforcement & Anti-Bypass

Prevents LAN devices from bypassing router DNS to access external DoH/DoT resolvers. Supports remote encrypted DNS threat domain and IP blocklists to ensure unified network protection.

GeoIP & SOCKS5 Policy Outbound Routing

Smart traffic splitting based on GeoIP country databases and CIDR subnets. Supports multiple SOCKS5 proxy outbounds with independent TCP/UDP routing and graceful failover.

Wire-Speed Forwarding & Zero Latency

Overcome traditional proxy performance bottlenecks. Validated connections flow directly at native hardware line speed with minimal CPU overhead, preserving low ping for gaming and smooth 4K/8K streaming.

Multi-Source Rule Aggregation & Hot-Reload

Automatically synchronizes and deduplicates multiple remote HTTPS threat feeds and hosts blocklists. Built-in offline security database ensures instant protection and hot-reloading on changes.

Fail-Open Reliability & Zero Outages

Engineered for mission-critical stability. Unclassified traffic, service reloads, and background updates safely fall back to pass-through mode, ensuring your network never suffers accidental dropouts.

Built-in Real-Time Web Management Console

Self-contained responsive web dashboard with zero external server dependencies. Features real-time SSE connection audit streams, online rule & routing policy management, and health telemetry.

Visual Control

Intuitive Real-Time Management Dashboard

Audit network decisions, configure rule subscriptions, manage policy outbounds, and monitor throughput metrics directly from your web browser.

http://192.168.1.1:8088
TimeProtoClientTarget / DomainVerdictReason
14:20:01TLS192.168.1.108api.github.comAllowedDirect Security Pass
14:20:02QUIC192.168.1.142tracker.analytics-ad.comBlockedThreat Blocklist Hit
14:20:04UDP/53192.168.1.115cloudflare-dns.com:853BlockedEncrypted DNS Block
14:20:07TCP192.168.1.189104.244.42.1 (US)AllowedGeoIP Policy Routed
14:20:10QUIC192.168.1.102cdn.jsdelivr.netAllowedDirect Security Pass
14:20:12TCP192.168.1.164internal-dev.lanAllowedFail-Open Pass

Broad Compatibility

Ready for Modern Routers & Gateways

Built specifically for router firmware and Linux gateway servers across all standard CPU architectures.

OpenWrt Routers

Works seamlessly out of the box on x86_64 soft routers, embedded hardware, and OpenWrt devices.

Linux Gateways & Servers

Compatible with Debian, Ubuntu, Alpine, CentOS, Rocky Linux, and all mainstream Linux server distributions.

Multi-Architecture Support

Provides native, standalone static binaries for both x86_64 and ARM64 (aarch64) platforms.

Quick Start

Start Transparent Protection in 3 Steps

Single-file deployment with no database or complex runtime environment required.

1

1. Download Binary

Download the appropriate PulseGate executable and example configuration for your architecture.

2

2. Upload & Run

Upload the binary to your router, grant execution permissions, and start the service.

3

3. Open Web Dashboard

Navigate to http://<router-ip>:8088 in your browser to monitor traffic and manage rules in real time.

Deploy PulseGate Today for High-Speed Protection

PulseGate is free with no registration required. Get the latest release from GitHub Releases.

Supports OpenWrt · Linux · x86_64 / ARM64 · Standalone Portable Binary · Zero Dependencies