Distributed enforcement, central policy, continuous failover.
The same engine that runs locally in Console mode runs at your hubs in SASE mode. Spokes dial in over an encrypted overlay. Policy enforces at ingress. Identity travels with the user. Failover is atomic and measured in seconds.
Spokes dial out. Hubs inspect. Policy follows the user.
No new protocols to learn. The Zedmos engine you already understand, wrapped in a managed overlay that connects branches, cloud egress points, and roaming users to a shared policy plane.
When the primary hub degrades, traffic moves before a voice call drops.
The failover daemon runs inside the hub itself — not as a scheduled task. Probes run on a sub-second cadence with a composite score across ICMP, HTTP, and DNS. At threshold, peer and routing changes execute atomically, with no cleartext leak and no peer overlap.
Five steps to a live SASE mesh
A hardened orchestrator manages topology, policy distribution, identity mapping, and failover. It runs on a single node for smaller deployments or as a redundant pair for production.
- Multi-tenant-ready topology model
- Hardened data store with role-based access
- Central source of truth for policy and identity
Hub nodes host the Zedmos engine in routed posture with a dedicated encrypted interface. Every spoke flow passes through DPI, policy, TLS inspection, and logging at the hub.
- Same engine as Console — one binary, one behaviour
- Inline DPI and policy enforcement at ingress
- Primary and backup hubs ship as an active-standby pair
A spoke can be an OPNsense appliance at a branch, a compact Linux gateway, or a per-user roaming agent. Enrolment is token-based and fully automated from the hub.
- Zero-touch enrolment for branch appliances
- Roaming-user agent for hybrid workforces
- Automatic reconnection and re-keying
Directory services feed users, groups, and device posture into the hub. Every flow is tagged at inspection time, so policy can distinguish between people, not just addresses.
- Active Directory via domain-controller agent
- Entra / Azure AD via Microsoft Graph
- SCIM integration with Okta and compatible IDPs
A sub-second probing daemon runs inside the hub. When the primary degrades below threshold, the backup takes over atomically — no cron, no human, no cleartext leak.
- Composite health score across ICMP, HTTP, and DNS
- Hysteresis-aware switching to prevent flap
- Atomic peer swap with packet continuity