Skip to Content
Product · Secure Wireless Gateway

The browsing filter that runs inside the access point.

The Secure Wireless Gateway is an application that runs in the access point kernel, the core of the device's system, and inspects DNS, TLS/SNI and HTTP on the AP itself. The decision to allow or drop happens before traffic leaves the local network, with no dedicated appliance and without breaking the user's encryption.

Ring Zero Dome engine, NetExperience management, Dominus Cyber integration and support
No commitment. The technical team answers.
request allowedrequest dropped at the AP
Public announcement

In May 2026, Padtec, a Brazilian manufacturer listed on B3, announced this technology for its line of Wi-Fi 6 and Wi-Fi 7 enterprise access points, in partnership with Dominus Cyber. The certified models today are the Edgecore EAP101, EAP102, EAP105 and OAP101.

Read the official announcement ↗
Decision flow

How a request is evaluated

The request is evaluated in sequence inside the access point. If nothing matches the lists, it goes through. If it matches, it is dropped right there, without using link bandwidth.

01 · Query

The name is resolved

The DNS query is read on the AP itself and compared with the active lists before it goes out to the resolver.

02 · Destination

SNI reveals the destination

In HTTPS sessions, the SNI field of the TLS handshake shows where the connection is going without decrypting anything.

03 · Decision

Allow or drop

With no match, traffic flows normally. With a match, it is dropped at the edge and does not use the link.

How the solution is built

Two layers, one operation

One decides in milliseconds inside the access point. The other is the dashboard your team opens every day. Dominus provisions the fleet, defines the policy together with your team and runs the platform day to day.

Engine · Ring Zero Dome

Inspects and decides at the edge

Application that runs in the kernel of the access point itself. Brazilian technology, born at LabLua at PUC-Rio and selected in 2024 for OpenRAN@Brasil, coordinated by RNP and CPQD.

  • Reads DNS, TLS/SNI and HTTP metadata
  • Does not decrypt session content
  • Drops traffic before it uses the link
  • Blocks encrypted DNS and bypass VPNs
Management · NetExperience

Provisions, shows and proves

Cloud platform that controls the whole fleet.

  • Policy per customer, SSID or AP group
  • Role-based portals, no shared credentials
  • Bulk provisioning, RRM and self-healing
  • REST API and webhooks, IPv4 and IPv6
The dashboard

Secure Wireless Gateway screens

Screenshots of the NetExperience dashboard in the Dominus Cyber lab, with two EAP101 access points.

Secure Wireless Gateway dashboard with protected devices, blocked and allowed requests, and most blocked categories and domains
Gateway view. Protected devices, blocked and allowed requests, and the most blocked destinations in the period. In the lab, the test profile blocks a messaging service.
Policy profile editing with activity report and entries blocked by category, service and protocol
Policy profile. Each entry is a category, a service or a protocol. The activity report is turned on and off per profile.

IP and MAC addresses and user data have been hidden.

What changes in operations

Six practical effects of deciding at the edge

They all come from the same architecture choice: processing on the access point instead of sending traffic somewhere else.

No separate appliance

No need for a web filter or a dedicated appliance. The function comes inside the access point, on the same device that serves the Wi-Fi.

Privacy preserved

The analysis uses metadata. No user session is decrypted to make the decision.

Link savings

Trackers, ads and unwanted traffic are stopped before they cross the backhaul and the uplink.

Open standard

Runs on the open TIP OpenWiFi standard. The hardware is not proprietary, so your operation is not tied to a single vendor.

Licensing per AP

Cost per access point, with a density tier defined during sizing. The calculation does not depend on the company's headcount.

Centralized management

One dashboard for the whole fleet: policy, AP status and what was blocked, without opening one screen per site.

Specifications

Specifications for the current version

Numbers and limits of the current product version. Cases outside this range go through engineering validation.

Inspected protocolsDNS, TLS/SNI and HTTP
Analysis methodConnection metadata. No deep packet inspection and no breaking of encryption.
Where it runsIn-kernel application on the access point itself, at the access layer.
Policy rulesBy category, by service or by protocol, with lists updated continuously.
Network segmentationVLAN assigned dynamically through 802.1X or by individual password (MPSK).
BypassBlocking of encrypted DNS and bypass VPNs, according to NetExperience documentation.
Activity reportOptional per profile. When off, blocking continues and browsing is not logged.
LicensingPer access point, with the license activated in the dashboard and a density tier defined during sizing.
Hardware standardTIP OpenWiFi.
Certified hardwareEdgecore EAP101, EAP102 and EAP105 (indoor, Wi-Fi 6 and Wi-Fi 7) and OAP101 (outdoor), supplied by Padtec. The list grows as new models pass certification. See the equipment
Planned for 2027Switches and a gateway with the Secure Wireless Gateway, managed in the same dashboard.
ManagementSingle dashboard for policy, monitoring and blocking events.
Scope limits

What the gateway does not do

If your case falls into one of these points, let's talk before moving on.

It does not decrypt traffic

The decision uses metadata. The content of HTTPS sessions stays closed, including to the network operator. The destination shows up in the activity report, if it is turned on.

It does not replace a firewall or EDR

It works at the Wi-Fi access layer. Whatever protects the core, the perimeter and the endpoint is still needed.

It does not inspect payloads

If the requirement is to analyze packet content, this gateway alone does not meet it and the design needs another layer.

It does not see inside a VPN tunnel

The bypass VPN service can be blocked. What travels inside an authorized tunnel is outside the reach of inspection.

Want to see this on your network?

We size how many points your scenario needs and show what would be blocked at the edge. No commitment.