Ask SecureGuard a question. Answers come from this site's docs only. I will cite a page. I will not invent a product claim.
Licensed per appliance. Free is not a trial.
Every tier is the same image — the license decides scale and features. Community is perpetual and never throttled, so a lab, first-site, or branch install is a real appliance rather than a countdown, and paid tiers widen scale and unlock what a production perimeter needs. Which plans are currently on offer is listed below rather than asserted here.
What is on sale right now
This list is the current catalog: plans, payment, and license issuance. If it looks short, that is the truth of it rather than a rendering problem.
Community
The complete firewall at small scale, perpetually free and never throttled.
- Full policy engine: objects, zones, rules, NAT, static routing
- Web Filter, Safe Search, and DoH block
- One site-to-site tunnel (IPSec, WireGuard or SiteLink)
- Up to 10 remote-access VPN users
- Flood and reconnaissance protection
- Suricata IPS
- AI security in observe and suggest mode
- Preview, commit, rollback and per-service live logs
Business
The production feature set: identity, dynamic routing, and clustering.
- Everything in Home
- Up to 25 site-to-site tunnels, unlimited VPN users
- External authentication (RADIUS, LDAP, Active Directory, SSO)
- Dynamic routing (OSPF and BGP)
- Active/passive HA cluster with real-time config sync
Enterprise
Unlimited scale, node-bound licensing and the full security stack.
- Everything in Business
- Unlimited site-to-site tunnels and VPN users
- Every gated feature enabled
- Node-bound license management
- Priority updates and threat feeds
Home
Wider scale for a single site, branch, or small office.
- Everything in Community
- Up to 5 site-to-site tunnels
- Up to 50 remote-access VPN users
- Priority updates and threat feeds
Prices are annual, per appliance. Multi-appliance, MSP and distributor terms exist — Compare plans or ask about MSP or multi-appliance terms.
What each tier unlocks
This is the licensing model the appliance itself enforces, independent of which plans are currently for sale. Core firewalling, NAT, objects, zones, static routing, local admin login and AI in observe/suggest mode are never gated — a free appliance is a complete firewall, not a demo of one. HA clustering is tested and shipping on Business+. Threat feeds ship on Home+.
| Feature | Community | Home | Business | Enterprise |
|---|---|---|---|---|
| Site-to-site tunnels IPSec, WireGuard and SiteLink combined | 1 | 5 | 25 | Unlimited |
| Remote-access VPN users | 10 | 50 | Unlimited | Unlimited |
| Firewall, NAT, objects, zones, static routing Never gated — a free appliance is a complete firewall | ✓ | ✓ | ✓ | ✓ |
| Flood and reconnaissance protection | ✓ | ✓ | ✓ | ✓ |
| AI security: observe and suggest | ✓ | ✓ | ✓ | ✓ |
| Preview, commit, rollback, live logs | ✓ | ✓ | ✓ | ✓ |
| Priority updates and threat feeds Shipping on Home+ | — | ✓ | ✓ | ✓ |
| External authentication RADIUS, LDAP, Active Directory, SSO | — | — | ✓ | ✓ |
| Dynamic routing (OSPF, BGP) | — | — | ✓ | ✓ |
| Active/passive HA cluster Shipping on Business+ — tested | — | — | ✓ | ✓ |
Two steps, because a key is bound to a box
A SecureGuard license key has the appliance's node ID signed into it. That means the key cannot exist before you have installed the product and can read that ID off it — so nobody gets a license key from this website.
- Request. Tell us who you are (or pay, for a paid plan) and we email an activation code.
- Install. The appliance generates and shows its node ID during setup.
- Activate. Give the code and that node ID to the activation page and you receive the key for that box.
Re-submitting the same code and node ID is safe: it returns the existing key and does not consume another seat, so a double-click cannot cost you one.
An expired license does not drop your traffic
This is the part most appliance vendors get wrong, and it is a deliberate difference. When a paid license lapses, SecureGuard does not disable the firewall and it does not stop passing packets. It degrades:
- Throughput is limited to a grace floor — 10 Mbps unless your license sets another.
- Scale reverts to Community limits.
- Paid features stop being enableable; what is already running keeps running.
- The console says exactly what happened and what renewing restores.
The same principle applies to the commit gate: turning on a paid feature you are not entitled to is refused with an upgrade prompt, but a config that is already live is never ripped out from under a network. Losing connectivity is never the punishment for a lapsed invoice.
Existing customer? Your codes, licenses and downloads live in your account. Full licensing reference →
Need it operated for you? Request managed Guard.
SecureGuard is an appliance you run. Community, Home, and paid tiers are self-hosted licenses on hardware or a VM you control. Hosted or managed operation is by request only — not generally available, and not a published SKU.
What this is not
This is not a cloud firewall, not a point-of-presence network, and not an auto-blocking SaaS. It is a request that we operate the same appliance image for you, if and when that makes sense for the site.
Evaluate Community on the same image
Community is the same image as every paid tier. Request a node-locked key. Move up a tier when scale or features demand it — the license changes, not the deployment.