NIMBUS SUITE · SHIELD
DNS security that keeps your whole network clean
Nimbus Shield filters ads, trackers, malware and unwanted apps at the network level, for every device, without software on the endpoints. Think Pi-hole or AdGuard, but enterprise grade: multi-tenant, redundant, with encrypted DNS, parental controls, reporting and single sign-on.
From messy internet to controlled traffic
Ads, trackers and malicious domains cost bandwidth, privacy and security. Endpoint plugins never cover everything: guests, IoT, smart TVs and phones stay out of view. Shield tackles it at the source, at the DNS level, so every device on the network is protected automatically.
What Nimbus Shield does
Blocklists and catalog
Choose from a curated catalog (StevenBlack, AdGuard, HaGeZi, OISD, phishing and malware lists) or add your own lists. Automatic updates on a schedule you set yourself.
Block apps
Block entire services with one click: TikTok, Snapchat, gambling, streaming and dozens of other apps, per network or per group.
Parental controls
Enforce SafeSearch on Google, Bing and DuckDuckGo, and put YouTube in restricted mode. Per group, so a separate policy for children's devices.
Encrypted DNS
DNS-over-TLS and DNS-over-HTTPS with a valid certificate. A dedicated DoH address per device, so filtering keeps working on 4G or public wifi too.
Multi-tenant
One shared resolver fleet serves multiple customers or locations, strictly separated. Ideal for MSPs and organizations with multiple sites.
Redundant and self-healing
Multiple nodes behind a shared virtual IP (VRRP). Groups can follow a dynamic site IP via DynDNS, so a changing ISP address no longer takes anything down.
Live log and reporting
See in real time which domains are requested and blocked, per client. Filter, export to CSV or a branded PDF report, and unblock with one click.
Block page
Show your own branded page when something is blocked, with an explanation of why and a pointer to the service desk. Fully customizable per customer.
Rewrites and forwarders
Internal split-horizon names, conditional forwarding to internal zones, reverse DNS (PTR) and DNSSEC validation. The full toolkit of a real resolver.
What it looks like
A clean console you operate in a few clicks, with everything at hand to steer traffic and account for it.
Everything at a glance
The dashboard shows straight away how much is being requested and blocked, how well the cache performs and which domains are stopped most often. Per location or customer.
- Real-time figures per customer or site
- Most-blocked domains and services
- Traffic per hour in a clear chart
See exactly what happens
A live log of every DNS request, per device. Filter by blocked, group or domain, and unblock with one click. Export to CSV or a branded PDF report.
- Traceable per client, even behind a single internet line
- Reason visible: which blocklist or service matched
- Block and unblock straight from the log
A block that explains itself
No dead connection, but a neat page in your own house style. Users see why something is blocked and how to reach the service desk.
- Title, text and contact details fully configurable
- The reason for the block is filled in automatically
- A dedicated, branded page per customer
Why Shield instead of a standalone Pi-hole
Hobby solutions work at home, but do not scale to multiple locations, customers or compliance requirements. Shield is built from the ground up for remote management and business use.
| Feature | Standalone Pi-hole/AdGuard | Nimbus Shield |
|---|---|---|
| Multiple customers/locations separated | limited | ✓ |
| Redundant with failover | manual | ✓ |
| Encrypted DNS per device | limited | ✓ |
| Single sign-on (SSO) | — | ✓ |
| Reporting and export | basic | ✓ |
| Managed remotely | do it yourself | ✓ |
Under the hood
- Protocols Do53 (UDP/TCP), DNS-over-TLS, DNS-over-HTTPS, DNSSEC
- Filtering blocklists, blocked apps, allow/deny, rewrites, forwarders
- Supervision SafeSearch, YouTube restriction, per-group policy
- Management web console, multi-tenant, roles, audit log
- Visibility live query log, analytics, CSV and PDF report
- Deployment redundant nodes, VRRP-VIP, DynDNS-linked groups
- Access Nimbus Gate SSO, device profiles (iPhone, Omada)
Who it is for
SMBs and offices
Protect every device on the network against malware and phishing, keep bandwidth free and demonstrate provable policy for audits and NIS2.
MSPs and multiple locations
Manage all customers from a single console, strictly separated, with redundant resolvers and reporting per tenant.
Schools and families
Enforce safe search, restrict YouTube and block distracting apps, with a neat explanation page instead of a dead connection.
Put Nimbus Shield to work for you
We set up Shield for your network or customers, including blocklists, policy and reporting. Request a demo or let us review your current DNS setup.
Frequently asked questions
Do I have to install software on every device?
No. You point the DNS address of your router or DHCP to Shield, and every device on the network is protected immediately. For devices on the move there is an encrypted DoH profile per device.
Does it work away from the office too?
Yes. With DNS-over-HTTPS and a dedicated address per device, filtering keeps working on 4G, 5G and public wifi.
Can I set different rules per group?
Yes. You create client groups (for example office, guests, children) each with their own blocklists, blocked apps and parental controls.
What happens if a resolver goes down?
Shield runs redundantly behind a shared virtual IP, so a second node takes over seamlessly. Groups can also follow a changing site IP via DynDNS.
Can I see what has been blocked?
Yes. There is a live log per client, with analytics and export to CSV or a branded PDF report. Unblocking is one click from the log.
Is it suitable for multiple customers?
Yes. Shield is multi-tenant with strict separation and single sign-on, designed for MSPs and organizations with multiple sites.
