Nimbus Cloudworks

NIMBUS SUITE · SHIELD

DNS security that keeps your whole network clean

Nimbus Shield filters ads, trackers, malware and unwanted apps at the network level, for every device, without software on the endpoints. Think Pi-hole or AdGuard, but enterprise grade: multi-tenant, redundant, with encrypted DNS, parental controls, reporting and single sign-on.

1resolver for the whole site, no agents needed
200k+domains blocked per blocklist
DoT / DoHencrypted DNS, even on the move
99.9%uptime target via redundant nodes

From messy internet to controlled traffic

Ads, trackers and malicious domains cost bandwidth, privacy and security. Endpoint plugins never cover everything: guests, IoT, smart TVs and phones stay out of view. Shield tackles it at the source, at the DNS level, so every device on the network is protected automatically.

What Nimbus Shield does

Blocklists and catalog

Choose from a curated catalog (StevenBlack, AdGuard, HaGeZi, OISD, phishing and malware lists) or add your own lists. Automatic updates on a schedule you set yourself.

Block apps

Block entire services with one click: TikTok, Snapchat, gambling, streaming and dozens of other apps, per network or per group.

Parental controls

Enforce SafeSearch on Google, Bing and DuckDuckGo, and put YouTube in restricted mode. Per group, so a separate policy for children's devices.

Encrypted DNS

DNS-over-TLS and DNS-over-HTTPS with a valid certificate. A dedicated DoH address per device, so filtering keeps working on 4G or public wifi too.

Multi-tenant

One shared resolver fleet serves multiple customers or locations, strictly separated. Ideal for MSPs and organizations with multiple sites.

Redundant and self-healing

Multiple nodes behind a shared virtual IP (VRRP). Groups can follow a dynamic site IP via DynDNS, so a changing ISP address no longer takes anything down.

Live log and reporting

See in real time which domains are requested and blocked, per client. Filter, export to CSV or a branded PDF report, and unblock with one click.

Block page

Show your own branded page when something is blocked, with an explanation of why and a pointer to the service desk. Fully customizable per customer.

Rewrites and forwarders

Internal split-horizon names, conditional forwarding to internal zones, reverse DNS (PTR) and DNSSEC validation. The full toolkit of a real resolver.

What it looks like

A clean console you operate in a few clicks, with everything at hand to steer traffic and account for it.

Everything at a glance

The dashboard shows straight away how much is being requested and blocked, how well the cache performs and which domains are stopped most often. Per location or customer.

  • Real-time figures per customer or site
  • Most-blocked domains and services
  • Traffic per hour in a clear chart
shield.nimbuscloudworks.nl
Nimbus Shield analytics dashboard with live statistics and most-blocked domains

See exactly what happens

A live log of every DNS request, per device. Filter by blocked, group or domain, and unblock with one click. Export to CSV or a branded PDF report.

  • Traceable per client, even behind a single internet line
  • Reason visible: which blocklist or service matched
  • Block and unblock straight from the log
shield.nimbuscloudworks.nl/query-log
Nimbus Shield live query log per client with blocked and allowed requests

A block that explains itself

No dead connection, but a neat page in your own house style. Users see why something is blocked and how to reach the service desk.

  • Title, text and contact details fully configurable
  • The reason for the block is filled in automatically
  • A dedicated, branded page per customer
example-tracker.com
Example of the branded Nimbus Shield block page with reason and service desk contact

Why Shield instead of a standalone Pi-hole

Hobby solutions work at home, but do not scale to multiple locations, customers or compliance requirements. Shield is built from the ground up for remote management and business use.

FeatureStandalone Pi-hole/AdGuardNimbus Shield
Multiple customers/locations separatedlimited
Redundant with failovermanual
Encrypted DNS per devicelimited
Single sign-on (SSO)
Reporting and exportbasic
Managed remotelydo it yourself

Under the hood

  • Protocols Do53 (UDP/TCP), DNS-over-TLS, DNS-over-HTTPS, DNSSEC
  • Filtering blocklists, blocked apps, allow/deny, rewrites, forwarders
  • Supervision SafeSearch, YouTube restriction, per-group policy
  • Management web console, multi-tenant, roles, audit log
  • Visibility live query log, analytics, CSV and PDF report
  • Deployment redundant nodes, VRRP-VIP, DynDNS-linked groups
  • Access Nimbus Gate SSO, device profiles (iPhone, Omada)

Who it is for

SMBs and offices

Protect every device on the network against malware and phishing, keep bandwidth free and demonstrate provable policy for audits and NIS2.

MSPs and multiple locations

Manage all customers from a single console, strictly separated, with redundant resolvers and reporting per tenant.

Schools and families

Enforce safe search, restrict YouTube and block distracting apps, with a neat explanation page instead of a dead connection.

Put Nimbus Shield to work for you

We set up Shield for your network or customers, including blocklists, policy and reporting. Request a demo or let us review your current DNS setup.

Frequently asked questions

Do I have to install software on every device?

No. You point the DNS address of your router or DHCP to Shield, and every device on the network is protected immediately. For devices on the move there is an encrypted DoH profile per device.

Does it work away from the office too?

Yes. With DNS-over-HTTPS and a dedicated address per device, filtering keeps working on 4G, 5G and public wifi.

Can I set different rules per group?

Yes. You create client groups (for example office, guests, children) each with their own blocklists, blocked apps and parental controls.

What happens if a resolver goes down?

Shield runs redundantly behind a shared virtual IP, so a second node takes over seamlessly. Groups can also follow a changing site IP via DynDNS.

Can I see what has been blocked?

Yes. There is a live log per client, with analytics and export to CSV or a branded PDF report. Unblocking is one click from the log.

Is it suitable for multiple customers?

Yes. Shield is multi-tenant with strict separation and single sign-on, designed for MSPs and organizations with multiple sites.