Firewall logs and guest Wi-Fi, in one panel, fully compliant.
izgate matches every connection from your firewall with the person who made it, then archives the records in a signed, timestamped and tamper-evident form. Your guests get online in seconds with SMS, Turkish ID verification, or a visitor code.
Archive segment signedSHA-256 · Ed25519 · Kamu SM (daily)
mg-4a300c → GuestTurkish ID · NVİ verified
Guest Wi-Fi
Enter the code sent to your phone
4829
I have read and accept the privacy notice.
Connect
Works with
FortiGate
Sophos
Palo Alto
pfSense
OPNsense
MikroTik
One product, two strong pillars
Log management and Wi-Fi authentication can't be treated separately
The legal value of a record is measured by whether it can show the person behind it. That's why izgate manages firewall logs and wireless network authentication on the same platform, tied together.
Firewall Log Management
Collects logs from your office firewalls securely, makes them searchable in seconds, and writes them to an archive whose integrity can be proven the way Law No. 5651 requires.
Live search: results in milliseconds by time, IP, user, MAC and destination.
Signed archive: SHA-256 chain, Ed25519 signature and a daily qualified timestamp (Kamu SM).
Restore from archive: verify an old period with one click and make it searchable again.
Serial-number device identity: records keep going to the right device even if its address changes.
A branded login page for your guest network; RADIUS-based user authentication for your office network. Every connection is tied to a person, and every person to a record.
10 login methods: SMS, Turkish ID (NVİ), visitor code, admin approval and more.
Automatic handoff to the firewall: a verified guest is authorized instantly on FortiGate, MikroTik or pfSense.
Portal that's yours: a ready-made theme or your own HTML design, with a live preview.
Privacy-friendly: the firewall gets a fixed alias code for each person, never their real identity.
6firewall families with a ready-made driver; devices are recognized automatically from their first log
10guest login methods; combine whichever you like, per network
3 layersof integrity proof: hash chain, digital signature, timestamp
0log-loss target: a record isn't acknowledged until it's on disk
How it works
Four steps from setup to your first signed archive
You don't need to build a complex logging infrastructure. izgate runs on a single server or in the İzHost cloud; you only add a few lines of configuration to your firewall.
1
Deploy
Installed on your on-premises server with a single command, or your İzHost cloud account is opened automatically.
2
Add your device
Enter your firewall's name and serial number; the panel prepares log-shipping settings specific to your device.
3
Open the guest network
Choose your login methods and portal design, then define the portal address on the firewall as the external login page.
4
Monitor and retain
Logs become searchable live and are written to the signed archive at the same time. You decide the retention periods.
Law No. 5651
A log record is only evidence if it can be proven unchanged
Law No. 5651 and its related regulation require organizations that provide internet access to retain traffic records with their accuracy, integrity and confidentiality preserved. izgate implements this principle with a three-layer chain of proof.
SHA-256 hash chainEvery archive segment carries the digest of the one before it; delete a single line and the chain breaks.
Ed25519 digital signatureSegments are signed with a key unique to your installation; a forged file produced afterward can't pass verification.
Daily qualified timestampOnce a day, an independent timestamp from Kamu SM (via İzHost's central service) confirms the moment the record existed.
sha256 9f2c…a41e prev e07b…11c9 sig Ed25519 ✓tsa ✓ 23:59:58
traffic · 2026-09-26 38,771 lines
sha256 4b7d…90f2 prev 9f2c…a41e sig Ed25519 ✓tsa ✓ 23:59:57
auth · 2026-09-26 1,126 lines
sha256 c11a…6d08 prev 4b7d…90f2 sig Ed25519 ✓tsa ✓ 23:59:59
Guest Wi-Fi
A login method for every type of business
Hotel, hospital, café, school, factory or office tower: you decide how you want to identify your guests. Combine methods per network, and add a network password or a privacy-notice acceptance step.
SMS verification
A one-time code to the phone; iOS suggests the code automatically.
Turkish ID + NVİ
Name, surname and birth year are matched against population records.
Visitor code
Codes generated in bulk, with an expiry date and a use limit.
Admin approval
Front desk or security staff approve the request with one click in the panel.
User account
A username and password for staff or members.
Organization lookup
A live query to your hotel PMS, student, or patient system.
Pre-registration
Your organization's system registers the guest ahead of time via API.
Firewall user
Direct login with existing accounts on the firewall.
Device registration
An approved device connects by MAC address without being asked for identity again.
Remember device
A returning guest within the period you set isn't sent a new code.
Why izgate?
Built for enterprise networks, tested in the field
Every component of izgate is built with one goal: never lose a record, produce evidence, and protect the administrator's time.
Vendor-independent
FortiGate, Sophos, Palo Alto, pfSense, OPNsense and MikroTik in one panel. Switch firewalls without changing your logging infrastructure.
Zero log-loss architecture
Every incoming line is written to a safe on-disk queue first; it isn't removed from the queue until it reaches both the search database and the signed archive. A power outage doesn't mean a lost record.
User ↔ log matching
Guest portal and RADIUS sessions merge automatically with firewall logs. "Who was on this IP at that time?" is answered in a single search.
Search in seconds
A column-oriented database filters millions of rows by time, IP, user, MAC and port in moments, with a timeline and summary charts.
Live and archive, in parallel
Every record is written to the fast search layer and to the signed archive on a separate disk at the same time. You choose independent retention periods for each.
Privacy first
Guest identities are stored encrypted; only a fixed alias code for the person goes to the firewall. Identity is only ever handed off to internal network addresses.
MikroTik one-click setup
Enter your RouterOS 7 REST API details and syslog, hotspot, login page and optional Wi-Fi (CAPsMAN) and Let's Encrypt steps are applied automatically. Passed tests against a mock device; field testing on real RouterOS hardware is on the roadmap.
Rules, plus Alerts and Events
View and edit FortiGate and MikroTik firewall rules from the panel; firewall events and izgate's own events (guest logins, approvals, rule changes, device status) merge into one stream.
Single sign-on with your İzHost account
Log in with your izgate.com/izhost.com account, or jump into the panel with one-click SSO; assign sub-users measured roles (viewing, logs, archive, devices, Wi-Fi management, settings) from a shared permission catalog.
Comparison
How it differs from ordinary logging software
Log tools tied to a single vendor, or manually configured syslog servers, fall short on today's multi-vendor, guest-heavy networks.
Feature
izgate
Single-vendor log software
Manually configured syslog server
Multi-vendor firewall support
6 families, one panel
Its own vendor only
Raw text only
Signed + timestamped archive
Hash chain, signature, daily Kamu SM timestamp
Varies by product
None
Guest Wi-Fi captive portal
10 methods, custom design
Limited
None
Turkish ID (NVİ) verification
Yes
Varies by product
None
User ↔ log matching
Automatic
Partial
Manual
RADIUS for office Wi-Fi
Built in
Usually none
Separate setup
Platform
Linux / Docker or cloud
Mostly Windows
Varies
Disk queue against log loss
Yes
Varies by product
Loss possible over UDP
Deployment models
Minutes in the cloud, full control on your own server
You can buy izgate Cloud online and have your account live right away; if you need your data to stay on your own server, you can get IzGate License through a quote. Both models share the same features and the same signed archive.
Buy online
izgate Cloud
Server, backups, updates and disk management live at İzHost; you just use your panel.
Firewall license count + log storage space (GB)You split the space between live logs and the archive (suggested 30/70, live at least 10 GB).
Your account opens automatically after checkout; log in/SSO with your İzHost account
Hosted in İzHost's data center in Turkey
Quota/usage tracking and split ratio from the Disk Management panel
Server maintenance and version upgrades are on us
Your data is never deleted, even if the service is suspended
Ready-made drivers exist for FortiGate, Sophos (XG/SFOS), Palo Alto Networks, pfSense, OPNsense and MikroTik. These devices send logs over syslog; izgate recognizes the device by its serial number and parses the fields automatically. See the supported devices page for details.
Is izgate enough to be 5651-compliant?
izgate collects internal IP allocation and traffic records, matches them to a user, signs and timestamps them so they can be proven unaltered, and retains them for however long you choose. We recommend getting your legal counsel's view on how the obligations apply to your organization. More detail: the 5651 guide.
How do our guests get online?
The browser on a device joining the guest network is redirected to the izgate login page. The guest is verified by the method you chose (SMS, Turkish ID, visitor code, etc.) and accepts the privacy notice; izgate then opens a temporary user for that person on your firewall and starts internet access within seconds. Access closes automatically when the session expires.
Should I choose on-premises or cloud?
You can buy izgate Cloud directly online from /satin-al and have your account live right away; this suits you if you don't want the burden of a server, disk or maintenance. If your logs must never leave your organization, IzGate License (on-premises) is the right fit; this model is currently available through a quote process. Both models have the same features.
What happens if my internet connection drops?
Log collection and archiving don't depend on an internet connection and continue uninterrupted. If an on-premises license can't reach the İzHost center, the system keeps working at full capacity for 3 days.
Can I try it before buying?
Yes. Reach us through the demo request form; we'll review your network together and set up a live demo and trial environment for you.