5651-compliant · Vendor-independent

Firewall logs and guest Wi-Fi, in one panel, fully compliant.

izgate matches every connection from your firewall with the person who made it, then archives the records in a signed, timestamped and tamper-evident form. Your guests get online in seconds with SMS, Turkish ID verification, or a visitor code.

  • FortiGate, Sophos, Palo Alto, pfSense, MikroTik
  • SHA-256 chain + signature + timestamp
  • On-premises or cloud
izgate admin panel Overview screen: log traffic, event categories, device status map, Wi-Fi usage and verification methods

Works with

  • FortiGate
  • Sophos
  • Palo Alto
  • pfSense
  • OPNsense
  • MikroTik
One product, two strong pillars

Log management and Wi-Fi authentication can't be treated separately

The legal value of a record is measured by whether it can show the person behind it. That's why izgate manages firewall logs and wireless network authentication on the same platform, tied together.

Firewall Log Management

Collects logs from your office firewalls securely, makes them searchable in seconds, and writes them to an archive whose integrity can be proven the way Law No. 5651 requires.

  • Live search: results in milliseconds by time, IP, user, MAC and destination.
  • Signed archive: SHA-256 chain, Ed25519 signature and a daily qualified timestamp (Kamu SM).
  • Restore from archive: verify an old period with one click and make it searchable again.
  • Serial-number device identity: records keep going to the right device even if its address changes.
Explore firewall log management

Wi-Fi Management

A branded login page for your guest network; RADIUS-based user authentication for your office network. Every connection is tied to a person, and every person to a record.

  • 10 login methods: SMS, Turkish ID (NVİ), visitor code, admin approval and more.
  • Automatic handoff to the firewall: a verified guest is authorized instantly on FortiGate, MikroTik or pfSense.
  • Portal that's yours: a ready-made theme or your own HTML design, with a live preview.
  • Privacy-friendly: the firewall gets a fixed alias code for each person, never their real identity.
Explore the guest Wi-Fi solution
6firewall families with a ready-made driver; devices are recognized automatically from their first log
10guest login methods; combine whichever you like, per network
3 layersof integrity proof: hash chain, digital signature, timestamp
0log-loss target: a record isn't acknowledged until it's on disk
How it works

Four steps from setup to your first signed archive

You don't need to build a complex logging infrastructure. izgate runs on a single server or in the İzHost cloud; you only add a few lines of configuration to your firewall.

1

Deploy

Installed on your on-premises server with a single command, or your İzHost cloud account is opened automatically.

2

Add your device

Enter your firewall's name and serial number; the panel prepares log-shipping settings specific to your device.

3

Open the guest network

Choose your login methods and portal design, then define the portal address on the firewall as the external login page.

4

Monitor and retain

Logs become searchable live and are written to the signed archive at the same time. You decide the retention periods.

Law No. 5651

A log record is only evidence if it can be proven unchanged

Law No. 5651 and its related regulation require organizations that provide internet access to retain traffic records with their accuracy, integrity and confidentiality preserved. izgate implements this principle with a three-layer chain of proof.

  • SHA-256 hash chainEvery archive segment carries the digest of the one before it; delete a single line and the chain breaks.
  • Ed25519 digital signatureSegments are signed with a key unique to your installation; a forged file produced afterward can't pass verification.
  • Daily qualified timestampOnce a day, an independent timestamp from Kamu SM (via İzHost's central service) confirms the moment the record existed.

5651 obligations and the izgate guide

Guest Wi-Fi

A login method for every type of business

Hotel, hospital, café, school, factory or office tower: you decide how you want to identify your guests. Combine methods per network, and add a network password or a privacy-notice acceptance step.

SMS verification

A one-time code to the phone; iOS suggests the code automatically.

Turkish ID + NVİ

Name, surname and birth year are matched against population records.

Visitor code

Codes generated in bulk, with an expiry date and a use limit.

Admin approval

Front desk or security staff approve the request with one click in the panel.

User account

A username and password for staff or members.

Organization lookup

A live query to your hotel PMS, student, or patient system.

Pre-registration

Your organization's system registers the guest ahead of time via API.

Firewall user

Direct login with existing accounts on the firewall.

Device registration

An approved device connects by MAC address without being asked for identity again.

Remember device

A returning guest within the period you set isn't sent a new code.

Why izgate?

Built for enterprise networks, tested in the field

Every component of izgate is built with one goal: never lose a record, produce evidence, and protect the administrator's time.

Vendor-independent

FortiGate, Sophos, Palo Alto, pfSense, OPNsense and MikroTik in one panel. Switch firewalls without changing your logging infrastructure.

Zero log-loss architecture

Every incoming line is written to a safe on-disk queue first; it isn't removed from the queue until it reaches both the search database and the signed archive. A power outage doesn't mean a lost record.

User ↔ log matching

Guest portal and RADIUS sessions merge automatically with firewall logs. "Who was on this IP at that time?" is answered in a single search.

Search in seconds

A column-oriented database filters millions of rows by time, IP, user, MAC and port in moments, with a timeline and summary charts.

Live and archive, in parallel

Every record is written to the fast search layer and to the signed archive on a separate disk at the same time. You choose independent retention periods for each.

Privacy first

Guest identities are stored encrypted; only a fixed alias code for the person goes to the firewall. Identity is only ever handed off to internal network addresses.

MikroTik one-click setup

Enter your RouterOS 7 REST API details and syslog, hotspot, login page and optional Wi-Fi (CAPsMAN) and Let's Encrypt steps are applied automatically. Passed tests against a mock device; field testing on real RouterOS hardware is on the roadmap.

Rules, plus Alerts and Events

View and edit FortiGate and MikroTik firewall rules from the panel; firewall events and izgate's own events (guest logins, approvals, rule changes, device status) merge into one stream.

Single sign-on with your İzHost account

Log in with your izgate.com/izhost.com account, or jump into the panel with one-click SSO; assign sub-users measured roles (viewing, logs, archive, devices, Wi-Fi management, settings) from a shared permission catalog.

Comparison

How it differs from ordinary logging software

Log tools tied to a single vendor, or manually configured syslog servers, fall short on today's multi-vendor, guest-heavy networks.

FeatureizgateSingle-vendor log softwareManually configured syslog server
Multi-vendor firewall support6 families, one panelIts own vendor onlyRaw text only
Signed + timestamped archiveHash chain, signature, daily Kamu SM timestampVaries by productNone
Guest Wi-Fi captive portal10 methods, custom designLimitedNone
Turkish ID (NVİ) verificationYesVaries by productNone
User ↔ log matchingAutomaticPartialManual
RADIUS for office Wi-FiBuilt inUsually noneSeparate setup
PlatformLinux / Docker or cloudMostly WindowsVaries
Disk queue against log lossYesVaries by productLoss possible over UDP
Deployment models

Minutes in the cloud, full control on your own server

You can buy izgate Cloud online and have your account live right away; if you need your data to stay on your own server, you can get IzGate License through a quote. Both models share the same features and the same signed archive.

On-premises · by quote

IzGate License

The software runs on your own server; logs never leave your organization.

Annual license per firewall deviceModules: Hotspot, Wi-Fi, 5651 — take only what you need.
  • Single-command Docker-based deployment
  • Separate disks for live logs and the archive (for integrity and performance)
  • Licenses are assigned per device from the panel, and are portable
  • Keeps running at full capacity for up to 3 days without internet
  • Log collection and archiving never stop, even if the license expires
Get a Quote
Frequently asked questions

Things you might be wondering

Which firewalls does izgate work with?

Ready-made drivers exist for FortiGate, Sophos (XG/SFOS), Palo Alto Networks, pfSense, OPNsense and MikroTik. These devices send logs over syslog; izgate recognizes the device by its serial number and parses the fields automatically. See the supported devices page for details.

Is izgate enough to be 5651-compliant?

izgate collects internal IP allocation and traffic records, matches them to a user, signs and timestamps them so they can be proven unaltered, and retains them for however long you choose. We recommend getting your legal counsel's view on how the obligations apply to your organization. More detail: the 5651 guide.

How do our guests get online?

The browser on a device joining the guest network is redirected to the izgate login page. The guest is verified by the method you chose (SMS, Turkish ID, visitor code, etc.) and accepts the privacy notice; izgate then opens a temporary user for that person on your firewall and starts internet access within seconds. Access closes automatically when the session expires.

Should I choose on-premises or cloud?

You can buy izgate Cloud directly online from /satin-al and have your account live right away; this suits you if you don't want the burden of a server, disk or maintenance. If your logs must never leave your organization, IzGate License (on-premises) is the right fit; this model is currently available through a quote process. Both models have the same features.

What happens if my internet connection drops?

Log collection and archiving don't depend on an internet connection and continue uninterrupted. If an on-premises license can't reach the İzHost center, the system keeps working at full capacity for 3 days.

Can I try it before buying?

Yes. Reach us through the demo request form; we'll review your network together and set up a live demo and trial environment for you.

See all questions

Making your network Law No. 5651 compliant is a one-day job.

Configure izgate Cloud based on your number of firewall devices and storage needs; no setup, get started in minutes. Call us with any questions.