Cloud or on-premises

Minutes to set up in the cloud, full control on-premises.

Buy izgate Cloud online and have your account live right away, or deploy izgate on your own server with Docker and run it under IzGate License. Both models have the same features and the same signed-archive guarantee. Below you'll find the setup steps, port list and license terms for each model.

Cloud details · On-premises details

Disk Management in the izgate Cloud panel: live/archive split and fill-level gauges
Disk Management: live/archive split and fill-level gauges.
Cloud · buy online

izgate Cloud: server and disk management at İzHost

If you don't want to run your own server, izgate Cloud delivers the same features through an account hosted by İzHost. Your account opens automatically once the order is completed on the /satin-al page; you just use your panel.

  • Firewall license count + log storage space (GB)Sized by how many firewalls you'll connect (up to 100) and your total log storage need.
  • You split the diskTotal disk space is split between live logs and the archive by default at 30/70; the live side needs at least 10 GB, and you can change the ratio from Settings > Disk Management.
  • Account opens automaticallyOnce the order completes, your tenant account is created automatically on İzHost's infrastructure; you change the temporary admin password on first login.
  • Data isn't deleted, even if suspendedIf your tenant is suspended, the portal and panel display shut off while collection continues; if disabled, login is refused — 5651 means data is never deleted in either case.

Buy izgate Cloud

On-premises

izgate License: the software runs on your own server

Your logs never leave your organization. izgate is deployed with Docker on a single Linux server and managed from the panel.

System requirements

  • Linux host + DockerShipped as a single image; no extra dependencies to install.
  • 2+ CPU, 4 GB RAMMinimum hardware for small and mid-sized office networks.
  • Two separate disks: /log and /archiveThe install script enforces this and stops the setup if the disks aren't separate.

Why two separate disks? Live logs and the signed archive have different access patterns; a separate disk isolates the archive's integrity from the live write load, protects performance, and means one side filling up doesn't put the other's records at risk.

Setup steps

1

Prepare the server

A Linux host with Docker installed, 2+ CPU, 4 GB RAM, and two separate disks for /log and /archive.

2

Run install.sh

The install script formats and mounts the disks and brings up the Docker stack.

3

Log in to the panel

The panel opens at http://<server>:8080; the admin password is written to the log once during initial setup.

4

Enter your license key

Enter your İzHost license key under Settings > License.

5

Add your device

Devices > New Device: enter the name, type and serial number; the address is learned automatically from the first log. The "Log Shipping" screen generates the configuration to apply on the firewall.

6

Open the guest network

Define the portal address on the firewall as the external captive portal; choose your login methods.

Explore log management features

Network requirements

Ports in use

Keep the following ports open when planning firewall rules and VLAN routing.

ServicePortProtocolDescription
Admin panel / API8080TCP (HTTP)izgate-server: panel, API, license, search
Guest portal8443TCP (HTTPS)izgate-portal; exposed only to the guest VLAN
Syslog (fast)5514UDPFirewall traffic/threat logs
Syslog (reliable)5515TCPGuaranteed-delivery log shipping
Syslog (encrypted)6514TLSEncrypted log shipping, if a certificate is configured
RADIUS authentication1812UDPOffice Wi-Fi and guest handoff on some devices
RADIUS accounting1813UDPSession start/end records
License

Annual per firewall device, assigned from the panel

In the on-premises model, the license belongs not to the whole install but to each individual firewall device. Pick only the modules you need, and pay only for those.

Per-device seat

The license is bought annually per firewall device and assigned or moved to whichever device you want from the panel.

Modular

Hotspot (guest Wi-Fi), Wi-Fi (office RADIUS) and 5651 (log archive) modules are enabled separately; take only what you need.

Encrypted, signed protocol

The license request is encrypted to İzHost's public key, and the response is a digitally signed document; the document can't be bypassed by manually editing something on the server.

3-day offline tolerance

If the İzHost license center can't be reached because of an internet outage, the system keeps running at full capacity for 3 days; if the connection comes back before that time's up, the outage is never felt.

Collection continues on an unlicensed device

Even without a license seat for a device, syslog collection and signed archiving aren't interrupted; only that device's search, statistics and guest portal screens go dark.

License states

License states you may see in the panel

The license state is shown in the panel's top bar and on the Settings > License page.

StateMeaning
validLicense is valid, all features are on.
missingNo key has been entered.
invalidThe center rejected the key (expired, revoked, over quota, etc.).
unreachableThe center can't be reached; the panel keeps working through a 3-day countdown tolerance, then locks once it runs out.
suspended (cloud only)Tenant is suspended: the portal and panel display shut off, collection continues.
disabled (cloud only)Tenant is disabled: login and existing sessions are refused, data is never deleted.

In an unlicensed or invalid state, log collection and archiving continue; only search, statistics and device metrics are hidden, and the guest portal returns a "license required" error — no record is ever lost.

Which should I choose?

On-premises and cloud, side by side

Both models have the same features; the difference is who's responsible for the server and the disk.

FeatureCloudOn-premises
Where your data livesİzHost data centerYour own server
Server and maintenance responsibilityİzHost'sYours
Disk managementİzHost's; you set the ratioYours (two separate disks set up)
Pricing basisFirewall license count + log storage space (GB)A license per connected firewall
Account setupAutomatic after checkout (/satin-al)Via the install script, by quote
Version upgradesHandled by İzHostStarted by you from the panel
Log collection and archivingSame architectureSame architecture
Details

What you should know about deployment and licensing

The reasoning behind the two-separate-disk rule

In an on-premises install, install.sh requires separate physical disks for /log and /archive and stops the setup if that condition isn't met. There are three reasons for this. The first is integrity: when the signed archive is physically isolated from the live log's write load, a disk problem on the live side doesn't affect the archive. The second is performance: the live disk, constantly written to by the column-oriented ClickHouse database, has a different access pattern than the archive disk, which is written rarely but read occasionally; a separate disk lets each run at its own speed. The third is fill-level isolation: when the live log disk starts filling up, it doesn't affect how full the archive disk is, so the risk of the signed archive failing to write stays independent of a surge on the live side.

Why panel, portal and RADIUS ports are kept separate

The admin panel (8080) and the guest portal (8443) deliberately run as separate processes: the portal is only exposed to the guest Wi-Fi VLAN and carries no management API, so a device on the guest network can never reach the admin panel. The RADIUS ports (1812/1813) are used both for office Wi-Fi user authentication and for guest handoff on some firewall models, and are usually configured to be reachable only from the internal network.

How the license protocol works

On-premises license verification begins with a request that the izgate instance on your server sends to the İzHost license center. This request is encrypted to İzHost's public key; İzHost verifies the information the server provided and returns a digitally signed, time-limited document. izgate decides the license state purely by verifying this signed document; manually editing the license field in the database opens nothing, because the gate trusts the signed document, not the record. If the center can't be reached because of an internet outage, the system keeps working at full capacity for up to three days; if that period also runs out, the device drops into an unlicensed state, but log collection and archiving continue without interruption.

Changing the disk split in the cloud

In izgate Cloud, your total disk space is split between live logs and the archive by default at a 30/70 ratio; the live side needs at least 10 GB. As your usage pattern changes (for example, if you want a longer archive retention period), you can re-set this ratio from Settings > Disk Management. The panel shows a warning once fill level crosses a certain threshold, but records are never automatically deleted because of disk fill level.

Migration and growth

For organizations that want to move between on-premises and cloud, the operating logic doesn't change, since both models share the same log, search and archive architecture; what changes is only who's responsible for the server and the disk. As your device count or log volume grows, you can buy additional license seats and scale up your hardware in the on-premises model, or increase disk and device capacity with a plan upgrade in the cloud model.

First steps after deployment

Once the panel is up and the license key is entered, the first task is usually adding your firewall as a device and applying the configuration on the "Log Shipping" screen to the device. Once the log flow is verified, you can define your guest Wi-Fi network and enter the portal address on the firewall as an external captive portal, and add the RADIUS shared secret to the device record for your office Wi-Fi. Thanks to the modular license structure, you can start by enabling only the modules you need (hotspot, office Wi-Fi, 5651 log archive) and bring the others online as your needs grow.

Support and the quoting process

After discussing your organization's network structure, firewall brand, device count and retention needs, the right deployment model and license scope are worked out together. No pricing is shared on this page; for a quote tailored to your size, simply use the demo request form.

How version upgrades are handled

There's no automatic update in an on-premises install; when a new version is released, the upgrade is started by you from the panel, so you can schedule it around your own maintenance window. In izgate Cloud, server maintenance and version upgrades are carried out by İzHost; you just keep using your panel. In both models, release notes are published in short, plain language without technical detail.

Frequently asked questions

About deployment and licensing

Why do I need separate disks for /log and /archive?

Live logs and the signed archive have different write patterns; a separate disk protects integrity, performance and fill-level isolation. The install script (install.sh) enforces this separation and stops the setup if the disks aren't separate.

Should I choose on-premises or cloud?

You can buy izgate Cloud directly online from /satin-al right away; this suits you if you want to avoid the burden of a server, disk and maintenance. If your logs must never leave your organization, IzGate License (on-premises) is the right fit; this model is currently available through a quote process. Both models have the same features.

What happens if the license expires?

In an on-premises license, if the İzHost center can't be reached for 3 days, the system keeps working at full capacity; after that, the license state moves from unreachable to invalid/locked: log collection and archiving continue, but search, statistics and the guest portal screens go dark. If a cloud tenant is suspended or disabled, data is never deleted either.

Where can I get pricing?

In izgate Cloud, pricing is calculated instantly on the purchase page based on your firewall license count and log storage needs. For on-premises IzGate License, pricing depends on the number of firewall devices and the modules chosen; you can use the demo request form for that.

How long does setup take?

In the cloud, the account opens automatically after checkout. For an on-premises install, once the server and disks are ready, the install.sh script brings the stack up within minutes; the system is ready to receive logs once the first device is added and log shipping is configured.

See all questions

Making your network Law No. 5651 compliant is a one-day job.

Configure izgate Cloud based on your number of firewall devices and storage needs; no setup, get started in minutes. Call us with any questions.