-
Notifications
You must be signed in to change notification settings - Fork 0
Home
AsaTyr2018 edited this page Mar 17, 2026
·
25 revisions
Welcome to the DomNexDomain wiki.
This guide is intentionally written for non-technical users and operators who want clear, practical steps.
- Quick Start (10 Minutes)
- Prerequisites
- Installation (Bare Metal)
- First Login & Initial Setup
- Initial Setup Assistant and OTS
- Domain Wizard
- Subdomain Wizard
- SSH Bastion Client Guide
- Subdomain Settings (HA, Auth Page, GeoIP, Maintenance/Disable)
- Dashboard Widget Guide
- UI Style Profiles and Branding
-
Access Control in the Web UI
- users
- groups
- permission matrix
- API tokens
- Users and Roles
- Identity Providers (LDAP + OIDC)
- API Tokens and Automation
- Threat Intel Operations
- Logservers and External SIEM
- Operating Profiles (Quickstart Gate / Warden Gate)
- API Usage Guide
- Product Roadmap
- Technical Reference
- Logs, Monitoring, and Health
- Data Retention and Privacy Baseline
- Security Best Practices
- Backup and Restore
- Troubleshooting
- Glossary
- Support
- Home lab users
- Small teams with multiple internal services
- Operators who want one Linux service instead of a stack of separate tools
- New first-boot Setup Assistant with OTS unlock and setup API gating
- In-house MFA/2FA upgrades:
- per-role MFA enforcement in
Settings -> MFA(admin,domain-admin,read-only) - per-user MFA self-service in
My Account - admin MFA reset with break-glass operational path
- security coupling:
Disable IP checkis only allowed for MFA-enabled users
- per-role MFA enforcement in
-
Strategic Intelis now the unified analytics workspace:-
Overview,Events,Telemetry,Geo,Investigations,Notifications - cleaner navigation for big-data operations
- geo map embedded directly in the
Geotab -
Investigationsnow pivots directly on trace IDs and shows chronologicalflow,evidence, andactionentries
-
- Resilience upgrades after internet/provider drops:
- Public WAN IP sync now runs every 10 minutes and performs startup reconcile
- DNS maintenance worker runs every 1 minute for apex + subdomain reachability transitions
- automatic Cloudflare domain/host reconciliation on mismatch
- maintenance writes change events only (no periodic check spam)
- Built-in edge WAF baseline:
- automatic temporary block on unknown-host flood patterns
- 15-minute TTL (no permanent auto-block)
- Threat Intel management upgrades:
- two policy modes:
Monitor onlyandAuto mode - allowlist-first behavior across both modes
- XP/Level/Tier model with
New,Watched, andBlockedviews - feed intelligence is backend-first (no direct hard block on feed sync)
- first real feed/signature-driven contact enters the watched band (Level 3) instead of instant block
- hard blocks age into watch state after long inactivity for controlled lifecycle
- hard-block requests are edge-dropped (
proxy.block.hard_drop) instead of rendered as normal error pages
- two policy modes:
- Trace collection upgrades:
- dedicated trace timeline store for reproducible investigations
- first-contact flow capture at the edge
- trace retention limited to
60 dayswith automatic pruning
- Retention controls in
Settings -> Advanced:- configurable data retention per data domain
- automatic daily purge job
- audit evidence via
retention.purgeactions inStrategic Intel -> Events
- Smart error pages:
- branded DomNexDomain pages for routing/policy/origin failures
- embedded trace IDs for direct log correlation
- Style system and branding:
-
Monolith,CyberMonolith, andCustomthemes - logo integrated across navigation, login, and error pages
-
- Dedicated
Backupmenu with encrypted packages, scheduler, FTP target, and post-restore check/cert warmup - GeoIP data pipeline upgrades:
- multi-source ingest (
.mmdb,.csv,.mmdb.gz,.csv.gz,.zip) - compiled Source-of-Truth MMDB for runtime lookups
- auto-compile on upload/start + scheduled compile checks
-
Settings -> GeoIP Sourcesnow includes source index, dataset stats, and upload progress
- multi-source ingest (
- Restrict admin access to trusted networks only.
- Complete first-boot setup immediately after installation and store admin credentials securely.
- Use
HTTPSfor all external access whenever possible.
- GitHub issues: use the repository issue tracker for bugs and feature requests.
- Discord: https://discord.gg/GnAUmXhfeG
- Home
- Quick Start
- Prerequisites
- Installation
- First Login
- Initial Setup Assistant and OTS
- Domain Wizard
- Subdomain Wizard
- SSH Bastion Client Guide
- Subdomain Settings
- Dashboard Widget Guide
- UI Styles and Branding
- Access Control (Users, Groups, Permission Matrix, API Tokens)
- Users and Roles
- Identity Providers (LDAP + OIDC)
- API Tokens
- Threat Intel
- Logservers and External SIEM
- Operating Profiles
- API Usage Guide
- Product Roadmap
- Technical Reference
- Strategic Intel (Logs and Monitoring)
- Data Retention
- Security
- Backup and Restore
- Troubleshooting
- Glossary
- Support