COSGrid ReFleX-Edge

SD-WAN Gateway and Secure Branch Edge Appliance

SD-WAN, NGFW, and encrypted tunnels in one vCPE — deployed anywhere, across any transport.

COSGrid ReFleX-Edge

What is COSGrid ReFleX Edge?

COSGrid ReFleX-Edge is the SD-WAN gateway of COSGrid ReFleX-WAN, COSGrid's SD-WAN solution. It is deployed at branch offices, factories, retail stores, data centres, or cloud environments to connect multiple WAN links such as broadband, MPLS, DIA, 4G/5G, and Wi-Fi. ReFleX-Edge intelligently selects the best path for each application to ensure reliable and high-performance connectivity.

BUILT IN

SD-WANNext-Gen FirewallVPNRoutingNATApplication-Aware QoS

DEPLOYED AT

Branch offices, factories, retail stores, data centres, or cloud environments.

CONNECTS

Multiple WAN links such as broadband, MPLS, DIA, 4G/5G, and Wi-Fi.

AVAILABLE AS

Hardware Appliance Hardware Appliance
|
Virtual Machine Virtual Machine
|
Cloud Cloud

How ReFleX-Edge Works

Branch
Branch
Connect
Multi-Transport
Multi-Transport
Secure the Path
Encrypted Overlay
Encrypted Overlay
Optimize Traffic
PoP / DC / Cloud
PoP / DC / Cloud
Govern Centrally
Connect 01
Zero-touch provisioning

The appliance is shipped or the image is booted, and it calls home to the COSGrid Guider controller over any available link. It authenticates with a device certificate, pulls its site configuration, and comes online without an engineer on site.

Every transport is claimed

Hardware, virtual, or cloud
one policy model

ReFleX-Edge is delivered in three form factors that share a single configuration and policy model, so a policy written for a branch appliance applies unchanged to a virtual appliance in your data centre or a cloud image in AWS.

Hardware appliance

Hardware appliance

A fanless desktop or rack-mount appliance for branch, retail, and factory sites. Zero-touch provisioning means it is unboxed and powered on by site staff, not an engineer.

Virtual appliance

Virtual appliance

A VM image for KVM, Proxmox, OpenStack, and standard enterprise hypervisors—for data centres, colocation, and sites that already run a virtualisation host.

Cloud image

Cloud image

Native AWS and Azure images built for each cloud’s accelerated networking path rather than converted from a generic disk image, providing native performance.

Role in the COSGrid Architecture

COSGrid ReFleX Edge
COSGrid ReFleX Edge
COSGrid GuiderCOSGrid Guider
COSGrid ZGridCOSGrid ZGrid
COSGrid SARCOSGrid SAR
COSGrid MZA App ClientCOSGrid MZA App Client
MicroZAccess & ZT-NACMicroZAccess & ZT-NAC

COSGrid Guider

COSGrid Guider (management plane) provisions and configures every ReFleX-Edge with zero-touch over an encrypted, mutually authenticated control channel. It securely pushes signed policies that every edge verifies before applying. Telemetry such as latency, loss, jitter, SLA status, and faults continuously streams back to Guider for centralized monitoring.

COSGrid ZGrid

COSGrid ZGrid provides the distributed cloud backbone for ReFleX Edge. It interconnects branches, cloud workloads, and data centres with secure encrypted overlays, ensuring low-latency connectivity and resilient routing across geographically distributed locations.

COSGrid SAR

COSGrid Security Analyser & Responder continuously receives telemetry from every ReFleX Edge. Using behavioural analytics and machine learning, it detects anomalies, performs threat hunting, and orchestrates automated responses through integrated policy enforcement.

COSGrid MZA App Client

The COSGrid MZA App Client securely connects remote users to enterprise applications through ReFleX Edge. It authenticates users and devices, establishes encrypted connectivity, validates device posture, and enforces Zero Trust access policies before granting application access.

MicroZAccess & ZT-NAC

MicroZAccess and ZT-NAC integrate with ReFleX Edge to provide Zero Trust Network Access and Network Access Control. They continuously verify user identity, device posture, and security compliance before allowing access to enterprise resources while maintaining a unified policy across the entire COSGrid architecture.

Key Features of COSGrid ReFleX-Edge

Application-aware path selection
Continuously measures loss, latency, and jitter on every link and classifies traffic by application, then steers each class to the path that meets its requirement. Moves traffic when a link degrades, not only when it dies — so a brownout is invisible to users.
All transports, all active
Terminates broadband, DIA, MPLS, 4G/5G, and Wi-Fi on one gateway, with two to four uplinks active at once. There is no idle standby circuit — every link carries traffic, and the encrypted overlay is transport-agnostic, so the carrier is an interchangeable underlay.
Next-generation firewall on the same box
Stateful and application-aware firewalling, NAT, intrusion prevention, and application control run on the gateway, so branch traffic is inspected locally instead of being backhauled to a central firewall. One device replaces the branch router, VPN concentrator, and firewall.
Zero-touch deployment
Shipped to site, connected to power and any link, and powered on by site staff — it authenticates to Guider, pulls its configuration, and joins the network with no engineer visit and no on-site CLI.
Any form factor, one policy
Hardware appliance, virtual appliance on standard hypervisors, or native cloud image for AWS and Azure — the same configuration and policy model applies to all three, including post-quantum hybrid key exchange for overlay tunnels.

Technical specifications

Capability
WAN links per gateway
Underlay transports
Link health probing
Load balancing · failover
Session persistence
App-aware steering · SLA path selection
QoS · NAT
Firewall
Overlay encryption
Intrusion prevention · app-ID
Segmentation
Posture enforcement
Support
2–4 concurrent uplinks
Broadband, DIA, MPLS, 4G/5G, Wi-Fi
Active loss/latency/jitter probes
Weighted, per-flow; sub-second failover with hysteresis
Sticky across failover
DPI classification; per-class loss/latency/jitter thresholds
Application QoS, DSCP; source/destination NAT
Stateful + next-generation (application-aware)
IPsec (IKEv2); WireGuard
Signature IPS; DPI
VLAN and overlay-based
Enforces MicroZAccess (ZTNA) and ZT-NAC decisions on the same device