Themelio is a modern, self-hosted DDI platform that brings DNS, DHCP and IP Address Management together in a single console — reliable, secure and owned by you. It runs entirely inside your own network: no cloud dependency, no call-home, perpetual licensing.
DDI stands for DNS, DHCP and IPAM — the three core network services that assign and resolve every IP address on a network, managed together from one platform instead of three separate tools.
Resolves human-readable names to IP addresses. A DDI platform manages authoritative and recursive zones, records, split-horizon views and DNSSEC signing from one console.
Hands out IP addresses and network settings automatically as devices join. DDI covers IPv4 and IPv6 subnets, pools, reservations, client classes and live leases.
Plans and tracks the address space itself — a hierarchical inventory of every subnet and address, reconciled against what DNS and DHCP are actually serving.
When core network services are managed in disconnected tools, routine changes become a leading cause of outages and audit gaps.
A single platform for every core network service — without the cost and complexity of legacy DDI suites.
DNS, DHCP & IPAM in one console — every IP correlated with its record, lease and device.
Validated changes, automatic rollback, DHCP HA, manager HA and encrypted backup / restore.
Role-based access, MFA and a complete audit trail — enforced at the API layer, on your infrastructure.
Reservation workflows, discovery, REST API and infrastructure-as-code that fit your pipelines.
Start with one appliance; grow to distributed DNS/DHCP nodes under one management grid.
Ask your network in plain language over an on-prem MCP server — read-only by default, every call audited.
RPZ firewall, DGA & tunneling detection, encrypted DNS transport and offline threat-feed packs.
Top talkers, top domains and custom dashboards, with scheduled reports your auditor can read.
Your data stays in-house. Air-gap friendly, no internet call-home — ever.
Install a single, self-contained package — a standalone node for a site, or a managed grid across many sites and data centers. Each node joins the central Manager over a secure, outbound-only connection. No appliances, no cloud dependency, no internet required.
Virtual IP and database replication keep the control plane available; automatic failover targets under 60 seconds.
Nodes connect to the Manager over mutual-TLS with no inbound management ports to expose.
Linux on VM or bare metal — VMware, Proxmox, Hyper-V — fully offline / air-gap capable.
Themelio deploys as a single software package and is managed entirely from one console. Bring nodes online, import your existing zones and scopes with a preview, then serve — with validation and automatic rollback on every change.
Install one self-contained package — a standalone node, or a managed grid — entirely inside your own network.
Each node joins the central Manager over a secure, outbound-only connection — no inbound ports to open.
Import DNS zones and DHCP scopes with a preview — including Microsoft DNS/DHCP sync — then stage changes safely.
Deploy with validation and automatic rollback, then run the whole estate from one screen — auditable end to end.
Themelio is pure software — so your DDI is never trapped on a vendor appliance with a refresh deadline. Deploy on the platforms you already run, and grow by adding software nodes instead of forklift-replacing hardware.
VMware, Proxmox, Hyper-V, KVM, bare metal, private cloud and air-gapped sites — one package, no proprietary box to rack.
Go vertical (a bigger VM) or horizontal (more DNS/DHCP nodes in one grid) — from a single standalone node at a branch to a highly available grid across many sites and data centers.
No End-of-Sale / End-of-Support date forcing a hardware buy every few years. A perpetual license and in-place updates keep you current.
Themelio ships a built-in MCP (Model Context Protocol) endpoint, so an AI assistant can read and reason over your live DNS, DHCP and IPAM — the real-time signal at the core of every network — without a human digging through consoles.
“Which subnets are nearly full?” “Where is this IP used?” — answered from your own source of truth, in seconds.
The AI can look, not touch. Scoped API keys, RBAC and a full audit trail apply to the assistant just like any user.
The MCP server runs inside your perimeter over standard JSON-RPC 2.0 — your DDI data never leaves your network.
Measured results from sustained load testing of a single standalone node running DNS, DHCP, IPAM and management together. Scale beyond one node with dedicated DNS/DHCP nodes in a Standard or Enterprise grid.
| Tier | vCPU / RAM | DNS throughput | DHCP throughput | Typical use |
|---|---|---|---|---|
| Small | 4 · 8 GB | 30,000 QPS | 500 leases/s | Branch / small campus |
| Medium | 8 · 16 GB | 65,000 QPS | 750 leases/s | Campus / department |
| Large | 16 · 32 GB | 100,000 QPS | 1,000 leases/s | Data center / core site |
// Figures are benchmarked single-node results on the stated VM profile (10 GbE NIC on Large). Log storage is provisioned separately to retention. Deploy dedicated DNS/DHCP nodes to scale further.
A perpetual, host-based license — buy once, add annual maintenance. Node count is a separate axis: choose any edition with 1 to N nodes.
Complete DDI for a single site — DNS, DHCP and IPAM with management, audit and backup.
Adds high availability, automation and integrations for multi-site and mission-critical networks.
Every capability — DNS security suite, AI assistant, multi-tenancy and the longest retention.
All core capabilities for 30 days on your own hardware. No credit card, no call-home.
// Perpetual, host-based licensing — buy once, add annual maintenance. Talk to Network365 for node-count sizing and multi-site grids.
Data stays inside your perimeter and never calls home. DNS operations are signed and filtered, every action is authenticated and scoped, and every change is evidence.
Automatic DNSSEC signing, validation and key rollover, plus an RPZ firewall, RRL and ACLs against poisoning and abuse.
Role-based access down to zone / subnet / site, a read-only Auditor role, MFA and maker-checker approval on sensitive change.
TLS 1.2+ on all interfaces, mutual TLS between components, and AES-256 for secrets at rest.
Any organization that must keep its core network services reliable, auditable and under its own control — from a single branch to a multi-site estate.
On-prem with DNSSEC for signed-domain mandates and long-term log retention for audit.
Data and control never leave the perimeter.
Separation of duties, maker-checker and a complete audit trail for every DNS and DHCP change.
Every change is evidence, ready for the regulator.
High availability for critical services, plus endpoint visibility across clinical and IoMT devices.
<60s failover keeps care systems online.
Runs at the edge and in air-gapped plants — one standalone node per site, no cloud dependency.
Fully offline-capable for OT networks.
One platform and one source of truth replace three separate tools — or a metered cloud appliance that bills by the query.
| Capability | ThemelioUnified DDI | 3 separate toolsDNS + DHCP + IPAM | Metered cloud DDISaaS appliance |
|---|---|---|---|
| Single console & source of truth | |||
| Perpetual license (no per-query tax) | Varies | ||
| Runs on-premise / air-gap | |||
| Validation, rollback & audit on every change | Partial | ||
| DNSSEC · RPZ · RRL built in | Add-on | ||
| Data stays in your perimeter |
// Comparison reflects typical trade-offs of unified on-prem DDI vs. point tools vs. metered cloud DDI.
DDI ย่อมาจาก DNS, DHCP และ IPAM (IP Address Management) — บริการหลัก 3 อย่างที่ทำหน้าที่กำหนดและแปลง IP address ทุกตัวในเครือข่าย DDI Platform รวมทั้ง 3 บริการนี้ให้บริหารจากที่เดียว แทนการใช้เครื่องมือแยกกัน 3 ชุด
Themelio คือ DDI platform แบบ self-hosted ที่รวม DNS, DHCP และ IPAM ไว้ในคอนโซลเดียว ทำงานภายในเครือข่ายขององค์กรเอง ไม่พึ่ง cloud ไม่มี call-home ใช้ perpetual license และขยายด้วยการเพิ่ม node — ตั้งแต่ node เดียวสำหรับสาขา ไปจนถึง grid แบบ high availability หลายไซต์
Perpetual license คือซื้อขาดเป็นเจ้าของสิทธิ์ถาวร ไม่คิดค่าใช้ตามจำนวน query หรือรายเดือน ต่างจาก DDI แบบ cloud/metered ที่ค่าใช้จ่ายเพิ่มตามขนาดเครือข่าย Themelio คิดตาม node ทำให้ต้นทุนคงที่และคาดการณ์ได้ ไม่มี per-query tax และไม่ผูกขาดกับ cloud
Themelio รองรับ DNSSEC (เซ็นและตรวจสอบ zone อัตโนมัติ + key rollover), RPZ DNS firewall (บล็อกโดเมนอันตราย), Response Rate Limiting กัน amplification/abuse, ACLs และ secure zone transfer (TSIG) พร้อมเข้ารหัส TLS 1.2+ ทุก interface และ AES-256 สำหรับ secret ที่ rest
รองรับเต็มที่ — Themelio ทำงานบน Linux (VM หรือ bare metal), VMware/Proxmox/Hyper-V และใช้งานแบบ offline/air-gap ได้ ไม่ต้องต่อ internet มีเครื่องมือ sync/import กับ Microsoft DNS/DHCP และ import zone/scope แบบ preview จึงย้ายจากระบบเดิม (เช่น Infoblox, BlueCat) ได้ราบรื่น
node เดียวรองรับได้ถึง 100,000 DNS queries/sec และ 850 DHCP leases/sec (ผลทดสอบ benchmark) พร้อม automatic HA failover ภายใน 60 วินาที ด้วย management แบบ active/standby + database replication และ DHCP แบบ load-balanced ขยายเพิ่มได้ด้วยการเพิ่ม DNS/DHCP node แยกใน grid แบบ Standard หรือ Enterprise
Bring DNS, DHCP and IPAM together on infrastructure you own — perpetual, on-premise and audit-ready. Our engineers will scope, migrate and support your DDI end to end.