Themelio consolidates your organization's core network services into a single, centrally managed console — reliable, secure and fully auditable. Deploy one all-in-one appliance for a growing SME, or a high-availability grid across enterprise sites.
DDI stands for DNS, DHCP and IPAM — the three core network services that assign and resolve every IP address on a network, managed together from one platform instead of three separate tools.
Resolves human-readable names to IP addresses. A DDI platform manages authoritative and recursive zones, records, split-horizon views and DNSSEC signing from one console.
Hands out IP addresses and network settings automatically as devices join. DDI covers IPv4 and IPv6 subnets, pools, reservations, client classes and live leases.
Plans and tracks the address space itself — a hierarchical inventory of every subnet and address, reconciled against what DNS and DHCP are actually serving.
Run separately, these three drift apart: a record is updated in one tool, a lease in another, and a spreadsheet records something else again. A DDI platform keeps them in a single database, so every IP address has one correlated record — its hostname, its lease and its owner. See how Themelio does it.
When core network services are managed in disconnected tools, routine changes become a leading cause of outages and audit gaps.
A single platform for every core network service — without the cost and complexity of legacy DDI suites.
DNS, DHCP & IPAM in one console — every IP correlated with its record, lease and device.
Validated changes, automatic rollback, DHCP HA, manager HA and encrypted backup / restore.
Role-based access, MFA and a complete audit trail — enforced at the API layer, on your infrastructure.
Reservation workflows, discovery, REST API and infrastructure-as-code that fit your pipelines.
Start with one appliance; grow to distributed DNS/DHCP nodes under one management grid.
Ask your network in plain language over an on-prem MCP server — read-only by default, every call audited.
RPZ firewall, DGA & tunneling detection, encrypted DNS transport and offline threat-feed packs.
Top talkers, top domains and custom dashboards, with scheduled reports your auditor can read.
Your data stays in-house. Air-gap friendly, no internet call-home — ever.
Built for growing networks
One platform across the whole range — the same console whether you run a single appliance or a multi-site grid.
The same interface your team uses to run DNS, DHCP and IPAM across every site.





Prefer to just look? Open the full-size preview — all five screens as images.
Run every core service on a single appliance, or deploy a redundant cluster for zero-downtime operations and higher throughput.
A single virtual appliance runs DNS, DHCP, IPAM and NTP together — the simplest, fastest way to get network services live.
Manager active-standby behind a virtual IP with streaming replication, plus DHCP HA pairs and distributed DNS nodes across sites.
A single manager drives serving nodes across sites over mutually-authenticated TLS. Nodes keep answering even when the manager is offline.
Several DNS nodes announce the same service IP over BGP/FRR. Clients reach the closest node, and a node withdraws its route the moment named goes unhealthy.
All-in-one node running manager + DNS + DHCP + IPAM. Simple to run, easy to back up.
Manager plus DNS primary/secondary and a DHCP HA pair — resilient without complexity.
Manager HA pair, recursive + authoritative DNS tiers and DHCP HA per site, centrally governed.
Measured results from sustained load testing of a single standalone node running DNS, DHCP, IPAM and management together on the stated virtual-machine profile. Choose a tier by your peak query and lease rates, and treat these as the starting point for your own capacity test.
| Tier | vCPU | RAM | System disk* | NIC | DNS throughput | DHCP throughput | Typical use |
|---|---|---|---|---|---|---|---|
| Small | 4 | 8 GB | 100 GB SSD | 1 GbE | 30,000 QPS | 500 leases/s | Branch / small campus |
| Medium | 8 | 16 GB | 200 GB SSD | 1 GbE | 65,000 QPS | 750 leases/s | Campus / department |
| Large | 16 | 32 GB | 400 GB SSD | 10 GbE | 110,000 QPS | 1,000 leases/s | Data center / core site |
Swipe the table sideways to see every column
On-premise by design. No internet call-home — ever. Your network data stays in-house.
Role-based access control with TOTP multi-factor authentication for every operator.
Every change logged with old → new values, searchable and exportable.
Pre-hardened Linux image for VMware, Proxmox, Hyper-V or KVM — no proprietary box, no hardware refresh. Air-gap capable.
Manager HA, DHCP HA and encrypted backup / restore with DR support.
Built for regulated environments — controls, retention and cryptography that an auditor can verify.
Access control, logging, configuration management, backup and cryptography controls.
Data stays on-premise, with retention policy, access audit and ROPA templates.
Signing and validation to current standards, for signed-domain mandates.
Full dual-stack across DNS, DHCP and IPAM — not a bolt-on.
Operating-system and platform hardening guide with a self-assessment.
Long-term, tamper-evident log retention with integrity manifests.
The same platform, sized and governed differently for each environment.
Compared by product category rather than by brand. This is positioning, not a feature-by-feature audit — evaluate any shortlist against your own requirements.
| Capability | ThemelioOn-prem DDI software | Commercial DDI applianceSubscription vendors, appliance + cloud | OS-bundled DNS/DHCPShipped with the server operating system |
|---|---|---|---|
| Delivery model | On-prem software | Appliance + cloud | Bundled with the OS |
| Unified DNS + DHCP + IPAM | Partial | ||
| Licensing | Perpetual + maintenance | Subscription | OS licence / CAL |
| 100% on-prem, no call-home | Varies by vendor | ||
| Validate & roll back changes | Limited | ||
| REST API & infrastructure-as-code | Limited | ||
| Air-gap / offline activation | Varies by vendor |
Swipe the table sideways to see every column
Categories describe how each class of product is typically delivered and licensed. Individual products within a category differ — confirm the details with any vendor you shortlist.
A perpetual, host-based license — buy once, add annual maintenance. Node count is a separate axis: choose any edition with 1 to N nodes.
| Capability | Basic | Pro | Enterprise | Free Trial |
|---|---|---|---|---|
| Core — included in every edition | ||||
| DNS — authoritative & recursive, views, DNSSEC, AXFR/TSIG, DDNS | ||||
| DHCP — scopes, pools, reservations, options, client classes | ||||
| DHCP HA — hot-standby & load-balancing | ||||
| DHCPv6 + prefix delegation | ||||
| IPAM — unified IP ↔ DNS ↔ DHCP ↔ MAC, discovery, VRF | ||||
| Device recognition — fingerprint & device icons | ||||
| Central management + RBAC + MFA + audit trail | ||||
| Dashboards + Prometheus metrics | ||||
| SNMP monitoring (v2c/v3) | ||||
| Backup / restore (encrypted) + DR | ||||
| In-place upgrade from the console | ||||
| Report Center — standard service & audit reports | ||||
| Compliance pack — ISO 27001 / CIS self-assessment | Limited | |||
| Scale & integrate — Pro and above | ||||
| SIEM export | 1 destination | Multi + HEC/LEEF/ECS | Multi + HEC/LEEF/ECS | |
| Lease history & retention | 90 days | 180 days | Up to 730 days | 30 days |
| Manager HA — active/standby | ||||
| REST API + API token | ||||
| Terraform provider + Ansible collection | ||||
| Microsoft DNS / DHCP sync | ||||
| Query analytics — top talkers, domains, custom dashboards | ||||
| Scheduled reports by email | ||||
| Secure & govern — Enterprise | ||||
| RPZ / DNS firewall | ||||
| DGA & DNS-tunneling anomaly detection | ||||
| DoT / DoH — encrypted DNS transport | ||||
| Threat-feed data pack (Subscription Add-Ons) | ||||
| AI assistant over MCP — read-only, audited | ||||
| Multi-tenancy / delegated administration | ||||
| Commercials | ||||
| Nodes | Buy 1..N | Buy 1..N | Buy 1..N | 4 (default) |
| Support | Standard | Priority | Premium (top SLA) | Community |
Everything you need to know about running Themelio on your own infrastructure.