Software
Expanse Network Stack
Modular command-line utilities for network communication across unidirectional data diode links. TCP bridging, reliable file transfer, and custom pipelines for Expanse deployments.
Sender side
cat filelist.txt | ens-file-reader | ens-pitcher --udp-target-address 10.10.1.2Receiver side
ens-catcher --udp-listen-port 8080 | ens-reorderer | ens-file-writerOverview
Protocol bridging for one-way links
Traditional protocols like TCP require bidirectional communication: the three-way handshake, acknowledgments, and flow control all depend on a return path. Data diodes physically prevent that. Without specialized software, their use is severely limited.
ENS bridges that gap. A collection of modular, interoperable utilities you chain together with standard Unix pipes, building custom data flow pipelines tailored to your deployment, from simple syslog forwarding to complex TCP session bridging.
Tool Suite
Three categories, one pipeline
Every ENS tool fits into Sources, Sinks, or Manipulators. Compose them into pipelines for any unidirectional data flow.
Sources
Convert raw data into ENS packets
- ens-stdin
- ens-file-reader
- ens-tcp-server
- ens-http-server
Sinks
Reconstruct ENS packets into usable data
- ens-stdout
- ens-file-writer
- ens-tcp-client
- ens-http-client
Manipulators
Optimize and process packet streams
- ens-buffer
- ens-reorderer
- ens-rate-limiter
- ens-error-on-dropped-packets
Network I/O
UDP transmission across the diode
- ens-pitcher (send)
- ens-catcher (receive)
Capabilities
Everything you need across the diode
TCP Bridging
Bridge TCP applications across unidirectional links. ens-tcp-server and ens-tcp-client maintain session traffic without requiring bidirectional handshakes on the diode.
Modular Pipelines
Chain tools with Unix pipes to build exactly the data flow your application needs. Born from GNURadio-style modularity with SDR-world terminology.
Packet Reordering
Automatic out-of-order packet handling via ens-reorderer. Essential when using UDP across diode links where packets may arrive out of sequence.
Reliable File Transfer
Drop-box file transfer with ens-file-reader and ens-file-writer. Forward error correction and retransmission reduce or eliminate packet loss.
Rate Limiting & Buffering
Control transmission rates and buffer data for performance. Prevent overwhelming receivers that cannot communicate back across the diode.
For Expanse Deployments
The complete toolkit for protocol bridging, file transfer, and custom pipelines across Expanse diode links — with no metered restrictions.
Pipelines
Typical deployment patterns
Compose sender and receiver pipelines independently. Each side mirrors the other's architecture.
Basic stream
Sender
ens-stdin | ens-pitcherReceiver
ens-catcher | ens-stdoutFile transfer
Sender
ens-file-reader | ens-pitcherReceiver
ens-catcher | ens-reorderer | ens-file-writerTCP bridge
Sender
ens-tcp-server | ens-pitcherReceiver
ens-catcher | ens-reorderer | ens-tcp-clientAdvanced
Sender
ens-tcp-server | ens-buffer | ens-rate-limiter | ens-pitcherReceiver
ens-catcher | ens-reorderer | ens-error-on-dropped-packets | ens-tcp-clientPacket Format
Custom ENS protocol
A purpose-built packet format with stream IDs, sequence numbers, and control flags, supporting multiple concurrent streams over a single diode link.
| Field | Size | Description |
|---|---|---|
| Magic | 3 bytes | Always "ENS" |
| Size | 2 bytes | Payload size |
| Flags | 2 bytes | EndOfStream, Error |
| Sequence | 4 bytes | Packet sequence within stream |
| Stream ID | 4 bytes | Unique stream identifier |
FAQ
Common questions
Is ENS included with Expanse hardware?
ENS is the software layer for Expanse deployments. Expanse Data Diode hardware enforces physical one-way flow; ENS adds TCP bridging, reliable file transfer, and composable pipelines across the link.
Do I need ENS for simple UDP protocols?
Not necessarily. Stateless UDP protocols like syslog, SNMP traps, and NetFlow can often be forwarded with standard Linux tools. ENS is designed for protocols requiring session management, reliable file transfer, or TCP bridging.
How does ENS differ from Lattice?
ENS is the modular toolkit of command-line utilities for building data flow pipelines. Lattice is the enterprise platform that orchestrates ENS tools, adds ticket-based file transfer with JWT authorization, and provides a web operations dashboard.
Where can I find documentation?
Licensed customers receive access to ENS documentation at docs.domainsystems.us, including quick-start guides, architecture patterns, performance tuning, and industry-specific deployment examples.
Hardware
Expanse Data Diode
Physical SFP+ modules that enforce one-way data flow. Pair with ENS for protocol bridging across the link.
Learn about ExpansePlatform
Lattice
Enterprise CDS software that orchestrates ENS pipelines, manages file transfers, and provides operator dashboards.
Learn about LatticeReady to build your first pipeline?
Contact our team for deployment guidance, architecture templates, and access to the full ENS documentation suite.