One engine. One pane.
Every network layer.
Zedmos is an inline security engine that fuses routing, encryption, and deep inspection into a single data plane. Installed as an OPNsense plugin, it integrates seamlessly into an existing appliance. Same policies, same data plane, same UI.
Every layer a modern firewall owes you — in one engine
Instead of stitching an IDS, a DPI layer, a TLS proxy, a content scanner, and a separate SASE overlay together, Zedmos ships one binary that runs every layer on the same zero-copy path.
- GAStateful packet inspectionIn-engine flow table
- GADeep packet inspection200+ protocols
- GATLS / SSL inspectionSNI · TLS fingerprinting · bump
- GAQUIC / DoT / DoH control
- GAIDS / IPSAho-Corasick binary rules
- GAApplication control
- GAURL / web filteringSuffix trie + TI feeds
- GAIdentity-aware policy (ZTNA)AD · Azure · SCIM
- GAEncrypted VPN overlayNative fast-path integration
- TestSD-WAN per-policy steeringSLA-aware failover
- TestCentralized SASE hub-spoke
- GAAnti-malware (inline)Streaming payload inspection
- GAThreat intelligence feedsIP · domain · URL · TLS fingerprint
- RoadmapWAF / reverse proxyDesign complete, shipping in a later release
- GAFile type / MIME filtering
- GACentralized mgmt (single pane)
- GASub-10 s failoverIn-process daemon
- GAHot-reload policies & feedsZero packet loss
- GASIEM / S3 / Kafka exportunified log plane
Run Zedmos on your hardware, or as a mesh you manage centrally
Same binary. Same policies. The only difference is where the packet path lives — on your own OPNsense box, or at distributed encrypted hubs that your spokes dial into.
Every packet stays on your box. No cloud dependency.
- Ships as a signed OPNsense module
- Monitor, bridge, or routed posture on your interfaces
- Local event store — data stays inside the perimeter
- Management UI served from the appliance itself
- Atomic policy and threat-intelligence hot-reload
Enforce the same policies at distributed hubs, centrally.
- Central orchestrator distributes policy and topology
- Spokes dial into the nearest hub over an encrypted overlay
- Zedmos engine enforces in-line at the hub
- Continuous sub-10-second failover between hub pairs
- Identity-aware access via Active Directory, Entra, and SCIM
Pick any block. It runs on the same pipeline.
Each capability below is a live feature of the engine, documented and deployable today. Click any card for the deep dive — architecture, config snippets, and benchmarks.
Shared-memory packet rings bypass the kernel socket path. ~14 Gbps on a single core.
SNI extraction, full client and server fingerprinting, forward-proxy bumping with a short-lived CA.
200+ application protocols, category pairs, encrypted traffic heuristics — all on the fast path.
allow / drop / reset / shape / redirect / quarantine / tarpit / scan / rewrite / exec / mark / escalate / route / log.
Route per app / category / SNI / user / geo. Strategy-pattern TX with SNAT and kernel FIB.
IP, domain, URL, and TLS-fingerprint blocklists. Suffix-trie matching. Atomic hot-swap via control socket.
AD DC agent, Azure Graph pull, SCIM hook, ARP/DHCP fingerprinting. Per-flow user tags.
ICMP / HTTP / DNS probes, composite health score, atomic peer swap. Hysteresis-aware.
SIGHUP and UNIX-socket commands swap policies, feeds, and routes with zero packet loss.
Protocol-aware payload reassembly across web, mail, and file-sharing traffic with content-type inference and per-flow deduplication.
Block or downgrade encrypted bypass paths per policy. 90% QUIC, 85% DoT effective.
Kernel driver patched so encrypted overlay peers can join the same fast path. Opt-in on bare-metal deployments; standard SASE still defaults to the kernel socket path.
Lock-free shared-memory ring into a dedicated writer daemon. File, syslog, SQLite, and Elasticsearch sinks today — with write-ahead log, circuit breaker, and adaptive sampling under load.
Intel 1/10 GbE multi-queue, NIC preflight, CPU affinity — 10× cache-miss reduction.