Zedmos

Zedmos NGFW

A next-generation firewall, built and run on your terms

Zedmos NGFW is a complete firewall: our own FreeBSD-based operating system, an inline inspection engine attached straight to the interfaces, and a policy model that decides once per session. Installed from an image onto hardware you choose.

Load, memory, disk and uptime beside the state of the engine services and the cloud link, with live throughput, a per-interface traffic graph and the top applications, remote hosts and devices.
The appliance at a glanceZedmOS · Dashboard
ZedmOSone imageRouting & NATIPsecWireGuardOpenVPNGREDHCP & DNSApp controlIDS / IPSTLS inspectionQUIC · DoT · DoHDLPAI gatewayFile scanningThreat intelDevice identity16 actionsSD-WANApp routingPrivate accessSIEM exportREST APIReports
  • Firewall platform
  • Inspection engine
  • Connectivity
  • Operations
Three planes · one of them leaves the buildingManagement plane · your serverZero Trust Consolea container, under your domainHoldstenancy treepolicy setscounters & reportsCustomer data stays hereconfiguration downcounters upthe only traffic between the two · no payloadAppliance · OPNsense, pfSense CE or Zedmos hardwareControl plane · one pipeline, one verdictIdentityApplicationCategoryReputationContentVerdictallow · shape · quarantine · stopConsole unreachable? The firewall keeps enforcing the policy it has.Data plane · at the interfacesLANigc0Fast pathclassify · inspect · enforce, in lineWANigc1no proxy host, no second appliance in the path

What Zedmos does to your traffic

The complete firewall, with the same engine and the same policy model as the plugin — on an operating system we maintain, installed from one image.

Live sessions on the firewall itself: a table of flows with start and end time, device, device category, protocol, both addresses and ports, application category and application, above tabs for threats, blocks, web traffic, DNS, TLS, antivirus and AI activity.
  1. Is it dangerous?

    Threats, blocks and antivirus findings for the same traffic, one tab away — signatures and intelligence applied before the session was allowed to continue.

  2. What is it carrying?

    Web requests, DNS queries and TLS sessions of the same flows, each on its own tab — including what was inspected inside an encrypted connection.

  3. What is it?

    Each flow carries the application the engine identified and the category it belongs to — classified by what crosses the wire, not by the port it used.

  4. Whose is it?

    The device and its category sit on the same row as the flow, with the hardware address beside them, so a policy can name a person or a group instead of an address.

Every column here was decided on the appliance, by the appliance. Nothing left it to reach the verdict.ZedmOS · Live Sessions

The capabilities it adds

Grouped by the question each one answers. The same set on OPNsense, on pfSense and on Zedmos NGFW — one engine, one policy model, three ways to run it. Each has a fuller technical write-up under Resources.

What is this traffic, really?

Recognises applications, not ports200+

Almost everything is HTTPS on 443, so a port-based rule can only permit or deny all of it.

TLS inspection, applied selectively

Bump what you choose to; leave banking and health traffic alone by rule.

Client fingerprinting

JA3, JA4 and ALPN identify the software behind a session even when it is not decrypted.

QUIC and HTTP/3

The protocol most of the web moved to, seen and controlled rather than left as a gap.

DNS over TLS and over HTTPS

Encrypted resolution routes around a classic firewall's name-based rules. Not around this one.

Live sessions, with the reason

Every flow on screen as it happens, carrying the decision and what drove it.

The application-control tab: a searchable catalogue of applications and categories, each with the action the policy takes on it.
Applications and categories are chosen from the classifier's own catalogue, not typed as ports.Zedmos · Policies · App Controls

Should it be allowed through?

Intrusion detection and prevention

Signatures evaluated inline on the same appliance — a match is a block, not a morning alert.

Threat intelligence, shipped daily26

Indicators gathered and cross-checked, then pushed to every firewall you manage.

Files scanned in flight

Attachments and downloads examined before they land, not after.

Sixteen things a rule can do16

Allow, log, rate-limit, quarantine, reset, drop — and the rest, on both platforms.

The intrusion detection and prevention tab: rule sources, the action taken on a match, and the severity threshold that governs it.
Detection and prevention are one setting per policy group, not a separate product bolted alongside.Zedmos · Policies · IDS/IPS

What are people typing into AI?

The shadow-AI inventory

Which assistants are in use and by whom — answered without reading a single prompt.

Prompts checked before they leave

Source code, credentials and regulated data caught on the way out, not in a breach report.

The verdict is reached on your premises

Deterministic matchers plus a local model. Sending content away to ask whether it may be sent is a contradiction.

Three postures, one engine

Watch and record; strip the sensitive part and redirect; or block outright. The rule's action verb is the only change.

Every assistant, including yours

ChatGPT, Claude, Gemini, Copilot, Perplexity, Mistral — and an in-house endpoint you declare yourself.

The AI gateway tab: the assistants recognised, what is inspected in a prompt, and what happens when a detector matches.
The assistants are listed by name, and the verdict is reached by a model running on your own hardware.Zedmos · Policies · AI Gateway

Is an agent acting on its own?

Who is really at the keyboard

Browser, SDK or script, autonomous agent, MCP client, or none of these — every request is placed in a class before an action is chosen.

Classified from what it sends

The user agent, the shape of the request envelope and the address it is posted to — a raw API endpoint and a chat surface are told apart.

Tool calls are their own decision

A request carrying tool definitions, calls or results is what turns an assistant into something that acts. It can be allowed, recorded or refused on that ground alone.

Unsanctioned providers, reached by script

Programmatic access to a provider nobody approved is its own case, separate from someone opening the same site in a browser.

Marked, not silently dropped

Marking forwards the request and records it with a reason and a sensitivity class on the AI activity page — so a class can be watched for a week before anyone decides to block it.

The AI agents tab: an action for each client class — browser, SDK or script, autonomous agent, MCP client and unknown — with separate dispositions for requests carrying tool calls and for programmatic access to an unsanctioned provider.
A person typing into a chat window and a script driving the same provider are not the same event, and they no longer get the same answer.Zedmos · Policies · AI Agents

Is confidential data leaving?

Detectors you switch on deliberately61

Card numbers, secrets, health and financial data, and national identity formats for twenty-two countries.

Uploads and messages both

A file attached to a web form and a paragraph pasted into a chat are the same risk.

A block you can defend

The record names the rule, what was detected and where — without keeping the content itself.

Fail closed where it matters

A control that lets traffic past when it cannot evaluate it is not a control on the path that matters.

The data-loss tab: the detector library grouped by family, with a checksum marker on the ones that validate what they match.
Sixty-one detectors, switched on deliberately rather than all at once; a checksum keeps the false positives down.Zedmos · Policies · DLP

Who and what is on the network?

Devices are recognised — and assessed

A managed laptop and a personal phone share a subnet and look identical to an address rule. For an enrolled remote device, your own Intune or CrowdStrike says whether it is healthy.

Users and groups from your directory

Active Directory, Entra ID or SCIM — and, for a remote person, your own OpenID Connect provider at enrolment. An entitlement follows the person, not their DHCP lease.

Quarantine without cutting off

A device restricted to what it needs to be fixed is a device you can still fix.

Policy by zone and schedule

Different rules for a guest network, a server segment, and outside business hours.

The device inventory: what each device is, the category it was placed in, and the identity attached to it.
A policy can name a person or a device class here, and keep meaning the same thing after the address changes.Zedmos · Devices

Where should it go, and what happened?

Each flow out the right link

Scored on loss, latency and jitter — a link that is up and losing packets is not a healthy link.

Encrypted overlay between sites

WireGuard, OpenVPN or GRE in four shapes — one hub, a hub pair, direct tunnels between spokes, full mesh — provisioned from one topology view rather than hand-built per firewall.

Rules change without a restart

A policy edit takes effect without dropping a packet or interrupting a session.

A feed your SOC already reads

Reports and live sessions on screen, and CEF, LEEF or syslog over TLS to whatever you run.

The application-routing tab: which application or category leaves by which egress, with the fallback when that egress is down.
Egress is chosen per policy — a second WAN, a tunnel or a plain interface — and falls back on its own.Zedmos · Policies · Application Routing

What is shipping now

Taken from the package repositories rather than typed into this page, so it does not drift the way a hand-written version string does.

Zedmos for OPNsensePlugin, from the package repository
26.10.1_101
Zedmos for pfSensePlugin, from the package repository
26.10.1_101
Zero Trust ConsoleSelf-hosted, installed by you
1.3.0

The console and the firewall are released on their own schedules, so their numbers do not track each other. Which version each of your firewalls is running is in your console.

200+
Protocols classified
26
Threat categories
16
Policy actions

The appliance at a glance

Dashboard · 1 of 11

The appliance at a glance — Load, memory, disk and uptime beside the state of the engine services and the cloud link, with live throughput, a per-interface traffic graph and the top applications, remote hosts and devices.

Load, memory, disk and uptime beside the state of the engine services and the cloud link, with live throughput, a per-interface traffic graph and the top applications, remote hosts and devices.

How it behaves in the path

Inspection that runs on the box

Traffic is classified, inspected and decided on the same appliance that routes it. No packet, no payload and no session record is sent to Zedmos.

One policy model

Applications, categories, domains, users, groups, devices and zones select traffic; sixteen actions decide what happens to it. The same model on both platforms.

Encrypted traffic, handled honestly

TLS inspection with fingerprinting and selective bumping, plus visibility and control over QUIC, DNS-over-TLS and DNS-over-HTTPS.

Replacing something already in the rack

One page per incumbent, built from that vendor’s own documents and public records — licensing, lifecycle, management, jurisdiction and exploit history, each row with its source.

Questions and answers

What is Zedmos NGFW?

A complete next-generation firewall: ZedmOS, a FreeBSD-based operating system, the Zedmos inline inspection engine attached directly to the interfaces, and a policy model that decides once per session. It is installed from an image onto x86 hardware you choose.

Does Zedmos NGFW send my traffic to a cloud for inspection?

No. Traffic is classified, inspected and decided on the appliance that routes it. No packet, payload or session record is sent to Zedmos. The console distributes policy and collects records; it is not in the packet path.

Which inspection features does Zedmos NGFW include?

Classification across more than 200 protocols, intrusion detection and prevention reading the Suricata rules format, TLS inspection with JA3/JA4 fingerprinting and selective decryption, control over QUIC, DNS-over-TLS and DNS-over-HTTPS, data loss prevention with 69 detectors, an AI gateway, per-application routing across uplinks, and WireGuard, OpenVPN and GRE overlays. One policy model with 16 actions and 26 threat categories.

How is Zedmos NGFW licensed?

Per firewall, with no hardware in the licence. Three tiers: Free (three firewalls for thirty days), Team (per firewall) and MSP (multi-tenant, unlimited firewalls, billed monthly in arrears). Prices are quoted on request. A lapsed licence makes the console read-only and never stops the firewall.

How does Zedmos compare with Fortinet, Sophos or Palo Alto Networks?

Zedmos is software on hardware you own rather than an appliance with a subscription bundle; management is self-hosted or hosted in Frankfurt rather than in a vendor cloud; the vendor is German and answers under EU law; and the exploit record is published: zero entries in the CISA Known Exploited Vulnerabilities catalogue. The comparison pages set each vendor's own documents beside Zedmos, with a source for every row.

Can I evaluate Zedmos without replacing my firewall?

Yes. The same engine installs as a package on an OPNsense or pfSense CE box you already run. Existing rules, interfaces, NAT and VPNs are untouched, and it uninstalls from the settings page in one step.