OPNSENSE + ZENARMOR

Zenarmor – Next-generation features for your OPNsense firewall

As an open-source firewall, OPNsense is solid, but without an additional module, it lacks the application-based deep analysis of modern NGFW systems. Zenarmor closes exactly this gap: Deep Packet Inspection, application recognition, and granular policies – even for encrypted traffic.

KEY POINTS
DPI analysis of web traffic
Even within encrypted connections.
Thousands of applications recognizable
Instead of just filtering ports and IP addresses.
Rules per user, group, time
Granular control instead of all-or-nothing.
Business NGFW recommended for SMEs
Free/Home are not licensed for corporate use.
No vendor lock-in
Full freedom of configuration on an open-source basis.

What is Zenarmor?

Zenarmor is an NGFW plugin for OPNsense that uses Deep Packet Inspection (DPI) to analyze all network traffic at the application level – even within TLS-encrypted connections. Instead of just filtering ports and IP addresses, Zenarmor recognizes thousands of individual applications (e.g., specific cloud services, messengers, or streaming platforms) and allows granular policies based on them per user, group, or time window.

This gives companies that prefer a flexible solution over a fixed manufacturer solution a comparably strong level of protection as with a Sophos XGS – usually more cost-effectively and with more freedom in configuration.

Extended Info: Setting up Zenarmor on OPNsense (Security-Insider Tool Tip, Video)

OPNsense + Zenarmor or Sophos XGS Xstream?

OPNSENSE + ZENARMOR

Modular & cost-efficient

Open-source basis without basic license costs
Zenarmor as an add-on NGFW module
Full freedom of configuration, individually adapted
We set it up and provide ongoing support
SOPHOS XGS XSTREAM

Integrated & from a single source

DPI integrated directly into the hardware appliance
One manufacturer for firewall, support, and updates
Centralized management via Sophos Central
Established enterprise support network

Overview of Zenarmor Editions

Important for corporate use: According to the manufacturer, the free Free and Home editions are expressly licensed only for private, non-commercial use. For companies, we generally recommend one of the commercial editions.

FREE / HOME

For private users

Basic monitoring and control. Not intended for companies according to license terms – not the right choice for your business operations.

BUSINESS NGFW

Our standard recommendation for SMEs

Application control, TLS inspection, protection against malware/phishing/botnets, and centralized reporting – the setup we configure for most customers.

SASE

For multiple locations & Zero Trust

Full SASE/Zero Trust package including secure remote access to internal applications – useful for growing companies with multiple locations or a lot of home office work.

TYPICAL DEPLOYMENT SCENARIO
ENGINEERING OFFICE · MULTIPLE LOCATIONS

From a pure port firewall to application-aware OPNsense

A typical case for Zenarmor: A company with an existing OPNsense firewall could filter ports and IP ranges, but could not identify which specific cloud services or applications were causing the most traffic. After setting up Zenarmor (Business NGFW Edition), applications are individually visible and controllable, TLS traffic is inspected, and anomalies are reported centrally – without the need for a new hardware appliance. We handle setup, rule maintenance, and ongoing monitoring.

Does Zenarmor fit your infrastructure? Let's check it together.
Get in touch
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.