Zenarmor – Next-generation features for your OPNsense firewall
As an open-source firewall, OPNsense is solid, but without an additional module, it lacks the application-based deep analysis of modern NGFW systems. Zenarmor closes exactly this gap: Deep Packet Inspection, application recognition, and granular policies – even for encrypted traffic.

What is Zenarmor?
Zenarmor is an NGFW plugin for OPNsense that uses Deep Packet Inspection (DPI) to analyze all network traffic at the application level – even within TLS-encrypted connections. Instead of just filtering ports and IP addresses, Zenarmor recognizes thousands of individual applications (e.g., specific cloud services, messengers, or streaming platforms) and allows granular policies based on them per user, group, or time window.
This gives companies that prefer a flexible solution over a fixed manufacturer solution a comparably strong level of protection as with a Sophos XGS – usually more cost-effectively and with more freedom in configuration.

OPNsense + Zenarmor or Sophos XGS Xstream?
Modular & cost-efficient
Integrated & from a single source
Overview of Zenarmor Editions
Important for corporate use: According to the manufacturer, the free Free and Home editions are expressly licensed only for private, non-commercial use. For companies, we generally recommend one of the commercial editions.
For private users
Basic monitoring and control. Not intended for companies according to license terms – not the right choice for your business operations.
Our standard recommendation for SMEs
Application control, TLS inspection, protection against malware/phishing/botnets, and centralized reporting – the setup we configure for most customers.
For multiple locations & Zero Trust
Full SASE/Zero Trust package including secure remote access to internal applications – useful for growing companies with multiple locations or a lot of home office work.
From a pure port firewall to application-aware OPNsense
A typical case for Zenarmor: A company with an existing OPNsense firewall could filter ports and IP ranges, but could not identify which specific cloud services or applications were causing the most traffic. After setting up Zenarmor (Business NGFW Edition), applications are individually visible and controllable, TLS traffic is inspected, and anomalies are reported centrally – without the need for a new hardware appliance. We handle setup, rule maintenance, and ongoing monitoring.
