Layer 7 application control, TLS inspection, and real-time cloud-delivered threat intelligence that installs in minutes on OPNsense, turning it into an enterprise security powerhouse.
Start Your Free TrialFree tier available. Most teams are filtering Layer 7 traffic the same day.
From traditional commercial appliances, to the open-source firewalls many teams have migrated to, to the modern NGFW layer that brings them up to today's standard.
Fortinet, Cisco, SonicWall, consumer routers
A modern, open-source firewall
The full modern NGFW stack
✓ Full · △ Possible with DIY effort · ✕ Not available
Enterprise-grade next-gen firewall capability, deployed in minutes. No new hardware. No rip-and-replace.
Deep packet inspection that sees inside encrypted traffic. Identify and control thousands of applications and protocols, even when they ride on port 443. Certificate-based or full TLS inspection catches malware and evasive threats other firewalls miss.

Allow Microsoft 365 but block consumer Dropbox. Throttle streaming on guest VLANs. Per-user, per-group, per-app policy.

Live feeds for malicious IPs, domains, phishing, C2, and crypto-jackers. Everything is updated continuously, no manual rules.

120+ URL categories, SafeSearch enforcement, and policy-based filtering across 300M+ sites. A perfect fit for K-12, healthcare, MSP, and enterprise alike.

* Basic TLS Inspection is included. Full TLS Inspection requires an SSE license.
One site or fifty branches? Easily manage policy, view live traffic, and run forensics from a single Zenconsole. Real-time dashboards. Per-user reports. Exportable for audit and compliance.
Push consistent rules to every node, OPNsense or otherwise, from one console.
See top apps, users, threats, and bandwidth in real time.
PDF and CSV exports for compliance, ops review, and customer billing.
"For our teams, it's reassurance that we are running a system that is as secure as we can make it. Handling sensitive data requires us to use the highest grade software and devices available."
— Darren Yeates, Vice-chair and Technology Officer, Lowland Rescue Search Dogs Sussex
Recognized By
TMCnet Zero Trust Security Excellence Award
“Vendor to Watch” in Network Security
2026 Finalist — Best SASE Solution
Network Computing Awards 2026 FinalistWhat OPNsense teams are saying
"Many organizations struggle to introduce modern security capabilities without disrupting existing network deployments."
"As an organization in the health industry, securing our network is not just best practice; it's a necessity."
"The system integration with Zenarmor has allowed 5th Mountain to compete for and win the business of large network providers."
Yes. Zenarmor Free Edition is available at no cost for home labs and small networks, with core app control and basic filtering included.
Zenarmor is engineered for line-rate inspection on modest hardware. Sizing guidance is published for everything from a Protectli to multi-Gbps appliances.
Zenarmor installs as a one-command plugin on current OPNsense stable releases, and is also supported on a range of other deployment targets including bare-metal Linux, virtual machines, and cloud workloads.
Zenarmor supersedes most DIY stacks with a single integrated engine: L7 app control, threat intel, content filtering, and reporting, all managed from one UI.
Yes. Zenconsole lets you push policy, view analytics, and run reports across every connected node from one place, whether you have one site or fifty.
Install takes minutes on OPNsense or your platform of choice. Free tier available.
Start Your Free Trial