Firewalls and network security
Open-source firewalls, built and operated by a listed partner of the manufacturers.

Open-source firewalls have a reputation for being cheap. Their real advantage is a different one: they do not tie you down. No per-user subscription, no feature that moves behind a higher licence tier after you have bought it, no hardware that becomes worthless when support ends. What you need instead is someone who genuinely knows the platform – because here, experience replaces the vendor support that comes bundled with commercial appliances.
Where we are listed
- Netgate – Authorized Partner with MSP status, for pfSense Plus and pfSense CE. Listed in the Partner Locator (opens in a new tab) under Munich.
- Deciso – Authorized Partner, for OPNsense and OPNsense Business Edition. Listed under Where to buy (opens in a new tab).
- Zenarmor – in the global partner directory (opens in a new tab), for Zenarmor NGFW, Secure Web Gateway and SSE.
You can check all three listings on the manufacturers’ own sites. They oblige us to no sales volumes: whether pfSense, OPNsense or a commercial platform is the right choice depends on your requirements.
pfSense or OPNsense
Both descend from the same ancestor and do the same basic work: packet filtering, NAT, VPN, high availability. The differences lie in operations.
pfSense is more widely used in German-speaking countries, has the larger knowledge base, and has Netgate behind it – a hardware manufacturer whose appliances are tuned to the software. That makes procurement and replacement easier.
OPNsense ships on a fixed twice-yearly rhythm, has a tidier interface and a stricter separation between core and add-on packages. Teams planning to run much of it themselves often get on better with it.
We run both in production. Which platform it becomes is decided after the assessment, not before.
Zenarmor as the next-generation layer
A classic packet filter sees addresses and ports. What it does not see: which application sits behind a connection, whether a session is reaching a known command server, what content flows through an encrypted channel. That is exactly what Zenarmor adds – application awareness, content filtering, reporting per user and device.
The difference from a commercial next-generation firewall lies less in the features than in the model: you keep control of the platform, and costs stay predictable.
Typical engagements
Replacing appliances at end of support, segmenting flat networks, site-to-site links over IPsec or WireGuard, high-availability pairs, introducing application awareness and content filtering, cleaning up and documenting rule sets, co-managed operations.
At a laboratory services provider in Bavaria we moved the network architecture across twelve sites to pfSense; at a manufacturer of industrial components in Baden-Württemberg, OPNsense with Zenarmor runs under a managed model.
Frequently asked questions
How long does a pfSense migration take?
For a straightforward installation with one WAN and few rules, two to four hours in total, of which 15 to 30 minutes is actual downtime. A typical mid-sized setup with VLANs, several networks, DHCP and VPN comes to four to seven hours. Add multi-WAN, several VPN links, IDS/IPS, a proxy or VoIP and we plan for a full working day. For high-availability pairs in critical environments, one to three days of planning and testing is appropriate; the switchover itself then often takes only minutes.
The time rarely goes into importing the configuration – that takes minutes. It goes into the assessment, mapping the interfaces, and testing what is business-critical: telephony, Microsoft 365, remote access, ERP, site-to-site links.
What happens to our existing rules?
They are not lost. pfSense keeps the entire configuration in a single XML file: firewall and NAT rules, aliases, VLANs, DHCP and DNS, VPN connections, certificates. A full backup can be restored onto the new appliance.
What has to be checked are differences in interfaces, network card drivers, hardware and version levels – we do that before the switchover, not after. The old firewall stays unchanged and ready to be cabled back in as a fallback.
Which appliance do we need?
That depends on throughput, the number of networks, and what the firewall is meant to do beyond packet filtering. Four size classes from the Netgate range with pfSense Plus:
A home office or small site with few devices is served by the entry-level model. A small office with gigabit connectivity, VLANs and VPN links sits one class above. More demanding sites with several uplinks, many tunnels and application awareness need the mid range. Data centres and high-availability pairs call for the larger models.
We quote prices with the offer, alongside the setup effort – hardware prices change, and a figure on a website dates quickly. What the setup costs depends on scope; see the question on migration time.