Firewalls and network security

Open-source firewalls, built and operated by a listed partner of the manufacturers.

Server cabinets in a darkened data centre, densely routed orange and turquoise patch cables between green status lights

Open-source firewalls have a reputation for being cheap. Their real advantage is a different one: they do not tie you down. No per-user subscription, no feature that moves behind a higher licence tier after you have bought it, no hardware that becomes worthless when support ends. What you need instead is someone who genuinely knows the platform – because here, experience replaces the vendor support that comes bundled with commercial appliances.

Where we are listed

These listings can be verified on the manufacturers’ own sites. They oblige us to no sales volumes: whether pfSense, OPNsense or a commercial platform is the right choice depends on your requirements.

pfSense or OPNsense

Both descend from the same ancestor and do the same basic work: packet filtering, NAT, VPN, high availability. The differences lie in operations.

pfSense is more widely used in German-speaking countries, has the larger knowledge base, and has Netgate behind it – a hardware manufacturer whose appliances are tuned to the software. That makes procurement and replacement easier.

OPNsense ships on a fixed twice-yearly rhythm, has a tidier interface and a stricter separation between core and add-on packages. Teams planning to run much of it themselves often get on better with it.

We run both in production. Which platform it becomes is decided after the assessment, not before.

Zenarmor as the next-generation layer

A classic packet filter sees addresses and ports. What it does not see: which application sits behind a connection, whether a session is reaching a known command server, what content flows through an encrypted channel. That is exactly what Zenarmor adds – application awareness, content filtering, reporting per user and device.

The difference from a commercial next-generation firewall lies less in the features than in the model: you keep control of the platform, and costs stay predictable.

Typical engagements

Replacing appliances at end of support, segmenting flat networks, site-to-site links over IPsec or WireGuard, high-availability pairs, introducing application awareness and content filtering, cleaning up and documenting rule sets, co-managed operations.

At a laboratory services provider in Bavaria we moved the network architecture across twelve sites to pfSense; at a manufacturer of industrial components in Baden-Württemberg, OPNsense with Zenarmor runs under a managed model.

Discuss your firewall project See our projects