Zedmos

Next-generation firewall · Engineered in Germany

Turn OPNsense and pfSense into a next-generation firewall. Run every one of them from a console you host.

Application control, TLS inspection, IDS/IPS, DLP and AI governance in one engine — installed as a package on the OPNsense or pfSense CE boxes you already run, or from an image as ZedmosOS. Every firewall in one multi-tenant console on your server, or ours in Frankfurt. Under German and EU law.

Free tier: 3 firewalls for 30 days. After that read-only — never blocked. FreeBSD-based operating system · WireGuard and GRE in the engine · CycloneDX SBOM per release · EU Cyber Resilience Act · Self-hosted management

Zedmos Console — live sessions on a managed firewall
Live sessions · a managed firewallconsole.zedmos.com

Why switch

What changes when you leave an incumbent

Four reasons, each with its source. The full comparisons are a page each.

No hardware refresh clock

The market

Incumbent firewalls are sold as hardware plus an annual security bundle, on a five-year clock after which updates and support stop. Appliance prices rose 5–20 % at one vendor in March 2026 and 10 % at another in July.

Zedmos

Zedmos is software. It runs on x86 hardware you own, and the support period is the software's — published, at least five years, and independent of any box.

Source: Vendor earnings calls and price notices, 2026

A public exploit record

The market

The CISA catalogue of vulnerabilities known to be exploited lists 29 entries for the largest firewall vendor and 17 for another. It is a public record, counted from the catalogue itself.

Zedmos

Ours is zero, and we publish it — together with our Cyber Resilience Act class, an SBOM per release and the support period. The page stays up whatever the number becomes.

Source: CISA KEV catalogue v2026.09.01

The console is yours, and so is the jurisdiction

The market

Most incumbent management consoles are cloud services operated by US-headquartered companies. US law obliges them to disclose customer data regardless of where it is stored; an EU hosting region does not change that. Firewall logs are personal data under the GDPR.

Zedmos

The Zedmos Console is a container on your server, under your domain. Nothing in it leaves. Our own licence and threat-intelligence services run in Frankfurt, under German and EU law.

Source: 18 U.S.C. § 2713; CJEU C-582/14

Keep the platform you standardised on

The market

The one request MSPs running OPNsense and pfSense have repeated since 2017 is central management. What arrived is tied to one platform's paid edition, priced per device, and blocks third-party packages.

Zedmos

Zedmos installs as a package on the OPNsense or pfSense CE box you already run, and manages both from one multi-tenant console. Evaluate it before you touch any hardware.

Source: r/msp, 2017–2026; vendor product pages

Hardware

The hardware it runs on

Zedmos does not make hardware. These are the three configurations it is validated on, so you can build to a known-good specification, buy one built to it, or ship it under your own brand.

Z-200 — Branch, Fanless desktop

Z-200 Branch

Form factor
Fanless desktop
Processor
4–8 cores, x86-64
Memory
8–16 GB
Storage
128–256 GB NVMe
Data interfaces
4 × 2.5 GbE
Sizing
Up to 250 devices
Z-800 — Campus, 1U rack

Z-800 Campus

Form factor
1U rack
Processor
6–10 cores, x86-64
Memory
16–32 GB
Storage
256–512 GB NVMe
Data interfaces
6 × 2.5 GbE
Sizing
250–2500 devices
Z-2400 — Datacenter, 1U rack

Z-2400 Datacenter

Form factor
1U rack
Processor
Up to 20 cores, x86-64
Memory
64 GB
Storage
512 GB NVMe
Data interfaces
6 × 2.5 GbE + 2 × 10 GbE SFP+
Sizing
2500+ devices

Zedmos Threat Intelligence

Curated daily, shipped to every firewall

Indicators are gathered, cross-checked against an allowlist of the domains the internet actually runs on, tiered by how much corroboration each one has, and shipped to your firewalls. The figures below are read from the service as this page loads.

CN 51,030US 43,067IN 12,961FR 12,432BR 9,444GB 9,092RU 7,714Frankfurt · catalogue
live · read 02:03 UTC941,915 geolocated indicators across 212 countriesHigh counts in cloud-rich countries and networks include hyperscaler-hosted threats, not nationally attributed actors.

Source countries

  1. CNChina51,030
  2. USUnited States43,067
  3. INIndia12,961
  4. FRFrance12,432
  5. DEGermany11,606
  6. BRBrazil9,444
  7. GBUnited Kingdom9,092
  8. RURussia7,714
  9. SGSingapore5,211
  10. IDIndonesia4,405
12M
Indicators in the catalogue
12K
New in the last 24 hours
87
Sources ingested
31K
MITRE ATT&CK objects
221K
Allowlisted to prevent false positives
255K
Indicators with a named malware family

Figures read from the service

How the catalogue is built

The console

What it actually looks like

The real interface, photographed from a working system. Site names, addresses and people are stand-ins, and the example estate is shown fully connected — your own console shows the state your own links are actually in.

Every site on one map

Fleet · 1 of 9

Every site on one map — The console opens on the whole estate: organisations, branches and gateways in one tree, and every site placed on a live map with its current health.

The console opens on the whole estate: organisations, branches and gateways in one tree, and every site placed on a live map with its current health.

See it against your own traffic

A demonstration runs on your topology rather than ours. For pricing, a partner conversation or a technical walkthrough, one email is enough.