One engine. One pane.
Every network layer.
Zedmos is an inline security engine that fuses routing, encryption, deep inspection, and curated threat intel into a single data plane. Installed as an OPNsense plugin, it integrates seamlessly into an existing appliance. Same policies, same data plane, same UI.
Verified, datacenter-aware, and inline
The CTI Hub feeds the same engine that runs your firewall. Every IOC is scored, every ASN ranked, every country and TLD weighted before the snapshot reaches your data plane.
Threat sources from across the globe — one decision per packet
The Zedmos CTI Hub continuously ingests curated feeds, scores every indicator with STIX 2.1 confidence, and ships only the corroborated set to your firewalls. Hot-reload, zero packet loss, datacenter-aware allowlist so legitimate cloud SaaS never breaks.
- Multi-source consensus → verified tier promotion
- Offline GeoASN lookup at line rate (3.3M ops/s)
- Cloud-AS exception keeps Microsoft 365 / Google Workspace alive
- Public verification endpoint for cross-validation
Every layer a modern firewall owes you — in one engine
Instead of stitching an IDS, a DPI layer, a TLS proxy, a content scanner, and a separate SASE overlay together, Zedmos ships one binary that runs every layer on the same zero-copy path.
- GAStateful packet inspectionIn-engine flow table
- GADeep packet inspection200+ protocols
- GATLS / SSL inspectionSNI · TLS fingerprinting · bump
- GAQUIC / DoT / DoH control
- GAIDS / IPSAho-Corasick binary rules
- GAApplication control
- GAURL / web filteringSuffix trie + TI feeds
- GAIdentity-aware policy (ZTNA)AD · Azure · SCIM
- GAEncrypted VPN overlayNative fast-path integration
- TestSD-WAN per-policy steeringSLA-aware failover
- TestCentralized SASE hub-spoke
- GAAnti-malware (inline)Streaming payload inspection
- GAThreat intelligence feedsIP · domain · URL · TLS fingerprint
- RoadmapWAF / reverse proxyDesign complete, shipping in a later release
- GAFile type / MIME filtering
- GACentralized mgmt (single pane)
- GASub-10 s failoverIn-process daemon
- GAHot-reload policies & feedsZero packet loss
- GASIEM / S3 / Kafka exportunified log plane
Run Zedmos on your hardware, or as a mesh you manage centrally
Same binary. Same policies. The only difference is where the packet path lives — on your own OPNsense box, or at distributed encrypted hubs that your spokes dial into.
Every packet stays on your box. No cloud dependency.
- Ships as a signed OPNsense module
- Monitor, bridge, or routed posture on your interfaces
- Local event store — data stays inside the perimeter
- Management UI served from the appliance itself
- Atomic policy and threat-intelligence hot-reload
Enforce the same policies at distributed hubs, centrally.
- Central orchestrator distributes policy and topology
- Spokes dial into the nearest hub over an encrypted overlay
- Zedmos engine enforces in-line at the hub
- Continuous sub-10-second failover between hub pairs
- Identity-aware access via Active Directory, Entra, and SCIM
Pick any block. It runs on the same pipeline.
Each capability below is a live feature of the engine, documented and deployable today. Click any card for the deep dive — architecture, config snippets, and benchmarks.
Shared-memory packet rings bypass the kernel socket path. ~14 Gbps on a single core.
SNI extraction, full client and server fingerprinting, forward-proxy bumping with a short-lived CA.
200+ application protocols, category pairs, encrypted traffic heuristics — all on the fast path.
allow / drop / reset / shape / redirect / quarantine / tarpit / scan / rewrite / exec / mark / escalate / route / log.
Route per app / category / SNI / user / geo. Strategy-pattern TX with SNAT and kernel FIB.
IP, domain, URL, and TLS-fingerprint blocklists. Suffix-trie matching. Atomic hot-swap via control socket.
AD DC agent, Azure Graph pull, SCIM hook, ARP/DHCP fingerprinting. Per-flow user tags.
ICMP / HTTP / DNS probes, composite health score, atomic peer swap. Hysteresis-aware.
SIGHUP and UNIX-socket commands swap policies, feeds, and routes with zero packet loss.
Protocol-aware payload reassembly across web, mail, and file-sharing traffic with content-type inference and per-flow deduplication.
Block or downgrade encrypted bypass paths per policy. 90% QUIC, 85% DoT effective.
Kernel driver patched so encrypted overlay peers can join the same fast path. Opt-in on bare-metal deployments; standard SASE still defaults to the kernel socket path.
Lock-free shared-memory ring into a dedicated writer daemon. File, syslog, SQLite, and Elasticsearch sinks today — with write-ahead log, circuit breaker, and adaptive sampling under load.
Intel 1/10 GbE multi-queue, NIC preflight, CPU affinity — 10× cache-miss reduction.