Recognises applications, not ports200+
Almost everything is HTTPS on 443, so a port-based rule can only permit or deny all of it.
OPNsense Plugin
Installs from a package repository and appears under Services. Nine pages — dashboard, devices, live sessions, reports, policies, settings, notifications, update and support — inside the interface your team already uses.

The firewall you run today decides by address and port. Zedmos installs into it and decides by what the traffic actually is, who it belongs to, and what it is carrying — without replacing anything that already works.

Every flow, classified by application rather than by port — the connections tab is the raw material for everything else.
The device, its category and its hardware address on the same row as the flow, so a policy can name a person or a group instead of an address.
Threats, blocks and antivirus findings for the same firewall, one tab away — signatures and intelligence applied before the session was forwarded.
TLS sessions and AI activity: which services were used, by whom, and what the content inspection found in what was sent.
Customer, site and firewall chosen at the top. The same view exists for every firewall in the estate, whichever platform it runs.
Grouped by the question each one answers. The same set on OPNsense, on pfSense and on Zedmos NGFW — one engine, one policy model, three ways to run it. Each has a fuller technical write-up under Resources.
Almost everything is HTTPS on 443, so a port-based rule can only permit or deny all of it.
Bump what you choose to; leave banking and health traffic alone by rule.
JA3, JA4 and ALPN identify the software behind a session even when it is not decrypted.
The protocol most of the web moved to, seen and controlled rather than left as a gap.
Encrypted resolution routes around a classic firewall's name-based rules. Not around this one.
Every flow on screen as it happens, carrying the decision and what drove it.
Signatures evaluated inline on the same appliance — a match is a block, not a morning alert.
Indicators gathered and cross-checked, then pushed to every firewall you manage.
Attachments and downloads examined before they land, not after.
Allow, log, rate-limit, quarantine, reset, drop — and the rest, on both platforms.
Which assistants are in use and by whom — answered without reading a single prompt.
Source code, credentials and regulated data caught on the way out, not in a breach report.
Deterministic matchers plus a local model. Sending content away to ask whether it may be sent is a contradiction.
Watch and record; strip the sensitive part and redirect; or block outright. The rule's action verb is the only change.
ChatGPT, Claude, Gemini, Copilot, Perplexity, Mistral — and an in-house endpoint you declare yourself.
Card numbers, secrets, health and financial data, and national identity formats for twenty-two countries.
A file attached to a web form and a paragraph pasted into a chat are the same risk.
The record names the rule, what was detected and where — without keeping the content itself.
A control that lets traffic past when it cannot evaluate it is not a control on the path that matters.
A managed laptop and a personal phone share a subnet and look identical to an address rule.
Active Directory, Entra ID or SCIM — an entitlement follows the person, not their DHCP lease.
A device restricted to what it needs to be fixed is a device you can still fix.
Different rules for a guest network, a server segment, and outside business hours.
Scored on loss, latency and jitter — a link that is up and losing packets is not a healthy link.
WireGuard, OpenVPN or GRE, provisioned from one topology view rather than hand-built per firewall.
A policy edit takes effect without dropping a packet or interrupting a session.
Reports and live sessions on screen, and CEF, LEEF or syslog over TLS to whatever you run.
Inside OPNsense
Dashboard · 1 of 6

Engine and service health, top threats, applications and devices — rendered inside the OPNsense interface your team already knows.
Demo & pricing: info@zedmos.com
Request a demo