Zedmos

Zedmos NGFW

A next-generation firewall, built and run on your terms

Zedmos NGFW is a complete firewall: our own FreeBSD-based operating system, an inline inspection engine attached straight to the interfaces, and a policy model that decides once per session. Installed from an image onto hardware you choose.

Live sessions of one firewall in the Zedmos console: a table of flows with device, protocol and address columns.
Live sessions of one firewall, opened from the consoleconsole.zedmos.com

What Zedmos does to your traffic

The complete firewall, with the same engine and the same policy model as the plugin — on an operating system we maintain, installed from one image.

The live-sessions view of one firewall in the console: a table of flows with device, protocol and address columns, and tabs for threats, blocks, TLS sessions and AI activity.
  1. What is it?

    Every flow, classified by application rather than by port — the connections tab is the raw material for everything else.

  2. Whose is it?

    The device, its category and its hardware address on the same row as the flow, so a policy can name a person or a group instead of an address.

  3. Is it dangerous?

    Threats, blocks and antivirus findings for the same firewall, one tab away — signatures and intelligence applied before the session was forwarded.

  4. What is it carrying?

    TLS sessions and AI activity: which services were used, by whom, and what the content inspection found in what was sent.

  5. Inside the console you host

    Customer, site and firewall chosen at the top. The same view exists for every firewall in the estate, whichever platform it runs.

Every column here was decided on the appliance. Nothing left it to reach the verdict.console.zedmos.com · Live Sessions

The capabilities it adds

Grouped by the question each one answers. The same set on OPNsense, on pfSense and on Zedmos NGFW — one engine, one policy model, three ways to run it. Each has a fuller technical write-up under Resources.

What is this traffic, really?

Recognises applications, not ports200+

Almost everything is HTTPS on 443, so a port-based rule can only permit or deny all of it.

TLS inspection, applied selectively

Bump what you choose to; leave banking and health traffic alone by rule.

Client fingerprinting

JA3, JA4 and ALPN identify the software behind a session even when it is not decrypted.

QUIC and HTTP/3

The protocol most of the web moved to, seen and controlled rather than left as a gap.

DNS over TLS and over HTTPS

Encrypted resolution routes around a classic firewall's name-based rules. Not around this one.

Live sessions, with the reason

Every flow on screen as it happens, carrying the decision and what drove it.

Should it be allowed through?

Intrusion detection and prevention

Signatures evaluated inline on the same appliance — a match is a block, not a morning alert.

Threat intelligence, shipped daily26

Indicators gathered and cross-checked, then pushed to every firewall you manage.

Files scanned in flight

Attachments and downloads examined before they land, not after.

Sixteen things a rule can do16

Allow, log, rate-limit, quarantine, reset, drop — and the rest, on both platforms.

What are people typing into AI?

The shadow-AI inventory

Which assistants are in use and by whom — answered without reading a single prompt.

Prompts checked before they leave

Source code, credentials and regulated data caught on the way out, not in a breach report.

The verdict is reached on your premises

Deterministic matchers plus a local model. Sending content away to ask whether it may be sent is a contradiction.

Three postures, one engine

Watch and record; strip the sensitive part and redirect; or block outright. The rule's action verb is the only change.

Every assistant, including yours

ChatGPT, Claude, Gemini, Copilot, Perplexity, Mistral — and an in-house endpoint you declare yourself.

Is confidential data leaving?

Detectors you switch on deliberately61

Card numbers, secrets, health and financial data, and national identity formats for twenty-two countries.

Uploads and messages both

A file attached to a web form and a paragraph pasted into a chat are the same risk.

A block you can defend

The record names the rule, what was detected and where — without keeping the content itself.

Fail closed where it matters

A control that lets traffic past when it cannot evaluate it is not a control on the path that matters.

Who and what is on the network?

Devices are recognised

A managed laptop and a personal phone share a subnet and look identical to an address rule.

Users and groups from your directory

Active Directory, Entra ID or SCIM — an entitlement follows the person, not their DHCP lease.

Quarantine without cutting off

A device restricted to what it needs to be fixed is a device you can still fix.

Policy by zone and schedule

Different rules for a guest network, a server segment, and outside business hours.

Where should it go, and what happened?

Each flow out the right link

Scored on loss, latency and jitter — a link that is up and losing packets is not a healthy link.

Encrypted overlay between sites

WireGuard, OpenVPN or GRE, provisioned from one topology view rather than hand-built per firewall.

Rules change without a restart

A policy edit takes effect without dropping a packet or interrupting a session.

A feed your SOC already reads

Reports and live sessions on screen, and CEF, LEEF or syslog over TLS to whatever you run.

200+
Protocols classified
26
Threat categories
16
Policy actions

How it behaves in the path

Inspection that runs on the box

Traffic is classified, inspected and decided on the same appliance that routes it. No packet, no payload and no session record is sent to Zedmos.

One policy model

Applications, categories, domains, users, groups, devices and zones select traffic; sixteen actions decide what happens to it. The same model on both platforms.

Encrypted traffic, handled honestly

TLS inspection with fingerprinting and selective bumping, plus visibility and control over QUIC, DNS-over-TLS and DNS-over-HTTPS.