Zedmos

For managed service providers

Every client in one console. Hosted by you, or by us in Frankfurt.

Multi-tenant from the first firewall, on the OPNsense or pfSense CE boxes your clients already run. Unlimited firewalls on the MSP tier, billed monthly in arrears. Your brand on the console and on the box. And if the console is ever unreachable, every firewall keeps enforcing what it already holds.

The home page of the Zedmos console with the organisations, branches and gateways it manages.
The console: every customer and every firewall, on your serverconsole.zedmos.com

Where your customers live in the tool

Four levels. A role is granted at one of them and reaches everything below it — which is how a first-line engineer sees the customer they are assigned and nobody else's.

The organisations page of the console: a tenant switcher at the top, counters for organisations, branches, gateways and owners, and the organisation directory beneath.
  1. Console — yours

    Installed on your server, under your domain. Every customer you manage is an organisation in it; the count here is the whole estate.

  2. Organisation — one per customer

    Switch it at the top and every page below follows: their firewalls, their policy, their reports, and no sight of anyone else's.

  3. Branch — one per site

    A customer with eleven offices is eleven branches under one organisation. A site engineer can be scoped to exactly one of them.

  4. Firewall — the appliance itself

    Whichever platform it runs, it registers into its branch on first boot and reports here.

  5. Three roles, granted per level

    Owner changes anything including who else has access; administrator changes policy and configuration; viewer reads reports and sessions and changes nothing.

A role is granted at one level and reaches everything below it, and nothing beside it.console.zedmos.com · Organizations

How a new customer is brought on

Nobody has to be on site, and nobody types the customer's network settings into the console. The appliance arrives, is plugged in, and places itself.

The gateways page of the console: a register-token button, counters for total, online, connected and offline nodes, filters, and a list of firewalls with their version, an update button and a live-watch button.
  1. One token per customer

    Generate a register token, put it in the installer, and the firewall registers itself into the right organisation and branch on first boot.

  2. The estate at a glance

    Registered, online, connected, offline. A firewall that stopped reporting is a number here before it is a phone call.

  3. Filter by customer, site or state

    The same list serves one engineer looking after one customer and the person responsible for all of them.

  4. Versions, per firewall

    Every firewall shows what it runs. A release is offered, not forced: a few firewalls first, then the rest, or the whole estate at once.

  5. Live watch, from here

    Open the live sessions of any firewall in the list without logging in to the firewall itself.

Zedmos publishes the releases. You decide which firewalls take them, and when.console.zedmos.com · Gateways
  1. You

    Create the customer

    One organisation for the customer and a branch for each of their sites. This is the structure their reports, their policy and their invoices will hang from.

  2. You

    Mint an install token

    The token carries which customer the firewall belongs to. It is short-lived and can be revoked before it is used, so handing one to an installer is not handing over your console.

  3. Zedmos

    The firewall places itself

    On first boot it redeems the token and appears under the right customer, in the right branch. Nobody reconciles a list of serial numbers afterwards.

  4. Zedmos

    Your baseline applies

    Policy attached at the customer or the branch reaches the new firewall without an edit — and reaches the next one they add, too. Their one exception is recorded at their scope, not by forking your baseline.

2
Platforms: OPNsense and pfSense CE
Unlimited
Firewalls on the MSP tier
Monthly
Billed in arrears
3 × 3
Roles across scopes

Every site on one map

Fleet · 1 of 9

Every site on one map — The console opens on the whole estate: organisations, branches and gateways in one tree, and every site placed on a live map with its current health.

The console opens on the whole estate: organisations, branches and gateways in one tree, and every site placed on a live map with its current health.

What a service provider actually needs

Central management, at last

Add a VPN user, change a rule or read a report for any client without logging into that client's box. Organisations, branches and firewalls sit in one tree; a change to a group reaches every member.

Hosted where you decide

Run the console as a container on your own server under your domain, or use ours at console.zedmos.com, operated from Frankfurt. Same product, same features. The choice is a procurement conversation, not a technical one.

Delegation that matches your org chart

Three roles across three scopes. First-line support sees the customer they are assigned; a senior engineer sees the estate; a client can be given a read-only view of their own firewalls.

Your brand, not ours

The console, the firewall interface and branded appliance builds can carry your name and your colours. Your customers see your product.

A management outage is not a security outage

Management and enforcement are separate. If the console is unreachable, every firewall keeps enforcing the policy it holds. When a licence lapses, management goes read-only; traffic is never dropped.

Records your SOC already reads

CEF, LEEF and syslog over TLS to the SIEM you run. Per-client reports for the quarterly review, from the same console.