Converteix OPNsense en un NGFW complet amb control d'aplicacions
Zenarmor (abans Sensei), de Sunny Valley Cyber Security, és el plugin que afegeix les funcions de nova generació a OPNsense. Un tallafocs open source treballa a capa 3 i 4 —IPs i ports—; Zenarmor hi afegeix inspecció profunda de paquets (DPI) a capa 7 per identificar i controlar aplicacions, filtrar web per categories i donar analítica en temps real.
Converteix una plataforma open source en un NGFW real, sense el cost d'un appliance comercial.
Funciona bé fins i tot sense desxifrat TLS complet: analitza les fases inicials no xifrades de la sessió, el SNI i les metadades.
La informació que dona és directament útil: veus qui fa servir què, sense haver d'excavar en fitxers de log.
S'integra amb la resta de la configuració d'OPNsense en mode encaminat, conviu amb les regles i serveis existents.
Identifica centenars d'aplicacions i protocols per signatures DPI, independentment del port. Permet bloquejar una aplicació concreta sense tancar tot un servei.
Filtratge d'URL per categories, amb més d'un centenar de categories per bloquejar contingut maliciós o inadequat.
Anàlisi del trànsit xifrat (opcional) i quadre de comandament en temps real amb sessions actives, usuaris i aplicacions més utilitzades.
L'opció més compatible i estable: s'integra amb la inspecció estàndard del tallafocs sense canvis complexos de xarxa.
Polítiques per usuari amb integració amb Active Directory (edició Business).
El DPI consumeix recursos: dimensionem RAM i CPU segons l'ample de banda real a inspeccionar.
Per a entorns amb molts clients es pot fer servir Elasticsearch com a backend de dades.
Informes exportables i enviament automàtic per correu a l'edició Business.
Gestió de múltiples desplegaments, útil quan un client té diverses seus.
Convierte OPNsense en un NGFW completo con control de aplicaciones
Zenarmor (antes Sensei), de Sunny Valley Cyber Security, es el plugin que añade las funciones de nueva generación a OPNsense. Un firewall open source trabaja en capa 3 y 4 —IPs y puertos—; Zenarmor añade inspección profunda de paquetes (DPI) en capa 7 para identificar y controlar aplicaciones, filtrar web por categorías y dar analítica en tiempo real.
Convierte una plataforma open source en un NGFW real, sin el coste de un appliance comercial.
Funciona bien incluso sin descifrado TLS completo: analiza las fases iniciales no cifradas de la sesión, el SNI y los metadatos.
La información que da es directamente útil: ves quién usa qué, sin tener que excavar en ficheros de log.
Se integra con el resto de la configuración de OPNsense en modo enrutado, convive con las reglas y servicios existentes.
Identifica cientos de aplicaciones y protocolos por firmas DPI, independientemente del puerto. Permite bloquear una aplicación concreta sin cerrar todo un servicio.
Filtrado de URL por categorías, con más de un centenar de categorías para bloquear contenido malicioso o inadecuado.
Análisis del tráfico cifrado (opcional) y cuadro de mando en tiempo real con sesiones activas, usuarios y aplicaciones más utilizadas.
La opción más compatible y estable: se integra con la inspección estándar del firewall sin cambios complejos de red.
Políticas por usuario con integración con Active Directory (edición Business).
El DPI consume recursos: dimensionamos RAM y CPU según el ancho de banda real a inspeccionar.
Para entornos con muchos clientes se puede usar Elasticsearch como backend de datos.
Informes exportables y envío automático por correo en la edición Business.
Gestión de múltiples despliegues, útil cuando un cliente tiene varias sedes.
Turns OPNsense into a full NGFW with application control
Zenarmor (formerly Sensei), by Sunny Valley Cyber Security, is the plugin that adds next-generation features to OPNsense. An open source firewall works at layers 3 and 4 —IPs and ports—; Zenarmor adds deep packet inspection (DPI) at layer 7 to identify and control applications, filter the web by category and provide real-time analytics.
Turns an open source platform into a real NGFW, without the cost of a commercial appliance.
Works well even without full TLS decryption: it analyses the initial unencrypted stages of the session, the SNI and metadata.
The information it surfaces is immediately useful: you see who uses what, without digging through log files.
Integrates with the rest of the OPNsense configuration in routed mode, coexisting with existing rules and services.
Identifies hundreds of applications and protocols through DPI signatures, regardless of port. It lets you block one specific application without shutting a whole service.
Category-based URL filtering, with over a hundred categories to block malicious or inappropriate content.
Encrypted traffic analysis (optional) and a real-time dashboard with live sessions, users and most-used applications.
The most compatible and stable option: it integrates with the firewall's standard inspection with no complex network changes.
Per-user policies with Active Directory integration (Business edition).
DPI consumes resources: we size RAM and CPU against the real bandwidth to be inspected.
For environments with many clients, Elasticsearch can be used as the data backend.
Exportable reports and automatic email delivery in the Business edition.
Management across multiple deployments, useful when a client has several sites.