NGFW Features Requiring Plugins/Add-ons:
Here’s the updated table highlighting which features are not free (like Zenarmor) and indicating which ones are native features of OPNsense:
NGFW Feature | Plugin/Add-on in OPNsense | Free/Not Free | Native Feature |
---|---|---|---|
1. Deep Packet Inspection (DPI) |
...
- Requires installing plugins like Suricata (Intrusion Detection System - IDS) for DPI and intrusion prevention.
Suricata | Free | ❌ |
2. Intrusion Detection and Prevention |
...
(IDPS) |
...
- Suricata is the plugin needed for IDPS, which provides both detection and prevention features.
Suricata | Free | ❌ | |
3. Application Awareness and Control |
...
- Requires plugins or custom configurations, such as setting up Suricata with rule sets that can recognize and control specific applications.
Zenarmor (Sensei) | Not Free | ❌ | |
4. Advanced Threat Protection (ATP) |
...
- Available through integration with Suricata or third-party services, but requires configuring it.
Suricata (with rulesets) and Zenarmor (Sensei) | Partially Free (Suricata) / Not Free (Zenarmor) | ❌ |
5. SSL/TLS Decryption and Inspection |
...
- This is handled through the Web Proxy with the SSL Inspection plugin, which allows decryption and inspection of HTTPS traffic.
SSL Inspection (enabled via Web Proxy) | Free | ✅ | |
6. URL Filtering and Web Content Control |
...
...
Web Proxy and Zenarmor (Sensei) |
...
Partially Free (Web Proxy) / Not Free (Zenarmor) | ✅ | |
7. Integrated Antivirus and Antimalware |
...
- Requires installing the ClamAV plugin for antivirus scanning in conjunction with the web proxy for malware detection.
...
Threat Intelligence Integration:
- Can be integrated through plugins like ET (Emerging Threats) rule sets in Suricata or other third-party integrations.
Conclusion:
...
ClamAV (integrated with Web Proxy) | Free | ✅ | |
8. Identity-Based Access Controls | Zenarmor (Sensei) or Active Directory integration | Not Free | ❌ |
9. Threat Intelligence Integration | Suricata (ET Pro rulesets) | Free | ❌ |
10. Cloud-based Threat Detection | Not natively supported without paid services | Not Free | ❌ |
11. Centralized Management and Reporting | OPNsense GUI, Zenarmor (Sensei) (advanced reporting) | Free (OPNsense GUI) / Not Free (Zenarmor) | ✅ |
12. Policy Enforcement across Multiple Layers | Suricata, Zenarmor (Sensei) | Partially Free (Suricata) / Not Free (Zenarmor) | ❌ |
13. DNS Security | Unbound DNS with custom configurations or Zenarmor (Sensei) | Free (Unbound DNS) / Not Free (Zenarmor) | ✅ |
14. Virtualization and Cloud Compatibility | Native in OPNsense (no plugin needed) | Free | ✅ |
15. IoT and BYOD Security | Zenarmor (Sensei) | Not Free | ❌ |
16. Layer 7 (Application Layer) Visibility | Suricata, Zenarmor (Sensei) | Partially Free (Suricata) / Not Free (Zenarmor) | ❌ |
17. Automatic Policy Updates | Suricata (automatic rule updates) | Free | ❌ |
Summary:
- Not Free: Zenarmor (Sensei), which provides advanced features that are not available in the free version.
- Native Features of OPNsense: SSL/TLS decryption, URL filtering (via Web Proxy), integrated antivirus (ClamAV), DNS security, and virtualization/cloud compatibility.