NGFW for Homelab & Practitioners

Built for people who actually know what they're doing

Zenarmor gives IT, network, and security practitioners a full-featured NGFW to run in their homelab on OPNsense, pfSense CE, bare metal, or any Linux box. Deep inspection, real visibility, and a clear path to enterprise SASE when you're ready to take it to work.

  • No credit card required
  • Deploy in under 5 minutes
  • Cancel anytime
Zenarmor NGFW dashboard
25K+
Networks secured
180
Countries
60+
Reports
<5 min
From install to fully protected
(on any OS or hardware)

Who it's built for

Three reasons practitioners run Zenarmor at home

Whether you're stress-testing security architecture, locking down your home network, or evaluating Zenarmor before rolling it out at work, this is the right starting point.

Homelab & lab environments
Run Zenarmor on your OPNsense box, Proxmox VM, Raspberry Pi, or any bare-metal Linux machine. Get hands-on with deep packet inspection, policy management, and real-time threat detection; no vendor restrictions, no sandboxed demo.
  • OPNsense
  • pfSense CE
  • Proxmox
  • Bare metal
  • Linux
Home network security & parental controls
Apply per-device and per-user policies across your entire home network. Block categories of content for specific devices, enforce safe browsing for kids, inspect encrypted traffic, and get full visibility into every connection leaving your network.
  • Content filtering
  • Per-device policies
  • Safe browsing
  • TLS inspection
Evaluate before you deploy at work
Most practitioners who run Zenarmor in their homelab end up deploying it at their organization. The architecture is identical; same engine, same policies, same Zenconsole. What you learn at home transfers directly to your business deployment.
  • Same engine
  • Business-ready
  • SASE upgrade path

Capabilities

Full-featured, no artificial limits

The homelab version runs the same engine as the business product. You get every capability, not a stripped-down demo, so what you test is exactly what you'd deploy.

Web content filtering

Web content filtering

Category-based URL filtering backed by a cloud threat intelligence database covering hundreds of millions of sites, continuously updated against the latest threats, zero-days, and malicious domains. Set per-device rules for full household control. Block harmful content per device, from kids' tablets to IoT endpoints.

Application control

Application control

Identify and enforce policies on 5,000+ applications by name, not just port and protocol. Allow or block by app, category, or device, giving you precise control over what's communicating on your network at any given time. Know exactly what every device on your network is talking to and control it.

Deep packet inspection

Deep packet inspection

Full layer-7 inspection including encrypted TLS/SSL traffic inline, without proxy detours or performance penalties. See what's actually inside the packets traversing your network, not just metadata. No more black boxes, full visibility into every flow, including encrypted sessions.

Real-time threat prevention

Real-time threat prevention

Block malware, ransomware, phishing, and C2 traffic before it reaches your devices, powered by live global threat intelligence. Catches threats that DNS blocklists and basic firewalls miss entirely. Enterprise-grade threat prevention running on your homelab hardware.

User & device identity policies

User & device identity policies

Assign different security policies to different users or devices, kids get content filtering, adults get full access, IoT devices get isolated. No AD required for home use; simple local identity management built in. Granular per-user and per-device control, without enterprise overhead.

Device identification

Device identification

Automatically discover and categorize every device on your network by type, OS, and identity. Instantly see what's connected; smart TVs, IoT sensors, phones, laptops and assign policies accordingly. Full network inventory and policy assignment automatically, on first boot.

Reporting & analytics

Reporting & analytics

Industry's best-in-class analytics; 60+ visually rich, drill-down reports covering threats, application usage, device activity, and traffic patterns. Filter to the most granular level to understand exactly what's happening on your network. The visibility you've always wanted over your home network, finally available.

Cloud-based central management

Cloud-based central management

Manage your entire Zenarmor deployment from Zenconsole, a cloud-based dashboard accessible from anywhere. The same multi-tenant management interface used in business deployments, so what you learn here maps directly to production use. Manage your home deployment the same way you'd manage a business fleet.

Your lab today. Your business tomorrow.

The same engine, the same policies, ready when you are

Zenarmor is the only NGFW where your homelab becomes your proof of concept. The architecture you test at home is identical to what you'd deploy at work and when you're ready to scale, ZTNA, SWG, CASB, and SD-WAN are already in the same platform waiting for you.

1

Deploy in your homelab

Install on OPNsense, pfSense CE, any Linux box, or a VM. Full NGFW running in under 5 minutes. No licensing restrictions on features.

2

Get comfortable, go deep

Learn the policy engine, explore the reporting, stress-test the architecture. The skills you build here transfer directly to a business deployment.

3

Take it to work or go full SASE

Scale to your organization on the same platform. Add ZTNA, SWG, and CASB when you're ready. No vendor change, no re-architecture, no wasted learning.

Runs on your stack

Your hardware, your OS, your tools

Zenarmor runs natively on the platforms practitioners actually use; no proprietary hardware, no forced cloud dependency.

Linux, BSD & cloud

Ubuntu, Debian, FreeBSD, CentOS, Amazon Linux, RedHat. If it runs Linux or BSD, it runs Zenarmor.

OPNsense & pfSense CE

One-click plugin install on OPNsense or pfSense CE, full NGFW on your existing open-source firewall in minutes.

Proxmox & bare metal

Run as a VM or directly on hardware. Works on everything from a Raspberry Pi to a rack server.

Splunk / Wazuh / Elastic

Native Syslog for log forwarding to your home SIEM or lab monitoring stack.

Datadog

Stream firewall events and threat data into your observability setup.

RESTful API

Full API access for automation, scripting, and integration into your homelab workflows.

From the community

What practitioners are saying

Real feedback from the homelab and security community; no PR, no fluff.

Get started

Your homelab. Enterprise-grade security.
Under 5 minutes.

Install Zenarmor on the hardware you already have. Full feature access, no credit card, no artificial limits.

Start free trial