License & Deployment Mix: 34 tools – 16 OSS, 1 SaaS. (OSS and SaaS counts can overlap when an open-source tool also offers a vendor-hosted edition.)

Introduction

This directory evaluates platforms that provide network perimeter security (firewalls, UTM, NGFW) and Layer 3 packet forwarding (software routers, routing daemons, white-box switch NOS). Many platforms span both domains – VyOS, pfSense, OPNsense, Juniper SRX, and FortiGate all provide firewall rule enforcement alongside dynamic routing (BGP, OSPF). Evaluating them together avoids artificial splits and reflects how networks are actually built.

The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.

Comparison

This evaluation covers the full firewall/UTM and routing platform landscape – 33 tools total (18 firewalls + 15 routing platforms).


Overview Comparison

Firewall Platforms (18 tools)

ToolTypeLicenseDeploymentPricing
pfSenseFirewall/RouterApache-2.0 (CE)Self-hosted (bare metal/VM)Free (CE); Plus from $129/yr
OPNsenseFirewall/RouterBSD-2-ClauseSelf-hosted (bare metal/VM)Free OSS
IPFireHardened FWGPL-3.0Self-hosted (bare metal/VM)Free OSS
VyOSNetwork OSGPL-2.0Self-hosted (bare metal/VM)Free (rolling); LTS paid
FirewalldHost FirewallGPL-2.0Host-level daemonFree OSS
nftablesKernel NetfilterGPL-2.0Kernel-levelFree OSS
ShorewallNetfilter ConfigGPL-2.0Host-level configFree OSS
FortiGateNGFW/UTMProprietaryAppliance / VM / cloudAppliance + subs
Palo AltoNGFWProprietaryAppliance / VM / cloudAppliance + subs
Sophos XGSNGFW/UTMProprietaryAppliance / VM / cloudAppliance + subs
Cisco FirepowerNGFWProprietaryAppliance / VMAppliance + subs
Check PointNGFWProprietaryAppliance / VM / cloudAppliance + subs
WatchGuardUTM/NGFWProprietaryAppliance / VM / cloudAppliance + subs
Untangle NGUTMProprietarySoftware (bare metal/VM)Free (ltd); $50/yr+
BarracudaNGFWProprietaryAppliance / VM / cloudAppliance + subs
SonicWallNGFWProprietaryAppliance / VM / cloudAppliance + subs
Juniper SRXNGFW/RouterProprietaryAppliance / VM / cloudAppliance + subs
UniFi GatewaySMB GatewayProprietaryApplianceHardware only

Routing Platforms (15 tools)

ToolTypeLicenseDeploymentPricing
FRRoutingRouting SuiteGPL-2.0Self-hosted (any Linux)Free OSS
BIRDRouting DaemonGPL-2.0Self-hosted (Linux/BSD)Free OSS
OpenBGPDBGP DaemonISC (BSD)Self-hosted (OpenBSD/Linux)Free OSS
GoBGPBGP Impl.Apache-2.0Self-hosted (any OS)Free OSS
ExaBGPBGP API EngineBSD-3-ClauseSelf-hosted (Python)Free OSS
MikroTikSoftware RouterProprietaryHardware / VM$45-$250 (CHR/x86)
OpenWrtEmbedded RouterGPL-2.0Embedded / VMFree OSS
TNSRVPP RouterProprietaryBare metal / VM / cloud~$1,500/yr+
SONiCWhite-Box NOSApache-2.0White-box switchesFree OSS
Cumulus LinuxWhite-Box NOSProprietaryNVIDIA Spectrum switches~$4,500-$15,000/sw
Arista cEOSVirtual RouterProprietaryContainer / VM / cloud~$495/mo+ sub
Juniper cRPDContainer RPDProprietaryDocker containerFlex subscription
DANOSNetwork OSLGPL-2.1uCPE / white-box / VMFree (comm.); paid
OcNOSWhite-Box NOSProprietaryWhite-box switchesPer-device license
Pica8 PicOSWhite-Box NOSProprietaryWhite-box switches~$6,000-$14,000/sw

Open-source firewall leaders: OPNsense (modern UI, weekly updates, plugin ecosystem), pfSense (mature, widely deployed), VyOS (CLI-driven, advanced routing)

Commercial firewall leaders: FortiGate (market share, ASIC performance), Palo Alto (enterprise NGFW leader), Cisco Firepower (Cisco ecosystems)

Open-source routing leaders: FRRouting (de facto standard, multi-protocol), BIRD (IXP route servers, filter language), SONiC (hyperscale, Apache-2.0)

Commercial routing leaders: Arista cEOS (EOS parity, gNMI), Juniper cRPD (Junos in a container), OcNOS (carrier-grade SP)


Core Firewall Features

Firewall tools only (18 tools).

ToolStatefulNATIPv6VLANsShapingHA
pfSenseYes (pf)FullYesYesYes (ALTQ)CARP
OPNsenseYes (pf)FullYesYesYes (ALTQ)CARP
IPFireYesFullPartialYesYes (QoS)No
VyOSYes (nft)FullYesYesYes (tc)VRRP
FirewalldYes (nft)Masq/fwdYesN/ANoN/A
nftablesYesFullYesN/AVia tcN/A
ShorewallYesFullYesN/AYes (tc)No
FortiGateYes (ASIC)FullYesYesYesA/A, A/P
Palo AltoYesFullYesYesYes (QoS)A/A, A/P
Sophos XGSYes (Xstream)FullYesYesYesA/P
Cisco FPYes (Snort)FullYesYesYes (QoS)A/S, multi
Check PointYes (SecureXL)FullYesYesYes (QoS)ClusterXL
WatchGuardYesFullYesYesYesA/P
UntangleYesFullPartialYesYes (BWM)No
BarracudaYesFullYesYesYesA/P
SonicWallYes (RFDPI)FullYesYesYes (BWM)A/S
Juniper SRXYes (Junos)FullYesYesYes (CoS)Chassis cluster
UniFi GWYesFullPartialYesYes (SQ)No

Routing Protocol Support

All 33 tools. For firewalls, notes indicate routing capabilities. For routing platforms, the data comes from per-tool evaluations.

ToolBGPOSPFIS-ISMPLSVXLAN/EVPNBFDECMPSeg RtePBR
pfSenseVia FRR pkgVia FRR pkgNoNoNoNoNoNoNo
OPNsenseVia FRR pluginVia FRR pluginNoNoNoNoNoNoNo
IPFireNoNoNoNoNoNoNoNoNo
VyOSYesYesYesYesYes (EVPN)YesYesYesYes
FirewalldNoNoNoNoNoNoNoNoNo
nftablesNoNoNoNoNoNoNoNoNo
ShorewallNoNoNoNoNoNoNoNoNo
FortiGateYesYesNoNoYes (VXLAN)YesYesNoYes
Palo AltoYesYesNoNoNoYesYesNoYes
Sophos XGSStatic onlyStatic onlyNoNoNoNoNoNoNo
Cisco FPStatic onlyStatic onlyNoNoNoNoNoNoNo
Check PointStatic onlyStatic onlyNoNoNoNoNoNoNo
WatchGuardStatic onlyStatic onlyNoNoNoNoNoNoNo
UntangleStatic onlyStatic onlyNoNoNoNoNoNoNo
BarracudaStatic onlyStatic onlyNoNoNoNoNoNoNo
SonicWallStatic onlyYes (basic)NoNoNoNoNoNoNo
Juniper SRXYesYesYesYesNoYesYesNoYes
UniFi GWStatic onlyStatic onlyNoNoNoNoNoNoNo
FRRoutingYes (full)Yes (v2/v3)YesYes (LDP)Yes (EVPN)YesYes (64-way)YesYes
BIRDYes (full)Yes (v2/v3)NoYes (basic)NoYesYesNoNo
OpenBGPDYes (full)NoNoNoNoNoNoNoNo
GoBGPYes (full)NoNoYes (label)Yes (EVPN)NoNoYesNo
ExaBGPYes (API)NoNoYes (label)Yes (EVPN)NoNoYes (SRv6)No
MikroTikYesYesYes (v7)Yes (LDP, RSVP)VXLAN onlyYesYesNoYes
OpenWrtVia FRR pkgVia FRR pkgVia FRR pkgLimitedNoVia FRRVia FRRNoYes
TNSRYes (FRR)Yes (FRR)Yes (FRR)Yes (LDP)VXLAN onlyYesYesNoYes
SONiCYes (FRR)Yes (FRR)Yes (FRR)YesYes (EVPN)YesYesYesNo
CumulusYes (FRR)Yes (FRR)Yes (FRR)YesYes (EVPN)YesYesYesYes
Arista cEOSYesYesYesYes (LDP, RSVP)Yes (EVPN)YesYesYesNo
Juniper cRPDYesYesYesYes (LDP, RSVP)Yes (EVPN)YesYesYesNo
DANOSYes (FRR)YesYesYesVXLAN onlyYesYesNoNo
OcNOSYesYesYesYes (full)Yes (EVPN)YesYesYesNo
Pica8YesYesNoStatic onlyYes (EVPN)YesYesNoNo

Full routing stacks: FRRouting (most feature-complete OSS), Arista cEOS (EOS parity), Juniper cRPD (Junos in a container), OcNOS (carrier-grade)

Firewall + routing: VyOS (full routing via FRR), Juniper SRX (BGP/OSPF/IS-IS/MPLS built-in), FortiGate (BGP/OSPF built-in), Palo Alto (BGP/OSPF built-in)

BGP-only specialists: OpenBGPD (security-first), GoBGP (gRPC API-first), ExaBGP (programmable BGP control plane), BIRD (IXP route servers)


WireGuard Support

All 33 tools.

ToolWireGuardNotes
pfSenseYes (package)Community package; FreeBSD kernel module
OPNsenseYes (built-in)Native plugin; kernel module
IPFireYes (built-in)Native kernel support
VyOSYes (built-in)Native; first-class tunnel interface
FirewalldN/AHost firewall only
nftablesN/AKernel netfilter only
ShorewallN/AConfig tool only
FortiGateNoDiscontinued OpenVPN; no WireGuard
Palo AltoNoIPsec and GlobalProtect only
Sophos XGSNoIPsec and Sophos Connect only
Cisco FPNoIPsec and AnyConnect only
Check PointNoIPsec and Mobile Access only
WatchGuardNoIPsec and SSL VPN only
UntangleYes (built-in)Native WireGuard support
BarracudaNoIPsec and SSL VPN only
SonicWallNoIPsec and NetExtender only
Juniper SRXNoIPsec only; Junos stack
UniFi GWYes (built-in)Native WireGuard in UniFi OS
FRRoutingOS-levelRoutes over kernel WG interfaces
BIRDOS-levelRoutes over kernel WG interfaces
OpenBGPDOS-levelRoutes over kernel WG interfaces
GoBGPN/AControl plane only; no forwarding
ExaBGPN/AControl plane only; no forwarding
MikroTikYes (native)First-class in RouterOS v7
OpenWrtYes (native)kmod-wireguard + LuCI integration
TNSRYes (native)VPP WireGuard plugin; high throughput
SONiCNoSwitch ASIC; no crypto in data plane
CumulusOS-levelKernel WG module; CPU-only (1-2 Gbps)
Arista cEOSNoIPsec only; EOS protocol stack
Juniper cRPDNoIPsec only; Junos protocol stack
DANOSNoDPDK data plane; no kernel WG path
OcNOSNoCarrier-grade; kernel not exposed
Pica8NoKernel not exposed; no module loading

Native WireGuard: OPNsense, VyOS, IPFire, Untangle, UniFi Gateway, MikroTik, OpenWrt, TNSR

Via package/plugin: pfSense (FreeBSD WG package)

OS-level only (routes over WG interfaces): FRRouting, BIRD, OpenBGPD, Cumulus Linux

Not supported: All commercial NGFWs (FortiGate, Palo Alto, Sophos, Cisco, Check Point, WatchGuard, Barracuda, SonicWall, Juniper SRX), all NOS platforms (SONiC, Arista, Juniper cRPD, OcNOS, Pica8, DANOS)


NGFW / UTM Features

Firewall tools only (18 tools).

ToolApp CtrlIDS/IPSWeb FilterAnti-MalwareSSL Insp.DPI
pfSenseNo (via IDS)Yes (Suricata pkg)Yes (pfBlockerNG)NoNoPartial
OPNsenseNo (via IDS)Yes (Suricata)Yes (plugin)No (ClamAV)NoPartial
IPFireNoYes (Suricata)Yes (URL Filter)Yes (ClamAV)NoNo
VyOSNoNoNoNoNoNo
FirewalldNoNoNoNoNoNo
nftablesNoNoNoNoNoNo
ShorewallNoNoNoNoNoNo
FortiGateYes (5000+)Yes (FortiGuard)Yes (80+ cat)Yes (sandbox)Yes (deep)Yes
Palo AltoYes (App-ID)Yes (Threat Prev)Yes (PAN-DB)Yes (WildFire)YesYes
Sophos XGSYes (Sync)Yes (Xstream)YesYes (dual AV)Yes (Xstream)Yes
Cisco FPYes (AVC)Yes (Snort NGIPS)Yes (Talos)Yes (AMP)YesYes
Check PointYes (blade)Yes (IPS blade)Yes (blade)Yes (SandBlast)YesYes
WatchGuardYesYes (IPS)Yes (WebBlocker)Yes (APT)YesYes
UntangleYesYes (IPS)YesYes (Virus Blk)YesYes
BarracudaYesYes (IPS)Yes (URL)Yes (ATP)YesYes
SonicWallYes (App Intel)Yes (IPS, GAV)Yes (CFS)Yes (Capture)Yes (DPI-SSL)Yes
Juniper SRXYes (AppSecure)Yes (IDP)Yes (UTM)Yes (Sky ATP)YesYes
UniFi GWYes (basic DPI)Yes (basic)No (DNS only)NoNoYes (basic)

NGFW leaders: Palo Alto (App-ID gold standard), Fortinet (ASIC-accelerated DPI), Check Point (blade architecture)

OSS with IDS/IPS: OPNsense (Suricata built-in), pfSense (Suricata package), IPFire (Suricata addon)


VPN Capabilities

Firewall tools only (18 tools).

ToolIPsecOpenVPNWireGuardSSL PortalS2SRA
pfSenseYes (IKEv1/v2)YesYes (pkg)NoYesYes
OPNsenseYes (IKEv1/v2)YesYesNoYesYes
IPFireYes (IKEv1/v2)YesYesNoYesYes
VyOSYes (IKEv1/v2)YesYesNoYesYes
FirewalldN/AN/AN/AN/AN/AN/A
nftablesN/AN/AN/AN/AN/AN/A
ShorewallN/AN/AN/AN/AN/AN/A
FortiGateYes (IKEv1/v2)NoNoYes (FortiClient)YesYes
Palo AltoYes (IKEv1/v2)NoNoYes (GlobalProtect)YesYes
Sophos XGSYes (IKEv1/v2)YesNoYes (Sophos Connect)YesYes
Cisco FPYes (IKEv1/v2)NoNoYes (AnyConnect)YesYes
Check PointYes (IKEv1/v2)NoNoYes (Mobile Access)YesYes
WatchGuardYes (IKEv1/v2)YesNoYes (SSL VPN)YesYes
UntangleYes (IKEv2)YesYesNoYesYes
BarracudaYes (IKEv1/v2)NoNoYes (SSL VPN)YesYes
SonicWallYes (IKEv1/v2)NoNoYes (NetExtender)YesYes
Juniper SRXYes (IKEv1/v2)NoNoYes (Secure Connect)YesYes
UniFi GWYes (IKEv2)YesYesNoYesYes

BGP Advanced Features

Routing tools + firewall tools that support BGP.

Tool4B ASNRPKI/ROAAdd-PathFlowSpecGraceful RstRoute RefreshMP-BGP
VyOSYesYesYesYesYesYesYes
FortiGateYesNoNoNoYesYesYes
Palo AltoYesNoNoNoYesYesYes
SonicWallYesNoNoNoNoYesNo
Juniper SRXYesYesYesYesYesYesYes
FRRoutingYesYesYesYesYesYesYes
BIRDYesYesYesYesYesYesYes
OpenBGPDYesYesRecv onlyNoYesYesYes
GoBGPYesYesYesYesYesYesYes
ExaBGPYesNoYesYesYesYesYes
MikroTikYesYes (v7)NoYes (v7)YesYesYes
OpenWrtVia FRRVia FRRVia FRRVia FRRVia FRRVia FRRVia FRR
TNSRYesYesYesYesYesYesYes
SONiCYesNoYesNoYesYesYes
CumulusYesNoYesNoYesYesYes
Arista cEOSYesYesYesNoYesYesYes
Juniper cRPDYesYesYesYesYesYesYes
DANOSYesNoNoNoYesYesYes
OcNOSYesNoYesNoYesYesYes
Pica8YesNoNoNoYesYesYes

Most complete BGP: FRRouting (RPKI, FlowSpec, Add-Path, BMP, EVPN), BIRD (RPKI, FlowSpec, Add-Path, roles RFC 9234), GoBGP (RPKI, FlowSpec, BMP, gRPC), Juniper cRPD (Junos-grade BGP)

BGP on firewalls: VyOS (full FRR-based BGP), Juniper SRX (Junos BGP), FortiGate (basic BGP), Palo Alto (basic BGP)


High Availability

All tools that support HA.

ToolHA MethodNotes
pfSenseCARP (active/passive)Stateful failover; config sync
OPNsenseCARP (active/passive)Stateful failover; config sync
VyOSVRRPGateway redundancy; config sync via automation
FortiGateActive/Active, A/PFortiGate HA cluster; session sync
Palo AltoActive/Active, A/PHA cluster; session sync
Sophos XGSActive/PassiveHA cluster; automatic failover
Cisco FPActive/Standby, multiMulti-instance; stateful failover
Check PointClusterXL A/A, A/SSmartConsole managed; session sync
WatchGuardActive/PassiveFireCluster; stateful failover
BarracudaActive/PassiveHA cluster; config sync
SonicWallActive/StandbyStateful HA; zero-touch deployment
Juniper SRXChassis clusterStateful failover; RG-based
MikroTikVRRPGateway redundancy; no session sync
TNSRN/AVPP HA via external orchestration
SONiCMC-LAG, warm restartSwitch-pair redundancy; BGP GR
CumulusMLAG (clagd)Active-active dual-homing
Arista cEOSMLAG, VRRPSwitch-pair MLAG; VRRP for gateways
Juniper cRPDN/ALightweight container; BGP GR
DANOSN/ANo native HA; external orchestration
OcNOSMC-LAGSwitch-pair redundancy; BFD-assisted
Pica8VRRP, stackingVirtual chassis; gateway redundancy

Best firewall HA: FortiGate (A/A + A/P), Palo Alto (A/A + A/P), Check Point ClusterXL (A/A + A/S)

Best switch HA: SONiC (MC-LAG + warm restart), Cumulus (MLAG + ISSU), Arista (MLAG + SSO)


Management & Automation

All 33 tools.

ToolCLIWeb UIAPIAnsibleNETCONFgNMI
pfSenseShellYesFauxAPI; Plus RESTCommunityNoNo
OPNsenseShellYesYes (REST)CommunityNoNo
IPFireShellYesNoNoNoNo
VyOSYes (Vyatta)NoYes (HTTP, NETCONF)YesYesNo
FirewalldYesNoYes (D-Bus)YesNoNo
nftablesYes (nft)NoNoNoNoNo
ShorewallYesNoNoNoNoNo
FortiGateYesYesYes (REST)YesNoNo
Palo AltoYesYesYes (XML/REST)YesNoNo
Sophos XGSLtdYesYes (REST)LimitedNoNo
Cisco FPYesYes (FMC)Yes (FMC REST)YesNoNo
Check PointYesYes (Smart)Yes (Mgmt API)YesNoNo
WatchGuardYesYesYes (REST)NoNoNo
UntangleLtdYesYes (REST)NoNoNo
BarracudaYesYesYes (REST)NoNoNo
SonicWallYesYesYes (REST)NoNoNo
Juniper SRXYes (Junos)YesYes (REST, XML)YesYesNo
UniFi GWLtdYesYes (UniFi API)CommunityNoNo
FRRoutingYes (vtysh)NoSNMP; YANG (evolving)Yes (frr.frr)PartialNo
BIRDYes (birdc)NoNo (birdwatcher 3rd)NoNoNo
OpenBGPDYes (bgpctl)NoNoNoNoNo
GoBGPYes (gobgp)NoYes (gRPC)NoNoNo
ExaBGPNo (daemon)NoYes (HTTP, stdin)NoNoNo
MikroTikYesYes (WebFig)Yes (REST v7)CommunityNoNo
OpenWrtYes (ash)Yes (LuCI)Yes (ubus JSON-RPC)CommunityNoNo
TNSRYes (CLISH)NoYes (RESTCONF)YesYesNo
SONiCYes (KLISH)Yes (SONiC-UI)Yes (REST, gNMI)YesYesYes
CumulusYes (NVUE)NoYes (NVUE REST)Yes (official)YesNo
Arista cEOSYes (EOS)NoYes (eAPI, REST)Yes (official)YesYes
Juniper cRPDYes (Junos)NoYes (REST, XML)Yes (official)YesYes
DANOSYes (Vyatta)NoYes (REST)YesYesNo
OcNOSYes (IOS-style)NoYes (REST)YesYesYes
Pica8Yes (Juniper)AmpConYes (REST)YesYesNo

Best firewall automation: FortiGate (REST + Ansible + FortiManager), Palo Alto (REST + Ansible

  • Panorama), Juniper SRX (NETCONF + Ansible)

Best routing automation: Arista cEOS (eAPI + gNMI + NETCONF + Ansible), Juniper cRPD (NETCONF + gNMI + Ansible), SONiC (REST + gNMI + NETCONF)

gNMI streaming telemetry: SONiC, Arista cEOS, Juniper cRPD, OcNOS


SSO / OIDC Comparison

Firewall tools only – routing tools use RADIUS/TACACS+ for management access rather than web-based SSO.

The notes below assume Authentik as the identity provider. OIDC is the preferred SSO protocol.

ToolOIDCSAMLLDAPRADIUSAuthentik Notes
pfSenseNoNoYesYesVPN via Authentik LDAP; admin via LDAP
OPNsenseNoNoYesYesVPN via Authentik LDAP; TOTP built-in
IPFireNoNoNoNoLocal auth only
VyOSNoNoNoYesRADIUS via Authentik FreeRADIUS
FirewalldN/AN/AN/AN/APAM-based OS auth
nftablesN/AN/AN/AN/AKernel-level; OS auth
ShorewallN/AN/AN/AN/AConfig files; OS auth
FortiGateNoYes (FMgr)YesYesFortiManager SAML via Authentik
Palo AltoNoYes (Panorama)YesYesPanorama SAML via Authentik
Sophos XGSYes (Central)YesYesYesSophos Central OIDC via Authentik
Cisco FPNoYes (FMC)YesYesFMC SAML via Authentik
Check PointNoYes (Smart)YesYesSmartConsole SAML via Authentik
WatchGuardYes (Cloud)YesYesYesWG Cloud OIDC/SAML via Authentik
UntangleNoNoYesYesLDAP/RADIUS for user auth
BarracudaNoYes (Cloud)YesYesCloud portal SAML via Authentik
SonicWallNoYes (NSM)YesYesNSM SAML via Authentik
Juniper SRXNoYes (SD Cloud)YesYesCloud portal SAML; Junos RADIUS
UniFi GWYes (UniFi ID)NoNoYesUniFi SSO; no Authentik federation

Best SSO: WatchGuard Cloud (OIDC + SAML), Sophos Central (OIDC + SAML), cloud management consoles (SAML universally supported)

No SSO (device-level): All firewalls use LDAP/RADIUS at device level; SSO is at the central management console, not the device web UI


Central Management & Multi-Tenancy

Firewall tools only (18 tools).

ToolCentral MgmtMulti-TenantMSP ConsoleTemplatesAPI
pfSenseNo (FauxAPI)NoNoNoFauxAPI; Plus REST
OPNsenseNo (REST API)NoNoNoYes (REST)
IPFireNoNoNoNoNo
VyOSNo (Ansible)NoNoVia automationYes (HTTP, NETCONF)
FirewalldN/AN/AN/AN/AD-Bus
nftablesN/AN/AN/AN/AN/A
ShorewallN/AN/AN/AN/AN/A
FortiGateYes (FortiMgr)Yes (ADOMs)Yes (MSP mode)Yes (policies)Yes (REST)
Palo AltoYes (Panorama)Yes (DGs)Yes (Panorama)Yes (stacks)Yes (XML/REST)
Sophos XGSYes (Central)YesYes (Partner)Yes (policies)Yes (REST)
Cisco FPYes (FMC)Yes (domains)NoYes (inherit)Yes (REST)
Check PointYes (MDS)Yes (domains)NoYes (layers)Yes (Mgmt API)
WatchGuardYes (Cloud)Yes (tiers)Yes (MSP)Yes (cloud)Yes (REST)
UntangleYes (Cmd Ctr)YesYes (MSP)Yes (policy)Yes (REST)
BarracudaYes (FW CC)YesYes (MSP)Yes (repo obj)Yes (REST)
SonicWallYes (NSM/CSC)YesYes (MSP)Yes (templates)Yes (REST)
Juniper SRXYes (Junos Space)Yes (LSYS)NoYes (templates)Yes (REST, NETCONF)
UniFi GWYes (UniFi App)Partial (sites)NoYes (profiles)Yes (UniFi API)

Best central management: FortiGate (FortiManager ADOMs), Palo Alto (Panorama device groups), Check Point MDS (multi-domain)

Best MSP support: WatchGuard Cloud (purpose-built MSP), FortiGate (FortiManager MSP), SonicWall NSM, Barracuda Control Center


Monitoring Integration

All 33 tools. monitoring stack integration for platform health, routing protocol state, and security event monitoring.

ToolSNMPSyslogNetFlow/sFlowgNMIBMP
pfSenseYesYesYes (softflowd)NoNo
OPNsenseYesYesYes (netflow plugin)NoNo
IPFireYesYesNoNoNo
VyOSYesYesYes (NetFlow, sFlow)NoNo
FirewalldN/AYes (journald)N/ANoNo
nftablesN/AYes (kernel log)N/ANoNo
ShorewallN/AYes (syslog)N/ANoNo
FortiGateYes (full MIB)YesYes (NetFlow, sFlow)NoNo
Palo AltoYes (full MIB)YesYes (NetFlow)NoNo
Sophos XGSYes (full MIB)YesYes (NetFlow)NoNo
Cisco FPYes (full MIB)YesYes (NSEL)NoNo
Check PointYes (full MIB)YesYes (R81+)NoNo
WatchGuardYes (full MIB)YesNoNoNo
UntangleYesYesNoNoNo
BarracudaYes (full MIB)YesYes (NetFlow)NoNo
SonicWallYes (full MIB)YesYes (IPFIX)NoNo
Juniper SRXYes (full MIB)YesYes (J-Flow, sFlow)NoNo
UniFi GWYesYesNoNoNo
FRRoutingYes (AgentX)YesNoNoYes
BIRDNoYesNoNoNo
OpenBGPDNoYesNoNoNo
GoBGPNoYesNoNoYes
ExaBGPNoYes (JSON)NoNoNo
MikroTikYes (full MIB)YesYes (NetFlow/IPFIX)NoNo
OpenWrtYes (snmpd pkg)YesNoNoNo
TNSRYesYesYes (IPFIX)NoNo
SONiCYesYesNoYesNo
CumulusYesYesNoNoNo
Arista cEOSYesYesNoYesNo
Juniper cRPDYesYesNoYesNo
DANOSYesYesNoNoNo
OcNOSYesYesNoYesNo
Pica8YesYesNoNoNo

Best monitoring integration (firewall): pfSense / OPNsense (Telegraf on-device, syslog + EVE JSON, community Grafana dashboards), VyOS (SNMP + NetFlow + syslog), UniFi (UnPoller for InfluxDB)

Best monitoring integration (routing): SONiC (SNMP + gNMI streaming), Arista cEOS (SNMP + gNMI + eAPI), Juniper cRPD (SNMP + gNMI + JTI), MikroTik (SNMP + NetFlow + REST API)

Best flow export: VyOS (NetFlow + sFlow), FortiGate (NetFlow + sFlow), Juniper SRX (J-Flow + sFlow), SonicWall (IPFIX), MikroTik (NetFlow/IPFIX), TNSR (IPFIX via VPP)

BMP (BGP Monitoring Protocol): FRRouting, GoBGP

gNMI streaming telemetry: SONiC, Arista cEOS, Juniper cRPD, OcNOS


Tools

35 tools.

Arista cEOS / CloudEOS

Arista cEOS (containerized EOS) and CloudEOS are virtual form factors of Arista’s Extensible Operating System.

License: Proprietary (proprietary) · Kind: web · Deploy: docker · SSO: none

Website

Barracuda CloudGen Firewall

Barracuda CloudGen Firewall is a cloud-connected NGFW platform designed for distributed enterprise and MSP deployments.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none

Website

BIRD Internet Routing Daemon

BIRD (BIRD Internet Routing Daemon) is a high- performance routing daemon developed by CZ.NIC, the Czech domain registry.

License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Check Point

Check Point is a pioneer in firewall technology, having invented the stateful inspection firewall in 1993.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none

Website

Cisco Firepower

Cisco Firepower is Cisco’s next-generation firewall platform, combining the legacy ASA (Adaptive Security Appliance) firewall with the Firepower Threat Defense (FTD) software that integrates Snort-based IPS, application visibility and contr…

License: Proprietary (proprietary) · Kind: web · Deploy: appliance · SSO: none

Website

DANOS (Disaggregated Network Operating System)

DANOS (Disaggregated Network Operating System) is a network operating system originally seeded by AT&T to the Linux Foundation in 2018.

License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

ExaBGP

ExaBGP is a programmable BGP API engine designed for route injection, health-checking, anycast management, DDoS mitigation, and route analytics.

License: BSD-3-Clause (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Firewalld

Firewalld is the standard dynamic firewall manager for Red Hat Enterprise Linux (RHEL), Fedora, CentOS Stream, Rocky Linux, AlmaLinux, and SUSE Linux Enterprise.

License: GPL-2.0-only (OSS) · Kind: web · Deploy: docker, appliance · SSO: none

Website · Source

Fortinet FortiGate

Fortinet FortiGate is the world’s most deployed firewall platform, dominant in the SMB, midmarket, and increasingly in enterprise segments.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none

Website

FRRouting (FRR)

FRRouting (FRR) is the de facto standard open-source routing suite for Linux. Forked from the Quagga project in 2017, FRR is developed under the Linux Foundation and has rapidly become the routing engine embedded in major network operating…

License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

GoBGP

GoBGP is a BGP implementation written in Go, designed from the ground up for programmatic control via a gRPC API.

License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

IP Infusion OcNOS

IP Infusion OcNOS (Open Compute Network Operating System) is a carrier-grade network operating system for disaggregated white-box switches and routers.

License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none

Website

IPFire

IPFire is a hardened Linux-based firewall distribution focused on security, simplicity, and minimalism.

License: GPL-3.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Juniper cRPD

Juniper cRPD (Containerized Routing Protocol Daemon) is the Junos routing stack extracted from Juniper hardware and packaged as a Docker container.

License: Proprietary (proprietary) · Kind: web · Deploy: docker · SSO: none

Website

Juniper SRX

Juniper SRX Series is a family of next-generation firewalls that combine Junos OS routing capabilities with integrated security services.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none

Website

LibreQoS

LibreQoS is a self-hosted traffic management and network operations platform designed for ISPs and enterprise networks.

License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

MikroTik RouterOS

MikroTik RouterOS is a network operating system that runs on all MikroTik hardware (routers, switches, APs) and on x86 hardware via the Cloud Hosted Router (CHR) virtual machine image.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, docker, appliance · SSO: none

Website

nftables / iptables

nftables is the modern Linux kernel packet filtering framework that replaces iptables, ip6tables, arptables, and ebtables. It provides a unified interface for IPv4, IPv6, ARP, and bridging packet classification and filtering.

License: GPL-2.0-only (OSS) · Kind: web · Deploy: docker, k8s · SSO: none

Website · Source

NVIDIA Cumulus Linux

NVIDIA Cumulus Linux is a Linux-based network operating system for white-box and open networking switches.

License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none

Website

OpenBGPD

OpenBGPD is a security-focused BGP daemon from the OpenBSD project, developed primarily by Henning Brauer and Claudio Jeker. It follows the OpenBSD philosophy of code correctness, minimal attack surface, and privilege separation.

License: ISC (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

OpenWrt

OpenWrt is a Linux-based operating system targeting embedded networking devices. It provides a fully writable filesystem with a package management system (opkg), allowing users to install software packages to customise the device for their…

License: GPL-2.0-only (OSS) · Kind: web · Deploy: docker, appliance · SSO: none

Website · Source

OPNsense

OPNsense is a FreeBSD-based firewall and routing platform forked from pfSense in 2015 by Deciso, a Dutch network security company.

License: BSD-2-Clause (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Palo Alto Networks

Palo Alto Networks is the enterprise NGFW market leader, known for pioneering application-aware firewalling with App-ID technology.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none

Website

pfSense

pfSense is a FreeBSD-based firewall and router platform that has been a staple of open-source network security since 2004.

License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Pica8 PicOS

Pica8 PicOS is a commercial network operating system for white-box and brite-box Ethernet switches, supporting L2/L3 switching and routing plus OpenFlow/SDN, managed centrally via the AmpCon platform.

License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none

Website

Shorewall

Shorewall (Shoreline Firewall) is a high-level configuration tool for the Linux netfilter firewall. It reads human-readable configuration files and compiles them into nftables or iptables rules.

License: GPL-2.0-only (OSS) · Kind: web · Deploy: appliance · SSO: none

Website · Source

SONiC (Software for Open Networking in the Cloud)

SONiC (Software for Open Networking in the Cloud) is an open-source network operating system for white-box switches, originally developed by Microsoft for Azure data center networks and later contributed to the Linux Foundation.

License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

SonicWall

SonicWall is a commercial next-generation firewall vendor for SMB and MSP markets, running SonicOS with RFDPI deep packet inspection, IPS, content filtering, Capture ATP sandboxing, and VPN.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none

Website

Sophos XGS (Sophos Firewall)

Sophos XGS is Sophos’s next-generation firewall platform, running Sophos Firewall OS (SFOS) on purpose-built XGS hardware with Xstream flow processors for hardware-accelerated TLS inspection and DPI.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none

Website

TNSR

TNSR is a high-performance commercial software router from Netgate, using fd.io VPP and DPDK for line-rate forwarding, FRR dynamic routing, and native WireGuard and IPsec VPN on x86 hardware.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none

Website

Ubiquiti UniFi Gateway

Ubiquiti UniFi Gateway (formerly UniFi Security Gateway / UniFi Dream Machine) is a line of gateway/firewall appliances managed through the UniFi Network Application.

License: Proprietary (proprietary) · Kind: web · Deploy: appliance · SSO: none

Website

Untangle NG Firewall (Arista Edge Threat Management)

Untangle NG Firewall, now marketed as Arista Edge Threat Management following Arista Networks’ acquisition in 2022, is a software-based UTM platform that runs on commodity x86 hardware.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none

Website

VyOS

VyOS is a Linux-based network operating system that provides enterprise routing, firewalling, and VPN capabilities via a unified CLI modeled after Juniper Junos and Cisco IOS.

License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

WatchGuard Firebox

WatchGuard Firebox is a UTM/NGFW platform aimed at MSPs and SMBs, running Fireware OS with firewall, VPN, IPS, web filtering, and sandboxing, managed centrally through WatchGuard Cloud.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none

Website

Zenarmor

Zenarmor (formerly Sensei) is a proprietary next-gen firewall plug-in adding L7 app control, web filtering, and DPI to OPNsense, pfSense, FreeBSD, and Linux.

License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none

Website

ResorsIT Tools Catalog Search