License & Deployment Mix: 34 tools – 16 OSS, 1 SaaS. (OSS and SaaS counts can overlap when an open-source tool also offers a vendor-hosted edition.)
Introduction
This directory evaluates platforms that provide network perimeter security (firewalls, UTM, NGFW) and Layer 3 packet forwarding (software routers, routing daemons, white-box switch NOS). Many platforms span both domains – VyOS, pfSense, OPNsense, Juniper SRX, and FortiGate all provide firewall rule enforcement alongside dynamic routing (BGP, OSPF). Evaluating them together avoids artificial splits and reflects how networks are actually built.
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
This evaluation covers the full firewall/UTM and routing platform landscape – 33 tools total (18 firewalls + 15 routing platforms).
Overview Comparison
Firewall Platforms (18 tools)
| Tool | Type | License | Deployment | Pricing |
|---|---|---|---|---|
| pfSense | Firewall/Router | Apache-2.0 (CE) | Self-hosted (bare metal/VM) | Free (CE); Plus from $129/yr |
| OPNsense | Firewall/Router | BSD-2-Clause | Self-hosted (bare metal/VM) | Free OSS |
| IPFire | Hardened FW | GPL-3.0 | Self-hosted (bare metal/VM) | Free OSS |
| VyOS | Network OS | GPL-2.0 | Self-hosted (bare metal/VM) | Free (rolling); LTS paid |
| Firewalld | Host Firewall | GPL-2.0 | Host-level daemon | Free OSS |
| nftables | Kernel Netfilter | GPL-2.0 | Kernel-level | Free OSS |
| Shorewall | Netfilter Config | GPL-2.0 | Host-level config | Free OSS |
| FortiGate | NGFW/UTM | Proprietary | Appliance / VM / cloud | Appliance + subs |
| Palo Alto | NGFW | Proprietary | Appliance / VM / cloud | Appliance + subs |
| Sophos XGS | NGFW/UTM | Proprietary | Appliance / VM / cloud | Appliance + subs |
| Cisco Firepower | NGFW | Proprietary | Appliance / VM | Appliance + subs |
| Check Point | NGFW | Proprietary | Appliance / VM / cloud | Appliance + subs |
| WatchGuard | UTM/NGFW | Proprietary | Appliance / VM / cloud | Appliance + subs |
| Untangle NG | UTM | Proprietary | Software (bare metal/VM) | Free (ltd); $50/yr+ |
| Barracuda | NGFW | Proprietary | Appliance / VM / cloud | Appliance + subs |
| SonicWall | NGFW | Proprietary | Appliance / VM / cloud | Appliance + subs |
| Juniper SRX | NGFW/Router | Proprietary | Appliance / VM / cloud | Appliance + subs |
| UniFi Gateway | SMB Gateway | Proprietary | Appliance | Hardware only |
Routing Platforms (15 tools)
| Tool | Type | License | Deployment | Pricing |
|---|---|---|---|---|
| FRRouting | Routing Suite | GPL-2.0 | Self-hosted (any Linux) | Free OSS |
| BIRD | Routing Daemon | GPL-2.0 | Self-hosted (Linux/BSD) | Free OSS |
| OpenBGPD | BGP Daemon | ISC (BSD) | Self-hosted (OpenBSD/Linux) | Free OSS |
| GoBGP | BGP Impl. | Apache-2.0 | Self-hosted (any OS) | Free OSS |
| ExaBGP | BGP API Engine | BSD-3-Clause | Self-hosted (Python) | Free OSS |
| MikroTik | Software Router | Proprietary | Hardware / VM | $45-$250 (CHR/x86) |
| OpenWrt | Embedded Router | GPL-2.0 | Embedded / VM | Free OSS |
| TNSR | VPP Router | Proprietary | Bare metal / VM / cloud | ~$1,500/yr+ |
| SONiC | White-Box NOS | Apache-2.0 | White-box switches | Free OSS |
| Cumulus Linux | White-Box NOS | Proprietary | NVIDIA Spectrum switches | ~$4,500-$15,000/sw |
| Arista cEOS | Virtual Router | Proprietary | Container / VM / cloud | ~$495/mo+ sub |
| Juniper cRPD | Container RPD | Proprietary | Docker container | Flex subscription |
| DANOS | Network OS | LGPL-2.1 | uCPE / white-box / VM | Free (comm.); paid |
| OcNOS | White-Box NOS | Proprietary | White-box switches | Per-device license |
| Pica8 PicOS | White-Box NOS | Proprietary | White-box switches | ~$6,000-$14,000/sw |
Open-source firewall leaders: OPNsense (modern UI, weekly updates, plugin ecosystem), pfSense (mature, widely deployed), VyOS (CLI-driven, advanced routing)
Commercial firewall leaders: FortiGate (market share, ASIC performance), Palo Alto (enterprise NGFW leader), Cisco Firepower (Cisco ecosystems)
Open-source routing leaders: FRRouting (de facto standard, multi-protocol), BIRD (IXP route servers, filter language), SONiC (hyperscale, Apache-2.0)
Commercial routing leaders: Arista cEOS (EOS parity, gNMI), Juniper cRPD (Junos in a container), OcNOS (carrier-grade SP)
Core Firewall Features
Firewall tools only (18 tools).
| Tool | Stateful | NAT | IPv6 | VLANs | Shaping | HA |
|---|---|---|---|---|---|---|
| pfSense | Yes (pf) | Full | Yes | Yes | Yes (ALTQ) | CARP |
| OPNsense | Yes (pf) | Full | Yes | Yes | Yes (ALTQ) | CARP |
| IPFire | Yes | Full | Partial | Yes | Yes (QoS) | No |
| VyOS | Yes (nft) | Full | Yes | Yes | Yes (tc) | VRRP |
| Firewalld | Yes (nft) | Masq/fwd | Yes | N/A | No | N/A |
| nftables | Yes | Full | Yes | N/A | Via tc | N/A |
| Shorewall | Yes | Full | Yes | N/A | Yes (tc) | No |
| FortiGate | Yes (ASIC) | Full | Yes | Yes | Yes | A/A, A/P |
| Palo Alto | Yes | Full | Yes | Yes | Yes (QoS) | A/A, A/P |
| Sophos XGS | Yes (Xstream) | Full | Yes | Yes | Yes | A/P |
| Cisco FP | Yes (Snort) | Full | Yes | Yes | Yes (QoS) | A/S, multi |
| Check Point | Yes (SecureXL) | Full | Yes | Yes | Yes (QoS) | ClusterXL |
| WatchGuard | Yes | Full | Yes | Yes | Yes | A/P |
| Untangle | Yes | Full | Partial | Yes | Yes (BWM) | No |
| Barracuda | Yes | Full | Yes | Yes | Yes | A/P |
| SonicWall | Yes (RFDPI) | Full | Yes | Yes | Yes (BWM) | A/S |
| Juniper SRX | Yes (Junos) | Full | Yes | Yes | Yes (CoS) | Chassis cluster |
| UniFi GW | Yes | Full | Partial | Yes | Yes (SQ) | No |
Routing Protocol Support
All 33 tools. For firewalls, notes indicate routing capabilities. For routing platforms, the data comes from per-tool evaluations.
| Tool | BGP | OSPF | IS-IS | MPLS | VXLAN/EVPN | BFD | ECMP | Seg Rte | PBR |
|---|---|---|---|---|---|---|---|---|---|
| pfSense | Via FRR pkg | Via FRR pkg | No | No | No | No | No | No | No |
| OPNsense | Via FRR plugin | Via FRR plugin | No | No | No | No | No | No | No |
| IPFire | No | No | No | No | No | No | No | No | No |
| VyOS | Yes | Yes | Yes | Yes | Yes (EVPN) | Yes | Yes | Yes | Yes |
| Firewalld | No | No | No | No | No | No | No | No | No |
| nftables | No | No | No | No | No | No | No | No | No |
| Shorewall | No | No | No | No | No | No | No | No | No |
| FortiGate | Yes | Yes | No | No | Yes (VXLAN) | Yes | Yes | No | Yes |
| Palo Alto | Yes | Yes | No | No | No | Yes | Yes | No | Yes |
| Sophos XGS | Static only | Static only | No | No | No | No | No | No | No |
| Cisco FP | Static only | Static only | No | No | No | No | No | No | No |
| Check Point | Static only | Static only | No | No | No | No | No | No | No |
| WatchGuard | Static only | Static only | No | No | No | No | No | No | No |
| Untangle | Static only | Static only | No | No | No | No | No | No | No |
| Barracuda | Static only | Static only | No | No | No | No | No | No | No |
| SonicWall | Static only | Yes (basic) | No | No | No | No | No | No | No |
| Juniper SRX | Yes | Yes | Yes | Yes | No | Yes | Yes | No | Yes |
| UniFi GW | Static only | Static only | No | No | No | No | No | No | No |
| FRRouting | Yes (full) | Yes (v2/v3) | Yes | Yes (LDP) | Yes (EVPN) | Yes | Yes (64-way) | Yes | Yes |
| BIRD | Yes (full) | Yes (v2/v3) | No | Yes (basic) | No | Yes | Yes | No | No |
| OpenBGPD | Yes (full) | No | No | No | No | No | No | No | No |
| GoBGP | Yes (full) | No | No | Yes (label) | Yes (EVPN) | No | No | Yes | No |
| ExaBGP | Yes (API) | No | No | Yes (label) | Yes (EVPN) | No | No | Yes (SRv6) | No |
| MikroTik | Yes | Yes | Yes (v7) | Yes (LDP, RSVP) | VXLAN only | Yes | Yes | No | Yes |
| OpenWrt | Via FRR pkg | Via FRR pkg | Via FRR pkg | Limited | No | Via FRR | Via FRR | No | Yes |
| TNSR | Yes (FRR) | Yes (FRR) | Yes (FRR) | Yes (LDP) | VXLAN only | Yes | Yes | No | Yes |
| SONiC | Yes (FRR) | Yes (FRR) | Yes (FRR) | Yes | Yes (EVPN) | Yes | Yes | Yes | No |
| Cumulus | Yes (FRR) | Yes (FRR) | Yes (FRR) | Yes | Yes (EVPN) | Yes | Yes | Yes | Yes |
| Arista cEOS | Yes | Yes | Yes | Yes (LDP, RSVP) | Yes (EVPN) | Yes | Yes | Yes | No |
| Juniper cRPD | Yes | Yes | Yes | Yes (LDP, RSVP) | Yes (EVPN) | Yes | Yes | Yes | No |
| DANOS | Yes (FRR) | Yes | Yes | Yes | VXLAN only | Yes | Yes | No | No |
| OcNOS | Yes | Yes | Yes | Yes (full) | Yes (EVPN) | Yes | Yes | Yes | No |
| Pica8 | Yes | Yes | No | Static only | Yes (EVPN) | Yes | Yes | No | No |
Full routing stacks: FRRouting (most feature-complete OSS), Arista cEOS (EOS parity), Juniper cRPD (Junos in a container), OcNOS (carrier-grade)
Firewall + routing: VyOS (full routing via FRR), Juniper SRX (BGP/OSPF/IS-IS/MPLS built-in), FortiGate (BGP/OSPF built-in), Palo Alto (BGP/OSPF built-in)
BGP-only specialists: OpenBGPD (security-first), GoBGP (gRPC API-first), ExaBGP (programmable BGP control plane), BIRD (IXP route servers)
WireGuard Support
All 33 tools.
| Tool | WireGuard | Notes |
|---|---|---|
| pfSense | Yes (package) | Community package; FreeBSD kernel module |
| OPNsense | Yes (built-in) | Native plugin; kernel module |
| IPFire | Yes (built-in) | Native kernel support |
| VyOS | Yes (built-in) | Native; first-class tunnel interface |
| Firewalld | N/A | Host firewall only |
| nftables | N/A | Kernel netfilter only |
| Shorewall | N/A | Config tool only |
| FortiGate | No | Discontinued OpenVPN; no WireGuard |
| Palo Alto | No | IPsec and GlobalProtect only |
| Sophos XGS | No | IPsec and Sophos Connect only |
| Cisco FP | No | IPsec and AnyConnect only |
| Check Point | No | IPsec and Mobile Access only |
| WatchGuard | No | IPsec and SSL VPN only |
| Untangle | Yes (built-in) | Native WireGuard support |
| Barracuda | No | IPsec and SSL VPN only |
| SonicWall | No | IPsec and NetExtender only |
| Juniper SRX | No | IPsec only; Junos stack |
| UniFi GW | Yes (built-in) | Native WireGuard in UniFi OS |
| FRRouting | OS-level | Routes over kernel WG interfaces |
| BIRD | OS-level | Routes over kernel WG interfaces |
| OpenBGPD | OS-level | Routes over kernel WG interfaces |
| GoBGP | N/A | Control plane only; no forwarding |
| ExaBGP | N/A | Control plane only; no forwarding |
| MikroTik | Yes (native) | First-class in RouterOS v7 |
| OpenWrt | Yes (native) | kmod-wireguard + LuCI integration |
| TNSR | Yes (native) | VPP WireGuard plugin; high throughput |
| SONiC | No | Switch ASIC; no crypto in data plane |
| Cumulus | OS-level | Kernel WG module; CPU-only (1-2 Gbps) |
| Arista cEOS | No | IPsec only; EOS protocol stack |
| Juniper cRPD | No | IPsec only; Junos protocol stack |
| DANOS | No | DPDK data plane; no kernel WG path |
| OcNOS | No | Carrier-grade; kernel not exposed |
| Pica8 | No | Kernel not exposed; no module loading |
Native WireGuard: OPNsense, VyOS, IPFire, Untangle, UniFi Gateway, MikroTik, OpenWrt, TNSR
Via package/plugin: pfSense (FreeBSD WG package)
OS-level only (routes over WG interfaces): FRRouting, BIRD, OpenBGPD, Cumulus Linux
Not supported: All commercial NGFWs (FortiGate, Palo Alto, Sophos, Cisco, Check Point, WatchGuard, Barracuda, SonicWall, Juniper SRX), all NOS platforms (SONiC, Arista, Juniper cRPD, OcNOS, Pica8, DANOS)
NGFW / UTM Features
Firewall tools only (18 tools).
| Tool | App Ctrl | IDS/IPS | Web Filter | Anti-Malware | SSL Insp. | DPI |
|---|---|---|---|---|---|---|
| pfSense | No (via IDS) | Yes (Suricata pkg) | Yes (pfBlockerNG) | No | No | Partial |
| OPNsense | No (via IDS) | Yes (Suricata) | Yes (plugin) | No (ClamAV) | No | Partial |
| IPFire | No | Yes (Suricata) | Yes (URL Filter) | Yes (ClamAV) | No | No |
| VyOS | No | No | No | No | No | No |
| Firewalld | No | No | No | No | No | No |
| nftables | No | No | No | No | No | No |
| Shorewall | No | No | No | No | No | No |
| FortiGate | Yes (5000+) | Yes (FortiGuard) | Yes (80+ cat) | Yes (sandbox) | Yes (deep) | Yes |
| Palo Alto | Yes (App-ID) | Yes (Threat Prev) | Yes (PAN-DB) | Yes (WildFire) | Yes | Yes |
| Sophos XGS | Yes (Sync) | Yes (Xstream) | Yes | Yes (dual AV) | Yes (Xstream) | Yes |
| Cisco FP | Yes (AVC) | Yes (Snort NGIPS) | Yes (Talos) | Yes (AMP) | Yes | Yes |
| Check Point | Yes (blade) | Yes (IPS blade) | Yes (blade) | Yes (SandBlast) | Yes | Yes |
| WatchGuard | Yes | Yes (IPS) | Yes (WebBlocker) | Yes (APT) | Yes | Yes |
| Untangle | Yes | Yes (IPS) | Yes | Yes (Virus Blk) | Yes | Yes |
| Barracuda | Yes | Yes (IPS) | Yes (URL) | Yes (ATP) | Yes | Yes |
| SonicWall | Yes (App Intel) | Yes (IPS, GAV) | Yes (CFS) | Yes (Capture) | Yes (DPI-SSL) | Yes |
| Juniper SRX | Yes (AppSecure) | Yes (IDP) | Yes (UTM) | Yes (Sky ATP) | Yes | Yes |
| UniFi GW | Yes (basic DPI) | Yes (basic) | No (DNS only) | No | No | Yes (basic) |
NGFW leaders: Palo Alto (App-ID gold standard), Fortinet (ASIC-accelerated DPI), Check Point (blade architecture)
OSS with IDS/IPS: OPNsense (Suricata built-in), pfSense (Suricata package), IPFire (Suricata addon)
VPN Capabilities
Firewall tools only (18 tools).
| Tool | IPsec | OpenVPN | WireGuard | SSL Portal | S2S | RA |
|---|---|---|---|---|---|---|
| pfSense | Yes (IKEv1/v2) | Yes | Yes (pkg) | No | Yes | Yes |
| OPNsense | Yes (IKEv1/v2) | Yes | Yes | No | Yes | Yes |
| IPFire | Yes (IKEv1/v2) | Yes | Yes | No | Yes | Yes |
| VyOS | Yes (IKEv1/v2) | Yes | Yes | No | Yes | Yes |
| Firewalld | N/A | N/A | N/A | N/A | N/A | N/A |
| nftables | N/A | N/A | N/A | N/A | N/A | N/A |
| Shorewall | N/A | N/A | N/A | N/A | N/A | N/A |
| FortiGate | Yes (IKEv1/v2) | No | No | Yes (FortiClient) | Yes | Yes |
| Palo Alto | Yes (IKEv1/v2) | No | No | Yes (GlobalProtect) | Yes | Yes |
| Sophos XGS | Yes (IKEv1/v2) | Yes | No | Yes (Sophos Connect) | Yes | Yes |
| Cisco FP | Yes (IKEv1/v2) | No | No | Yes (AnyConnect) | Yes | Yes |
| Check Point | Yes (IKEv1/v2) | No | No | Yes (Mobile Access) | Yes | Yes |
| WatchGuard | Yes (IKEv1/v2) | Yes | No | Yes (SSL VPN) | Yes | Yes |
| Untangle | Yes (IKEv2) | Yes | Yes | No | Yes | Yes |
| Barracuda | Yes (IKEv1/v2) | No | No | Yes (SSL VPN) | Yes | Yes |
| SonicWall | Yes (IKEv1/v2) | No | No | Yes (NetExtender) | Yes | Yes |
| Juniper SRX | Yes (IKEv1/v2) | No | No | Yes (Secure Connect) | Yes | Yes |
| UniFi GW | Yes (IKEv2) | Yes | Yes | No | Yes | Yes |
BGP Advanced Features
Routing tools + firewall tools that support BGP.
| Tool | 4B ASN | RPKI/ROA | Add-Path | FlowSpec | Graceful Rst | Route Refresh | MP-BGP |
|---|---|---|---|---|---|---|---|
| VyOS | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| FortiGate | Yes | No | No | No | Yes | Yes | Yes |
| Palo Alto | Yes | No | No | No | Yes | Yes | Yes |
| SonicWall | Yes | No | No | No | No | Yes | No |
| Juniper SRX | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| FRRouting | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| BIRD | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| OpenBGPD | Yes | Yes | Recv only | No | Yes | Yes | Yes |
| GoBGP | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| ExaBGP | Yes | No | Yes | Yes | Yes | Yes | Yes |
| MikroTik | Yes | Yes (v7) | No | Yes (v7) | Yes | Yes | Yes |
| OpenWrt | Via FRR | Via FRR | Via FRR | Via FRR | Via FRR | Via FRR | Via FRR |
| TNSR | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| SONiC | Yes | No | Yes | No | Yes | Yes | Yes |
| Cumulus | Yes | No | Yes | No | Yes | Yes | Yes |
| Arista cEOS | Yes | Yes | Yes | No | Yes | Yes | Yes |
| Juniper cRPD | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| DANOS | Yes | No | No | No | Yes | Yes | Yes |
| OcNOS | Yes | No | Yes | No | Yes | Yes | Yes |
| Pica8 | Yes | No | No | No | Yes | Yes | Yes |
Most complete BGP: FRRouting (RPKI, FlowSpec, Add-Path, BMP, EVPN), BIRD (RPKI, FlowSpec, Add-Path, roles RFC 9234), GoBGP (RPKI, FlowSpec, BMP, gRPC), Juniper cRPD (Junos-grade BGP)
BGP on firewalls: VyOS (full FRR-based BGP), Juniper SRX (Junos BGP), FortiGate (basic BGP), Palo Alto (basic BGP)
High Availability
All tools that support HA.
| Tool | HA Method | Notes |
|---|---|---|
| pfSense | CARP (active/passive) | Stateful failover; config sync |
| OPNsense | CARP (active/passive) | Stateful failover; config sync |
| VyOS | VRRP | Gateway redundancy; config sync via automation |
| FortiGate | Active/Active, A/P | FortiGate HA cluster; session sync |
| Palo Alto | Active/Active, A/P | HA cluster; session sync |
| Sophos XGS | Active/Passive | HA cluster; automatic failover |
| Cisco FP | Active/Standby, multi | Multi-instance; stateful failover |
| Check Point | ClusterXL A/A, A/S | SmartConsole managed; session sync |
| WatchGuard | Active/Passive | FireCluster; stateful failover |
| Barracuda | Active/Passive | HA cluster; config sync |
| SonicWall | Active/Standby | Stateful HA; zero-touch deployment |
| Juniper SRX | Chassis cluster | Stateful failover; RG-based |
| MikroTik | VRRP | Gateway redundancy; no session sync |
| TNSR | N/A | VPP HA via external orchestration |
| SONiC | MC-LAG, warm restart | Switch-pair redundancy; BGP GR |
| Cumulus | MLAG (clagd) | Active-active dual-homing |
| Arista cEOS | MLAG, VRRP | Switch-pair MLAG; VRRP for gateways |
| Juniper cRPD | N/A | Lightweight container; BGP GR |
| DANOS | N/A | No native HA; external orchestration |
| OcNOS | MC-LAG | Switch-pair redundancy; BFD-assisted |
| Pica8 | VRRP, stacking | Virtual chassis; gateway redundancy |
Best firewall HA: FortiGate (A/A + A/P), Palo Alto (A/A + A/P), Check Point ClusterXL (A/A + A/S)
Best switch HA: SONiC (MC-LAG + warm restart), Cumulus (MLAG + ISSU), Arista (MLAG + SSO)
Management & Automation
All 33 tools.
| Tool | CLI | Web UI | API | Ansible | NETCONF | gNMI |
|---|---|---|---|---|---|---|
| pfSense | Shell | Yes | FauxAPI; Plus REST | Community | No | No |
| OPNsense | Shell | Yes | Yes (REST) | Community | No | No |
| IPFire | Shell | Yes | No | No | No | No |
| VyOS | Yes (Vyatta) | No | Yes (HTTP, NETCONF) | Yes | Yes | No |
| Firewalld | Yes | No | Yes (D-Bus) | Yes | No | No |
| nftables | Yes (nft) | No | No | No | No | No |
| Shorewall | Yes | No | No | No | No | No |
| FortiGate | Yes | Yes | Yes (REST) | Yes | No | No |
| Palo Alto | Yes | Yes | Yes (XML/REST) | Yes | No | No |
| Sophos XGS | Ltd | Yes | Yes (REST) | Limited | No | No |
| Cisco FP | Yes | Yes (FMC) | Yes (FMC REST) | Yes | No | No |
| Check Point | Yes | Yes (Smart) | Yes (Mgmt API) | Yes | No | No |
| WatchGuard | Yes | Yes | Yes (REST) | No | No | No |
| Untangle | Ltd | Yes | Yes (REST) | No | No | No |
| Barracuda | Yes | Yes | Yes (REST) | No | No | No |
| SonicWall | Yes | Yes | Yes (REST) | No | No | No |
| Juniper SRX | Yes (Junos) | Yes | Yes (REST, XML) | Yes | Yes | No |
| UniFi GW | Ltd | Yes | Yes (UniFi API) | Community | No | No |
| FRRouting | Yes (vtysh) | No | SNMP; YANG (evolving) | Yes (frr.frr) | Partial | No |
| BIRD | Yes (birdc) | No | No (birdwatcher 3rd) | No | No | No |
| OpenBGPD | Yes (bgpctl) | No | No | No | No | No |
| GoBGP | Yes (gobgp) | No | Yes (gRPC) | No | No | No |
| ExaBGP | No (daemon) | No | Yes (HTTP, stdin) | No | No | No |
| MikroTik | Yes | Yes (WebFig) | Yes (REST v7) | Community | No | No |
| OpenWrt | Yes (ash) | Yes (LuCI) | Yes (ubus JSON-RPC) | Community | No | No |
| TNSR | Yes (CLISH) | No | Yes (RESTCONF) | Yes | Yes | No |
| SONiC | Yes (KLISH) | Yes (SONiC-UI) | Yes (REST, gNMI) | Yes | Yes | Yes |
| Cumulus | Yes (NVUE) | No | Yes (NVUE REST) | Yes (official) | Yes | No |
| Arista cEOS | Yes (EOS) | No | Yes (eAPI, REST) | Yes (official) | Yes | Yes |
| Juniper cRPD | Yes (Junos) | No | Yes (REST, XML) | Yes (official) | Yes | Yes |
| DANOS | Yes (Vyatta) | No | Yes (REST) | Yes | Yes | No |
| OcNOS | Yes (IOS-style) | No | Yes (REST) | Yes | Yes | Yes |
| Pica8 | Yes (Juniper) | AmpCon | Yes (REST) | Yes | Yes | No |
Best firewall automation: FortiGate (REST + Ansible + FortiManager), Palo Alto (REST + Ansible
- Panorama), Juniper SRX (NETCONF + Ansible)
Best routing automation: Arista cEOS (eAPI + gNMI + NETCONF + Ansible), Juniper cRPD (NETCONF + gNMI + Ansible), SONiC (REST + gNMI + NETCONF)
gNMI streaming telemetry: SONiC, Arista cEOS, Juniper cRPD, OcNOS
SSO / OIDC Comparison
Firewall tools only – routing tools use RADIUS/TACACS+ for management access rather than web-based SSO.
The notes below assume Authentik as the identity provider. OIDC is the preferred SSO protocol.
| Tool | OIDC | SAML | LDAP | RADIUS | Authentik Notes |
|---|---|---|---|---|---|
| pfSense | No | No | Yes | Yes | VPN via Authentik LDAP; admin via LDAP |
| OPNsense | No | No | Yes | Yes | VPN via Authentik LDAP; TOTP built-in |
| IPFire | No | No | No | No | Local auth only |
| VyOS | No | No | No | Yes | RADIUS via Authentik FreeRADIUS |
| Firewalld | N/A | N/A | N/A | N/A | PAM-based OS auth |
| nftables | N/A | N/A | N/A | N/A | Kernel-level; OS auth |
| Shorewall | N/A | N/A | N/A | N/A | Config files; OS auth |
| FortiGate | No | Yes (FMgr) | Yes | Yes | FortiManager SAML via Authentik |
| Palo Alto | No | Yes (Panorama) | Yes | Yes | Panorama SAML via Authentik |
| Sophos XGS | Yes (Central) | Yes | Yes | Yes | Sophos Central OIDC via Authentik |
| Cisco FP | No | Yes (FMC) | Yes | Yes | FMC SAML via Authentik |
| Check Point | No | Yes (Smart) | Yes | Yes | SmartConsole SAML via Authentik |
| WatchGuard | Yes (Cloud) | Yes | Yes | Yes | WG Cloud OIDC/SAML via Authentik |
| Untangle | No | No | Yes | Yes | LDAP/RADIUS for user auth |
| Barracuda | No | Yes (Cloud) | Yes | Yes | Cloud portal SAML via Authentik |
| SonicWall | No | Yes (NSM) | Yes | Yes | NSM SAML via Authentik |
| Juniper SRX | No | Yes (SD Cloud) | Yes | Yes | Cloud portal SAML; Junos RADIUS |
| UniFi GW | Yes (UniFi ID) | No | No | Yes | UniFi SSO; no Authentik federation |
Best SSO: WatchGuard Cloud (OIDC + SAML), Sophos Central (OIDC + SAML), cloud management consoles (SAML universally supported)
No SSO (device-level): All firewalls use LDAP/RADIUS at device level; SSO is at the central management console, not the device web UI
Central Management & Multi-Tenancy
Firewall tools only (18 tools).
| Tool | Central Mgmt | Multi-Tenant | MSP Console | Templates | API |
|---|---|---|---|---|---|
| pfSense | No (FauxAPI) | No | No | No | FauxAPI; Plus REST |
| OPNsense | No (REST API) | No | No | No | Yes (REST) |
| IPFire | No | No | No | No | No |
| VyOS | No (Ansible) | No | No | Via automation | Yes (HTTP, NETCONF) |
| Firewalld | N/A | N/A | N/A | N/A | D-Bus |
| nftables | N/A | N/A | N/A | N/A | N/A |
| Shorewall | N/A | N/A | N/A | N/A | N/A |
| FortiGate | Yes (FortiMgr) | Yes (ADOMs) | Yes (MSP mode) | Yes (policies) | Yes (REST) |
| Palo Alto | Yes (Panorama) | Yes (DGs) | Yes (Panorama) | Yes (stacks) | Yes (XML/REST) |
| Sophos XGS | Yes (Central) | Yes | Yes (Partner) | Yes (policies) | Yes (REST) |
| Cisco FP | Yes (FMC) | Yes (domains) | No | Yes (inherit) | Yes (REST) |
| Check Point | Yes (MDS) | Yes (domains) | No | Yes (layers) | Yes (Mgmt API) |
| WatchGuard | Yes (Cloud) | Yes (tiers) | Yes (MSP) | Yes (cloud) | Yes (REST) |
| Untangle | Yes (Cmd Ctr) | Yes | Yes (MSP) | Yes (policy) | Yes (REST) |
| Barracuda | Yes (FW CC) | Yes | Yes (MSP) | Yes (repo obj) | Yes (REST) |
| SonicWall | Yes (NSM/CSC) | Yes | Yes (MSP) | Yes (templates) | Yes (REST) |
| Juniper SRX | Yes (Junos Space) | Yes (LSYS) | No | Yes (templates) | Yes (REST, NETCONF) |
| UniFi GW | Yes (UniFi App) | Partial (sites) | No | Yes (profiles) | Yes (UniFi API) |
Best central management: FortiGate (FortiManager ADOMs), Palo Alto (Panorama device groups), Check Point MDS (multi-domain)
Best MSP support: WatchGuard Cloud (purpose-built MSP), FortiGate (FortiManager MSP), SonicWall NSM, Barracuda Control Center
Monitoring Integration
All 33 tools. monitoring stack integration for platform health, routing protocol state, and security event monitoring.
| Tool | SNMP | Syslog | NetFlow/sFlow | gNMI | BMP |
|---|---|---|---|---|---|
| pfSense | Yes | Yes | Yes (softflowd) | No | No |
| OPNsense | Yes | Yes | Yes (netflow plugin) | No | No |
| IPFire | Yes | Yes | No | No | No |
| VyOS | Yes | Yes | Yes (NetFlow, sFlow) | No | No |
| Firewalld | N/A | Yes (journald) | N/A | No | No |
| nftables | N/A | Yes (kernel log) | N/A | No | No |
| Shorewall | N/A | Yes (syslog) | N/A | No | No |
| FortiGate | Yes (full MIB) | Yes | Yes (NetFlow, sFlow) | No | No |
| Palo Alto | Yes (full MIB) | Yes | Yes (NetFlow) | No | No |
| Sophos XGS | Yes (full MIB) | Yes | Yes (NetFlow) | No | No |
| Cisco FP | Yes (full MIB) | Yes | Yes (NSEL) | No | No |
| Check Point | Yes (full MIB) | Yes | Yes (R81+) | No | No |
| WatchGuard | Yes (full MIB) | Yes | No | No | No |
| Untangle | Yes | Yes | No | No | No |
| Barracuda | Yes (full MIB) | Yes | Yes (NetFlow) | No | No |
| SonicWall | Yes (full MIB) | Yes | Yes (IPFIX) | No | No |
| Juniper SRX | Yes (full MIB) | Yes | Yes (J-Flow, sFlow) | No | No |
| UniFi GW | Yes | Yes | No | No | No |
| FRRouting | Yes (AgentX) | Yes | No | No | Yes |
| BIRD | No | Yes | No | No | No |
| OpenBGPD | No | Yes | No | No | No |
| GoBGP | No | Yes | No | No | Yes |
| ExaBGP | No | Yes (JSON) | No | No | No |
| MikroTik | Yes (full MIB) | Yes | Yes (NetFlow/IPFIX) | No | No |
| OpenWrt | Yes (snmpd pkg) | Yes | No | No | No |
| TNSR | Yes | Yes | Yes (IPFIX) | No | No |
| SONiC | Yes | Yes | No | Yes | No |
| Cumulus | Yes | Yes | No | No | No |
| Arista cEOS | Yes | Yes | No | Yes | No |
| Juniper cRPD | Yes | Yes | No | Yes | No |
| DANOS | Yes | Yes | No | No | No |
| OcNOS | Yes | Yes | No | Yes | No |
| Pica8 | Yes | Yes | No | No | No |
Best monitoring integration (firewall): pfSense / OPNsense (Telegraf on-device, syslog + EVE JSON, community Grafana dashboards), VyOS (SNMP + NetFlow + syslog), UniFi (UnPoller for InfluxDB)
Best monitoring integration (routing): SONiC (SNMP + gNMI streaming), Arista cEOS (SNMP + gNMI + eAPI), Juniper cRPD (SNMP + gNMI + JTI), MikroTik (SNMP + NetFlow + REST API)
Best flow export: VyOS (NetFlow + sFlow), FortiGate (NetFlow + sFlow), Juniper SRX (J-Flow + sFlow), SonicWall (IPFIX), MikroTik (NetFlow/IPFIX), TNSR (IPFIX via VPP)
BMP (BGP Monitoring Protocol): FRRouting, GoBGP
gNMI streaming telemetry: SONiC, Arista cEOS, Juniper cRPD, OcNOS
Tools
35 tools.
Arista cEOS / CloudEOS
Arista cEOS (containerized EOS) and CloudEOS are virtual form factors of Arista’s Extensible Operating System.
License: Proprietary (proprietary) · Kind: web · Deploy: docker · SSO: none
Barracuda CloudGen Firewall
Barracuda CloudGen Firewall is a cloud-connected NGFW platform designed for distributed enterprise and MSP deployments.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none
BIRD Internet Routing Daemon
BIRD (BIRD Internet Routing Daemon) is a high- performance routing daemon developed by CZ.NIC, the Czech domain registry.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none
Check Point
Check Point is a pioneer in firewall technology, having invented the stateful inspection firewall in 1993.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none
Cisco Firepower
Cisco Firepower is Cisco’s next-generation firewall platform, combining the legacy ASA (Adaptive Security Appliance) firewall with the Firepower Threat Defense (FTD) software that integrates Snort-based IPS, application visibility and contr…
License: Proprietary (proprietary) · Kind: web · Deploy: appliance · SSO: none
DANOS (Disaggregated Network Operating System)
DANOS (Disaggregated Network Operating System) is a network operating system originally seeded by AT&T to the Linux Foundation in 2018.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none
ExaBGP
ExaBGP is a programmable BGP API engine designed for route injection, health-checking, anycast management, DDoS mitigation, and route analytics.
License: BSD-3-Clause (OSS) · Kind: web · Deploy: native · SSO: none
Firewalld
Firewalld is the standard dynamic firewall manager for Red Hat Enterprise Linux (RHEL), Fedora, CentOS Stream, Rocky Linux, AlmaLinux, and SUSE Linux Enterprise.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: docker, appliance · SSO: none
Fortinet FortiGate
Fortinet FortiGate is the world’s most deployed firewall platform, dominant in the SMB, midmarket, and increasingly in enterprise segments.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none
FRRouting (FRR)
FRRouting (FRR) is the de facto standard open-source routing suite for Linux. Forked from the Quagga project in 2017, FRR is developed under the Linux Foundation and has rapidly become the routing engine embedded in major network operating…
License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none
GoBGP
GoBGP is a BGP implementation written in Go, designed from the ground up for programmatic control via a gRPC API.
License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none
IP Infusion OcNOS
IP Infusion OcNOS (Open Compute Network Operating System) is a carrier-grade network operating system for disaggregated white-box switches and routers.
License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none
IPFire
IPFire is a hardened Linux-based firewall distribution focused on security, simplicity, and minimalism.
License: GPL-3.0-only (OSS) · Kind: web · Deploy: native · SSO: none
Juniper cRPD
Juniper cRPD (Containerized Routing Protocol Daemon) is the Junos routing stack extracted from Juniper hardware and packaged as a Docker container.
License: Proprietary (proprietary) · Kind: web · Deploy: docker · SSO: none
Juniper SRX
Juniper SRX Series is a family of next-generation firewalls that combine Junos OS routing capabilities with integrated security services.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none
LibreQoS
LibreQoS is a self-hosted traffic management and network operations platform designed for ISPs and enterprise networks.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none
MikroTik RouterOS
MikroTik RouterOS is a network operating system that runs on all MikroTik hardware (routers, switches, APs) and on x86 hardware via the Cloud Hosted Router (CHR) virtual machine image.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, docker, appliance · SSO: none
nftables / iptables
nftables is the modern Linux kernel packet filtering framework that replaces iptables, ip6tables, arptables, and ebtables. It provides a unified interface for IPv4, IPv6, ARP, and bridging packet classification and filtering.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: docker, k8s · SSO: none
NVIDIA Cumulus Linux
NVIDIA Cumulus Linux is a Linux-based network operating system for white-box and open networking switches.
License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none
OpenBGPD
OpenBGPD is a security-focused BGP daemon from the OpenBSD project, developed primarily by Henning Brauer and Claudio Jeker. It follows the OpenBSD philosophy of code correctness, minimal attack surface, and privilege separation.
License: ISC (OSS) · Kind: web · Deploy: native · SSO: none
OpenWrt
OpenWrt is a Linux-based operating system targeting embedded networking devices. It provides a fully writable filesystem with a package management system (opkg), allowing users to install software packages to customise the device for their…
License: GPL-2.0-only (OSS) · Kind: web · Deploy: docker, appliance · SSO: none
OPNsense
OPNsense is a FreeBSD-based firewall and routing platform forked from pfSense in 2015 by Deciso, a Dutch network security company.
License: BSD-2-Clause (OSS) · Kind: web · Deploy: native · SSO: none
Palo Alto Networks
Palo Alto Networks is the enterprise NGFW market leader, known for pioneering application-aware firewalling with App-ID technology.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none
pfSense
pfSense is a FreeBSD-based firewall and router platform that has been a staple of open-source network security since 2004.
License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none
Pica8 PicOS
Pica8 PicOS is a commercial network operating system for white-box and brite-box Ethernet switches, supporting L2/L3 switching and routing plus OpenFlow/SDN, managed centrally via the AmpCon platform.
License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none
Shorewall
Shorewall (Shoreline Firewall) is a high-level configuration tool for the Linux netfilter firewall. It reads human-readable configuration files and compiles them into nftables or iptables rules.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: appliance · SSO: none
SONiC (Software for Open Networking in the Cloud)
SONiC (Software for Open Networking in the Cloud) is an open-source network operating system for white-box switches, originally developed by Microsoft for Azure data center networks and later contributed to the Linux Foundation.
License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none
SonicWall
SonicWall is a commercial next-generation firewall vendor for SMB and MSP markets, running SonicOS with RFDPI deep packet inspection, IPS, content filtering, Capture ATP sandboxing, and VPN.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none
Sophos XGS (Sophos Firewall)
Sophos XGS is Sophos’s next-generation firewall platform, running Sophos Firewall OS (SFOS) on purpose-built XGS hardware with Xstream flow processors for hardware-accelerated TLS inspection and DPI.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none
TNSR
TNSR is a high-performance commercial software router from Netgate, using fd.io VPP and DPDK for line-rate forwarding, FRR dynamic routing, and native WireGuard and IPsec VPN on x86 hardware.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none
Ubiquiti UniFi Gateway
Ubiquiti UniFi Gateway (formerly UniFi Security Gateway / UniFi Dream Machine) is a line of gateway/firewall appliances managed through the UniFi Network Application.
License: Proprietary (proprietary) · Kind: web · Deploy: appliance · SSO: none
Untangle NG Firewall (Arista Edge Threat Management)
Untangle NG Firewall, now marketed as Arista Edge Threat Management following Arista Networks’ acquisition in 2022, is a software-based UTM platform that runs on commodity x86 hardware.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none
VyOS
VyOS is a Linux-based network operating system that provides enterprise routing, firewalling, and VPN capabilities via a unified CLI modeled after Juniper Junos and Cisco IOS.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none
WatchGuard Firebox
WatchGuard Firebox is a UTM/NGFW platform aimed at MSPs and SMBs, running Fireware OS with firewall, VPN, IPS, web filtering, and sandboxing, managed centrally through WatchGuard Cloud.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: none
Zenarmor
Zenarmor (formerly Sensei) is a proprietary next-gen firewall plug-in adding L7 app control, web filtering, and DPI to OPNsense, pfSense, FreeBSD, and Linux.
License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none