NetFlow can can be easier than implementing PCAP on your network. Also, NetFlow can help identify the traffic (source, destination, port, protocol, etc.) My UTM has an Executive Report that shows the standard stuff - Top Clients, Top Servers, 24 hour bandwidth timeline (per interface on the UTM, not per client), Top Web domains, etc.
From Virtual Private Networking to Intrusion Detection, Best in class, FREE Open Source Project.
Version 21.1 - 'Marvelous Meerkat'
From Virtual Private Networking to Intrusion Detection, Best in class, FREE Open Source Project.
On the other hand, the top reviewer of Sophos XG writes 'Light and stable with excellent real-time control '. OPNsense is most compared with pfSense, Untangle NG Firewall, Sophos UTM, Fortinet FortiGate and Kerio Control, whereas Sophos XG is most compared with Fortinet FortiGate, pfSense, Sophos UTM, WatchGuard Firebox and Sophos Cyberoam UTM. Sophos SG firewalls support IPFIX, which is compatible with Auvik TrafficInsights. These instructions assume: The date, time, and time zone are correctly set on the firewall. You have admin access to the Sophos SG web admin console. The IP address of your Auvik collector is known. Access the Sophos SG web interface.
Also checkout the Business Edition
Commercial firmware repository, OVA image, Central Management, integrated GeoIP database, 20% discount on business support package and an easy way to support the project!
SUBSCRIBE
OPNsense® FEATURES
Free & Open source - Everything essential to protect your network and more
FIREWALL
Stateful firewall with support for IPv4 and IPv6 and live view on blocked or passed traffic.MULTI WAN
Multi WAN capable including load balancing and failover support.
VIRTUAL PRIVATE NETWORKING
Integrated support for IPsec (including route based), OpenVPN as well as pluggable support for Tinc (full mesh VPN) and WireGuard.
HARDWARE FAILOVER
When you cannot afford downtime use our automatic and seamless hardware failover with state synchronization utilizing the common address redundancy protocol (CARP) to get the highest possible availability.SD-WAN
For easy setup, configuration and monitoring the ZeroTier plugin can be used to setup your Software Defined WAN within minutes.
INTRUSION DETECTION & PREVENTION
Get rid of the Trojans & CNC bots with state of the art inline intrusion prevention utilizing Suricata and Proofpoint's Emerging Threats Open rules integrated. Optional ET PRO (commercial subscription) or ET PRO Telemetry (sign-up for free).
TWO FACTOR AUTHENTICATION
2FA is supported throughout the system, for both the user interface as services such as VPN.
ROUTING PROTOCOLS
Pluggable support for OSPF and BGP using the Free Range Router project.
WEB FILTERING
Fully integrated web proxy with access control and support for external blacklists to filter unwanted traffic.
Other options include firewall aliases and DNS blacklisting.
INTUITIVE USER INTERFACE
The most intuitive fully responsive user interface you'll find in any open source firewall with integrated search option.
MULTI LANGUAGE
User selectable language support including English, Czech, Chinese, French, German, Italian, Japanese, Portuguese, Russian and Spanish.
ONLINE DOCUMENTATION
Fully searchable free online documentation.
WEB APPLICATION FILTERING - SENSEI (FREE & COMMERCIAL OPTION)
As part of our cooperation with Sunny Valley Networks a free version of Sensei can be installed as plugin.
For enhanced features a commercial version can be acquired online directly from Sunny Valley Networks.
AND MUCH MORE
CAPTIVE PORTAL, TCP/HTTP LOAD BALANCER, NETFLOW MONITORING, REST API, and more...
BUSINESS EDITION
The OPNsense® Business Edition is intended for companies, enterprises and professionals looking for a more selective upgrade path (lags behind the community edition), additional
commercial features and who want to support the project in a more commercial way compared to donating. Order your license today direct from our online shop.
OPNsense is a Deciso® Open Source Project
Deciso B.V. started the OPNsense project in 2014 with its first official release in 2015.
CHECKOUT DECISO