Hey folks. I've been knee-deep in firewall rules and log files since the days of IPChains, and I'm always on the lookout for the next tool that actually makes life easier, not just adds another dashboard. Lately, I've been hearing a lot of buzz about Zenarmor (formerly Sensei) for OPNsense and pfSense.
I'm currently managing a few small business setups and a couple of personal home labs, all on OPNsense. The built-in reporting is... fine. But the application-level insight and real threat prevention Zenarmor promises is tempting. My big question is about scaling this up.
For those running it in an MSP or multi-tenant scenario:
* How does the pricing actually shake out? The per-endpoint model looks clean on paper, but I've been burned before when "endpoint" definitions get fuzzy with servers, IoT, etc. Does it feel fair?
* More importantly, how's the multi-tenant separation in practice? Can I truly silone off Client A's policies and reports from Client B, while managing it all from a single pane? Or am I better off spinning up separate firewalls/instances for each?
I remember trying to force-fit an early NGFW into a shared environment a decade ago. Ended up with a spaghetti mess of VLANs and policy groups that still haunts my dreams. 😅 Hoping this is more elegant.
If you're running it, what's your real-world throughput hit like on, say, a Protectli box with 4-6 cores? My rule of thumb is to cut the vendor's datasheet numbers in half, then maybe half again for good measure.
Appreciate any war stories or hard-earned config tips.
-- Dad
it worked on my machine
Been running it across about a dozen small business clients for the past eight months, so I can speak to the scaling. Your hunch about the endpoint definition is spot on. In my experience, it's been pretty transparent - it counts anything with an IP on your monitored networks. For most SMBs, that's user devices and servers, but you'll want to do a quick audit of "quiet" IoT stuff before committing.
On the multi-tenant front, the separation works well for policies and reporting. You can absolutely silo Client A from Client B from a single console, which is a huge time saver. The only caveat I've found is that global configuration changes, like updating threat intelligence feeds, apply across all tenants. It's not a deal-breaker, but it means you can't fine-tune that per client. For my use case, the single-pane management outweighs that limitation. Spinning up separate instances would be overkill unless you need completely independent admin roles.
Sample size matters.