OpenFrame Gen1 is Here · AI-driven, autonomous IT management. Out of beta and ready for production.

Network Management and Monitoring

Real-time signature-based IDS/IPS powered by Suricata with community and emerging-threats rule sets plus email alerting.
IPsec, OpenVPN, and WireGuard site-to-site and remote-access VPNs configured directly via the WebGUI.
Squid-based caching proxy with URL filtering, category blocklists, and AD/LDAP authentication.
Recursive/forwarding DNS via Knot Resolver with DNS-over-TLS, malware/ad-domain firewalling, and SafeSearch enforcement.
Built-in package manager for installing extensions such as Icinga monitoring, Tor, and ModSecurity without leaving the managed OS.
Bandwidth prioritization and shaping rules for managing network performance across zones.
GPLv3 licensed with no feature paywalls; full firewall/VPN/IDS functionality is available at no cost.
Well known for low resource requirements, making it attractive for budget or repurposed-hardware deployments.
Near-monthly Core Updates deliver active security patching and new features.
WireGuard, OpenVPN, IPsec, and Suricata are integrated and configurable without add-ons.
A native add-on ecosystem lets admins bolt on monitoring (Icinga), Tor, and more.
The WebGUI has historically been limited to a single admin account, with multi-user role-based access a long-standing unresolved request.
2FA exists for OpenVPN client authentication, but the WebGUI admin login itself lacks built-in MFA.
Automation/integration relies on unofficial, experimental third-party projects rather than a supported API.
Only unofficial community-built Docker images exist; native container/K8s support remains an open request.
Fewer commercial integrations and cloud marketplace offerings than OPNsense/pfSense.
Be the first to share your experience with IPFire.
Reduce costs and increase revenue with OpenFrame innovative open source solutions. Coming soon…
Learn More about OpenFrame