Markets & Features

DefenseBolt® – High-End Security Made Easy
Your Next Gen DefenseBolt Really Protects Your Network.


Markets

Businesses

Protect your business network and secure your connections using OpenVPN or IPsec. From the stateful inspection firewall to the inline intrusion detection & prevention system everything is included for free.Use the traffic shaper to enhance your network performance and prioritise voice over ip above other traffic. Backup your configuration to the cloud automatically, no need for manual backups anymore!

Remote Offices & SOHO

Utilise the integrated site to site VPN (IPsec or SSL VPN / OpenVPN) to create a secure network connection to and from your remote offices. Enjoy the easy configuration and online searchable documentation with simple how-to type of articles to get you started, quickly.

School Networks

Limit and share available bandwidth evenly amongst students and utilise the category based web filtering to filter unwanted traffic such as adult content and malicious websites. Its easy to setup as no additional plugins nor packages are required. Teach about security or use our development documentation to show how an Model Viewer Controller works. You and your students are invited to join the effort and OPNsense community!

Hotels & Campings

Hotels and campings usually utilise a captive portal to allow guests (paid) access to internet for a limited duration. Guests need to login using a voucher they can either buy or obtain for free at the reception. OPNsense has a built-in captive portal with voucher support and can easily create them on the fly.


FEATURE HIGHLIGHTS

DefenseBolt Features a complete high-end security platform for free.

Take a look at some of our  highlights, but remember DefnseBolt Features much more than we can showcase.

✓ QoS ✓ 2FA ✓ OpenVPN ✓ IPSec ✓ CARP ✓ Captive Portal ✓ Proxy ✓ Webfilter ✓ IDPS ✓ Netflow ✓ and More

Dashboard

DefenseBolt offers a dashboard feature to quickly check the status of your DefenseBolt. Shown is the latest version with drag and drop multi collumn support.

Modern User Interface

The modern user interface offers a great user experience with multi language support, built-in help and quick navigation with the searchbox.
Shown is the fast search navigation option.

Stateful Firewall

A stateful firewall is a firewall that keeps track of the state of network connections (such as TCP streams, UDP communication) traveling across it. DefenseBolt offers grouping of Firewall Rules by Category, a great feature for more demanding network setups.

Aliases & GeoLite Country Database

Managing firewall rules have never been this easy. By using Aliases you can group mulitple IP’s or Host into one list, to be used in firewall rules. Additionally IP or Hostnames can be fetched from external URLs, examples are DROP (Do Not Route Or Peer), Abuse.ch’s Ransomware tracker and the built-in Maxmind GeoLite2 Country database.

Traffic Shaper

Traffic shaping within DefenseBolt is very flexible and is organised around pipes, queues and corresponding rules. The pipes define the allowed bandwidth, the queues can be used to set a weight within the pipe and finally the rules are used to apply the shaping to a certain package flow. The shaping rules are handled independently from the firewall rules and other settings.

Two-factor authentication

Two-factor authentication also known as 2FA or 2-Step Verification is an authentication method that requires two components, such as a pin/password + a token. DefenseBolt offers full support for Two-factor authentication ( 2FA ) throughout the entire system utilising TOTP with for instance Google Authenticator.

Supported 2FA services include:

  • DefenseBolt Graphical User Interface
  • Captive Portal
  • Virtual Private Networking – OpenVPN & IPsec
  • Caching Proxy

Captive Portal

Captive Portal allows you to force authentication, or redirection to a click through page for network access. This is commonly used on hot spot networks, but is also widely used in corporate networks for an additional layer of security on wireless or Internet access. DefenseBolt offer most enterprise features including Radius and voucher support.

Virtual Private Network – IPsec  & OpenVPN GUI

DefenseBolt offers a wide range of VPN technologies ranging from modern SSL VPN’s to well known IPsec as well as older (now considered insecure) legacy options such as L2TP and PPTP. Site-to-Site and road warrior setups are possible and with the integrated OpenVPN client exporter, the client can be configured within minutes. Looking for a IPsec or OpenVPN GUI, you just found something better!

High Availability / Hardware Failover (CARP)

DefenseBolt utilises the Common Address Redundancy Protocol or CARP for hardware failover. Two or more firewalls can be configured as a failover group. If one interface fails on the primary or the primary goes offline entirely, the secondary becomes active. Utilising this powerful feature of DefenseBolt creates a fully redundant firewall with automatic and seamless fail-over. While switching to the backup network connections will stay active with minimal interruption for the users.

Caching Proxy

The caching proxy offered by DefenseBolt is fully featured and includes category based webfiltering, extensive Access Control Lists and can run in transparent mode. The proxy can be combined with the traffic shaper to enhance user experience. Integration with most professional Anti-Virus solutions is possble trough the ICAP interface.

SSL Finger Printing

The IPS option to allow user defined rules include the option for SSL fingerprinting. With this option SSL communication can be blocked at the inital connection attempt by dropping the SSL key exchange.

Backup & Restore

Better safe than sorry, always keep an up to date backup of your configuration. It’s easy with DefenseBolt.

History
Automatic backups of configuration changes make it possible to review history and restore previous settings.

Backup
Easily download a backup from within the GUI and store on a safe place.
Encrypt the backup with a strong password and make plain text unreadable for unauthorised persons.

Restore
Upload your configuration backup file and restore it with ease.

Cloud Backup
DefenseBolt supports encrypted cloud backup of your configuration with the option to keep backups of older files (history). For this purpose Google drive support has been integrated into the user interface.

Reporting & Monitoring

DefenseBolt offers many options for reporting and monitoring the system, these include:

System Health
A modern take on RRD graphs with the option to zoom in and export data.

Netflow Exporter
Use your favorite netflow analyser to see most active users, interfaces, ports & applications.

Insight – Intergrated Netflow Analyser
DefenseBolt also offers an integrated Netflow analyser without the need for additional plugins or tools, similar to what you may find in high-end commercial products.

Firmware & Plugins

Offering a robust firmware upgrade path to react on emerging threats in a fashionable time; DefenseBolt is equipped with a reliable and secure update mechanism to provide weekly security updates. A plugin mechanism can be used to install additional packages and customisations.

Free Up-to-Date Online Manual

Our online documentation is completely searchable, up-to-date and offered for free. Features are explained in detail and examples are provided in the form of how-to’s , making configuring DefenseBolt as simple as possible. And if you are a developer then you’ll find all about our framework, coding guidelines and hello-world plugin well organised in the Developers section. See https://docs.defensebolt.in/.