Average Ratings 2 Ratings

Total
ease
features
design
support

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

CacheGuard-OS is an open-source Linux-based UTM gateway appliance OS that has been in active development since 2002. It is designed to run on commodity x86 hardware and act as the default route between an internal network and the internet, replacing the ISP-provided router as the traffic checkpoint. The stack integrates: Squid (web cache and proxy), ClamAV (web antivirus), ModSecurity (WAF), StrongSwan (IPsec/IKEv2 VPN), IPRoute2 (QoS and WAN load balancing), NetFilter (stateful firewall), SSL inspection, and URL filtering. All components are configured through a web-based admin interface rather than directly, making the platform accessible to operators without deep Linux expertise while remaining auditable by those who want to inspect the underlying configuration. The OS has been open-source since its first release — source ships on every installed appliance. It was recently published publicly on GitHub to make the codebase easier to browse and audit. Target deployments are small to medium networks — SMBs, schools, and branch offices — where a commercial UTM appliance is overkill on budget but the threat surface is the same. Runs on bare metal or common hypervisors (VMware, VirtualBox, KVM, Hyper-V). No vendor lock-in, no subscription, no licence cost. GitHub: cacheguard/CacheGuard-OS

Description

In today's communication networks, IP-based systems are increasingly central to connectivity. The rapid expansion of these networks is driven by a diverse range of users, including businesses, government bodies, and private individuals, all of whom depend on advanced and intricate services for their communication needs. This surge in network use presents significant challenges for information security, as vast quantities of data—potentially containing harmful elements like worms, viruses, or Trojans—are transmitted across public networks. To combat these threats, network security strategies can be applied both within the network and at the individual hosts connected to access routers. Adopting a host-based security approach has distinct advantages, particularly in terms of scalability; for instance, implementing security measures such as firewalls or antivirus software on separate hosts allows for uninterrupted data flow across the network. This flexibility enhances overall security without compromising network performance.

API Access

Has API Yes 

API Access

Has API No 

Screenshots View All

Screenshots View All

Integrations

Proxmox VE Yes 
VMware ESXi Yes 
VirtualBox Yes 

Integrations

Proxmox VE No 
VMware ESXi No 
VirtualBox No 

Pricing Details

$0
Free for any number of users. Optional paid support available.
Free Trial No 
Free Version Yes 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Deployment

Web-Based Yes 
On-Premises Yes 
iPhone App Yes 
iPad App Yes 
Android App Yes 
Windows Yes 
Mac Yes 
Linux Yes 
Chromebook No 

Deployment

Web-Based No 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows Yes 
Mac Yes 
Linux Yes 
Chromebook No 

Customer Support

Business Hours Yes 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) Yes 
In Person Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Vendor Details

Company Name

CacheGuard Technologies

Founded

2025

Country

France

Website

www.cacheguard.com

Vendor Details

Company Name

NeSSi2

Website

www.nessi2.de/framework.htm

Product Features

Network Security

Access Control Yes 
Analytics / Reporting No 
Compliance Reporting No 
Firewalls Yes 
Internet Usage Monitoring No 
Intrusion Detection System No 
Threat Response No 
VPN Yes 
Vulnerability Scanning No 

Web Application Firewalls (WAF)

Access Control / Permissions Yes 
Alerts / Notifications No 
Automate and Orchestrate Security No 
Automated Attack Detection No 
DDoS Protection No 
Dashboard Yes 
IP Reputation Checking Yes 
Managed Rules Yes 
OWASP Protection Yes 
Reporting / Analytics Yes 
Secure App Delivery No 
Server Cloaking Yes 
Virtual Patching Yes 
Zero-Day Attack Prevention No 

Product Features

Network Security

Access Control No 
Analytics / Reporting No 
Compliance Reporting No 
Firewalls No 
Internet Usage Monitoring No 
Intrusion Detection System No 
Threat Response No 
VPN No 
Vulnerability Scanning No 

Alternatives

SONiC Reviews

SONiC

NVIDIA Networking

Alternatives

Kerio Control Reviews

Kerio Control

GFI Software