Average Ratings 2 Ratings
Average Ratings 0 Ratings
Description
CacheGuard-OS is an open-source Linux-based UTM gateway appliance OS that has been in active development since 2002. It is designed to run on commodity x86 hardware and act as the default route between an internal network and the internet, replacing the ISP-provided router as the traffic checkpoint.
The stack integrates: Squid (web cache and proxy), ClamAV (web antivirus), ModSecurity (WAF), StrongSwan (IPsec/IKEv2 VPN), IPRoute2 (QoS and WAN load balancing), NetFilter (stateful firewall), SSL inspection, and URL filtering. All components are configured through a web-based admin interface rather than directly, making the platform accessible to operators without deep Linux expertise while remaining auditable by those who want to inspect the underlying configuration.
The OS has been open-source since its first release — source ships on every installed appliance. It was recently published publicly on GitHub to make the codebase easier to browse and audit.
Target deployments are small to medium networks — SMBs, schools, and branch offices — where a commercial UTM appliance is overkill on budget but the threat surface is the same. Runs on bare metal or common hypervisors (VMware, VirtualBox, KVM, Hyper-V). No vendor lock-in, no subscription, no licence cost.
GitHub: cacheguard/CacheGuard-OS
Description
The unique PICOS open NOS, equipped with closely integrated control planes, provides network operators with precise and non-intrusive oversight of their enterprise applications, allowing for extensive and adaptable traffic analysis and real-time attack prevention. For achieving zero-trust networking and establishing software-defined perimeters, PICOS stands out as the optimal solution. Our premier open network operating system is compatible with open switches ranging from 1G to 100G interfaces, sourced from a diverse selection of Tier 1 manufacturers. This comprehensive licensing package delivers unparalleled support for enterprise functionalities available in the market. It incorporates the Debian Linux distribution, featuring an unchanged kernel to enhance DevOps programmability to its fullest extent. Furthermore, the Enterprise Edition is enhanced by AmpCon, an automation framework based on Ansible, which integrates Zero-Touch Provisioning (ZTP) with the Open Network Install Environment (ONIE), streamlining the deployment and management of open network switches throughout the enterprise. With such advanced capabilities, organizations can ensure their networks are not only efficient but also secure against evolving threats.
API Access
Has API
Yes
API Access
Has API
No
Integrations
Chef
No
NEC EXPRESSCLUSTER
No
ONOSYS
No
Proxmox VE
Yes
Puppet Enterprise
No
Rackspace OpenStack
No
SaltStack
No
VMware ESXi
Yes
VirtualBox
Yes
Zabbix
No
Integrations
Chef
Yes
NEC EXPRESSCLUSTER
Yes
ONOSYS
Yes
Proxmox VE
No
Puppet Enterprise
Yes
Rackspace OpenStack
Yes
SaltStack
Yes
VMware ESXi
No
VirtualBox
No
Zabbix
Yes
Pricing Details
$0
Free for any number of users. Optional paid support available.
Free Trial
No
Free Version
Yes
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
Yes
iPhone App
Yes
iPad App
Yes
Android App
Yes
Windows
Yes
Mac
Yes
Linux
Yes
Chromebook
No
Deployment
Web-Based
No
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
Yes
Chromebook
No
Customer Support
Business Hours
Yes
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
Yes
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
Yes
In Person
Yes
Types of Training
Training Docs
Yes
Webinars
Yes
Live Training (Online)
No
In Person
Yes
Vendor Details
Company Name
CacheGuard Technologies
Founded
2025
Country
France
Website
www.cacheguard.com
Vendor Details
Company Name
Pica8
Founded
2009
Country
United States
Website
www.pica8.com/product/
Product Features
Network Security
Access Control
Yes
Analytics / Reporting
No
Compliance Reporting
No
Firewalls
Yes
Internet Usage Monitoring
No
Intrusion Detection System
No
Threat Response
No
VPN
Yes
Vulnerability Scanning
No
Web Application Firewalls (WAF)
Access Control / Permissions
Yes
Alerts / Notifications
No
Automate and Orchestrate Security
No
Automated Attack Detection
No
DDoS Protection
No
Dashboard
Yes
IP Reputation Checking
Yes
Managed Rules
Yes
OWASP Protection
Yes
Reporting / Analytics
Yes
Secure App Delivery
No
Server Cloaking
Yes
Virtual Patching
Yes
Zero-Day Attack Prevention
No