Average Ratings 2 Ratings
Average Ratings 0 Ratings
Description
CacheGuard-OS is an open-source Linux-based UTM gateway appliance OS that has been in active development since 2002. It is designed to run on commodity x86 hardware and act as the default route between an internal network and the internet, replacing the ISP-provided router as the traffic checkpoint.
The stack integrates: Squid (web cache and proxy), ClamAV (web antivirus), ModSecurity (WAF), StrongSwan (IPsec/IKEv2 VPN), IPRoute2 (QoS and WAN load balancing), NetFilter (stateful firewall), SSL inspection, and URL filtering. All components are configured through a web-based admin interface rather than directly, making the platform accessible to operators without deep Linux expertise while remaining auditable by those who want to inspect the underlying configuration.
The OS has been open-source since its first release — source ships on every installed appliance. It was recently published publicly on GitHub to make the codebase easier to browse and audit.
Target deployments are small to medium networks — SMBs, schools, and branch offices — where a commercial UTM appliance is overkill on budget but the threat surface is the same. Runs on bare metal or common hypervisors (VMware, VirtualBox, KVM, Hyper-V). No vendor lock-in, no subscription, no licence cost.
GitHub: cacheguard/CacheGuard-OS
Description
The recognition of web attacks utilizes a combination of AI and predefined rules, ensuring robust anti-bypass capabilities and maintaining low rates of both false negatives and false positives. This system effectively protects against prevalent web threats, such as those listed in the OWASP top 10, which encompasses issues like SQL injection, unauthorized access, cross-site scripting, and cross-site request forgery, among others. Additionally, users have the option to store essential web content in the cloud, enabling the publication of cached web pages that serve as backups to mitigate the risks associated with web page alterations. The backend infrastructure is safeguarded through a comprehensive strategy that includes concealing servers and applications before an attack occurs, preventing attacks during ongoing incidents, and replacing or concealing sensitive data after an event. Furthermore, the Web Application Firewall (WAF) conducts extensive DNS verification across the nation for the domains provided by customers, allowing it to identify and report any hijacking attempts affecting the protected domain names in different areas, which is crucial for preventing data breaches and financial losses linked to user hijacking on websites. This multifaceted approach not only fortifies security but also enhances user trust in web services.
API Access
Has API
Yes
API Access
Has API
No
Integrations
Proxmox VE
Yes
Tencent Cloud
No
VMware ESXi
Yes
VirtualBox
Yes
Pricing Details
$0
Free for any number of users. Optional paid support available.
Free Trial
No
Free Version
Yes
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
Yes
iPhone App
Yes
iPad App
Yes
Android App
Yes
Windows
Yes
Mac
Yes
Linux
Yes
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
Yes
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
Yes
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
Yes
In Person
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
CacheGuard Technologies
Founded
2025
Country
France
Website
www.cacheguard.com
Vendor Details
Company Name
Tencent
Founded
2013
Country
China
Website
intl.cloud.tencent.com/product/waf
Product Features
Network Security
Access Control
Yes
Analytics / Reporting
No
Compliance Reporting
No
Firewalls
Yes
Internet Usage Monitoring
No
Intrusion Detection System
No
Threat Response
No
VPN
Yes
Vulnerability Scanning
No
Web Application Firewalls (WAF)
Access Control / Permissions
Yes
Alerts / Notifications
No
Automate and Orchestrate Security
No
Automated Attack Detection
No
DDoS Protection
No
Dashboard
Yes
IP Reputation Checking
Yes
Managed Rules
Yes
OWASP Protection
Yes
Reporting / Analytics
Yes
Secure App Delivery
No
Server Cloaking
Yes
Virtual Patching
Yes
Zero-Day Attack Prevention
No
Product Features
Web Application Firewalls (WAF)
Access Control / Permissions
No
Alerts / Notifications
No
Automate and Orchestrate Security
No
Automated Attack Detection
No
DDoS Protection
No
Dashboard
No
IP Reputation Checking
No
Managed Rules
No
OWASP Protection
No
Reporting / Analytics
No
Secure App Delivery
No
Server Cloaking
No
Virtual Patching
No
Zero-Day Attack Prevention
No