Control D
Control D is a customizable DNS filtering and traffic redirection platform that leverages Secure DNS protocols like DNS-over-HTTPS, DNS-over-TLS and DNS-over-QUIC, with support for Legacy DNS.
With Control D you can: block malicious threats, block unwanted types of content network wide (ads & trackers, IoT telemetry, adult content, socials, and more), redirect traffic using transparent proxies and gain visibility on network events and usage patterns, with client level granularity.
Think of it as your personal Authoritative DNS resolver for the entire Internet that gives you granular control over what domains get resolved, redirected or blocked.
Learn more
Cloudflare
Cloudflare is the foundation of your infrastructure, applications, teams, and software. Cloudflare protects and ensures the reliability and security of your external-facing resources like websites, APIs, applications, and other web services. It protects your internal resources, such as behind-the firewall applications, teams, devices, and devices. It is also your platform to develop globally scalable applications. Your website, APIs, applications, and other channels are key to doing business with customers and suppliers. It is essential that these resources are reliable, secure, and performant as the world shifts online. Cloudflare for Infrastructure provides a complete solution that enables this for everything connected to the Internet. Your internal teams can rely on behind-the-firewall apps and devices to support their work. Remote work is increasing rapidly and is putting a strain on many organizations' VPNs and other hardware solutions.
Learn more
Cisco Umbrella
Are you enforcing acceptable web use in accordance with your internal policies? Are you required by law to comply with internet safety regulations like CIPA? Umbrella allows you to effectively manage your user's internet connection through category-based content filtering, allow/block list enforcement, and SafeSearch browsing enforcement.
Learn more
CacheGuard
CacheGuard-OS is an open-source Linux-based UTM gateway appliance OS that has been in active development since 2002. It is designed to run on commodity x86 hardware and act as the default route between an internal network and the internet, replacing the ISP-provided router as the traffic checkpoint.
The stack integrates: Squid (web cache and proxy), ClamAV (web antivirus), ModSecurity (WAF), StrongSwan (IPsec/IKEv2 VPN), IPRoute2 (QoS and WAN load balancing), NetFilter (stateful firewall), SSL inspection, and URL filtering. All components are configured through a web-based admin interface rather than directly, making the platform accessible to operators without deep Linux expertise while remaining auditable by those who want to inspect the underlying configuration.
The OS has been open-source since its first release — source ships on every installed appliance. It was recently published publicly on GitHub to make the codebase easier to browse and audit.
Target deployments are small to medium networks — SMBs, schools, and branch offices — where a commercial UTM appliance is overkill on budget but the threat surface is the same. Runs on bare metal or common hypervisors (VMware, VirtualBox, KVM, Hyper-V). No vendor lock-in, no subscription, no licence cost.
GitHub: cacheguard/CacheGuard-OS
Learn more