Zedmos

Firewall as a Service

Sell the firewall as a monthly service, without a vendor cloud in the middle

Zedmos is licensed per firewall and billed monthly in arrears on the MSP tier. It runs on hardware you choose, or on the OPNsense and pfSense CE boxes your customers already have. When a licence lapses, management goes read-only; the firewall keeps enforcing.

The organisations page of the Zedmos console with counters for organisations, branches, gateways and owners.
Organisations: one per customer, in one treeconsole.zedmos.com

How a new customer is brought on

Nobody has to be on site, and nobody types the customer's network settings into the console. The appliance arrives, is plugged in, and places itself.

The gateways page of the console: a register-token button, counters for total, online, connected and offline nodes, filters, and a list of firewalls with their version, an update button and a live-watch button.
  1. One token per customer

    Generate a register token, put it in the installer, and the firewall registers itself into the right organisation and branch on first boot.

  2. The estate at a glance

    Registered, online, connected, offline. A firewall that stopped reporting is a number here before it is a phone call.

  3. Filter by customer, site or state

    The same list serves one engineer looking after one customer and the person responsible for all of them.

  4. Versions, per firewall

    Every firewall shows what it runs. A release is offered, not forced: a few firewalls first, then the rest, or the whole estate at once.

  5. Live watch, from here

    Open the live sessions of any firewall in the list without logging in to the firewall itself.

Zedmos publishes the releases. You decide which firewalls take them, and when.console.zedmos.com · Gateways
  1. You

    Create the customer

    One organisation for the customer and a branch for each of their sites. This is the structure their reports, their policy and their invoices will hang from.

  2. You

    Mint an install token

    The token carries which customer the firewall belongs to. It is short-lived and can be revoked before it is used, so handing one to an installer is not handing over your console.

  3. Zedmos

    The firewall places itself

    On first boot it redeems the token and appears under the right customer, in the right branch. Nobody reconciles a list of serial numbers afterwards.

  4. Zedmos

    Your baseline applies

    Policy attached at the customer or the branch reaches the new firewall without an edit — and reaches the next one they add, too. Their one exception is recorded at their scope, not by forking your baseline.

How the service is built

Per firewall, monthly, in arrears

You are billed for what ran last month. Add a customer in March, pay for March in April. No per-device count on the firewall, no per-seat surprise when a client grows.

Hardware you choose

Standard x86 from the validated configurations, an appliance from your OEM partner under your brand, or the box the customer already runs. The licence does not care which.

Enforcement survives billing

An expired licence makes the firewall read-only in the console. It never drops the customer's traffic. Your service does not go dark because an invoice is late.