Your rules keep working
Existing firewall rules, interfaces, NAT and VPNs are untouched. Zedmos adds inspection and policy above them rather than replacing them.
Migration
You do not have to replace anything to evaluate Zedmos. The same inspection engine that ships inside Zedmos NGFW also installs as a package on an OPNsense or pfSense box you already run, so you can put it in front of real traffic before you commit to hardware — and move the whole system across when it has earned it.
Existing firewall rules, interfaces, NAT and VPNs are untouched. Zedmos adds inspection and policy above them rather than replacing them.
The same nine pages and the same policy model on OPNsense and pfSense, so a mixed estate costs nothing extra to operate.
It installs from a package repository and uninstalls from the settings page. A trial commits the estate to nothing.