Skip to content

Nuface Blog

隨意隨手記 Casual Notes

Menu
  • Home
  • About
  • Services
  • Blog
  • Contact
  • Privacy Policy
  • Login
Menu

Zenarmor Post-Installation Configuration & Usage Guide

Posted on 2025-11-122025-11-12 by Rico

1️⃣ Verify Status

Go to

Zenarmor → Dashboard

Check:

  • Engine status: Running
  • Monitored interface: LAN
  • Last update time
    → If all look fine, Zenarmor is ready.

2️⃣ Create and Apply Policies

Navigate to:

Zenarmor → Policies

Click Add Policy:

  • Name: Office_Network_Policy
  • Mode: Active or Monitor
  • Interface: LAN

🔹 Application Control

Block or allow specific app categories:

  • Social Media (Facebook, TikTok)
  • Streaming (YouTube, Netflix)
  • Games (Steam, Epic Games)

👉 Start in Monitor mode to evaluate before enforcing.


🔹 Web Controls

Enable or block website categories:

  • Adult, Gambling, Streaming, Shopping
    Use Whitelist / Blacklist for exceptions.

🔹 Security Controls

Activate:

  • Threat Intelligence feeds
  • DNS & IP reputation blocking
  • Malware domain prevention

🔹 Bandwidth Control (Business edition)

Assign limits per app type:

AppLimitPriority
VoIP2 MbpsHigh
Web2 MbpsMedium
FTP1 MbpsLow

3️⃣ Deploy Policy

Click Save & Deploy → confirm Active status.
You can verify results under Reports.


4️⃣ Analyze Reports

Go to:

Zenarmor → Reports

Useful dashboards:

  • Top Applications
  • Top Users
  • Blocked Connections
  • Threat Intelligence Alerts

Use time filters to drill down into specific hours or VLANs.


5️⃣ Advanced Tips

FeatureRecommendation
Threat IntelAlways enable
UpdateDaily auto-update
Policy ProfilesUse per VLAN/department
StorageUse Elasticsearch for large data
IntegrationCombine with OPNsense Firewall + Traffic Shaper

6️⃣ Best Practices

  1. Start in Monitor mode → then Active.
  2. Roll out policies gradually per VLAN.
  3. Review weekly reports and adjust.
  4. Combine L3/L4 (firewall) with L7 (Zenarmor) for full security coverage.

✅ 7️⃣ Conclusion

After setup, your OPNsense firewall now supports:

  • Deep application-level visibility
  • Content-based blocking
  • Real-time reporting and threat defense

Together, OPNsense + Zenarmor form a powerful NGFW solution
suitable for modern enterprise environments.

Recent Posts

  • Postfix + Let’s Encrypt + BIND9 + DANE Fully Automated TLSA Update Guide
  • Postfix + Let’s Encrypt + BIND9 + DANE TLSA 指紋自動更新完整教學
  • Deploying DANE in Postfix
  • 如何在 Postfix 中部署 DANE
  • DANE: DNSSEC-Based TLS Protection

Recent Comments

  1. Building a Complete Enterprise-Grade Mail System (Overview) - Nuface Blog on High Availability Architecture, Failover, GeoDNS, Monitoring, and Email Abuse Automation (SOAR)
  2. Building a Complete Enterprise-Grade Mail System (Overview) - Nuface Blog on MariaDB + PostfixAdmin: The Core of Virtual Domain & Mailbox Management
  3. Building a Complete Enterprise-Grade Mail System (Overview) - Nuface Blog on Daily Operations, Monitoring, and Performance Tuning for an Enterprise Mail System
  4. Building a Complete Enterprise-Grade Mail System (Overview) - Nuface Blog on Final Chapter: Complete Troubleshooting Guide & Frequently Asked Questions (FAQ)
  5. Building a Complete Enterprise-Grade Mail System (Overview) - Nuface Blog on Network Architecture, DNS Configuration, TLS Design, and Postfix/Dovecot SNI Explained

Archives

  • December 2025
  • November 2025
  • October 2025

Categories

  • AI
  • Apache
  • Cybersecurity
  • Database
  • DNS
  • Docker
  • Fail2Ban
  • FileSystem
  • Firewall
  • Linux
  • LLM
  • Mail
  • N8N
  • OpenLdap
  • OPNsense
  • PHP
  • QoS
  • Samba
  • Switch
  • Virtualization
  • VPN
  • WordPress
© 2025 Nuface Blog | Powered by Superbs Personal Blog theme