Average Ratings 2 Ratings

Total
ease
features
design
support

Average Ratings 1 Rating

Total
ease
features
design
support

Description

CacheGuard-OS is an open-source Linux-based UTM gateway appliance OS that has been in active development since 2002. It is designed to run on commodity x86 hardware and act as the default route between an internal network and the internet, replacing the ISP-provided router as the traffic checkpoint. The stack integrates: Squid (web cache and proxy), ClamAV (web antivirus), ModSecurity (WAF), StrongSwan (IPsec/IKEv2 VPN), IPRoute2 (QoS and WAN load balancing), NetFilter (stateful firewall), SSL inspection, and URL filtering. All components are configured through a web-based admin interface rather than directly, making the platform accessible to operators without deep Linux expertise while remaining auditable by those who want to inspect the underlying configuration. The OS has been open-source since its first release — source ships on every installed appliance. It was recently published publicly on GitHub to make the codebase easier to browse and audit. Target deployments are small to medium networks — SMBs, schools, and branch offices — where a commercial UTM appliance is overkill on budget but the threat surface is the same. Runs on bare metal or common hypervisors (VMware, VirtualBox, KVM, Hyper-V). No vendor lock-in, no subscription, no licence cost. GitHub: cacheguard/CacheGuard-OS

Description

The premier hybrid and multi-cloud platform offers an advanced suite of security features including next-gen WAF, API Security, RASP, Enhanced Rate Limiting, Bot Defense, and DDoS protection, specifically engineered to address the limitations of outdated WAF systems. Traditional WAF solutions were not built to handle the complexities of modern web applications that operate in cloud, on-premise, or hybrid settings. Our cutting-edge web application firewall (NGWAF) and runtime application self-protection (RASP) solutions enhance security measures while ensuring reliability and maintaining high performance, all with the most competitive total cost of ownership (TCO) in the market. This innovative approach not only meets the demands of today's digital landscape but also prepares organizations for future challenges in web application security.

API Access

Has API

API Access

Has API

Screenshots View All

Screenshots View All

Integrations

Expel
Indent
JupiterOne
Proxmox VE
VMware ESXi
VirtualBox

Integrations

Expel
Indent
JupiterOne
Proxmox VE
VMware ESXi
VirtualBox

Pricing Details

$0
Free for any number of users. Optional paid support available.
Free Trial
Free Version

Pricing Details

No price information available.
Free Trial
Free Version

Deployment

Web-Based
On-Premises
iPhone App
iPad App
Android App
Windows
Mac
Linux
Chromebook

Deployment

Web-Based
On-Premises
iPhone App
iPad App
Android App
Windows
Mac
Linux
Chromebook

Customer Support

Business Hours
Live Rep (24/7)
Online Support

Customer Support

Business Hours
Live Rep (24/7)
Online Support

Types of Training

Training Docs
Webinars
Live Training (Online)
In Person

Types of Training

Training Docs
Webinars
Live Training (Online)
In Person

Vendor Details

Company Name

CacheGuard Technologies

Founded

2025

Country

France

Website

www.cacheguard.com

Vendor Details

Company Name

Signal Sciences

Founded

2014

Country

United States

Website

www.signalsciences.com

Product Features

Network Security

Access Control
Analytics / Reporting
Compliance Reporting
Firewalls
Internet Usage Monitoring
Intrusion Detection System
Threat Response
VPN
Vulnerability Scanning

Web Application Firewalls (WAF)

Access Control / Permissions
Alerts / Notifications
Automate and Orchestrate Security
Automated Attack Detection
DDoS Protection
Dashboard
IP Reputation Checking
Managed Rules
OWASP Protection
Reporting / Analytics
Secure App Delivery
Server Cloaking
Virtual Patching
Zero-Day Attack Prevention

Product Features

Application Security

Analytics / Reporting
Open Source Component Monitoring
Source Code Analysis
Third-Party Tools Integration
Training Resources
Vulnerability Detection
Vulnerability Remediation

Firewall

Alerts / Notifications
Application Visibility / Control
Automated Testing
Intrusion Prevention
LDAP Integration
Physical / Virtual Environment
Sandbox / Threat Simulation
Threat Identification

Network Security

Access Control
Analytics / Reporting
Compliance Reporting
Firewalls
Internet Usage Monitoring
Intrusion Detection System
Threat Response
VPN
Vulnerability Scanning

Web Application Firewalls (WAF)

Access Control / Permissions
Alerts / Notifications
Automate and Orchestrate Security
Automated Attack Detection
DDoS Protection
Dashboard
IP Reputation Checking
Managed Rules
OWASP Protection
Reporting / Analytics
Secure App Delivery
Server Cloaking
Virtual Patching
Zero-Day Attack Prevention

Alternatives

SONiC Reviews

SONiC

NVIDIA Networking

Alternatives

Traceable Reviews

Traceable

Harness