7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

6 alternatives ranked by real activity

Open-source Cisco Umbrella alternatives

A curated, ranked list of the 6 best open-source alternatives to Cisco Umbrella.

The best open-source alternative to Cisco Umbrella is Pi-hole. If that doesn't suit you, other good options are AdGuard Home, Technitium DNS Server, Blocky and OPNsense.

Cisco Umbrella alternatives are mainly networking & VPN tools, but some are also security tools. 5 of them shipped code in the last 30 days, 6 can be self-hosted, and 3 use a permissive licence.

Last updated October 3, 2026 · ranked by GitHub stars, growth and recent commits

Pi-hole

A network-wide ad blocker that works as a DNS sinkhole on your own Linux hardware, with a web dashboard and no client software needed.

GitHub stars
61k
Last commit
6 days ago
Latest release
v6.4.3
Self-hosted
Yes
pi-hole.netPi-hole homepage screenshot

Pi-hole is a DNS sinkhole that blocks unwanted content, mainly ads, for every device on your network without installing client-side software. You run it on your own Linux hardware, such as a Raspberry Pi, and point your network's DNS at it. The project is written mostly in shell script, and GitHub lists its license as 'Other'.

Because blocking happens at the DNS level, it also covers non-browser locations such as ad-heavy mobile apps and smart TVs, and it speeds up everyday browsing by caching DNS queries. It includes a command-line interface and a responsive web dashboard for viewing and controlling the instance, can optionally act as a DHCP server so all devices are protected automatically, and blocks over both IPv4 and IPv6.

An automated installer walks through setup in under ten minutes, and alternative methods allow reviewing the code first: cloning the repository, downloading the installer manually, or using the official Docker images. Pi-hole runs on modest hardware and, on server-grade machines, can handle very large query volumes. It suits home networks and small offices that want central ad and tracker blocking.

Key features

  • Network-wide ad blocking via DNS
  • No client-side software required
  • Web dashboard for monitoring and control
  • Optional built-in DHCP server
  • DNS query caching
  • IPv4 and IPv6 blocking
  • Official Docker images

Pricing: Free and open source software that runs on your own hardware.

Read more about Pi-holeWebsite GitHub

AdGuard Home

AdGuard Home is a self-hosted DNS server that blocks ads and trackers for every device on your network without client software.

GitHub stars
37k
Last commit
today
Latest release
v0.107.79
Licence
GPL-3.0
Self-hosted
Yes
adguard.comAdGuard Home homepage screenshot

AdGuard Home is network-wide software for blocking ads and tracking. Once it is set up, it covers all devices on your home network without any client-side software. It works as a DNS server that redirects tracking and advertising domains to a black hole, so devices never connect to those servers. It is free and open source under the GPL-3.0 license.

The server is written mainly in Go with a TypeScript web interface, and it shares a lot of code with the public AdGuard DNS service. Encrypted DNS protocols are supported, including DNS-over-HTTPS, DNS-over-TLS, DNS-over-QUIC and DNSCrypt. Installation is done with an automated script for Linux, Unix, macOS, FreeBSD and OpenBSD, or manually following the wiki, and there is an HTTP API. The project documents how it differs from Pi-hole and from browser-based ad blockers.

Key features

  • Network-wide ad and tracker blocking via DNS
  • No software needed on client devices
  • DNS-over-HTTPS, TLS, QUIC and DNSCrypt support
  • Web interface and HTTP API
  • Automated install script for Unix-like systems
  • Wiki guides and build-from-source instructions

Pricing: Free and open source under the GPL-3.0 license.

Read more about AdGuard HomeWebsite GitHub

Technitium DNS Server

Technitium DNS Server, a self-hosted authoritative and recursive DNS server with ad blocking, encrypted DNS and a web console.

GitHub stars
10k
Last commit
6 days ago
Latest release
v15.5.1
Licence
GPL-3.0
Self-hosted
Yes
technitium.comTechnitium DNS Server homepage screenshot

Technitium DNS Server is an open-source DNS server that can act as both an authoritative and a recursive resolver. People host it themselves for privacy and security, and it works out of the box with little or no configuration. A friendly web console is reachable from any modern browser.

It can block ads and malware at the DNS level for an entire network. By forwarding queries over DNS-over-TLS, DNS-over-HTTPS or DNS-over-QUIC, it limits what an internet provider can see or tamper with. A local DNS server also gives logs and statistics for understanding network activity, serves many queries from cache, and allows network-wide domain blocking. Repository topics also mention DHCP server functions and DNS-over-Tor.

The server is written in C# on .NET and runs on Windows, Linux, macOS and Raspberry Pi, with Docker support. It is released under the GPL-3.0 license, and the project site at technitium.com provides downloads and documentation. It is suited to home networks and organizations that want more control over name resolution.

Key features

  • Authoritative and recursive DNS server
  • Network-wide ad and malware blocking
  • DNS-over-TLS, HTTPS and QUIC forwarders
  • Browser-based web console
  • DNS logs and statistics
  • Windows, Linux, macOS and Raspberry Pi support

Pricing: Free and open source under the GPL-3.0 license.

Blocky

Blocky is a Go-based DNS proxy and ad blocker for local networks, with per-client rules, caching and modern DNS protocol support.

GitHub stars
7k
Last commit
4 days ago
Latest release
v0.35.0
Licence
Apache-2.0
Self-hosted
Yes
0xerr0r.github.ioBlocky homepage screenshot

Blocky is a Go program that acts as a DNS proxy and ad blocker for local networks. It answers DNS queries for devices on the network and blocks unwanted domains using external lists for ads and malware, along with allowlists. It is a self-hosted alternative in the same space as Pi-hole.

Blocking rules can differ per client group, such as kids or smart home devices, and lists reload periodically. Blocky can inspect CNAME responses and IP addresses as well as request domains, and supports regular expressions. Beyond blocking it offers custom DNS resolution for chosen names, conditional forwarding, per-group upstream resolvers, caching with prefetching of frequent queries, DNS over HTTPS, TLS, QUIC and HTTP/3, DNSSEC validation, Prometheus metrics and Grafana dashboards.

Blocky is licensed under Apache-2.0. According to its README it collects no user data, telemetry or statistics, and it uses a low memory footprint, which makes it practical to run on small home servers.

Key features

  • DNS blocking with external lists
  • Allow and deny lists per client group
  • Custom DNS and conditional forwarding
  • Caching with prefetching
  • DNS over HTTPS, TLS and QUIC
  • DNSSEC validation
  • Prometheus metrics and Grafana dashboards

Pricing: Free and open source under the Apache-2.0 licence.

Read more about BlockyWebsite GitHub

OPNsense

An open-source firewall and routing platform; this repository holds its web GUI, API and system backend, licensed under BSD-2-Clause.

GitHub stars
4.7k
Last commit
yesterday
Licence
BSD-2-Clause
Self-hosted
Yes
opnsense.orgOPNsense homepage screenshot

OPNsense is an open-source firewall project, and this repository contains its web GUI, API and systems backend. Its topics point to a broad feature set that includes a firewall, intrusion prevention, proxy, VPN, traffic shaping, a captive portal and routing, built on a BSD base.

The project invites developers to contribute and has designed its build process so that anyone can build and write code. Build tools are freely available in a separate tools repository, an architecture overview is on docs.opnsense.org, and the repository offers Makefile targets such as make package for assembling a package from the current state of the code. The team aims to evolve toward a new codebase gradually rather than in one big switch.

OPNsense is written mostly in PHP and is committed to staying available under the 2-clause BSD license, with every contribution required to carry the same terms. Contributions can be as simple as testing functionality, filing bug reports or sending pull requests.

Key features

  • Web GUI for firewall management
  • API and system backend
  • Intrusion prevention and proxy
  • VPN and traffic shaping
  • Captive portal and routing
  • BSD-based platform

Pricing: Free and open source under the BSD-2-Clause licence.

Read more about OPNsenseWebsite GitHub

pfSense

Free firewall and router distribution based on FreeBSD, managed through a web interface and extendable with packages.

GitHub stars
5.7k
Last commit
6 mo ago
Licence
Apache-2.0
Self-hosted
Yes
pfsense.orgpfSense homepage screenshot

pfSense is a network firewall distribution built on the FreeBSD operating system. It uses a custom kernel and bundles third-party free software to cover routing and security tasks. The project began in 2004 as a fork of the m0n0wall project and has since diverged significantly.

All components are configured through a web interface, so the project says no UNIX knowledge or command-line work is needed and rule sets never have to be edited by hand. A package system adds functionality, and the project states that with packages it can match or exceed the functionality of common commercial firewalls, without artificial limits. It lists products from Check Point, Cisco, Juniper, Sonicwall, Netgear and Watchguard among those it has replaced.

pfSense is copyright Rubicon Communications (Netgate) and published under an open source license, listed as Apache-2.0 on GitHub. Netgate sells bundled hardware appliances and commercial support, which is the main way the team funds development. Administrators used to commercial firewalls may find the interface familiar, though others face a learning curve.

Key features

  • FreeBSD-based firewall and router distribution
  • Web interface for all configuration tasks
  • Package system for extra functionality
  • No command-line work required for setup
  • Hardware appliances and commercial support available

Pricing: Free open-source software; Netgate sells bundled hardware appliances and commercial support.

Read more about pfSenseWebsite GitHub

Cisco Umbrella alternatives: questions

What is the best open-source alternative to Cisco Umbrella?
Pi-hole is the top-ranked open-source alternative to Cisco Umbrella on Enlisted: A network-wide ad blocker that works as a DNS sinkhole on your own Linux hardware, with a web dashboard and no client software needed. Other strong options are AdGuard Home, Technitium DNS Server, Blocky and OPNsense.
Are these Cisco Umbrella alternatives free?
All 6 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer.
How is this list of Cisco Umbrella alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 5 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all