Thoughts on pfSense?

Ian

Administrator
Joined
Feb 23, 2002
Messages
19,873
Reaction score
1,499
I was wondering if we've got any users of pfSense firewall here?

It's an open-source firewall that has some really high-end features (https://www.pfsense.org). I've got no need to switch to this firewall, but it was often mentioned when I was looking in to which router/firewall to buy. It looks like it's quite a popular option for home-labs, etc...

I did a search and saw that @Captain Jack Sparrow has used this before, so I'd be really interested to hear what you think of it :).
 

Captain Jack Sparrow

Anti-cryptominer
Joined
Jul 1, 2007
Messages
561
Reaction score
118
Hi Ian,

Sorry for the delay in getting back to you. Now, onto my impromptu review...

pfSense is a BSD-based versatile and free networking appliance. But I’m guessing you already knew that.

Here’s what you might not know, pfSense is optimised to run on very low performing hardware, and is good for ARM and 64-bit processors. Of course, you will need at least two physical NICs for this to work properly.

How suitable pfSense is for you depends on your expectations. You can’t expect a 1.4GHz CPU to keep up with 350Mbps throughput comfortably.

You haven’t given me much to go on regarding requirements. For a home network, I personally think it’s overkill. If you’re running a home lab or enjoy experimenting then it’s a great choice.

pfSense is modular. You can install various modules, for example, gateway-level antivirus and web filtering (even filtering HTTPS traffic is possible) but this will again take a toll on performance.

Previously, I used Sophos UTM in conjunction with pfSense to provide network access around the home on several subnets. The Sophos UTM would manage desktop and laptop PCs and pfSense was in charge of the Wi-Fi network (although it still passed web traffic to Sophos UTM for web filtering). The routing system is very versatile in pfSense, you can do just about anything.

I found the solution was too cumbersome to maintain, so I switched to Sophos XG firewall which rendered both appliances redundant.

pfSense doesn’t have a great GUI and this was one of the factors I considered before switching. It does have a very steep learning curve, so bear this in mind. I recommend trying it out in a virtual machine environment before deploying it to any production environment. This allows you to configure and test in a virtual environment, and once you’re happy, simple restore the configuration to a production environment and you’re good to go.

Unfortunately I no longer use it so my experience is somewhat limited. But I hope this was helpful, if you need any more information, let me know.

- Captain Jack Sparrow
 

Ian

Administrator
Joined
Feb 23, 2002
Messages
19,873
Reaction score
1,499
Thanks Capt., that's really helpful :)

I've been using UniFi's USG quite a bit recently, but there were a few features that I'd need pfSense to fully implement (however these were just little things that aren't worth rolling out new hardware/software for). However, the more I read about pfSense the more it looked like it would be a good bit of software for "prosumers".

Maybe one day I'll fire it up in a VM and give it a whirl, just out of curiosity :D.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top