A stable and free solution that is easy to maintain and suitable for small businesses
What is our primary use case?
We use the product as a perimeter firewall.
What is most valuable?
We can run it on any hardware.
What needs improvement?
The product must provide integration with other solutions.
For how long have I used the solution?
We have been using the solution for ten years.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
The tool is not very scalable. That is why we are planning to switch to a different product. The solution is used by one administrator and 75 end users in our organization.
Which solution did I use previously and why did I switch?
I have used SonicWall, Sophos, FortiGate, and Cisco Meraki. The choice of product depends on the context. Netgate pfSense is suitable for small businesses and homes. It is not the best solution for large deployments or branch offices. Sophos and FortiGate would be suitable for large companies.
How was the initial setup?
It is easy to install the tool. We need two weeks to deploy it. One person can deploy the solution. It is also easy to maintain. One person can maintain the solution.
What's my experience with pricing, setup cost, and licensing?
It is an open-source solution.
What other advice do I have?
Overall, I rate the product an eight out of ten.
pfSense and Netgate are great
What do you like best about the product?
We don't need it often, but when we do the email support has been quick and great.
What do you dislike about the product?
I'd like to see more development on the CE edition.
What problems is the product solving and how is that benefiting you?
Remote office connectivity and Intrusion detection
Working with PfSense for 7 years
What do you like best about the product?
PfSense has helped me and the companies I've worked with in many ways as general firewall solution as specific requirements. From complex datacenter applications to simple on-premises firewalls at branch offices. It always works and is simply the best bang for the buck. Ready to use PfSense+ appliances have gotten better and better over the years and are my preferred choice over de community edition. Community edition is still a good choice for specific needs or low budget requirements.
What do you dislike about the product?
There are no specific functions I dislike, but there is always room for improvement :) I can't really point out anything specific at this point.
What problems is the product solving and how is that benefiting you?
I've used PfSense for many different cases. As virtual appliances and ready to use PfSense+ hardware appliances. Specific for a general firewall solution but also as a OpenVPN server with FreeRADIUS as MFA installed or virtual appliance for handling many site-to-site VPN's. It has always met the needs and requirements.
A solid performing firewall platform, ideal for budget conscious applications
What do you like best about the product?
Low cost (in many cases free) firewall solution which can be run on no-brand hardware.
Very stable.
Advanced features such as load balancing, traffic shaping, multi-WAN support, hardware encryption support for VPN, etc. The capabilities of pfSense is comparible to very expensive enterprise grade systems that most SME's would be unable to afford.
Incredibly flexible configuration allow policy based routing and incredibly granular control over how traffic is handled.
Paid support available if required, making it ideal for budget commercial applications.
Dedicated hardware is available if a turn-key solution is desired. However, the branded hardware is expensive for what it is, but comes with suppport, etc.
What do you dislike about the product?
The move from pfSense CE to Plus has made the platform feel a little less "open" (although still based on open source software).
Now, the only install images available are old and need to be upgraded to from CE to Plus,to get the latest release.
Some of the advanced features, if customised, can produce unexpected behavior. For example, I'm using traffic shaping and multi-WAN and have unresolved issues with incorrect shaping being applied during WAN fail-over scenarios.
Branded appliances are a little expensive for their technical specs.
What problems is the product solving and how is that benefiting you?
Providing a secure, multi-WAN firewall for my SME. I have 3 x WAN connections (2 high speed land-lines plus a 4G backup) and pfSense has the capabilities to dynamically load balance across on connections, or fail-over. Which LAN devices use which WAN connections can be fully customised via policy-based routing, allowing me to offload certain traffic to certain WAN connections to maximise the benefit of multi-WAN.
Great products and support
What do you like best about the product?
Full featured appliances and software with great support at a fraction of the cost of some other similar products
What do you dislike about the product?
Lack of native centralised management can make large deployments more time consuming to manage or require developing own management tools/processes
What problems is the product solving and how is that benefiting you?
Highly available networks with complex and diverse routing, multi WAN, VPN and many filtering options are easily solved
Easy to managment
What do you like best about the product?
Many of the opensourse tools e.g. surica, opevnpn etc.
What do you dislike about the product?
Its interface should be more user-friendly. And there should be no application control.
What problems is the product solving and how is that benefiting you?
In our company it helps us to network with our partners as well as our branches.
Rock solid network firewall platform
What do you like best about the product?
pfSense Plus has truly transformed my network experience. Its intuitive interface simplifies setup, making it accessible to all levels of users, even my coworker, which usually does not have much experience with firewalls can manage it.
What do you dislike about the product?
In a virtualized environment the performance is not the best unfortunately.
Although we use high performance network cards on our hypervisor, it usually achieves about 2.5 Gigabits per seconds. Our regular setups do not reach those speeds, so this issue is not really important to us.
What problems is the product solving and how is that benefiting you?
We use pfSense to access our internal services through a wireguard vpn.
Also we filter our dns requests using pfBlocker which has the benefit of blocking ads and unwanted hostnames.
Does everything I need it to do
What do you like best about the product?
Easy to install and use. Reliable. I have 4 sites set up for NAT, DHCP, and Site-to-Site IPSec tunnels, and they work great!
What do you dislike about the product?
Needs Wireguard support integrated as a first-party feature, not an add-on.
What problems is the product solving and how is that benefiting you?
I use my pfsense appliances for persistent, always-on Site-to-Site IPSec tunnels. These allow WFH and off-site backup.
Fantastic when deployed in a virtualized environment
What do you like best about the product?
pfSense is easy and fast to deploy on a variety of platforms, depending on the use case. As an enterprise service provider, we assist our customers with the deployment and hosting of systems in our cloud environment as well as on-prem datacenters. These are typically customers who for reasons of their own are not willing to trust a public cloud with their data. Having the ability to choose a hardware solution or virtualized installation of the pfSense software grants lots of freedom in design and deployment.
The web-based interface is intuitive and responsive. It's certainly competitive with other offerings.
We have engaged with support on a one-off as well as TAC subscription basis and find Netgate / pfSense support to be first rate. We appreciate having a trusted partner.
What do you dislike about the product?
pfSense update management can sometimes be a bit ungainly. We'd really appreciate the ability to enable automated updates, especially to patch security threats. Or perhaps even a notification that would be sent to the pfSense admin when a new update is available.
Oftentimes the only time a user realizes there is an update is when they log into the web interface, and many of our users can go weeks or months between log-ins. A push or email notification would be helpful in this regard.
Lower-end pfSense appliances from Netgate have shown themselves to be a bit flaky. They will lock up on updates, or sometimes lock up for no reason at all. When this happens, we've noted that even a reboot of the system doesn't bring it back online and it must be accessed via emulated serial console (over USB) in order to manually walk it through a startup sequence. This is extremely problematic at remote / unstaffed locations.
What problems is the product solving and how is that benefiting you?
pfSense is great at the customer edge. IPSEC tunnels are quick and easy and perform especially well in our virtualized environments. In addition, the built-in OpenVPN with the client config builder is a great timesaver.
We're also experimenting with multi-tenancy options that allow a single installation to reach across multiple VLAN'd networks, providing unique internal subnets and routing for each.
Enterprise Firewall/router/VPN server, and so much more.
What do you like best about the product?
1) The software is open-source, so I could learn/play with how it works first. I could then decide if I wanted to move forward in using it.
2) It was easy to use.
3) There was tons of good documentation and even youtube videos on every feature I was interested in.
4) The support is awesome, I got a reply in 30 mins, on a Sunday on a long weekend to a ticket I submitted. The reply was from someone who actually read the ticket! (so rare on a ticket system's first response). The back and forth was precise and knowledgeable, I understood my problem and the solution straight away.
What do you dislike about the product?
I've had a version upgrade that remotely fails, so kept working, just didn't upgrade, and needs an onsite visit to manually backup the configs, connected a USB stick with the latest firmware, and a console cable to wipe and install the new version. Not ideal as I have a fair number of remote customers. However, I'm hoping this is a one-off situation.
What problems is the product solving and how is that benefiting you?
A dedicated firewall at an affordable price for very small businesses.