The solution is being used for monitoring and as a firewall.
OPNsense® Firewall/Router/VPN/IDPS
OPNsense | OPNsense 25.1Linux/Unix, FreeBSD OPNsense® 25.1 - 64-bit Amazon Machine Image (AMI)
External reviews
External reviews are not included in the AWS star rating for the product.
A monitoring solution that is user friendly and easy to configure
What is our primary use case?
What is most valuable?
The solution is user-friendly and easy to configure.
What needs improvement?
You will need additional training before you can actually start to use it. You will need to gain some extensive knowledge.
For how long have I used the solution?
I have been using OPNsense for one year.
What do I think about the scalability of the solution?
It is a scalable solution. Approximately fifty people are using the solution.
Which solution did I use previously and why did I switch?
I have used FortiGate. For security reasons, we moved to OPNsense.
How was the initial setup?
The initial setup is straightforward. The deployment took a couple of minutes.
What's my experience with pricing, setup cost, and licensing?
We are using the paid version.
What other advice do I have?
I rate the overall solution an eight out of ten.
Which deployment model are you using for this solution?
Reliable and secure solution with community edition best-suited for small businesses and home networks
What is most valuable?
The most valuable feature is the Dual WAN in OPNSense, which offers advanced capabilities. It has cost-effective communication options and the flexibility to deploy on your hardware. I like the security aspects, particularly through package managers. It allows for subscription-based enhancements, providing an additional layer of security to the network.
What needs improvement?
I would like better documentation concerning the provided packages and their integration. Improved guidance on package usage and integration beyond relying on external tutorials or community support would be beneficial. Additionally, having community support available for the free edition, which is suitable for home users, would be valuable.
For how long have I used the solution?
I have been using the solution for the past two months.
What do I think about the stability of the solution?
The solution is stable. I rate it an eight out of ten.
What do I think about the scalability of the solution?
In terms of scalability, I rate it around eight out of ten because it excels in handling various tasks. Beyond security features, it supports routing, VPN setups, and traffic monitoring with additional packages like Snort and Suricata. This flexibility allows for a wide range of functionalities. I have 200 users for the solution.
How was the initial setup?
The initial setup was straightforward for me. It took me approximately two days to set up the system initially. Subsequently, I began testing by progressively increasing the number of connections, deploying it through the unified features, and carefully monitoring specific ports while observing how it handles DHCP releases, IPs, and overall traffic. This process extended over about a week.
To begin the initial setup, you need to search for and download the ISO to initiate the process, followed by a two-step procedure. Afterwards, you proceed with command-line configurations, including setting up IP addresses. Once this initial phase is complete, navigation through the graphical user interface (GUI) becomes more straightforward. However, certain commands and configurations may still pose challenges. I rate it a seven out of ten.
What's my experience with pricing, setup cost, and licensing?
I would rate the pricing a nine out of ten, especially considering the availability of a free community edition. This makes it an excellent solution for small businesses, home use, or scenarios with around fifty connections or computers.
Which other solutions did I evaluate?
I have worked with MikroTik and Ubiquiti Networks EdgeRouter.
What other advice do I have?
I would recommend testing the solution. It’s good for security features. For the community version of the solution, I rate it an eight out of ten.
Which deployment model are you using for this solution?
Has valuable VPN capabilities, but the scalability needs improvement
What is our primary use case?
It is a firewall.
How has it helped my organization?
The VPN has helped us a lot.
What is most valuable?
It has firewall and VPN capabilities, which are very valuable features.
What needs improvement?
The scalability needs improvement.
For how long have I used the solution?
I have been working with OPNsense for the past five years.
What do I think about the stability of the solution?
I would rate the stability a six out of ten because we've encountered issues with OPNsense when establishing a side-to-side VPN using IPSec.
What do I think about the scalability of the solution?
I would rate the scalability a five out of ten.
Which solution did I use previously and why did I switch?
The configuration and access VPN functionality in OPNsense are satisfactory and work well. Currently, I prefer using Azure Firewall for my firewall needs, even though it might not be the absolute best option. My preference is due to a lack of experience with other Windows-based solutions.
How was the initial setup?
The deployment process takes almost an hour. The installation process involves several steps. First, you need to install the software. Then, configure the interfaces as needed. After that, establish the necessary rules for the software to function correctly. Finally, configure the VPN settings to ensure secure communication. I rate the solution a seven out of ten.
What's my experience with pricing, setup cost, and licensing?
I would rate the pricing a three out of ten.
What other advice do I have?
It's easy to configure, and it's good. I rate it a seven out of ten.
Which deployment model are you using for this solution?
Robust network security and management offering a user-friendly interface, open-source flexibility, and cost-effectiveness, with challenges regarding initial setup and the absence of official support
What is our primary use case?
The primary use case is managing security and commercial network traffic.
What is most valuable?
The DNS-level filtering is impressive for thwarting time scanners. The VPN functionality is also crucial for my needs, as I connect to multiple locations simultaneously. Running the CBN server on the VPN is exceptionally reliable and efficient.
What needs improvement?
The interface is user-friendly, but there's room for improvement in terms of intuitiveness. The bundle management aspect requires additional attention to make it more intuitive, especially for inspecting high-level traffic. This is crucial, especially for larger companies where the existing features might not be the most optimal choice, given limitations like printer constraints. For high availability, it's crucial to have a method in place where a designated component oversees the entire process. Given that OPNsense plays a pivotal role as a firewall, safeguarding against various threats, having a reliable backup ensures uninterrupted protection even if unforeseen events impact the primary virtual machine. It would be beneficial if OPNsense supported additional virtualization platforms like Hyper-V from Microsoft and VMware, similar to how Kaspersky has integrated them.
For how long have I used the solution?
I have been working with it for approximately six months.
What do I think about the stability of the solution?
It usually demonstrates a high level of stability, with some minor challenges. I would rate it nine out of ten.
What do I think about the scalability of the solution?
During the installation process, there were some limitations, but it was generally fine for specific tasks. Aside from these aspects, it demonstrated good scalability. I would rate it eight out of ten.
How are customer service and support?
I haven't come across a dedicated support page. I've never had to use it, and generally, with open-source solutions like OPNsense, there's an assumption that there isn't an official support team, unlike proprietary options such as SysTrack, Sophos, or FortiGate.
How was the initial setup?
I would rate the initial setup as seven out of ten because sometimes we are facing issues, particularly with IP addressing. It takes a couple of hours to navigate and make the necessary preparations. Given that OPNsense is open-source, there isn't official support available at the moment, which adds an extra layer of complexity to issue resolution.
What about the implementation team?
Initially, I activated Hyper-V and downloaded the installation file. The setup process was straightforward but not entirely seamless. The installation itself took around fifteen minutes, but there was a hiccup during the assignment of IP addresses, particularly for WAN and LAN. OPNsense can function both as a production machine and an operating system, but for the latter, a server with two network cards is required—one for WAN and one for LAN.
What's my experience with pricing, setup cost, and licensing?
It is a free solution, and when you compare it to alternatives like FortiGate, which is quite powerful but also costly, the value becomes evident. Even with options like Sophos, where responsiveness might not be as high as FortiGate, the significant cost factor still applies. The contrast in functionality and the price difference makes OPNsense an attractive option, providing all the necessary features without the hefty price tag associated with some commercial solutions.
What other advice do I have?
It's crucial to have a firewall solution that aligns seamlessly with an open-source approach. Connecting it twice allows for a comprehensive understanding of the network, analyzing factors such as traffic volume, technical specifics, and the nature of inbound and outbound traffic. This step is paramount in selecting the right firewall, considering it provides a holistic view of the network's dynamics. Overall, I would rate it seven out of ten.
Which deployment model are you using for this solution?
An easy-to-use and open source solution that helps secure our network
What is our primary use case?
We use the solution to secure our network and kid’s Internet usage. Since COVID-19, remote work has become relatively standard.
What is most valuable?
OPNsense is easy to use and open source. When the setup is complete, you can forget about the software itself. You can check the logs occasionally and set up some automatic reporting.
What needs improvement?
The user interface could be improved, and the DNS section should be more intuitive.
For how long have I used the solution?
I have been using OPNsense for a few days. We use the updated version of the solution.
What do I think about the stability of the solution?
I rate the solution’s stability a ten out of ten.
What do I think about the scalability of the solution?
I rate the solution’s scalability a nine out of ten.
Which solution did I use previously and why did I switch?
I’ve used pfSense and openWRT before.
How was the initial setup?
The initial setup is straightforward. Being an engineer myself, I have no issues with systems on networks. The installation took around two hours to complete. When you download a system, it takes time. I’ve also installed one package named Zenarmor.
What other advice do I have?
Overall, I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Provides network checking, firewall, and web filtering capabilities
What is our primary use case?
I'm using it as a proxy in several scenarios.
What is most valuable?
There are a lot of features I like. One of the most valuable features is the network checking. Additionally, the firewall and web filtering functionalities are highly useful.
What needs improvement?
There are some add-ons that need enhancements to make management easier for users, especially the reporting features. Some reports don't show the level of detail I'm looking for, and I've had trouble installing certain add-ons, especially for Internet bandwidth shaping within my company. So, this is an area of improvement for me.
For how long have I used the solution?
I have been using OPNsense for more than six years. I currently use the latest version.
What do I think about the stability of the solution?
I would rate stability a seven out of ten. I've encountered some instability after a recent update.
It just doesn't respond, so I have to restart it over and over again to try to figure out what the problem is. I haven't been able to find the problem yet.
What do I think about the scalability of the solution?
I would rate the scalability a nine out of ten. There is room for improvement.
In my organization, there are 400 users, and OPNsense serves as our gateway and proxy for all of them. Therefore, all the users go through the gateway.
How was the initial setup?
The initial setup is very easy. The installation just takes minutes, but setting up everything may take a couple of hours.
What's my experience with pricing, setup cost, and licensing?
It's reasonably priced. It's not expensive.
What other advice do I have?
Overall, I would rate the solution an eight out of ten. I just want to say that it's the best open-source firewall. Strongly recommended.
Rock-solid stability and open source tool
What is most valuable?
It's open source.
What needs improvement?
There are a few weaknesses. For example, there is a lack of some features that I have in certain commercial products.
Some of the features include classified traffic and better blocking of newly registered DNS domains.
For how long have I used the solution?
I have been working with OPNsense for about three years. I use it both in my company and at home.
What do I think about the stability of the solution?
OPNsense is very stable, rock-solid.
What do I think about the scalability of the solution?
It is a scalable solution. We haven't encountered any performance issues.
How was the initial setup?
The initial setup was easy.
What other advice do I have?
Overall, I would rate OPNsense an eight out of ten. There is still some room for improvement.
A simple and free solution requiring no maintenance while providing stability to its users
What is our primary use case?
We use OPNsense in our company to secure our servers.
What is most valuable?
To be honest with you, I feel that its valuable features are that it is simple and free.
What needs improvement?
The interface of the solution is an area with shortcomings. The interface of the solution could be made better.
The user experience when we create policies can be made easier. Also, maybe some features should be added to the cloud.
For how long have I used the solution?
I have been using OPNsense for around six years. Also, I don't remember the version of the solution I am using.
What do I think about the stability of the solution?
Stability-wise, I rate the solution a ten out of ten.
What do I think about the scalability of the solution?
We have 25 users who are all technical people using OPNsense in my organization.
Scalability-wise, I rate the solution a seven out of ten.
Which solution did I use previously and why did I switch?
As technical people, we have used many solutions previously for our company and customers. For customers, we have used Fortinet, Palo Alto, and others.
I didn't switch from Palo Alto to OPNsense. I use OPNsense because Palo Alto is used for enterprises. For me, I prefer open-source products. It's more flexible for us.
How was the initial setup?
I believe the setup phase was a fusion of straightforwardness and complexity. It's not complicated, so it's fine.
It's deployed on-premises because we put it on our server, and it is hosted in Germany.
What's my experience with pricing, setup cost, and licensing?
It's a free solution.
What other advice do I have?
The solution requires no maintenance.
I would recommend OPNsense to others.
Overall, I rate the solution between seven to eight out of ten.
Which deployment model are you using for this solution?
Useful GUI, frequent updates, and free to use
What is our primary use case?
OPNsense is a firewall.
How has it helped my organization?
The solution has helped our organization because we are able to easily set up IPSec and VPN tunnels.
What is most valuable?
The most valuable features of OPNsense are the GUI and frequent updates.
What needs improvement?
When using the solution at the beginning was difficult. There was a steep learning curve.
In a feature release, it would be helpful to have some features that the new generation firewalls have, such as IPS.
For how long have I used the solution?
I used OPNsense within the last 12 months.
What do I think about the stability of the solution?
I rate the stability of OPNsense a ten out of ten.
What do I think about the scalability of the solution?
We have approximately two large customers using this solution.
I rate the scalability of OPNsense a seven out of ten.
How are customer service and support?
I needed to use the support twice. They could improve the support.
I rate the support of OPNsense a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I use Fortinet before in another company.
How was the initial setup?
The deployment took approximately two hours.
I rate the initial setup of OPNsense a seven out of ten.
What's my experience with pricing, setup cost, and licensing?
We are using the free open-source version of the solution. There is a paid version that has additional features.
I rate the price of OPNsense a five out of ten.
What other advice do I have?
I would recommend using this solution.
I rate OPNsense a nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
It's opnsense. Works well, if you read the docs.
If you've used opnsense on hardware, which you probably have if you're reading this - you know what to expect. It's a good product and super useful. What I will say is that between the confusion that can be AWS networking and the fact that the initial root password is shown once, it can be challenging. However, the documentation for this AMI is extremely good, and once set up, works exactly like you would expect it to. I would highly recommend it.