We just use the solution normally for its basic firewall functionality. OPNsense with WireGuard and CrowdSec bouncers handles all our requirements.
OPNsense® Firewall/Router/VPN/IDPS
OPNsense | OPNsense 25.1Linux/Unix, FreeBSD OPNsense® 25.1 - 64-bit Amazon Machine Image (AMI)
External reviews
External reviews are not included in the AWS star rating for the product.
no support for nitro systems -> no serial console
instance not reachable after update -> no support for nitro systems (not possible to pick such an instance) -> no serial console -> not working for me.
Full featured open source firewall
OPNsense has a ton of features. Everything I need.
For security reasons there is no default password. This is nice from security point of view but can be confusing for new users. Therefore check documentation https://docs.opnsense.org/manual/how-tos/installaws.html#step-11-initial-root-password and have a look at console output after first boot.
Not able to Upgrade from 21.7.8
Hi
When I am trying to upgrade the opnsense from 21.7.8 to a newer version it is showing the following error. This is happening for the past few months
***GOT REQUEST TO CHECK FOR UPDATES***
Currently running OPNsense 21.7.8 (amd64/OpenSSL) at Sat Nov 19 13:44:46 IST 2022
Fetching changelog information, please wait... fetch: https://pkg.opnsense.org/FreeBSD:13:amd64/21.7/sets/changelog.txz.sig: Not Found
Updating OPNsense repository catalogue...
pkg: https://pkg.opnsense.org/FreeBSD:13:amd64/21.7/latest/meta.txz: Not Found
repository OPNsense has no meta file, using default settings
pkg: https://pkg.opnsense.org/FreeBSD:13:amd64/21.7/latest/packagesite.txz: Not Found
Unable to update repository OPNsense
Error updating repositories!
pkg: Repository OPNsense cannot be opened. 'pkg update' required
Checking integrity... done (0 conflicting)
Your packages are up to date.
***DONE***
Good
The deployment is easy and hassle free because it come configured out of the box, just need to setup a proper AWS infrastructure for it to funtion. Overall, it works fine for me.
does not work
the default login credentials do not work rendering this useless. if i cant login to opnsense this image is useless
Free to use, easy to manage, and offers good security options
What is our primary use case?
How has it helped my organization?
This is a free and secure solution that is easy to use.
What is most valuable?
The normal security options are great.
It's light and easy to manage.
The solution is very stable.
The initial implementation process is simple.
The solution offers a free version.
What needs improvement?
While they do have paid options that actually give better features, for most of the clients, if they tend to take a paid option will instead opt for Fortinet.
They should make it so that it's easier to reverse proxy integration.
For how long have I used the solution?
I have been using this solution for two years.
What do I think about the stability of the solution?
The product is quite stable and the performance is good. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
We can easily scale the solution if we need to. It's not difficult.
How are customer service and support?
I've only used the free version of the solution. I just have to dig into the forums to find everything I need. There isn't a central place you can reach out to. I've found all the answers I've needed so far via the forums. There's a lot of information there.
How was the initial setup?
The initial setup is straightforward. It's not overly complex or difficult.
What's my experience with pricing, setup cost, and licensing?
We're a customer and an end-user.
We are using the telemetry-free version of the solution.
Overall, the solution is quite affordable.
Which other solutions did I evaluate?
I'm aware of Fortinet as well.
It depends on price versus performance. If you're willing to pay, Fortinet's great. If you don't have the budget, OPNsense is more affordable.
What other advice do I have?
We do supply the solution and we do use it for ourselves.
I'd advise users to get the Geo functionality. It's a nice add-on, which we make use of a lot. It allows which countries are allowed to access your instances, which is very helpful.
I'd rate the solution at a nine out of ten.