pfSense is a firewall and load management product available through the open source pfSense Community Edition, as well as a the licensed edition, pfSense Plus (formerly known as pfSense Enterprise). The solution provides combined firewall, VPN, and router functionality, and can be deployed through the cloud (AWS or Azure), or on-premises with a Netgate appliance. It as scalable capacities, with functionality for SMBs. As a firewall, pfSense offers Stateful packet inspection, concurrent…
$179
per appliance
Sophos SG Firewall Appliances
Score 8.5 out of 10
N/A
Sophos SG Firewall Appliances are designed to provide optimal protection for organizations of all sixes from small remote offices, to global organizations requiring high-availability and
pfSense is incredibly budget friendly and capable for organizations of all sizes. My specific scenario, working for a non-profit organization, requires budget consciences decisions without compromising security and function. pfSense has helped tremendously in accomplishing this. It specifically tackles advanced routing, static routing, remote access, intrusion prevention, in a single platform, mostly available for free.
Well suited in tech companies that have an IT person to monitor and adjust settings as needed. It is not SUPER user-friendly if you don't know what you are doing.
Easy to use. Good user interface design! Easy to understand and easy to set up.
Lower hardware requirement. 3 years ago, we used an old PC to run it. Now, we have changed to a router device with Celeron CPU and 8GB RAM. It runs smoothly with a 1000G commercial broadband.
I did kind of mention a Con in the Pro section with OpenVPN.
When I create a config for an employee other employees are able to login to that config.
I could be doing something wrong when I am making it - I am not afraid to admit that as I am pretty new to all of this, but it seems like it builds a key and I would think the key would be unique in some way to each employee, but I could be wrong.
I actually do not have a lot of Con's for this software - I did not get to set this up on our work network so I am not sure of any downfalls when installing.
I installed this on my personal machine in a Hyper-V environment to get a feel for it before I started working on it at work and it seemed pretty smooth. I didn't run into any issues.
I rated Sophos SG Firewall a 9 out of 10 because it has consistently provided strong and reliable security for our organization over the past five years. Its unified features like IPS, VPN, web filtering, and reporting make it easy to manage and highly effective in protecting our network. The interface is user-friendly, and support from Sophos has been timely and helpful. I deducted one point only because deeper cloud-native integration and more advanced analytics would further enhance its future readiness.
The pfSense UI is easy to navigate and pretty go look at. It is much better than some high dollar firewalls that just throw menus you you. The pfSense UI is quick and responsive and makes sense 99% of the time. Changes are committed quickly and the hardware rarely requires a reboot. It just runs.
I rated the availability of Sophos SG Firewall a 10 because, in our experience, it has been highly reliable and available whenever we needed it. We have not faced any significant application errors or unplanned outages. The system has been robust, ensuring continuous protection and minimal downtime, even during firmware updates or configuration changes. Its stability and uptime have been consistent, allowing us to trust it as a critical part of our network security infrastructure.
I rated the performance of Sophos SG Firewall a 10 because it consistently delivers fast and reliable results. Pages load quickly, reports are generated within a reasonable time frame, even for complex queries, and overall system responsiveness is excellent. Additionally, the firewall integrates seamlessly with other software and systems without causing any noticeable slowdowns or performance degradation. Its optimized performance has contributed to smooth network operations and minimal disruption to other services, making it a highly reliable solution for our needs.
The biggest selling point for sophos is their vendor support. Those guys put a smile on our faces. There are multiple ways you can contact their support like chat, or telephone or email. They are very responsive and they do have very knowledgable and patient support staff. We have raised tickets at all odd hours and they have been addressed correctly
I rated the in-person training a 10 because the sessions were thorough, engaging, and well-structured. The trainers had a deep understanding of the Sophos SG Firewall and were able to clearly explain both basic and advanced features. The hands-on approach allowed us to directly apply what we were learning, which made the training highly practical and valuable. Additionally, the trainers were available to address specific questions and provide real-time troubleshooting during the sessions, making it an overall positive experience.
I was very satisfied with the implementation of the Sophos SG Firewall, giving it a rating of 9. One key insight from the implementation process is that while the setup was relatively straightforward, it’s crucial to carefully plan the network configuration in advance, especially for high availability (HA) and VPN setups. Ensuring compatibility with existing infrastructure and performing thorough testing before going live can significantly reduce issues later on. Additionally, leveraging the built-in wizards and configuration guides helped streamline the process, but hands-on testing was essential to ensure everything worked as expected in our specific environment.
Meraki has a unified management login for all devices, which is nice. It also has decent content filtering, both areas where pfSense is weaker. Where pfSense far ouclasses Meraki is in the ease of use and the other width of features. These include features such as better VPN interoperability, non-subscription based pricing, auditability, not relying on the infrastructure of a third party, more transparency of what's actually going on, easier to deploy replacements if hardware fails. Additionally, the NAT management for pfSense seems to be a bit better, as you can NAT between any network segment and not just the LAN segments out the WAN interfaces.
It certainly stacks up well as it is very competitive in the pricing segment while having all the features that an ideal NGFW should possess. Basic functionalities like Network Firewall, Proxy and VPN work flawlessly while advanced features like IPS perform reasonably well. The detection content is very relevant and performs well.
I rated the contract terms and pricing structure a 9 because, overall, they were fair and competitive. The unit pricing for the Sophos SG Firewall was reasonable considering the features and performance offered, and the billing frequency was flexible, allowing us to align it with our budget cycles. However, one area that could be improved is the pricing for multi-year commitments—there could be more significant discounts or additional incentives for long-term agreements. Overall, the structure worked well for our needs, but some adjustments could make it even more cost-effective.
I rated the product's scalability a 9 because Sophos SG Firewall offers excellent flexibility and can be easily scaled across multiple departments and sites. It provides the ability to add more firewalls, manage them centrally, and integrate with other security solutions as our network grows. However, the only reason I didn’t give it a perfect score is that, in some complex environments, managing a large-scale deployment with many firewalls can become a bit challenging, especially in terms of centralized management and monitoring. Despite this, the overall scalability is highly effective for most use cases.
I rated the professional services a 10 because the support we received was outstanding. The team was highly skilled, responsive, and provided tailored solutions to meet our specific needs. They guided us through the entire implementation process, from setup to optimization, ensuring that the firewall was configured efficiently and securely. Their expertise helped us avoid potential pitfalls and ensured a smooth deployment, which greatly contributed to the success of our project.
pfSense can be installed on commodity hardware with no licensing fees. With a simple less than 10 minute restore time, on most hardware, it's an extremely inexpensive way to achieve the same results that some of the more expensive vendors provide.
The easy to use interface has allowed configuration management to be preformed by lower level technicians with quick and easy training.