pfSense offers an all in one network appliance that saves time and money!
Overall Satisfaction with pfSense
We use pfSense as our primary firewalls on two fiber connections into our organization. We also utilize pfSense for load balancing and fail over of incoming requests for our software and service hosting.
We needed something easy to setup and manage on a day to day basis that didn't come with expensive fees or recurring costs to reduce our financial exposure. As time marches on, we've definitely made the best choice in choosing pfSense as it fits our needs extremely well.
We needed something easy to setup and manage on a day to day basis that didn't come with expensive fees or recurring costs to reduce our financial exposure. As time marches on, we've definitely made the best choice in choosing pfSense as it fits our needs extremely well.
Pros
- Easily configure firewall rules through a well thought out web interface.
- Easy to configure VPN setups and if using OpenVPN, easy to deploy client setups.
- Many additional packages and features can be installed on the fly, including things like OpenBGPD, freeradius3, and lightsquid.
- Load Balancing and connection proxies built in and the ability to HAProxy easily.
- Backup and restore in minutes, not hours. A online (free) service is also offered to backup each and every change made to their cloud.
Cons
- There is no API for making changes. This can be a hindrance in environments where auto-deploying something needs firewall rules or HAProxy configs updated. Since all settings are stored in an XML file and then configs are generated from that, even manually updating config files cannot be done.
- Beware that some network cards can have issues. pfSense is based on FreeBSD, so it's best to look on their compatibility list before deploying.
- pfSense can be installed on commodity hardware with no licensing fees. With a simple less than 10 minute restore time, on most hardware, it's an extremely inexpensive way to achieve the same results that some of the more expensive vendors provide.
- The easy to use interface has allowed configuration management to be preformed by lower level technicians with quick and easy training.
While you can get the performance out of other products, pfSense offers the unique ability to put other services on the same device. Products such as Untagle's NG Firewall and SonicWall's TZ series offer cost effective options for firewall and VPN services, having incoming load balancing and connection proxies on the same device as the firewall offers extremely easy configuration and day to day management of network services.
Comments
Please log in to join the conversation