TrustRadius: an HG Insights company

pfSense

Score9.9 out of 10

72 Reviews and Ratings

What is pfSense?

pfSense is a firewall and load management product available through the open source pfSense Community Edition, as well as a the licensed edition, pfSense Plus (formerly known as pfSense Enterprise). The solution provides combined firewall, VPN, and router functionality, and can be deployed through the cloud (AWS or Azure), or on-premises with a Netgate appliance. It as scalable capacities, with functionality for SMBs.

As a firewall, pfSense offers Stateful packet inspection, concurrent IPv4 and IPv6 support, and intrusion prevention. Within its VPN capabilities, it provides SSL encryption, automatic or custom routing, and multiple tunneling options. pfSense also supports optional clustering and load-balancing, along with proxying and content filtering services. The product can also monitor and report on network traffic.

Categories & Use Cases

Top Performing Features

  • Policy-based Controls

    Firewall policy controls enable administrators to create firewall policies controlling what data is allowed to traverse the firewall

    Category average: 8.9

  • VPN

    VPN's implement encryption and anonymize IP addresses

    Category average: 9.1

  • High Availability

    Built-in capacity to prevent exposure if primary firewall stops working

    Category average: 9.2

Areas for Improvement

  • Proxy Server

    A proxy server changes your IP address and masks the origin of your network traffic

    Category average: 8.4

  • Identification Technologies

    Policy-based visibility and control over applications, users and content

    Category average: 8.3

  • Content Inspection

    Inspecting permitted application traffic by means of threat prevention, URL filtering and data filtering

    Category average: 8.5

Great product for the correct deployments.

Use Cases and Deployment Scope

I've used PFSense for home lab environments as well as small office environments. As far as a full-featured firewall, there are very few other competitors that can offer the same value today. For free, using the homelab license, you can perform many tasks that mimic an enterprise-grade firewall, such as setting up S2S VPN configurations, DHCP, and NAT. Plugs in well with Home Assistant and also serves as a good way to detect if someone or something has actually connected to the network.

Pros

  • Firewall configurations.
  • S2S Azure VPN Connection.
  • Plugins
  • Certificate Authority.
  • HomeAssistant Integration.

Cons

  • DHCP

Return on Investment

  • Can't get much cheaper than free for the right use cases.

Usability

Alternatives Considered

Fortinet FortiGate and Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series

pfSense is a great and reliable firewall solution

Use Cases and Deployment Scope

We use pfSense for firewall role, VPN and IPSec, DHCP, and an additional IDS with Suricata addon. We migrated IPTables and Sonicwall firewall solutions to pfSense, and it acomplish all of our needs and more. It is very flexible, easy and intuitive to configurate. We have deployed it both as stand alone and high availability with cluster, and works like a charm.

Pros

  • Geo location IP blocking
  • VPN with OpenVPN
  • IPSec
  • High availability and failover
  • Networkin simple roles

Cons

  • Graphs of usage
  • Alerts messaging
  • Updates deployment

Return on Investment

  • Positive, implementation
  • Positive, administration and management
  • Positive, high availability
  • Positive, applications
  • Negative, compliance

Usability

Alternatives Considered

Fortinet FortiGate and SonicWall SonicWave Series

Other Software Used

Grafana, Graylog, Fortinet FortiGate, Azion, Cloudflare, NGINX, Kong Gateway Community (Open Source)

pfSense is Best of Breed and Least Expensive

Use Cases and Deployment Scope

I have been using pfSense of over 15 years and have been extremely happy with it. I have use CISCO routers, Fortigate, SonicWAll, Ubiquiti UniFi and others, and the pfSense CE edition has more features and is is much easier to use while providing EXCELLENT protection. I have 18 pfSense CE versions running now on virtual or my on SuperMicro hardware at my hone and my servers at the WOW colocation facility in Tampa, FL and recommend it to all of my clients. I have upgraded many of them to pfSense Pluss which is $129 and fully supported by the Netgate team. (support hours additional $) It has more reliable updates and code than the CE edition. I HIGHLY recommend it.

Pros

  • Fully configurable custom, automated or combines outbound NAT
  • Floating rules that are applied before all others
  • Very easy to GUI
  • Logs for everything easily viewable in GUI
  • Advanced or Wizard configuration for almost everything

Cons

  • Some third party packages may not work with current version.

Return on Investment

  • + It is extremely Secure in Plus Version, inexpensive, can be virtualized
  • + It runs on any server hardware
  • + While being the best of the breed, it is also the least expensive
  • - The CE version is open source, possibly giving hackers a way to figure out vulnarabilities
  • + The Pluss version is NOT all opens source

Usability

Alternatives Considered

Cisco 1000 Series Aggregation Services Routers (ASR 1000) and Fortinet FortiGate

Other Software Used

Oracle Linux, Sangoma Asterisk, Oracle VM VirtualBox

Great routerfirewall platform

Use Cases and Deployment Scope

We use pfSense in redundant pairs to service large coworking spaces, and it’s proven reliable and secure for many years. It’s easy to configure, simple, and reliable. We’ve weathered a lot of different events that I’ve seen bring down other firewalls. We apply a significant number of filters to reduce malware C2 and still achieve excellent performance. At this point we’ve deployed these machines to a dozen locations globally and have come to trust it.

Pros

  • Ease of configuration
  • Redundancy
  • Performance
  • Low cost

Cons

  • Multi-instance management
  • Authentication

Return on Investment

  • Lowers cost to deploy networks
  • Improves network reputation

Usability

Alternatives Considered

Cisco ASA 5500-X with FirePOWER Services and Palo Alto Networks Advanced Threat Prevention

Other Software Used

Extreme Networks Wired Access - Switches

pfSense is a great bang for the buck

Use Cases and Deployment Scope

pfSense is used in a high availability pair as the primary firewall/router/gateway of our environment. It is also used as the primary VPN remote access solution. pfSense is also providing ids/ips, traffic shaping, and handling all layer 3 needs. pfSense addresses the licensing problem that most other firewalls have today. pfSense, while recently requiring a license, is not a continuous licensing investment like competitors.

Pros

  • routing/firewall
  • SSL VPN
  • Flexible

Cons

  • VPN
  • Cloud Management
  • Missing zone based rules and next gen firewall features
  • Little active directory integration
  • No Entra ID integration

Return on Investment

  • High ROI
  • Missing modern features
  • Development cycle is slow

Usability

Alternatives Considered

Fortinet FortiGate, Cisco Meraki MX and Sophos UTM

Other Software Used

Microsoft Exchange, SuperOps.ai, PaperCut