- Firewall rules
- Modules, e.g. Squid
IT Administrator at a tech services company with 51-200 employees
The product is stable although there were some small problems with setting up the modules.
What is most valuable?
How has it helped my organization?
It was very useful for our DHCP network (guests) and web browsing filtering.
What needs improvement?
I think the product has improved greatly, so I actually don't know.
For how long have I used the solution?
I've used it for one year.
Buyer's Guide
Netgate pfSense
June 2025

Learn what your peers think about Netgate pfSense. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
What was my experience with deployment of the solution?
No, it's very easy to deploy.
What do I think about the stability of the solution?
Absolutely not, as the product is stable like a rock.
What do I think about the scalability of the solution?
No need to scale in.
How are customer service and support?
We've used the community version.
Which solution did I use previously and why did I switch?
We have WatchGuard Firewall and pfSense firewall. They are used together and not as a substitution.
How was the initial setup?
We just had some small problems with setting up the modules. However, there was lots of documentation available online so there were no problems at all.
What about the implementation team?
We implemented it in-house.
What was our ROI?
Well it was great as I didn't need to buy a new firewal..
What's my experience with pricing, setup cost, and licensing?
Close to zero, because we've used an internal server for it.
Which other solutions did I evaluate?
No other options were evaluated.
What other advice do I have?
It's a good product, and it really could be a valid firewall solution.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Systems Engineer II at a tech services company with 51-200 employees
The product offers many additional functions except the ability to manage it from a mobile platform, which would be good to add.
What is most valuable?
Two particular features stand out to me:
- The WAN load balancing feature
- The product offers many additional functions such as router, WLC, and traffic analysis etc.
How has it helped my organization?
It has enhanced our organization because of its versatility. It doesn't need expensive hardware to build a robust firewall, therefore, providing a saving on cost. Also, its reliability is quite remarkable which allows IT to focus on other tasks, and how efficiently it manages our WAN traffic.
What needs improvement?
I think the dashboard/interface could be improved and the ability to manage it from a mobile platform.
For how long have I used the solution?
I have used this solution for the past two years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
I have never had to use customer service.
Technical Support:I've never used it, but their technical knowledge base, and via online documents and forums, is quite good, but not excellent.
Which solution did I use previously and why did I switch?
We didn't have a previous solution.
How was the initial setup?
It wasn't straightforward but at the same time not complex. The only issue was identifying relevant static routes to move traffic in and out our network.
What about the implementation team?
I implemented it myself.
What's my experience with pricing, setup cost, and licensing?
The setup cost was practically zero because we had servers in stock. Also, there is no real day-to-day cost attached with it either.
Which other solutions did I evaluate?
No evaluation took place, we just looked at the initial cost to implement a solution using the hardware we have, and how fast it could be rolled out
What other advice do I have?
Plan, research and test certain features and configurations in a lab environment first.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Netgate pfSense
June 2025

Learn what your peers think about Netgate pfSense. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
Corporate Trainer / Systems Administrator at a computer software company with 51-200 employees
It has the ability to do what other firewalls seem to fail at however, some of the available plug-ins that work very well on older pfSense versions, actually break the newer ones.
What is most valuable?
- Reliable
- Easily configurable
- Awesome plug-ins
- Very low maintenance
How has it helped my organization?
This product has allowed my current employer the ability to do what other firewalls seem to fail at, providing a reliable and secure point for allowing SIP traffic to pass. Training other admins how to use the features, and also creating custom user levels for various parts of access within the system has never been easier.
What needs improvement?
Some of the available plug-ins that work very well on older versions, and actually break the newer versions. If using a newer version of the software, then the list of available plug-ins should only list those capable/known to work with the version that you are running. Outside of that- it is a rock-solid firewall, now with support.
For how long have I used the solution?
I have used this product for a very long time, over 10 years.
What was my experience with deployment of the solution?
I have had very very few minor glitches in upgrading the product over the years. Most recently, I had the WAN side DNS change to default values. This is not a huge deal, but it took a little while to figure out why the external services were suddenly failing.
What do I think about the stability of the solution?
Stability is not a concern. I've enabled the HA features, and spread them across multiple ESXi hosts. The only thing that could take down my network, would be a lack of power to the hosts, or all of my ISP tanks at the same time.
What do I think about the scalability of the solution?
I've had no issues. I am using this on multiple sites, with reliable VPN tunnels and the traffic seems to remain a constant.
How are customer service and technical support?
Customer Service:
I have generally only used the forums. In fact, I don't recall *ever* using customer service, but that's only because this product rocks.
Technical Support:I have generally only used the forums. In fact, I don't recall *ever* using Technical Support, but that's only because this product rocks.
Which solution did I use previously and why did I switch?
I have merged pfSense with other products, but I have never chosen another product over pfSense unless I was unable to convince my client that free doesn't mean shoddy.
How was the initial setup?
The initial setup has gotten to be much more streamlined. I think that for the average home user experimenting with networks, this *might* be a *little* hard to figure out at first, but the overall setup is generally a breeze. There shouldn't be any reason that someone can't figure it out in more than 15 minutes a BASE installation and network configuration.
What about the implementation team?
I implemented it myself.
What was our ROI?
It's very high. I have replaced high-end Cisco, Juniper and Sonicwall systems with pfSense on very low-scale machines, and VMs. I have also created networks that are far more complex than any of those are capable of handling without some sort of annual license costing thousands of dollars.
What's my experience with pricing, setup cost, and licensing?
My original setup cost was US$40 for a used x86 Pentium 2 machine, purchased through Boeing Surplus, and additional US$20 ($10 x 2) for two additional NICs to run LAN and OPT1 networks. So, $60 total for self-installation of pfSense v1.1.
Which other solutions did I evaluate?
I looked at low-end Cisco/Linksys devices for physical hardware, and I played around with a variety of free *nix based installations including customized IPTables, IPCop, SmoothWall, and Enodian.
What other advice do I have?
If you want reliable, highly-customizable, and rock solid firewall, do not hesitate for one second to install/purchase this product.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Support Specialist at Tech Solutions
It has provided us with a low cost security solution but their testing prior to deployment needs to be improved.
What is most valuable?
- Open source
- Proximity security
- Content filtering
How has it helped my organization?
It has provided us with a low cost security solution using a quality router at a fraction of the cost of our previous solution.
What needs improvement?
- Testing prior to deployment
- Packages need better support
For how long have I used the solution?
I've used it for eight years.
What was my experience with deployment of the solution?
Rarely as long as the right precautions are taken during migration.
What do I think about the stability of the solution?
Sometimes there are issues with package deployment and one must refer to the forums for support.
What do I think about the scalability of the solution?
Being open source, scalability is not limited. The limits in place, are only set by available resources and time.
How are customer service and technical support?
Customer Service:
Customer service is available at a rate of $399 for 2 incidents, $899 for 5 incidents and $1,699 for 10 incidents. Most people refer to the forum and/or chat room.
Technical Support:Over 10/10.
Which solution did I use previously and why did I switch?
Yes, I have used many other routers but nothing offers the options pfSense does without spending a fortune. pfSense is constantly being improved on.
I switched due to router limitations and vulnerabilities.
How was the initial setup?
It's straight forward for anyone that's installed an OS before, however, I wouldn't recommend it for the novice.
What about the implementation team?
It has been implemented in house and at client locations. If implemented at client locations it does require some care if Snort (The proximity security system) is used as it needs to be fine tuned and touched up from time to time due to newly found vulnerabilities that cause legitimate sites to be blocked.
What was our ROI?
You can invest as little or as much as you want. Granted, some features require more hardware than others but some end users use old machines that no longer have a purpose.
What's my experience with pricing, setup cost, and licensing?
It's between US$50 to US$1500 depending on the hardware that is used.
Which other solutions did I evaluate?
We also looked at -
- Smoothwall
- Moonwall
- SonicWall
- Netgear
- IPCop
What other advice do I have?
Become familiar with the router before implementing it at customer sites. Realize that basic features require a basic amount of hardware. Advanced features require more RAM and if using an SSD, use the embedded installer to reduce wear and tear on your drive.
I would recommend having the following hardware as a minimum:
- At least 8GB for storage
- 256MB+ RAM
- A dual core 1.8Ghz CPU for single typical Internet connection
- The faster the internet connection, a faster CPU and more RAM are required
- If you run Snort and Squid it is recommended you have between 4GB to 8GB of RAM
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Program Manager at a healthcare company with 51-200 employees
Straightforward set-up but it does require some technical expertise to do it.
What is most valuable?
- Free
- Open source
- Robust
- Strong community support
- Strong author support
How has it helped my organization?
Critical network infrastructure has improved.
For how long have I used the solution?
I've used it for two years.
Which solution did I use previously and why did I switch?
I've also used Untangle and Sophos firewalls
How was the initial setup?
Straightforward, but it requires some technical expertise and tweaking.
What about the implementation team?
We implemented it entirely in-house.
What other advice do I have?
Make sure the implementer has programming experience.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager IT at a energy/utilities company with 501-1,000 employees
The proxy filtering is valuable except for blocking HTTPS which it can't do.
What is most valuable?
- MAC Filtered DHCP and DNS
- Captive Portal
- VPN
- Proxy Server
- Proxy Filter
How has it helped my organization?
It has provided us with secure internet browsing and a strong monitoring ability.
What needs improvement?
Proxy filters are not supported for the blocking of HTTPS sites.
For how long have I used the solution?
I've used it for two to three years.
What was my experience with deployment of the solution?
No issues encountered yet.
What do I think about the stability of the solution?
No issues encountered yet.
What do I think about the scalability of the solution?
No issues encountered yet.
How are customer service and technical support?
Customer Service:
I have not gotten any support from the customer service center because I can get all the solutions on their web blogs.
Technical Support:I think it is perfect.
Which solution did I use previously and why did I switch?
I was using another product, but it didn't have a bandwidth controller and monitoring tool like this product does. I switched because I can find everything in one window.
How was the initial setup?
Its installation setup & procedure is so simple that a layman could install it.
What about the implementation team?
I installed it by myself and used Google for assistance.
What was our ROI?
It's positive.
What's my experience with pricing, setup cost, and licensing?
I just downloaded the program from the website free of chard. The best thing is, this product can be installed on any machine.
Which other solutions did I evaluate?
No other options were evaluated.
What other advice do I have?
It is recommended, as it is a stable product.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Can any one have experienced to deploy Pfsense on Hyper-V ... I am planning to deploy this scenario.
Network Admin at a tech consulting company with 51-200 employees
The product is missing a graphic report implementation tool but performance, scalability and customization are valuable
What is most valuable?
Performance, cost effective, scalable, customizable
How has it helped my organization?
After switching from Cisco, Juniper, Astaro and Microsoft network response improved and more control of packet (for me, pfpacket technology is better than packet filter.)
What needs improvement?
Graphic report implementation tool (now possible with extra software)
For how long have I used the solution?
5+ years.
What do I think about the scalability of the solution?
No, perfect scalability from 20 to 500 users
Which solution did I use previously and why did I switch?
Cisco, Microsoft and when TMG progressively died it was necessary to switch to unix technology, many corporations require low budget and high performance.
How was the initial setup?
The initial approach is very complex because of the multiple functions, but after a short learning curve it is able to handle the standard functions.
What about the implementation team?
In my case, I buy network appliance from Lanner Inc. ltd (watchguard supplier) and deploy the image depending on the desired size and functionality required by the customer.
What's my experience with pricing, setup cost, and licensing?
Identify the most suitable hardware for the required size.
Which other solutions did I evaluate?
Yes, Astaro and PaloAlto plus Juniper, but the renewal planes (AV, UTM, etc.) are very expensive.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT consultant at a tech services company with 1-10 employees
Reliable, scalable, simple installation
Pros and Cons
- "I have found pfSense to be stable."
- "The solution could improve by having centralized management and API support online."
What is most valuable?
pfSense is very good because it allows us to do what we want.
What needs improvement?
The solution could improve by having centralized management and API support online.
For how long have I used the solution?
I have been using pfSense for a long time.
What do I think about the stability of the solution?
I have found pfSense to be stable.
How are customer service and support?
We are providing support for our customers here in Sweden.
How was the initial setup?
The initial setup of pfSense is simple.
What's my experience with pricing, setup cost, and licensing?
The price of pfSense is reasonable. However, there is a free version available.
What other advice do I have?
My advice to those wanting to implement pfSense is to start out with the free version before going with the appliance.
I rate pfSense a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner

Buyer's Guide
Download our free Netgate pfSense Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
OPNsense
Sophos XG
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
Check Point NGFW
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Sophos XGS
Fortinet FortiGate-VM
SonicWall NSa
Untangle NG Firewall
KerioControl
Buyer's Guide
Download our free Netgate pfSense Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Sophos and pfSense?
- How do I choose between Fortinet FortiGate and pfSense?
- How do I deploy anti-spam in pfSense or SonicWall TZ?
- What are the differences between Fortinet FortiGate and pfSense?
- Comparison between Sophos XG and pfSense as firewalls
- What is the difference between PfSense and OPNsense?
- Why is pfSense's firewall better than OPNsense's?
- Which solution do you prefer: pfSense or KerioControl?
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
Indeed this is a very powerful opensource solution but as you say it requires some technical expertise and tweaking (but actually which firewall technology does not require some now?). Fortunately the community and project documentation are rich and very helpful. Extra packages availability is also rich, it goes from the simple CLI tool like bmon to fully graphically managed RADIUS, SQUID, SNORT servers for instance (see : doc.pfsense.org). It also support natively High Availability Sync thanks to CARP and pfsync protocols (see: doc.pfsense.org). Few days ago I set up VPN SSL configuration with OpenVpn in TAP mode, all done through the GUI (no need to edit any files through CLI) what quite impressed me (usually bridge creation is done through CLI).
To conclude I really invite people looking for a free firewall solution to give a try with pfsense :-)
Just keep in mind such a solution is devoted to projects requiring "not so much speed", I mean 40G or even 100G firewalling and either not UTM inspection.