No more typing reviews! Try our Samantha, our new voice AI agent.
Glenn Ace Tenorio - PeerSpot reviewer
Senior Network Engineer at American School of Dubai
Real User
Feb 11, 2024
User-friendly, easy to manage the firewall, rule-wise and interface-wise
Pros and Cons
  • "For everyday tasks, we just get alerts. It's anything that's suspicious, including from our Netgate. So, it's part of how we maintain cybersecurity in our school. This is working alongside our endpoint security solution."
  • "For the third-party packages, I'd rather have it built-in, like a core feature of pfSense, part of the core model."

What is our primary use case?

Our most common use cases are for our corporate firewalls, and currently, I'm using it as our school firewall. So it's our perimeter firewall. So, we're running three firewalls on our network. 

So we have separate networks each because we have, like, different use cases. So we're running three at the moment.

We've been running it for six years now, and so far, it's been good.

How has it helped my organization?

Netgate pfSense has been utilized to create and manage VPNs within our organization. So we're running pfSense with VPN on one of our private cloud providers. So we're using IPSec VPN on that.

For everyday tasks, we just get alerts. It's anything that's suspicious, including from our Netgate. So, it's part of how we maintain cybersecurity in our school. This is working alongside our endpoint security solution. 

We were using an open-source endpoint solution for that. So we're integrating that with the one we have on pfSense. 

What is most valuable?

The ease of use. Like, it's easy to manage the firewall, rule-wise and interface-wise. For me, it's quite easy and friendly to use.

We have a set of rules so that it can manage all of our rules. We have a complex network here in our school. We have a lot of rules running, so it's really easy to match all of those rules using pfSense.

Integrating pfSense with other products was a bit tedious at first. We researched and tested for about a month, so it was not too hard but not instant.

What needs improvement?

For the third-party packages, I'd rather have it built-in, like a core feature of pfSense, part of the core model. This feature of pfSense would be great, instead of relying on a third-party module.

Buyer's Guide
Netgate pfSense
July 2026
Learn what your peers think about Netgate pfSense. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,834 professionals have used our research since 2012.

For how long have I used the solution?

I have been using it for six years. 

What do I think about the stability of the solution?

It's about 95% stable, not perfect, but quite reliable.

What do I think about the scalability of the solution?

If I needed to scale it and merge our pfSense machines into one, I'd prefer a dedicated hardware appliance instead of running multiple x86 servers on the firewall.

We have around 4,000 endpoints. 

How are customer service and support?

I reached out to support for an unusual CPU usage issue after an upgrade. They were responsive, and even though I ultimately found a solution, they were helpful in diagnosing.

Which solution did I use previously and why did I switch?

We used Fortinet. We opted for pfSense because of budget limitations. pfSense was a more affordable solution for our requirements.

pfSense is easier to manage and offers modularity for features. With FortiGate, everything is there, but we might not need everything, and too many features can be challenging.

How was the initial setup?

The initial setup is very straightforward and intuitive. 

We use the pfSense software directly and install it on our rack servers. So, we're adding three instances of that.

What about the implementation team?

I handle all the deployment processes. I am the core manager for the entire infrastructure, so I manage and deploy everything.

I consider how many users and gigabytes we expect on the network and try it on a test network first to validate before actual deployment.

Just my core team members manage the whole deployment, so that's enough for us.

Migrating the old one to the new one took around a month because we have many rules, and the new Netgate was quite different.

From the maintenance perspective, it is not difficult at all. 

While configuring or maintaining pfSense, we had high CPU usage on one firewall, but the GPAC subscription provided a good response. The support team was helpful, and we resolved it in a few hours. So, we had good support because of the support subscription. 

What's my experience with pricing, setup cost, and licensing?

We just have the yearly support subscription.

Which other solutions did I evaluate?

I just found pfSense online. I just tried it out on a home lab and found it worked well enough for us. So, just started out, like, searching online and responded and tried it.

What other advice do I have?

I would advise you to try to estimate your network first and do a test network just to have a proof of concept of what you want to run and check the routes you want to run against your network, making sure that your requirements are valid before deploying it.

Overall, I would rate the solution a nine out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2518620 - PeerSpot reviewer
Data Center Administrator Network Engineer at a insurance company with 1,001-5,000 employees
Real User
Jul 31, 2024
Supports a lot of VPN techniques, flexible, and has the ability to connect with different WAN connections
Pros and Cons
  • "The flexibility is very good; we have a lot of possibilities."
  • "The only thing that could be better is the hardware compatibility for LTE devices."

What is our primary use case?

I work in IT at a German insurance company, and I studied computer science. I also work in the network sector, so I know a lot about network solutions. I work with VPN solutions, Fortinet, and other products. For me, pfSense is a private home solution for my family. It's not the solution in my company.

I use pfSense as a firewall appliance, and the function is very good. But I think it's for users with more experience. It's not a solution for beginners.

If you are a professional, it's not difficult to add features to pfSense and configure them. But it is difficult if you are not. 

I utilize the core features. I have pfBlockerNG, SquidGuard, OpenSSL, and WireGuard. So, these are the core features I need.

How has it helped my organization?

The core benefits are that I can virtualize it with platforms like Proxmox or VMware, and I can buy third-party appliances. And Netgate offers a lot of hardware possibilities.

pfSense offers a lot of things that help to prevent data loss and intrusion, protect telemetry information, and so on. 

pfSense gives a single pane of glass management. But for me, it's not a problem because I have one appliance, but I think if you manage a lot of appliances, it could be better. It's important to be able to centralize management if I have 10 or 20 appliances.

I use pfSense Plus, it's called the "Zero-to-Ping" license [TAC Lite]. It's a very good solution, but it's a bit too expensive for private use. pfSense Plus is very good, but, for example, if I want to add another pfSense appliance for a cluster, it requires two licenses. For private use, if I want two licenses, it's very expensive.

pfSense Plus provides features to minimize downtime. One of the key features is ZFS. It's the file system. ZFS is very important for backups. I can make snapshots, and that is very good to make backups.

I am satisfied with the visibility that is provided by pfSense Plus. It is very good and optimizes performance because the hardware acceleration is very good for IPsec, SSL VPN, OpenSSL, and so on. This is very good support from pfSense.

What is most valuable?

The best feature is a function called pfBlockerNG. In pfSense, you can whitelist and blacklists for IP addresses or dangerous DNS sites. The top feature is the VPN. It's a very good SD-WAN solution and a very good VPN engine. It supports a lot of VPN techniques; it supports IPsec, SSL VPN, and WireGuard. It's the core feature of pfSense.

The flexibility is very good; we have a lot of possibilities. You can connect it with different WAN connections, whether you have a cable provider or fiber.

The feature list is good. For me, it's more important that we have fewer patches and better stability compared to OPNsense. I think OPNsense is too big. They support a lot of things, but pfSense is better. I think pfSense is better for stability.

What needs improvement?

The only thing that could be better is the hardware compatibility for LTE devices. This is a bit tricky for me; I wish the hardware compatibility were better for LTE devices.

I wish the FQ_CODEL limiters were improved. They're very good, but the FQ_PIE limiters don't work well. FQ_PIE limiters are important for cable modem connections. In Germany, we have a lot of cable providers for these interfaces, and the FQ_PIE limiters don't work well in pfSense.

For how long have I used the solution?

I have been using it for eight to ten years. It has been a very long time. pfSense is very popular in Germany.

I use the latest pfSense Plus version.

What do I think about the stability of the solution?

The stability is very good.

What do I think about the scalability of the solution?

I use it for my family, for maybe 20 or 30 devices. It's not a big environment.  

How are customer service and support?

I utilize the pfSense forum and the community forum, and it's okay for me.

Which solution did I use previously and why did I switch?

My preference in comparison with OPNsense is pfSense. I think it is better; it is stable.

The difference is that OPNsense has more features, but also has more bugs.

For me, pfSense is stable. It's better for my use case.

How was the initial setup?

The deployment process is very good. For example, I can set up a new appliance and boot directly from a config file. This is very good.

It's very simple. I download new images, and during the boot process, if you make an image, you have a directory. In the directory, you make the config file, and then you can directly boot with the setup. You can boot a finished version. It's a good thing.

I use it on-premises. The on-prem version is very good. The software is good.

Maintenance depends on the features you use. If you have a proxy server with SSL introspection, sometimes it creates a small firewall size. If you have an easy firewall setup, then it's not so complicated. It depends on your environment and feature settings.

What about the implementation team?

I did the deployment myself without the help of third parties or anything like that. It's very simple. I have enough skills because I studied computer science and work in the network sector. It's not a problem for me.

It took me ten minutes to deploy it. 

What was our ROI?

The ROI is good. pfSense is a very good solution, not only for home use, but also for middle-sized or larger companies.

What's my experience with pricing, setup cost, and licensing?

In comparison with pfSense CE (Community Edition), pfSense Plus is a little bit too expensive. The pricing is a little bit high for private users. 

With the inclusion of the firewall, VPN, and router functionalities, the total cost of ownership of the pfSense Plus solution is very good because pfSense Plus has a lot of features. For the VPN features, it is good for the total cost of ownership.

What other advice do I have?

I can recommend it if you are a professional or if you know what a firewall is.

It is a very good solution for the home sector, for companies, and for larger companies. I would recommend it to a lot of companies.

Overall, I would rate it an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Netgate pfSense
July 2026
Learn what your peers think about Netgate pfSense. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,834 professionals have used our research since 2012.
Freelance
Real User
Jul 23, 2024
The best feature is that it can be installed on any customized hardware but the interface and stability could be improved
Pros and Cons
  • "I like the dynamic DNS update and firewall feature"
  • "PfSense's interface could be improved. For example, the menu is ordered alphabetically instead of logically. The reboot button should be located near the shutdown, but it's in alphabetical order. Also, Netgear should create a home license for pfSense Plus for non-commercial use."

What is our primary use case?

I use pfSense for my home monitoring. It's used to build a subnet in my home environment to separate the IoT and my daily lab. 

How has it helped my organization?

PfSense can separate the network into subnets, which I can't do with an ordinary home router. It is relatively simple to add a multiple gigabit network port on the home router. For example, I can buy customized hardware with 6x 2.5 GbE. It helps me optimize performance. I use pfSense as my reverse proxy and have a single interface for managing all the SSL certificates using HAProxy.

What is most valuable?

The best feature of pfSense is that it can be installed on any customized hardware. I don't need to use Netgate hardware. I like the dynamic DNS update and firewall feature. Adding features is easy. If a feature is built-in, I can check it, install the package, and convert it. If it isn't built-in, I can't add it to pfSense. 

What needs improvement?

PfSense's interface could be improved. For example, the menu is ordered alphabetically instead of logically. The reboot button should be located near the shutdown, but it's in alphabetical order. Also, Netgear should create a home license for pfSense Plus for non-commercial use.

For how long have I used the solution?

I have used pfSense since 2020, so it's been about four years.

What do I think about the stability of the solution?

I rate pfSense six out of 10 for stability.

What do I think about the scalability of the solution?

I haven't tried to scale pfSense. I only use it locally. 

How are customer service and support?

I rate Netgate support five out of 10. They are helpful for basic questions, but if I ask something more complicated, they refuse because I am not a higher tier of support. The response time is acceptable.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I used OpenWrt before pfSense but for a relatively short period. PfSense is more feature-rich than previous solutions. 

How was the initial setup?

Deploying pfSense is a bit complicated, but It's nothing I can't handle. It requires some maintenance, such as when they release updates.

What was our ROI?

PfSense saves me the time I would spend doing things separately. For example, building a VM to set the rear-end policy would take a lot of time. 

What's my experience with pricing, setup cost, and licensing?

If it's not the free community edition, pfSense is relatively expensive for home use. It's okay for commercial use. The cost of ownership is low. I can save about a hundred dollars annually. 

What other advice do I have?

I rate Netgate pfSense seven out of 10. I recommend pfSense for advanced users. It's a good solution if you want to learn more about networking in a company environment/. 

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Works at a consultancy with 1-10 employees
Real User
Jul 14, 2024
Extremely flexible and can replace your consumer-grade firewall router
Pros and Cons
  • "It is a robust tool that can replace your consumer-grade firewall router solution."

    What is our primary use case?

    I USE Netgate pfSense for home networks, lab environments, and R&D. In production, professional career-wise, I have built pfSense production firewalls that run in various configurations and high availability for different organizations serving a different number of clients and servicing any amount of requests throughout any given day. 

    It also serves thousands to tens of millions of requests a second a day from small to large deployments.

    What is most valuable?

    Netgate pfSense is an extremely flexible solution. It is an open-source tool that has a very large community of professionals, enthusiasts, and hobbyists alike. There is a lot of flexibility in doing whatever you want with it. It also offers enterprise-grade support so that you can have something equivalent to the Cisco enterprise-grade data center firewall product. You could build that with pfSense or OpenSense, which is a derivative of pfSense.

    The initial benefit I saw of pfSense was way before I ever used it professionally. It is a robust tool that can replace your consumer-grade firewall router solution. I also saw immediate benefits in my professional career as it is a powerful solution that can be compared to other solutions like Palo Alto or Meraki today.

    Netgate pfSense can be a fully functional L7 firewall. You can not only have the base Layer 3 functionality of the firewall, but you can add things like Snort and pfBlockerNG to build out and become an L7 firewall doing actual inspection and security analysis.

    It is very easy to add and configure features to Netgate pfSense.

    pfSense has a built-in auto-configuration backup. While that is technically data loss from the sense of protecting the firewall, it is a feature Netgate offers to every pfSense user, licensed or not. You get this feature if you have a Netgate appliance. Just using pfSense won't get you that. There are third-party packages you can use to set up pfSense configuration backups if you don't have pfSense Plus.

    In terms of data loss outside of that, you configure it in a way that puts it as a security device. By default, pfSense is not inherently a security device. It is a Layer 3 filtering firewall. If you want it to be a security appliance beyond basic TCP/IP Layer 3 filtering, you can run Snort or pfBlockerNG to turn it into a security appliance. Doing so can aid in data loss prevention by using the tool for basic intrusion detection prevention.

    Netgate pfSense provides a single-pane-of-glass management capability. Its dashboard has a lot of prebuilt functionality, allowing you to have a single-page view of the firewall's status and everything going on with it.

    pfSense Plus provides features that help us minimize downtime as a supporting part of the infrastructure.

    pfSense Plus provides visibility that enables us to make data-driven decisions. The kind of data-driven decisions that could be made with information from pfSense are things like how much bandwidth I am using and what is the throughput of all my band connectivity.

    I can also decide whether I need to go from a 1 Gig network to a 10 Gig network or a 2.5 Gig network and whether I need to increase my commit for my WAN circuit because we see that we are averaging above 99%, etc. The kind of decisions that it can help you make are related to your network and your connectivity.

    The visibility that pfSense Plus provides helps us to optimize performance. It could help you to improve performance on the network side. It is, after all, a firewall router, so it is a network piece of equipment. It could help improve performance in that if you are actively monitoring, pulling data from pfSense, or actively reviewing the different types of information and graphs that pfSense provides, you could make decisions to see that a machine is consistently using lots of network traffic.

    For how long have I used the solution?

    I have been using Netgate pfSense for 15 years.

    What other advice do I have?

    I have pfSense Plus in production. I have both pfSense Plus and pfSense Community Edition (CE) running at home. They are essentially the same, and the only difference between them is the support and auto-configuration backup.

    Overall, I rate the solution a nine out of ten.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Christos Messios - PeerSpot reviewer
    Senior IT Engineer at Channel IT
    Reseller
    Jul 14, 2024
    I like the built-in blocker and the ability to easily add packages from the console
    Pros and Cons
    • "I like pfBlocker and the ability to install more packages from the pfSense console."
    • "PfSense could better utilize the interface and dashboard and include some packages in the built-in solution. For example, pfSense is sharing some other packages. You have to download and configure them within the package manager of pfSense. Some of those important ones, like the IPS and the monitor, could be installed on the solution's image and configured."

    What is our primary use case?

    We use pfSense for IT security and load balancing the internet traffic across our three lines. We also use a package available in pfSense called pfBlocker that blocks some DNS records. For example, it doesn't allow ads to appear on the website. We have a site-to-site VPN with our different sites. 

    How has it helped my organization?

    The benefits from pfSense were immediate. We tested pfSense on a third-party machine, and soon after, we purchased a Netgate machine. PfSense prevents data loss by blocking malicious sites or apps with pfBlocker and the Suricata package, which acts as an IPS. 

    PfSense has multiple WAN ports, helping to reduce downtime. We can set multiple Internet lines. If one line has an issue, we can still access the Internet from the other or communicate with the other sites. We also have a high availability feature with pfSense. For example, if we have two or three pfSense devices, we can have high availability. If one goes down, we can still work with the other one.

    The visibility that pfSense has enables us to make data-driven decisions. From the logs, we can see blocked or allowed traffic. We generally see what goes into the firewall and change the rules or configuration. 

    From the dashboard, we can see the utilization and how our lines behave during working hours. We can see if we need a higher-performance device, a line upgrade, or a feature.

    What is most valuable?

    I like pfBlocker and the ability to install more packages from the pfSense console. It's easy to add features, but you can check the user communities and videos if you encounter any difficulties. You have the flexibility to choose VPNs with WireGuard or OpenVPN and make firewall rules. It's easy to create a group with multiple IPs, hostnames, or areas and create a rule for that group.

    You can make your own configurations on every module and create custom packages, which makes it more flexible. The dashboard is customizable, so you can create your dashboard based on what you would like to see and have all the data there on the dashboard. You can start and stop everything on the dashboard. 

    What needs improvement?

    PfSense could better utilize the interface and dashboard and include some packages in the built-in solution. For example, pfSense is sharing some other packages. You have to download and configure them within the package manager of pfSense. Some of those important ones, like the IPS and the monitor, could be installed on the solution's image and configured.

    For how long have I used the solution?

    I have used pfSense for four years in business and at home.

    What do I think about the stability of the solution?

    I didn't notice any performance issues. 

    What do I think about the scalability of the solution?

    pfSense is scalable.

    How are customer service and support?

    I rate Netgate support nine out of 10. I have contacted them twice in the last six months, and they responded and resolved my issue quickly. 

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We used UniFi UDM, Hillstone, and OPNsense, which is similar to pfSense.

    How was the initial setup?

    Deploying pfSense is straightforward. It took about an hour to install and configure. After deployment, the only maintenance required is periodically checking for new updates or security fixes. 

    What's my experience with pricing, setup cost, and licensing?

    pfSense's price is excellent and similar to its competitors. It has a low total cost of ownership for all these features. 

    What other advice do I have?

    I rate Netgate pfSense eight out of 10. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Reseller
    PeerSpot user
    reviewer2509758 - PeerSpot reviewer
    Manager, Information Technology Systems at a construction company with 51-200 employees
    Real User
    Jul 14, 2024
    Open-source, easy to configure, and offers helpful support services
    Pros and Cons
    • "The open-source nature of pfSense, paired with the amount of support we receive, has been great."
    • "I'd like to see it become more of a next-gen firewall or deep packet inspection, however, I'm very happy with the way it is as of now."

    What is our primary use case?

    We primarily use the solution for firewalling, site-to-site VPNs, and VPN management.

    How has it helped my organization?

    We largely needed a good firewall solution. We wanted to find a suitable firewall for our company size and what we're doing with it.

    It's open-source and everything is available to me without having to pay subscription fees. 

    What is most valuable?

    The support with NetGate probably is the most value I've seen from it. They've been really, really helpful. The open-source nature of pfSense, paired with the amount of support we receive, has been great.

    The flexibility is great. It does everything I need it to do. The amount of open apps for it is extensive. I was able to help track some networking issues using the pfSense to scan the network.

    It's significantly easier than expected to configure the solution and simple to handle add-ons.

    pfSense can help prevent data loss. In our environment, things are fairly strict. However, it makes it easy to manage and configure the firewall and handle inter-VLAN routing and firewalls between them.

    We do have access to a single pane of glass management. It's easy to review traffic, usage between VLANs, threat monitoring, and user connectivity. I'd have to monitor items separately without this single pane which would make monitoring difficult. 

    We do use pfSense Plus. It provides us with the features we need to minimize downtime. The updates and everything that comes with it have been great.

    The visibility provided allows us to make data-driven decisions. The modules I have access to for network monitoring and management have been very helpful.

    We've been able to optimize performance. With NetGate support, I've been able to utilize traffic shaping and performance optimizers. 

    What needs improvement?

    I'd like to see it become more of a next-gen firewall or deep packet inspection, however, I'm very happy with the way it is as of now. 

    For how long have I used the solution?

    I've used the solution personally for about two years. My company has been using it for about eight years now.

    What do I think about the stability of the solution?

    The stability is very good. 

    What do I think about the scalability of the solution?

    We have two locations. I have yet to uncover any scalability limitations. 

    How are customer service and support?

    Support is quick to respond. For the amount we pay a year, the support has paid for itself. I'm very happy with the level of support we get. 

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I do have experience with Meraki and NetGate devices. I've used FortiGate devices in the past. The expense and support were not near the quality of pfSense.

    How was the initial setup?

    The initial setup was easy to set up and straightforward to configure. It did take a moment to learn where each tool set was. However, after that, it's really good. I handled the deployment myself. I was able to implement it within 16 hours. 

    There isn't really any maintenance; it is pretty much set and forget. I do updates every three months or so and that's it. 

    What about the implementation team?

    90% of the setup was handled in-house; I referred to NetGate support for a few items along the way. 

    What's my experience with pricing, setup cost, and licensing?

    We do pay about $600 a year for NetGate support. pfSense is free, however, NetGate, that made the appliance, charges for a support package. I'm very happy with the quality of service that I get for the price. 

    We would have paid another $7,000/year for subscription fees if we went anywhere else.

    What other advice do I have?

    I'd recommend the solution to others. I'd rate it ten out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Joe Whipple - PeerSpot reviewer
    Senior Cloud Engineer at IP Pathways
    MSP
    Jul 10, 2024
    Allows for modifications, easy deployment, and low maintenance
    Pros and Cons
    • "The most valuable features of pfSense are the high availability that easily allows failover to a backup unit and the Snort integration with pfSense and WireGuard."
    • "Netgate pfSense can improve by adding a different OS layer other than FreeBSD."

    What is our primary use case?

    I use pfSense for my home network firewall. I also manage two Cloud platforms that use it. 

    How has it helped my organization?

    Netgate pfSense is flexible allowing for modifications to meet our needs.

    With my strong security background and experience managing pfSense, adding and configuring new features is a breeze. While some might encounter challenges, my expertise allows me to navigate them with ease.

    pfSense impressed me with its ease of deployment and low maintenance. It excels in protection and firewall functionality and offers a wide range of add-ins to further customize my network. After considering alternatives like OPNsense and Untangle, pfSense emerged as the perfect fit for my needs.

    The single pane of glass provided by pfSense makes it easier to determine issues related to attacks and what is being blocked. I can see live logging of the firewalls and what rules apply to what.

    pfSense does a good job helping prevent data loss using Snort which identifies and blocks suspicious traffic before it enters our network.

    pfSense Plus offers a visibility feature that helps me optimize network performance. The dashboard displays clear traffic graphs and device load information, and I can customize it to show exactly what I need.

    The total cost of ownership is extremely reasonable. pfSense is a good option, especially for people conscious of recurring expenses.

    What is most valuable?

    The most valuable features of pfSense are the high availability that easily allows failover to a backup unit and the Snort integration with pfSense and WireGuard.

    What needs improvement?

    Netgate pfSense can improve by adding a different OS layer other than FreeBSD.

    For how long have I used the solution?

    I have been using Netgate pfSense for ten years. 

    What do I think about the stability of the solution?

    Netgate pfSense has been stable.

    What do I think about the scalability of the solution?

    pfSense's scalability is highly dependent on the hardware you choose, but despite this, it offers a strong ability to handle increased network demands overall.

    Which solution did I use previously and why did I switch?

    In addition to pfSense, I have used OPNsense, WatchGuard, and Cisco. The WatchGuard rules were more straightforward than pfSense. New pfSense users might find deciding between floating and interface rules for specific scenarios confusing.

    How was the initial setup?

    The installation is easy for those who are comfortable with command-line interfaces. It is quick and straightforward but they have to be careful when assigning the internal or external net because that can be challenging for some.

    One person is enough to deploy.   

    What's my experience with pricing, setup cost, and licensing?

    Netgate pfSense is competitively priced. The 4100 box is a good box for the price.

    What other advice do I have?

    I would rate Netgate pfSense nine out of ten.

    Before deploying pfSense in your lab, I recommend checking the pfSense forums to learn about any potential issues or considerations other users have encountered.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Network Administrator at a healthcare company with 51-200 employees
    Real User
    Jul 3, 2024
    It's rock solid, low maintenance, and doesn't cost too much for the features you get
    Pros and Cons
    • "My favorite thing about pfSense is its overall stability of the product. It's rock solid and low maintenance. I like that aspect. It doesn't cost much, and it's feature-rich, including mobile VPN, pfBlocker, and IPS."
    • "One area of improvement would be better communication. They kind of left a lot of people in the dark and misled them about the pfSense Plus Edition. I feel like they automatically switched people over and then followed that up with a required subscription model. That aggravated a lot of customers, including me, but I stuck with it regardless."

    What is our primary use case?

    I use pfSense as our primary firewall and router. We use several functions of pfSense, including the OpenVPN capabilities for mobile VPN and pfBlocker for DNS blocklisting. We also use Snort for IPS capabilities. 

    How has it helped my organization?

    The solution helped us secure the perimeter against vulnerabilities. I'm confident in the team's ability to keep things updated and all the security holes patched. It also has security add-ons like IDS, IPS, etc. We realized the benefits immediately.

    What is most valuable?

    My favorite thing about pfSense is its overall stability of the product. It's rock solid and low maintenance. I like that aspect. It doesn't cost much, and it's feature-rich, including mobile VPN, pfBlocker, and IPS. You have the flexibility to deploy it as bare metal or VM. 

    It's very easy to add features to pfSense and to configure them. The solution's management page offers a single pane of glass view. You can clearly see the various features on the main page, and it isn't difficult to drill down into the other sections for more details. 

    I can't say which features Plus provides that the community edition doesn't. I only knew that the Plus edition was the path forward. I was previously on a community edition for many years, but I've been on the Plus edition for at least a couple of years now.

    What needs improvement?

    One area of improvement would be better communication. They kind of left a lot of people in the dark and misled them about the pfSense Plus Edition. I feel like they automatically switched people over and then followed that up with a required subscription model. That aggravated a lot of customers, including me, but I stuck with it regardless.

    For how long have I used the solution?

    I have used pfSense for nearly a decade.

    What do I think about the stability of the solution?

    I rate pfSense 10 out of 10 for reliability. 

    What do I think about the scalability of the solution?

    pfSense is highly scalable. The only limitation is the hardware you have behind it. As long as you can upgrade your hardware when you scale, pfSense will be able to support it. 

    How are customer service and support?

    I rate pfSense support nine out of 10. I've typically gotten all the answers I sought when needed. They are highly responsive. I don't think I've ever had to wait more than an hour to get a reply. 

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    I wasn't involved in deploying pfSense. I maintain an existing one. For maintenance, you just need to periodically update to the latest version of pfSense Plus and maintain the different rulesets, such as firewall, IPS, and pfBlocker rules. 

    What was our ROI?


    What's my experience with pricing, setup cost, and licensing?

    The total cost of ownership of pfSense is rather low. After the recent subscription change, it doesn't cost us more than a couple hundred bucks a year. The only other thing I have to pay for is the business Snort license for the IDaaS IPS functionality. 

    What other advice do I have?

    I rate pfSense nine out of 10. I recommend doing a white box deployment because it's easier on the hardware. I tried pfSense on a Netgate appliance and wasn't impressed with the performance compared to the white box I already had in place. I suggest starting with a spare server you have — Dell, HP, etc. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Consultant at PM Solutions
    Consultant
    Nov 13, 2023
    Most functions are readily available, and additional features can be obtained by downloading and installing plugins
    Pros and Cons
    • "Its scalability is a strong point."
    • "One concern I have with Netgate pfSense is related to packet filtering. Specifically, issues can arise with certain functionalities like GP, and, at times, there may be bugs."

    What is our primary use case?

    I have used Netgate pfSense for a range of purposes. Initially, I employed it for VPN connections, mainly for personal and professional use. I also relied on it to maintain network equipment in a professional context. In the professional sphere, I have experience with both pfSense and Juniper, but eventually, I decided to phase out Juniper due to its high costs, especially for updates and the addition of new functionalities. pfSense's cost-effectiveness and the flexibility to transition to new hardware while retaining configurations made it a preferred choice. pfSense also stands out in terms of its rapid algorithm evolution compared to competitors like Juniper. Its scalability is another advantage, where adding a new box or reconfiguring can boost the firewall's capacity.

    On a personal note, I use Netgate pfSense to connect to my equipment at the data center. Currently, I have a highly available installation that requires two instances of pfSense. While I considered pfSense for this setup, I had to assess whether OpenSense might offer better features for future requirements before delving deeper into pfSense.

    What is most valuable?

    It's worth noting that Netgate pfSense's performance is independent of the hardware it runs on. As I mentioned earlier, its scalability is a strong point. Most functions are readily available, and additional features can be obtained by downloading and installing plugins, which are generally free. When you compare this to the alternative of purchasing a firewall from a different supplier, you'll find that the latter option typically doubles the cost of the firewall itself. This cost increase is often attributed to additional licenses for deep inspection and similar functionalities. While configuring pfSense may require more time and effort upfront, the long-term cost savings make it a more cost-effective choice.   

    What needs improvement?

    One concern I have with Netgate pfSense is related to packet filtering. Specifically, issues can arise with certain functionalities like GP, and, at times, there may be bugs. When creating IP lists, I've noticed that synchronization doesn't always function correctly. While it's not entirely dysfunctional, troubleshooting these synchronization problems can be quite challenging.

    For how long have I used the solution?

    I have been using Netgate pfSense since 2015-16.

    What do I think about the stability of the solution?

    I've experienced certain issues with Netgate pfSense in the past, particularly with the previous version, which was 2.5. It posed several problems. However, the current version appears to be more stable. Nonetheless, I still encounter troubleshooting challenges. For instance, there is an issue where it initially blocks an IP range but releases it after ten minutes. This behavior is somewhat peculiar, and it pertains to IP filtering.

    How are customer service and support?

    The support for Netgate pfSense mainly comes from online forums. These forums are populated by a significant number of individuals who are knowledgeable in pfSense and its related areas, making it a valuable resource.

    Which solution did I use previously and why did I switch?

    The choice of whether to use Netgate pfSense often depends on the company's preferences. In some cases, particularly in Switzerland, there is a strong preference for open source solutions. This choice is sometimes motivated by the desire for open source alternatives and can also be related to cost considerations.

    How was the initial setup?

    The Initial setup is very easy.

    What's my experience with pricing, setup cost, and licensing?

    Netgate pfSense is a cost-effective option. If you're not using a VPN, you can acquire a decent embedded PC for around a hundred dollars and install pfSense on it, effectively creating a robust firewall solution. With this setup, you can achieve a throughput of two hundred to three hundred megabits per second without any issues, provided you're handling relatively simple rules. The level of performance depends on the specific requirements and tasks.

    What other advice do I have?

    If you're considering using Netgate pfSense for the first time, I would recommend giving it a try. It's relatively easy to set up and use, especially if you have some prior knowledge of network and IT work. The user manual provides helpful guidance, and the basic configuration is straightforward. Just ensure you pay attention to the hardware requirements to make the most of it.

    It can be rated as an eight for simplicity. However, as you progress and introduce complexities, such as enabling deep packet inspection, adding extra features, or installing multiple plugins, the configuration can become more intricate. I encountered some issues with iOS in version 2.5, but they are expected to be resolved or have been resolved.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Works at a comms service provider with 1-10 employees
    Real User
    Aug 4, 2024
    Feature-rich and has a well-supported web interface
    Pros and Cons
    • "The solution's web interface is very feature-rich and well-supported."
    • "It would be nice for the code optimization to run on even slower processes."

    What is our primary use case?

    I use the solution in my home. It's my firewall, DNS server, DHCP server, intrusion detection server, and reverse proxy server.

    What is most valuable?

    The solution's web interface is very feature-rich and well-supported. There's a large community of users out there you can get to. There are many things that I'm not using at the time. It's got great support for VPNs. One of the ways that I'm using it is for VPN support as well. Netgate pfSense is a great product.

    Netgate pfSense is an extremely flexible solution.

    You'll see the benefits of Netgate pfSense immediately after you deploy it. The more features you use, the more benefits you get from it. I'm using the tool for VLAN support. That was something I implemented first, and it completely changed the way I was using my network. That was a real game-changer because it provided greatly enhanced security for my network and reduced the complexity of my network.

    The firewall, the intrusion detection service, the VPN support, and VLAN support keep me from getting hacked and possibly having problems with ransomware and potential data loss.

    pfSense Plus provides features that help us minimize downtime. You can create copies of different environments that you set up. If you want to try a setting but want to be protected from loss and downtime, you can create a copy of your current working environment.

    You should try adding the new change to your pfSense configuration. If that doesn't work, you can easily go back to the working configuration with just a simple change from within the web interface. It also does automatic backups of its configuration.

    The visibility of pfSense Plus helps us optimize performance. You can overcome latency issues through traffic shaping. I previously had buffer bloat issues, which I don't have currently.

    If you have a slower connection, you can use traffic shaping limiters and priority queues to ensure that your VoIP traffic, internet TV traffic, or streaming traffic has enough guaranteed bandwidth. In my case, my broadband connection is wide enough, and I do not have to really use those features.

    The cost of ownership of Netgate pfSense with the hardware cost was about $ 350.

    What needs improvement?

    It would be nice for the code optimization to run on even slower processes. It's optimized quite a bit, but there's always room for improvement.

    For how long have I used the solution?

    I have been using Netgate pfSense for two years.

    What do I think about the stability of the solution?

    We haven’t faced any issues with the solution’s stability.

    How was the initial setup?

    From my point of view, the solution's initial setup is pretty easy. Many YouTube videos are out there to help you get it up and running. There's a lot to try, a lot of things to do, and a lot of technology to play with, but I'm afraid I'm a bit of a tinkerer. To do what I initially wanted, I probably spent a day.

    What's my experience with pricing, setup cost, and licensing?

    I would like to see the solution's price reduced.

    What other advice do I have?

    There is some complexity to adding features to pfSense and configuring them. I would not say it's extremely complex, but it's got a high degree of complexity.

    The website is all you need to configure Netgate pfSense. If you choose to, you can use its SSH terminal interface, but that's not something that most users would do. I would think they would stick with its fully developed, mature web interface.

    The solution by itself does not need any maintenance. However, if you use the incursion detection plugins, you need to make sure that those are tuned properly. That involves periodic checks and possible adjustments. New users should be prepared to learn, read the manual, and utilize YouTube resources. It'll be worth it.

    Overall, I rate the solution ten out of ten.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Buyer's Guide
    Download our free Netgate pfSense Report and get advice and tips from experienced pros sharing their opinions.
    Updated: July 2026
    Product Categories
    Firewalls
    Buyer's Guide
    Download our free Netgate pfSense Report and get advice and tips from experienced pros sharing their opinions.