Netgate pfSense Plus Firewall/VPN/Router
Netgate | 24.11.0Linux/Unix, FreeBSD 14 - 64-bit Amazon Machine Image (AMI)
External reviews

External reviews are not included in the AWS star rating for the product.
pfSense
What do you like best about the product?
I like that it is based on free software, it has built-in features of switches, routers, firewall, dhcp server, proxy, it is easy to install, easy to configure, it supports protocols such as tunnels vpn ip sec, and it can be installed on site and in the cloud .
It allows load balancing and redundancy in WAN links.
It allows load balancing and redundancy in WAN links.
What do you dislike about the product?
Linux at the hardware level is manual, in many cases if the installation is done on a computer, the network cards will probably have to be installed manually
What problems is the product solving and how is that benefiting you?
Network infrastructure management on a single computer, everything is centralized, dhcp server, vpn tunnels with clients, built-in diagnostic tools, proxy, content filtering, it is also free of licensing, I really recommend it fully
Recommendations to others considering the product:
It is the best option, quality and low cost, all the tools integrated in the same system
- Leave a Comment |
- Mark review as helpful
pfSense
What do you like best about the product?
It is based on free software, very easy to install, it can be installed on a computer, hardware requirements are low, it allows communication protocols such as tunnels vpn ip sec, vlan, content filtering
What do you dislike about the product?
There are times when the network interface is inhibited or the operating system may be stuck and services must be restarted
What problems is the product solving and how is that benefiting you?
Increase in network security, load balancing, redundancy with multiple wan, creation and segmentation through vlans, integrated dhcp server
Recommendations to others considering the product:
Test it
Works well with AWS networking
I used the pfSense Netgate firewall/VPN/Router to help study for the AWS Advanced Network Specialty exam. Simple to set up, I used it to build VPNs w/BGP between two VPCs and a remote network using pfSense on two sides and a VGW in the middle. The latest version supports VTI interfaces so you can use route-based VPN instead of policy-based VPN. Without VTI interfaces you can set up a VPN but BGP doesn't work as expected. I had no problems setting up VTI interfaces in the VPN configuration, installing OpenBGPD, and routing traffic using CloudHub VPN and BGP to connect the two VPCs and my remote network together.
In my opinion, the pfSense firewall was easy to set up and the interface is fairly intuitive if you're familiar with networking and security. I've used the community edition for a while and the AWS version has the same look-and-feel. There's also a number of open source options that can be added to extend the functionality of the product.
I think the only downside is the pricing. I wish the t2.nano and t2.micro were both priced the same. The t2.nano is great for a trial run. However, if you install any options you'll probably want something larger than a t2.nano and that will create a significant price increase. Then again, Netgate's pricing seems to be much lower than comparable products in AWS marketplace so it looks like it cost less to run than other products with similar functionality.
I would recommend Netgate pfSense if you are looking for a low-cost stateful firewall that is built using open source software and can do VPN and routing too.
1 person found this helpful
Great option of perimeter firewall
What do you like best about the product?
The pfSense is an Open Source project that is being supported by Netgate and offers great perimeter security for small businesses that do not have the money for an ASA, FortiGate or other similar device. The application of traffic policies is very easy to do and personalization of these is very useful with the tools available to the system. It is great the system of packages that extend the functions, for example the package for IDS / IPS Snort is great, the OpenVPN for VPN is very easy to use and so other options that can be incorporated for free.
What do you dislike about the product?
In the last version the support to the unofficial packages was removed, this decision is very annoying because there are many very good packages that are not included in the pfSense library. Another point not so remarkable is the traffic monitoring options that pfSense has, however it fulfills its function for non-demanding users.
What problems is the product solving and how is that benefiting you?
The main advantage of pfSense is the cost, which is 0 and thanks to this, contracts were obtained with external clients that did not have enough funds for a commercial perimeter firewall. The function of VPN with OpenVPN and the application of Snort are the best features that have significantly improved the performance and productivity of our customers' networks.
Recommendations to others considering the product:
Consider the pfSense in case your network needs port security and minimal protection from the outside. If an active and more granular management of the threats and the traffic that passes through it is required, think about accumulating more resources to acquire another superior product.
Great open source firewall
What do you like best about the product?
Open source professional level firewall. Particularly features like multi-wan and how that is implemented into standard features like NAT etc.
What do you dislike about the product?
Many of the services I would like to run are add on packages not truly part of the system. Those have non-standard configs and interfaces because of it. They can be broken or unstable because of it.
What problems is the product solving and how is that benefiting you?
Multi-wan internet supplied by multiple ISP's and used directly without most staff even knowing it. Provides various switching and failover methods for bandwidth or times when an ISP is unreliable.
Recommendations to others considering the product:
While I really like this product, I have moved on to a fork of it called OPNSense that I would recommend over pfSense. pfSense a is good product but much has changed with the project and the company behind it. I put them in second place because that is where there software falls based on most usage. Hope their next release release with all the drastic changes announced a couple of years ago will change my mind.
Will not launch in the US-WEST-2 region
I've successfully launched this in other regions, but it will not launch in the US-WEST-2 region. Please fix this! The system log shows the operating system halting and rebooting constantly.
Great for Site-to-Site
Very easy to use.
The UI is Intuitive.
Site-toSite VPN is very stable.
You can upgrade to a newer version from the UI.
Strongly recommended!
1 person found this helpful
IPsec VPN routing issue
GUI is very easy to use, site-to-site VPN tunnel established easily.
However, it seems miss routing config, I could not find a way to route traffic into this VPN tunnel.
Very easy to install out of the gate and a robust routing platform.
What do you like best about the product?
Can't believe how easy it is to set up out of the box. Fire up the server, install the platform and then you assign a LAN/WAN interface... DONE!
What do you dislike about the product?
I would like to see more analytics or an easier way to get to client based data from the dashboard.
What problems is the product solving and how is that benefiting you?
I am looking for a secure, but easy and highly configurable platform that just plain WORKS. This seems to fit the bill.
So powerful
What do you like best about the product?
With this product being open source it amazing how powerful the features you get with it and the ability to configure to your needs is great!
What do you dislike about the product?
It can be hard to get the configuration you want at the start but you get there in the end!
What problems is the product solving and how is that benefiting you?
Free open source protection for your network what more could you want!
showing 311 - 320