PfSense 2.3-Release Now Available
blog.pfsense.org
PfSense 2.3-Release Now Available
1–10 of 33 posts
Re: PfSense 2.3-Release Now Available
#2Re: PfSense 2.3-Release Now Available
#3I had a backup server running Ubuntu with ZFS which was always on anyways so I just had to install pfSense on OS disk and it imported the ZFS disks right away. So for a long time it was both my backup server and the router/firewall.
But lately with all the upgrades (including 2.3 betas and RCs I ran) SAMBA throughput was reduced significantly - not entirely sure if it were the drivers, ZFS or something else. And I realized maybe it is not such a great practice to make your router/firewall double up as a backup server. So I virtualized the box using ESXi and ran pfSense and Debian in two VMs on it.
The box being weak and running virtualized along side another backup server VM exposed the performance issues with pfSense - I had given a single CPU and 512Mb to it and with the GUI and other process overheads - DNS cache, pingers etc. meant that I had noticeable slowdowns when both VMs were active.
I am giving VyOS a try - it's a debian based router distro and purely command line based but resource utilization wise it seems to be doing fine with 512Mb and single CPU.
Anyone having a low power dedicated box for pfSense should just use pfSense though - the UI is way too good in 2.3 release and stuff just works - IPV6, Tunneling, VPN are very easy to configure along with a bunch of other things limited only by the box you're running it on.
Re: PfSense 2.3-Release Now Available
#4Re: PfSense 2.3-Release Now Available
#5With the crappy, underpowered consumer routers with gaping security holes pfSense is a god send. Last few years I've been running pfSense and the experience has been fairly great. I had a backup server running Ubuntu with ZFS which was always on anyways so I just had to install pfSense on OS disk and it imported the ZFS disks right away. So for a long time it was both my backup server and the router/firewall. But lat…
The Ubiquiti edgemax routers are also pretty nice and cheap, they have a good GUI. I remember also someone here posting how he runs openbsd in the edgemax routers.
Re: PfSense 2.3-Release Now Available
#6With the crappy, underpowered consumer routers with gaping security holes pfSense is a god send. Last few years I've been running pfSense and the experience has been fairly great. I had a backup server running Ubuntu with ZFS which was always on anyways so I just had to install pfSense on OS disk and it imported the ZFS disks right away. So for a long time it was both my backup server and the router/firewall. But lat…
There's also OpenBSD which lends itself very nicely for router/firewall setups. The Ubiquiti edgemax routers are also pretty nice and cheap, they have a good GUI. I remember also someone here posting how he runs openbsd in the edgemax routers.
Re: PfSense 2.3-Release Now Available
#7Not that a firewall needs to look pretty, and yes, I know it's Bootstrap, but the new UI is so much more pleasant to look at! Worth it for this alone.
Re: PfSense 2.3-Release Now Available
#8Earlier quoted context omitted.
There's also OpenBSD which lends itself very nicely for router/firewall setups. The Ubiquiti edgemax routers are also pretty nice and cheap, they have a good GUI. I remember also someone here posting how he runs openbsd in the edgemax routers.
I have never looked into OpenBSD - but how is the driver support now a days? I did some searching around and looks like VMWare tools for example need to be installed in FBSD emulation mode. It might be a good idea from a security perspective, just not sure how well it will work either bare hardware or virtualized.
It doesn't support "vmware tools" as such, but does support the virtual interfaces for network, disk, ballooning etc...
Re: PfSense 2.3-Release Now Available
#9Either it needs a configuration language like Cisco/Juniper than can be dumped/imported/configured over SSH, or a web API (supposedly on the roadmap for pfsense 3.0 ... ?). I can't say I'm too familiar with the project, but it feels like it's just not a priority and that it's is going to remain very web UI focussed.
Re: PfSense 2.3-Release Now Available
#10I'd really love to see an API or a unified configuration system. At $WORK we have a need for many small firewall appliances, but I refuse to use anything we can't deploy zero-touch, automate, monitor and back up/restore in a semi-sane way. Either it needs a configuration language like Cisco/Juniper than can be dumped/imported/configured over SSH, or a web API (supposedly on the roadmap for pfsense 3.0 ... ?). I can't…
That's next (3.0)
> feels like it's just not a priority and that it's is going to remain very web UI focussed.
part of it is the audience we have. part of it is dealing with the architecture we have.
but... trust me, it's likely more important to me than you.