Live data from Hacker News

PfSense 2.2-Release Now Available

blog.pfsense.org

11–20 of 36 posts

Re: PfSense 2.2-Release Now Available

#12
post #8

Is ARM support on the radar? There is more and more capable ARM hardware by the day, while x86 is not getting any cheaper. I would be happy to try pfSense on something like BPI-R1 (dual-core 1 GHz Cortex-A7, Wi-Fi, etc., $69 for board) http://www.aliexpress.com/store/product/Newest-arrive-BPI-R1... http://www.bananapi.com/?layout=edit&id=59

MIPS is I believe planned first. Check out Netgate (company behind Pfsense), they already have development boards with MIPS.

Bigger upcoming feature is bhyve hypervisor on Pfsense :D

Re: PfSense 2.2-Release Now Available

#13
post #7
post #3

2.2-RELEASE also has a working 6rd implementation, so now I can finally use ipv6 :-)

You could have used it before with a gif tunnel. That's the way I've been doing 6rd on vanilla FreeBSD without any 6rd support. edit: Here's what you put in rc.conf cloned_interfaces="gif0" ipv6_activate_all_interfaces="YES" ifconfig_gif0="tunnel $MYIPv4 $THEIRIPv4" ifconfig_gif0_ipv6="inet6 alias $MYIPv6 $THEIRIPv6 prefixlen 128" ipv6_defaultrouter="$THEIRIPv6 -mtu 1280"

Great! Thanks!

Re: PfSense 2.2-Release Now Available

#14
post #11

We use it with about 30 offices, all connected via openvpn. 180GB transfer every day. No problem for months.... Hell of a software!

Chris Buechler the main developer is also hands down one of the most approachable and friendly people I've ever met.

Re: PfSense 2.2-Release Now Available

#15

It still ships an oudated port of PF. Horrible. Go run OpenBSD instead.

Does OpenBSD/newer PF have better throughput on 10Gbe+ hardware? I've heard that OpenBSD/PF tends to run into issues due to giant lock and SMP issues.

Since you seem knowledgeable, any pointers to information about that?

Re: PfSense 2.2-Release Now Available

#16
post #11

We use it with about 30 offices, all connected via openvpn. 180GB transfer every day. No problem for months.... Hell of a software!

Curious why you chose OpenVPN for your site-to-site links. I use it extensively for mobile VPN users, but for an "infrastructure" VPN, I use IPsec, which I find to be a much superior solution for that use case than OpenVPN.

Re: PfSense 2.2-Release Now Available

#17
I ran PfSense for a year or so... never could get the QoS working completely right and all the tutorials I found weren't the greatest.

Has anything changed with the QoS configuration?

I've since moved to an Untangle VM that has worked great... yes the interface might be "dumbed down", but everything has been working excellent.

Re: PfSense 2.2-Release Now Available

#19
I'm a big fan of pfSense - heavy home remote worker user, it stays up and connects to multiple OpenVPN servers, routing their spaces for my network, runs a remote access server inbound, an IPv6 tunnel via Tunnelbroker, multiple static IPs, including straightforward outbound NAT for my Apple TV to access NBA League Pass games (since the NBA in its wisdom has decided that the Puget Sound should be blacked out for Portland games and that I can just "tune into CSN Portland").

Re: PfSense 2.2-Release Now Available

#20

Great news. I've been running pfSense at home and work for the past few years, and it's been great. Very stable, easy to configure, and quick with security fixes. A pfSense box with a Ubiquiti UniFi access point is a really good combo. Far more stable than a typical consumer router, and not necessarily much more expensive.

I have the exact same setup. Works great.
Post reply on HN