Live data from Hacker News

Addressing Changes to PfSense Plus Home+Lab

netgate.com

11–20 of 63 posts

Re: Addressing Changes to PfSense Plus Home+Lab

#12
post #8

[flagged]

We often confuse Free and Open Source with "free beer". We have been using pfsense for years without paying a dime; if we could we would gladly have done it. It's simple fairness.

Also, what we forget is that if we are not paying, somebody else is paying. And somebody else is very likely not aligned with our interests.

There is this conventional wisdom that a lawyer is not really your lawyer until it is you who is paying them. I think it has much broader application and you want to be paying for technology. It is naive to think you can accept services of say Facebook, not pay a dime for it and assume it is all done in your best interests.

Re: Addressing Changes to PfSense Plus Home+Lab

#13

Massive influx of users to OPNsense

Sadly, pfSense lost me a long time ago. I'm happily on my 2nd OPNsense business license on Deciso embedded Ryzen-based hardware with 10 GigE optical links. Even takes care of PKI and has 2FA. I'm happy and I don't have to worry about massive, arbitrary license changes or big corporate enshitification.

Just couldn't get IPv6 working with pfSense, as they had really limited support.

Moved to OpenWRT a few years ago and been quite happy since.

Re: Addressing Changes to PfSense Plus Home+Lab

#14
post #8

Earlier quoted context omitted.

We often confuse Free and Open Source with "free beer". We have been using pfsense for years without paying a dime; if we could we would gladly have done it. It's simple fairness.

Also, what we forget is that if we are not paying, somebody else is paying. And somebody else is very likely not aligned with our interests. There is this conventional wisdom that a lawyer is not really your lawyer until it is you who is paying them. I think it has much broader application and you want to be paying for technology. It is naive to think you can accept services of say Facebook, not pay a dime for it and…

This is not the right mental model because:

- software is copyable for free

- contributing to open source doesn’t make the developers your agents like paying a lawyer does

Re: Addressing Changes to PfSense Plus Home+Lab

#16

I migrated to OPNsense during the wireguard fiasco. It was an extremely boring migration, and I mean that as compliment. It's been quietly doing its job ever since, with a minimum of fuss.

I have thought about moving from pfsense to opnsense but in my test install I had a feeling it has fewer features (and messy UI).

For example something I use pretty heavily is pfblocker that automatically geo-blocks ips from different countries that most attack my homelab (Russia, USA, china ,etc..) from accessing my homelab

Is there something like this on opnsense?

Re: Addressing Changes to PfSense Plus Home+Lab

#17

I migrated to OPNsense during the wireguard fiasco. It was an extremely boring migration, and I mean that as compliment. It's been quietly doing its job ever since, with a minimum of fuss.

Got any tips for the migration? I've been meaning to do it for a while, but I really need to limit down time or my wife and kids will bury me; preferably need to do it over an evening while they're all asleep.

I only have the one piece of hardware so I need a record of the configs somehow to refer to as I do the migration. Perhaps also some sort of backup so I can restore it in a pinch if I can't get OPNSense set up quick enough.

Re: Addressing Changes to PfSense Plus Home+Lab

#18
post #16

I migrated to OPNsense during the wireguard fiasco. It was an extremely boring migration, and I mean that as compliment. It's been quietly doing its job ever since, with a minimum of fuss.

I have thought about moving from pfsense to opnsense but in my test install I had a feeling it has fewer features (and messy UI). For example something I use pretty heavily is pfblocker that automatically geo-blocks ips from different countries that most attack my homelab (Russia, USA, china ,etc..) from accessing my homelab Is there something like this on opnsense?

This is important for me too. From my searching, they have "GeoIP aliases" which is supposed to be their alternative to PfBlocker-NG; I have no idea if/how it functions as I haven't made the mode yet, but this is a deal breaker if it doesn't work the way I need.

Re: Addressing Changes to PfSense Plus Home+Lab

#19

I migrated to OPNsense during the wireguard fiasco. It was an extremely boring migration, and I mean that as compliment. It's been quietly doing its job ever since, with a minimum of fuss.

Got any tips for the migration? I've been meaning to do it for a while, but I really need to limit down time or my wife and kids will bury me; preferably need to do it over an evening while they're all asleep. I only have the one piece of hardware so I need a record of the configs somehow to refer to as I do the migration. Perhaps also some sort of backup so I can restore it in a pinch if I can't get OPNSense set up…

I'm afraid I did it the slow way, and just nuked the router and set up OPNSense from scratch.

In older versions it was possible to import a PfSense backup - with a few glitches, but they're too different now. I think the slow way is the only way.

Re: Addressing Changes to PfSense Plus Home+Lab

#20
Here we go again.... I've been resisting the change from pfSense to OPNsense for a while now but I start to really think I should just move on and get it done. All these f*ups with licensing and bs* from Netgate starts to be annoying. Just make a 50 or 100 license for home users who need / want to deploy a better router / firewall and get done with it! I moved from CE to this PeshPlus thing because supposedly CE was going to cease to exist... Now the PeshPlus is actually the one being discontinued! Wtf Negate!!! Get a grip.
Post reply on HN