Live data from Hacker News

PfSense 2.2-Release Now Available

blog.pfsense.org

21–30 of 36 posts

Re: PfSense 2.2-Release Now Available

#21

Great news. I've been running pfSense at home and work for the past few years, and it's been great. Very stable, easy to configure, and quick with security fixes. A pfSense box with a Ubiquiti UniFi access point is a really good combo. Far more stable than a typical consumer router, and not necessarily much more expensive.

I run this exact same setup (pfSense-based Mini-ITX router and several UAP-ACs), and it works outstanding. I had used DD-WRT for several years, but having hack pile up on top of hack to keep things running on DD-WRT. When we moved to a larger house, we could no longer adequately cover the house from a single router/access point combo, so I took the leap and built a pfSense machine. Absolutely don't regret it. After getting it set up, it just works with minimal intervention.

With a little work, you can get the Ubiquiti controller software running on the actual pfSense machine itself. http://community.ubnt.com/t5/UniFi-Wireless/Tutorial-UniFi-3...

Re: PfSense 2.2-Release Now Available

#22
post #8

Is ARM support on the radar? There is more and more capable ARM hardware by the day, while x86 is not getting any cheaper. I would be happy to try pfSense on something like BPI-R1 (dual-core 1 GHz Cortex-A7, Wi-Fi, etc., $69 for board) http://www.aliexpress.com/store/product/Newest-arrive-BPI-R1... http://www.bananapi.com/?layout=edit&id=59

MIPS is I believe planned first. Check out Netgate (company behind Pfsense), they already have development boards with MIPS. Bigger upcoming feature is bhyve hypervisor on Pfsense :D

Worth noting that the Ubiquiti ERLite runs a MIPS board, but has TCP offload. It runs Debian current MIPS with Vyatta, and the web UI, while not as fully-featured as pfSense, is pretty usable. It still helps to be comfortable with CLI and Vyatta commands (very similar to Cisco IOS) for e.g. setting up L2TP VPN without an external RADIUS server.

I ran pfSense for years, and it does work great, but an x86 box running all the time just to do what a little 2-decks-of-cards box can do with 1/10th the power seems silly these days.

http://wiki.gentoo.org/wiki/MIPS/ERLite-3

Re: PfSense 2.2-Release Now Available

#24

Earlier quoted context omitted.

MIPS is I believe planned first. Check out Netgate (company behind Pfsense), they already have development boards with MIPS. Bigger upcoming feature is bhyve hypervisor on Pfsense :D

Worth noting that the Ubiquiti ERLite runs a MIPS board, but has TCP offload. It runs Debian current MIPS with Vyatta, and the web UI, while not as fully-featured as pfSense, is pretty usable. It still helps to be comfortable with CLI and Vyatta commands (very similar to Cisco IOS) for e.g. setting up L2TP VPN without an external RADIUS server. I ran pfSense for years, and it does work great, but an x86 box running a…

Also worth adding that the ERL runs EdgeOS, which is actually a fork of Vyatta 6.3 with some added features and certain hardware accelerations. [1]

Vyatta was acquired by Brocade in 2012, after which the community edition was sidelined and the main product became closed source. Thankfully Vyatta core was forked in 2013 and re-branded as VyOS (free and open source) and is under active development. [2]

I've used pfSense in the past and VyOS currently and found both to be excellent.

[1] https://community.ubnt.com/t5/EdgeMAX/EdgeOS-vs-Vyatta/td-p/...

[2] http://vyos.net/wiki/Main_Page

Re: PfSense 2.2-Release Now Available

#25
post #21

Great news. I've been running pfSense at home and work for the past few years, and it's been great. Very stable, easy to configure, and quick with security fixes. A pfSense box with a Ubiquiti UniFi access point is a really good combo. Far more stable than a typical consumer router, and not necessarily much more expensive.

I run this exact same setup (pfSense-based Mini-ITX router and several UAP-ACs), and it works outstanding. I had used DD-WRT for several years, but having hack pile up on top of hack to keep things running on DD-WRT. When we moved to a larger house, we could no longer adequately cover the house from a single router/access point combo, so I took the leap and built a pfSense machine. Absolutely don't regret it. After g…

I tried running the Ubiquiti controller software on the pfSense box for a while, but it was a pain - it took 5-10 minutes to start up, and it was lost whenever I did a pfSense upgrade. I've found it much easier to just point the access points at a general-purpose server (on-site if available, or on a remote VPS that I have already).

Re: PfSense 2.2-Release Now Available

#26
post #16
post #11

We use it with about 30 offices, all connected via openvpn. 180GB transfer every day. No problem for months.... Hell of a software!

Curious why you chose OpenVPN for your site-to-site links. I use it extensively for mobile VPN users, but for an "infrastructure" VPN, I use IPsec, which I find to be a much superior solution for that use case than OpenVPN.

Not the OP, but I've found OpenVPN easier to configure, and performance to be adequate. In what ways have you found IPsec to be superior?

Re: PfSense 2.2-Release Now Available

#27
post #16

Earlier quoted context omitted.

Curious why you chose OpenVPN for your site-to-site links. I use it extensively for mobile VPN users, but for an "infrastructure" VPN, I use IPsec, which I find to be a much superior solution for that use case than OpenVPN.

Not the OP, but I've found OpenVPN easier to configure, and performance to be adequate. In what ways have you found IPsec to be superior?

Well the #1 thing for me is that the majority of IPsec functions are in the kernel and don't require that a userland daemon be running (which OpenVPN requires). Beyond that, I've just found that, while a bit more arduous to configure initially, performance is far superior and stability is better than OpenVPN.

Beyond that, pretty much every router out there supports IPsec, so if you're needing to integrate with other non-pfsense hardware, IPSec is often your only option.

Re: PfSense 2.2-Release Now Available

#28
post #21

Earlier quoted context omitted.

I run this exact same setup (pfSense-based Mini-ITX router and several UAP-ACs), and it works outstanding. I had used DD-WRT for several years, but having hack pile up on top of hack to keep things running on DD-WRT. When we moved to a larger house, we could no longer adequately cover the house from a single router/access point combo, so I took the leap and built a pfSense machine. Absolutely don't regret it. After g…

I tried running the Ubiquiti controller software on the pfSense box for a while, but it was a pain - it took 5-10 minutes to start up, and it was lost whenever I did a pfSense upgrade. I've found it much easier to just point the access points at a general-purpose server (on-site if available, or on a remote VPS that I have already).

Weird. Other than the startup thing (which is not a big deal for me because I leave it running), I haven't had any problems upgrading. A few months ago I went to 2.1.5 and pretty much everything just worked.

Re: PfSense 2.2-Release Now Available

#29
post #28

Earlier quoted context omitted.

I tried running the Ubiquiti controller software on the pfSense box for a while, but it was a pain - it took 5-10 minutes to start up, and it was lost whenever I did a pfSense upgrade. I've found it much easier to just point the access points at a general-purpose server (on-site if available, or on a remote VPS that I have already).

Weird. Other than the startup thing (which is not a big deal for me because I leave it running), I haven't had any problems upgrading. A few months ago I went to 2.1.5 and pretty much everything just worked.

Minor upgrades were fine. It was a major one (2.0 to 2.1) that wiped it out for me. This was on the embedded version of pfSense - the full version might behave differently.

Otherwise, the upgrade was one of the smoothest I've ever had for this sort of thing.

Re: PfSense 2.2-Release Now Available

#30

Earlier quoted context omitted.

MIPS is I believe planned first. Check out Netgate (company behind Pfsense), they already have development boards with MIPS. Bigger upcoming feature is bhyve hypervisor on Pfsense :D

Worth noting that the Ubiquiti ERLite runs a MIPS board, but has TCP offload. It runs Debian current MIPS with Vyatta, and the web UI, while not as fully-featured as pfSense, is pretty usable. It still helps to be comfortable with CLI and Vyatta commands (very similar to Cisco IOS) for e.g. setting up L2TP VPN without an external RADIUS server. I ran pfSense for years, and it does work great, but an x86 box running a…

How much power does the ERLite-3 use? I've run PCEngine APU (http://www.pcengines.ch/apu.htm) boards with pfsense and it's worked great with very minimal power usage. Although they are usually a bit more expensive than an ARM board.
Post reply on HN