Live data from Hacker News

Addressing Changes to PfSense Plus Home+Lab

netgate.com

51–60 of 63 posts

Re: Addressing Changes to PfSense Plus Home+Lab

#52

I migrated to OPNsense during the wireguard fiasco. It was an extremely boring migration, and I mean that as compliment. It's been quietly doing its job ever since, with a minimum of fuss.

I did as well and started running it in a vm. It is so nice to just make a snapshot, update and revert if it breaks.

Re: Addressing Changes to PfSense Plus Home+Lab

#55
post #38
post #32

Earlier quoted context omitted.

> Hey, listen, the company is putting a lot of effort into pfSense for which they are not paid. And? pfsense uses thousands of packages that they don't pay for either, that's the spirit of open source, I can't understand who post this on HN without understanding it. @dang: Can we ban these comments? Lately they arrive like clockwork and bring very little to the comments, especially since it doesn't seem to be talking…

> pfsense uses thousands of packages that they don't pay for either, that's the spirit of open source You are miss-understanding what open source means. It doesn't mean everything has to be free. Many companies are built on top of open source software which allows them to do exactly that in their license. You also don't know if pfsense sponsors packages or contributes code to the packages they are using. It's the rig…

whole lotta people making a ton of money from FOSS, selling packages on hardware. everything android or MacOS comes to mind

Re: Addressing Changes to PfSense Plus Home+Lab

#56

Has Netgate provided any meaningful new features to pfsense over the last 5-10 years? Or is it just “support” for essentially what pfsense was a decade ago?

> Or is it just “support” for essentially what pfsense was a decade ago? "Just"? I'm sure all of use nerds and geeks on HN think commercial support is often not important, but there are plenty of SMEs that need to de-risk some things when running their infrastructure.

every large org I've been at pretty much requires escalation contacts and vendor support. is one of the reasons we pay for RHEL and Docker licenses, etc.

Re: Addressing Changes to PfSense Plus Home+Lab

#57

Has Netgate provided any meaningful new features to pfsense over the last 5-10 years? Or is it just “support” for essentially what pfsense was a decade ago?

> Or is it just “support” for essentially what pfsense was a decade ago? "Just"? I'm sure all of use nerds and geeks on HN think commercial support is often not important, but there are plenty of SMEs that need to de-risk some things when running their infrastructure.

Yes, I didn’t say there wasn’t value in support.

“Is this contractor responsible for the whole house or just the garage?” does not imply the garage isn’t important or that it’s trivial.

Re: Addressing Changes to PfSense Plus Home+Lab

#58

Massive influx of users to OPNsense

Sadly, pfSense lost me a long time ago. I'm happily on my 2nd OPNsense business license on Deciso embedded Ryzen-based hardware with 10 GigE optical links. Even takes care of PKI and has 2FA. I'm happy and I don't have to worry about massive, arbitrary license changes or big corporate enshitification.

The Deciso hardware is really nice! I also have a couple. Expensive but worth it.

Re: Addressing Changes to PfSense Plus Home+Lab

#59

Lots of comments about moving to OPNSense -- anyone using something Linux-based that they would recommend as a comparable alternative? My impression is that this might not exist yet (the currently available projects are significant lacking in either features or reliability), and that my odds of getting something user-friendly with tools like pfBlockerNG are even slimmer. I always feel so handicapped when something br…

I use a Linux box with at least two fast NICs - why not try it out?

The setup can be rough if one isn't that familiar/has high requirements... but making a router and so on is pretty basic stuff.

Basic in the sense that it's easy to do both well and terrifyingly incorrectly.

I'm curious about home users who truly need an interface because they're in there fiddling so much

I use Ansible to manage the config of mine, but that's more for rebuilding. I look at the thing maybe twice a year

Re: Addressing Changes to PfSense Plus Home+Lab

#60

I tried pfSense recently but I didn't love configuring my network through the UI. An API or something would make it amazing. But maybe that's the DevOps in me talking. I've been mostly happy with VyOS since then.

OPNsense is working towards that vision. They're rebuilding the car while it's driving down the road, so while some things aren't supported, many things can be done through the REST API. See https://docs.opnsense.org/development/architecture.html and https://docs.opnsense.org/development/api.html
Post reply on HN