Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Analista Senior at a tech services company
Real User
The gain in performance and security from configuring the VPN connections was significant
Pros and Cons
  • "The gain in performance and security from configuring the VPN connections was significant."
  • "It is a stable solution."
  • "My only observation is about the quality of the IPSec logs, which are difficult to interpret and are poor in filters."

What is our primary use case?

I use pfSense firewall, especially as an IPSec VPN Server. There are several VPN connections with equipment of various manufacturers at the other end.

I use ServerU as hardware instead of an ordinary PC, as most other people usually do.

How has it helped my organization?

The gain in performance and security from configuring the VPN connections was significant, since pfSense has replaced a server with a custom Linux open source version, which was running on outdated hardware.

What is most valuable?

Security and stability. The pfSense server acts as "IPSec VPN Server" for a small financial institution, but regardless of the company size, interruptions would cause significant financial impact.

What needs improvement?

pfSense serves us very well. My only observation is about the quality of the IPSec logs, which are difficult to interpret and are poor in filters. I have more than 10 IPSec VPN connections, and when there is a need for troubleshooting, the logs are of little help.

Buyer's Guide
Netgate pfSense
August 2024
Learn what your peers think about Netgate pfSense. Get advice and tips from experienced pros sharing their opinions. Updated: August 2024.
800,688 professionals have used our research since 2012.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

With regard to this configuration, I consider it a stable solution.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user607749 - PeerSpot reviewer
it_user607749Manager, Live Production at a computer software company with 1,001-5,000 employees
Real User

Thanks for the information!

PeerSpot user
Specialist in IT Infrastructure, Networks and Software Quality at a tech services company with 51-200 employees
Real User
An incomparable stability is achieved with other firewall systems
Pros and Cons
  • "An incomparable stability is achieved with other firewall systems."
  • "Firewall system for small, medium, and large data networks. It allows you to provide security to your environment: DMZ networks, LAN, WAN, etc."
  • "A very stable product that lasts over time, easy to understand, and administer."
  • "It is easy to use and has integrity with other systems, such as proxies and quality of service."
  • "It should integrate with LDAP, Active Directory, etc, to improve the way in which the traces and connections of each IP, or user connected through the firewall, are shown."

What is our primary use case?

Firewall system for small, medium, and large data networks. It allows you to provide security to your environment: DMZ networks, LAN, WAN, etc. A very stable product that lasts over time, easy to understand, and administer.

How has it helped my organization?

With pfSense, an incomparable stability is achieved with other firewall systems. It is easy to use and has integrity with other systems, such as proxies and quality of service.

What is most valuable?


  • Stability
  • Integration with other systems
  • Easy assimilation of its features
  • Easy administration
  • Multiple network management tools
  • Load balancing
  • Multiple links
  • High availability, etc.

What needs improvement?

The connections should be shown in a more specific way, as Kerio Control does. It should integrate with LDAP, Active Directory, etc, to improve the way in which the traces and connections of each IP, or user connected through the firewall, are shown.

For how long have I used the solution?

More than five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Netgate pfSense
August 2024
Learn what your peers think about Netgate pfSense. Get advice and tips from experienced pros sharing their opinions. Updated: August 2024.
800,688 professionals have used our research since 2012.
PeerSpot user
Sócio at a tech services company with 1-10 employees
Helps us maintain internet access for the company we support.

What is most valuable?

Outbound Load Balance for internet links work great. It's very good to keep internet access for the company we support.

How has it helped my organization?

I could keep my customers working even if they lose one internet link. Most of them have at least two links.

For how long have I used the solution?

We have been using this for 10 years.

What was my experience with deployment of the solution?

There was a problem when I ran a version update, then the server just stopped working. This was because pfSense (in this case FreeBSD) was no longer supporting the hardware of the server (HPE).

What do I think about the stability of the solution?

There were no stability issues. If there are issues, they usually stem from a hardware fault.

What do I think about the scalability of the solution?

There were no scalability issues.

How are customer service and technical support?

Customer Service:

It is usually easy to find answers in the forum.

Technical Support:

Technical support is good.

Which solution did I use previously and why did I switch?

I used Kerio and Microsoft. I switched because I was looking for something with better security and for someone who could fix bugs faster.

How was the initial setup?

The setup was easy. You can install it in two minutes. It takes more than five minutes to put it to work with a single internet link plus NAT.

What's my experience with pricing, setup cost, and licensing?

It is free.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user429552 - PeerSpot reviewer
Works with 51-200 employees
VPN has allowed me to deploy applications just for the organization and not to public servers.
Pros and Cons
  • "The ability to create a VPN allows me to monitor branch offices from a central location."
  • "A way to clean squid cache from the GUI."

How has it helped my organization?

VPN has allowed me to deploy applications just for the organization and not to public servers.

What is most valuable?

The ability to create a VPN allows me to monitor branch offices from a central location.

What needs improvement?

A way to clean squid cache from the GUI.

What do I think about the stability of the solution?

Not at all.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user284163 - PeerSpot reviewer
System Administrator at a media company with 1,001-5,000 employees
It's stable and features load balancing, although we've rebooted once in six months.

What is most valuable?

  • Snort
  • CARP
  • Load balancing
  • VPN

How has it helped my organization?

  • Reduced the cost of our firewall solution
  • Enhanced throughput compared with similar priced devices
  • Stability
  • Reliability

What needs improvement?

I'm no expert on this subject, and the OS performs all that is required.

For how long have I used the solution?

I've used it for over one year.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

We've only had to do one reboot in six months.

What do I think about the scalability of the solution?

None as yet, because the solution hasn't reached capacity yet.

How are customer service and technical support?

I'm yet to use the official tech support as the community provides all that I have required.

Which solution did I use previously and why did I switch?

  • Sonicwall
  • Cisco ASA

We switched due to licensing costs and scalability.

How was the initial setup?

It's relatively simple and straightforward, with enough documentation avalable online for the average user to install and setup.

What was our ROI?


Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user245433 - PeerSpot reviewer
Professional Internship - System Engineer at a tech services company with 51-200 employees
It's simple and easy to understand to begin using.

Valuable Features:

It's easy to access and configure in general.  As for features, the firewall and security  options were valuable.  These are valuable because I like simple things that are easy to work with, as too much difficulty or too much constraint is not good, and boring.

Improvements to My Organization:

It provided us with better security.

Use of Solution:

I used it for two months.

Deployment Issues:

There were no issues during the time I used it.

Stability Issues:

There were no issues during the time I used it.

Scalability Issues:

There were no issues during the time I used it.

Customer Service:

It was straightforward because it's simple and easy to understand to begin using.

Implementation Team:

We used a vendor team who had a good amount of knowledge,

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user179136 - PeerSpot reviewer
it_user179136Network Engineer at a tech services company with 501-1,000 employees
Real User

I find PfSense to be just what it claims to be. An enterprise class firewall for the world to enjoy for free! It has all the features and none of the costs. If you understand network engineering concepts, PfSense is your "Swiss-Army-Knife"
Need a firewall? PfSense
Need to do static routing? PfSense
Need to route with RIPv2, RIPng, BGP or OSPF? PfSense
Need VPNs? PfSense Yes that includes GRE tunnels over IPSEC
Need Dynamic DNS Clients? PfSense
Need enhanced object tracking for static routing? PfSense
Need multiple WAN connections load balanced? PfSense
Need traffic shaping? PfSense
Need a proxy server? PfSense
Need IDS? PfSense... install the snort package

I've only listed a few of the things it can do. It's been my home router firewall for 10 years.
I recommend it to SOHO owners and home IT enthusiasts alike whom are on a tight budget. It's got a great interface and it's rock stable. It'll run like a dream on an Intel P3 Processor with 640 Megabytes of RAM installed. It works great on a multitude of used / outdated hardware and offers paid support if you can't do the research/reading yourself. What else could you possibly ask for?

it_user222801 - PeerSpot reviewer
Technical Program Manager at a healthcare company with 51-200 employees
Straightforward set-up but it does require some technical expertise to do it.

What is most valuable?

  • Free
  • Open source
  • Robust
  • Strong community support
  • Strong author support

How has it helped my organization?

Critical network infrastructure has improved.

For how long have I used the solution?

I've used it for two years.

Which solution did I use previously and why did I switch?

I've also used Untangle and Sophos firewalls

How was the initial setup?

Straightforward, but it requires some technical expertise and tweaking.

What about the implementation team?

We implemented it entirely in-house.

What other advice do I have?

Make sure the implementer has programming experience.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user149982 - PeerSpot reviewer
it_user149982Project Manager at a tech vendor with 1,001-5,000 employees

Indeed this is a very powerful opensource solution but as you say it requires some technical expertise and tweaking (but actually which firewall technology does not require some now?). Fortunately the community and project documentation are rich and very helpful. Extra packages availability is also rich, it goes from the simple CLI tool like bmon to fully graphically managed RADIUS, SQUID, SNORT servers for instance (see : It also support natively High Availability Sync thanks to CARP and pfsync protocols (see: Few days ago I set up VPN SSL configuration with OpenVpn in TAP mode, all done through the GUI (no need to edit any files through CLI) what quite impressed me (usually bridge creation is done through CLI).
To conclude I really invite people looking for a free firewall solution to give a try with pfsense :-)
Just keep in mind such a solution is devoted to projects requiring "not so much speed", I mean 40G or even 100G firewalling and either not UTM inspection.

IT Consultant at a tech services company with 1-10 employees
Easy-to-use interface, with good web blocking and it's open-source
Pros and Cons
  • "The interface is straightforward and easy to use."
  • "Also, simplifying the rules for the GeoIP. Making it simpler to understand would be an improvement."

What is our primary use case?

The primary use case of this solution is to protect our business network.

What is most valuable?

I like the fact that it is open-source.

The Surakarta and the web blocking functionality seems to be quite good. It's not perfect, but none of them are.

The interface is straightforward and easy to use.

What needs improvement?

I would like to see the dashboard modernized.

If you look at some of the other providers, their dashboard is more modern looking.

Also, simplifying the rules for the GeoIP. Making it simpler to understand would be an improvement.

For how long have I used the solution?

I have been using pfSense for approximately one year.

What do I think about the stability of the solution?

It seems to be relatively stable. I haven't had very many issues.

If I do have any issues, it is more to do with the way that I have configured it. Other than that, it works fine.

What do I think about the scalability of the solution?

It's a scalable solution. We have 14 computers with more powerful hardware that allows us to deal with larger networks.

Apart from what you see on the interface, you can also use the command line to create a cluster if you need to.

How was the initial setup?

The initial setup is straightforward once you read the manual.

Which other solutions did I evaluate?

I did evaluate another solution but felt that the cost was too high for what it was. Based on the consumer market, I didn't feel that it was at the enterprise level.

What other advice do I have?

I would recommend reading the manual and the administration book. It has all of the proper information.

Many will jump into pfSense without reading the manual properly, or taking the time to understand the definitions, and how to set it up properly.

If you don't, then you might have a bad experience, which would not be fair to the product.

To give a fair comparison and trial, definitely read the technical documentation before implementing it.

Given the fact that it's open-source, relatively easy to use, and it seems to do the job quite well, I would rate pfSense a ten out of ten. I think it deserves that.

Which deployment model are you using for this solution?

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Netgate pfSense Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2024
Product Categories
Buyer's Guide
Download our free Netgate pfSense Report and get advice and tips from experienced pros sharing their opinions.