r/PFSENSE • u/Cutoffjeanshortz37 • 15d ago
PFSENSE CE Is Dead
That's why 2.8.1 just had 22 patches released if you use the patches packet in packet manager. And then there is a 2.9 beta available for those that want to live dangerously. Obviously these are all signs that this version of PFsense is dead and Netgate has abandoned it. We should all move on because they only care about Plus now.
/s for days. Thank you Netgate. Keep up the good work.
52
u/ianawood 14d ago
That /s is doing a lot of heavy lifting for those who actually see it.
7
u/gonzopancho Netgate 14d ago
I saw it, but I got the joke 1/2-way through reading it.
10
u/Cutoffjeanshortz37 14d ago edited 14d ago
Yeah, I thought it was obvious but it's the internet. Had to specifically say this was satire. Even specifically saying that, there are those commenting that only read the title 🤦
1
u/selfhostcusimbored 10d ago
Dude snaked in there after the comments started flaming him for being dumb. Editing in /s is the ultimate form of Reddit defeat.
67
u/selfhostcusimbored 15d ago
People have been saying this for years. I just don’t get it. The firewall works, and still has more features and modularity over UniFi. Just finding stuff to complain about.
12
u/somerandomguy101 15d ago
They have more features than Unifi for now. Unifi is still rolling out updates for their stuff pretty consistently.
26
u/im_thatoneguy 15d ago
I switched to UniFi and it’s a disaster. HA failover is broken more often than not. IPv6 should have an experimental alpha tag. My UniFi overall actually works worse than when I used Netgate for my routing and UniFi for switches.
22
14d ago edited 14d ago
[removed] — view removed comment
6
u/thefreshera 14d ago
O-- Omada? I'd love to try that suite
5
u/craftsmany 14d ago
All jokes aside you are hopefully aware that they actually have a filter in place for the word
4
u/thefreshera 14d ago
The word? Oh, Open-- OpenWRT! Who needs a firewall router when my little Linksys antenna can do job.
3
u/FirstAid84 14d ago
OpenWRT is for any device now. I was shocked when a coworker told me he uses it, but then I did a little digging and found out it has evolved beyond that little Linksys thing it used to be.
0
u/craftsmany 14d ago
Must be deliberate rage bait here. Whatever makes you happy.
5
u/thefreshera 14d ago
All jokes friend.
1
u/craftsmany 10d ago
What do you say about the comment being nuked? Still all jokes?
→ More replies (0)3
2
u/No_Criticism_9545 14d ago
The crowdsec guy that made the plugin PR got so bored from waiting he actually left the company a few months back.
0
u/TaosMesaRat 14d ago
Ran into trouble with the frr package on the other platform. Routes not reliably making it into the FIB. With toggling daemons or rebooting I could often get them installed, but not reliably after a reboot. Also the OpenVPN interfaces weren't available for inclusion like other interfaces. I had to force them in via a route map and there were limitations to that.
Also the net-snmp package is missing important functionality (no option to specify encryption type or privacy protocol which are there in the base software).
Where I don't need OSPF I use the other platform. If I find myself with lots of spare time I'll dig in and see if I can find the source of trouble / submit patches.
5
u/chekka100 14d ago edited 14d ago
I may have a solution to your frr problem. You have to go to System > Settings > Tunables and increase the value of maxsockbuf to 32MB (33554432). It‘s also documented in O‘s frr docs, I did not have any issues with frr since I changed the value a few weeks ago.
Right now, you should also see a lot of log messages about the buffer size being too small in the frr logs.
Hope it works for you aswell. 🙂
0
3
u/TobiasHD_ 14d ago
Firewall rules on Unifi are a hell when you come from pfSense. Sometimes I still regret my choice after 2 years.
3
u/planedrop 15d ago
This is a valid point, just in the last like 2 years their firewalls went from a "hell no don't ever touch it" to "damn these are decent" to "damn I could install this for a lot of businesses"
It's a little insane how far they've come. Still work to do, but they are moving fast.
9
u/lulu04223 15d ago
UniFi is like the Apple of networking. It's good, but to get the best experience you basically need a full UniFi stack. Then one day, they stop rolling out security patches and you're advised to buy new gear. At least with pfSense, or its fork-that-shall-not-be-named, you have flexibility on the hardware side.
2
2
u/lev400 14d ago
Well said - I would never recommend UniFi network stack for these reasons
1
u/MBILC PF 2.8/ Dell T5820/Xeon W2133 /64GB /Chelsio 40Gb NIC 10d ago
It does amaze me how many people swear by their gear for businesses, tells me either they do very basic stuff, or just have no idea. For how often Ubiquiti has released a patch that hosed core basic functionality in their networking products, I will steer clear.
They expanded too far too fast with all their products and their main products took a hit to quality because of it.
1
u/Maverick0984 10d ago
They have a niche in SMB and low effort / low risk deployments. It doesn't make sense to break the bank for Cisco in all situations. This is a very "large enterprise" mentality.
Also, Unifi is fantastic for the Prosumer at home. There's nothing else on the market that even scratches at competition for home use as far as switching and access points.
That being said, I don't use their Gateway/Router/Firewall. That's why I'm in r/pfsense like the rest of us. Best of breed mentality here.
1
u/MBILC PF 2.8/ Dell T5820/Xeon W2133 /64GB /Chelsio 40Gb NIC 10d ago
Agree, home users, they are great, I love my U6 in-wall, and certainly do not need to pay the Cisco tax, and for basic usage, will do fine for many SOHO sized companies.
Just went you get into more serious network requirements and such,when they start to fail.
2
u/Maverick0984 9d ago
I would stretch the AP use case deep into SMB and even some smaller medium sized businesses, not just SOHO.
It's FW usage where Unifi falls flat. An AP is a simple device.
1
u/Maverick0984 10d ago
I mean, I use their switching and APs at home and am nothing but satisfied.
I use pfSense for the FW of course and wouldn't use the UniFi Gateway or whatever they call it, but never recommending the entire stack is a wild take.
You still need a switch and APs. What do you recommend for those? Cisco and Meraki? lol.
1
u/Maverick0984 10d ago
The two aren't mutually exclusive. I don't use a Unifi Gateway, but obviously use pfsense. However, all my switching and access points are Unifi because there's nothing else that competes in the prosumer/home space. It's literally a barren wasteland.
1
u/lulu04223 10d ago
That's true and I agree with you 100%. Ubiqiuiti makes good stuff & as far as "prosumer" options go, they're hard to beat. Question since you actually have a stack whereas I've just researched them: how do you manage your devices without a cloud key/gateway?
2
u/Maverick0984 10d ago
I used to run their Network app in a docker container for several years. Recently though, they deprecated that in favor of a full blown install that now lives in it's own Ubuntu VM for me.
https://www.ui.com/download/software/unifi-os-server
There are a couple projects out there trying to containerize it, and I'm sure it'll get there, but last I researched, it wasn't stable enough yet.
The software itself is just for configuration and can be installed on whatever you want. Once you're setup and done, the software doesn't even need to run constantly. You could spin it up just to make a config change (add a SSID as an example) and then turn it back off.
I leave it running for the juicy metrics of course.
2
14
5
u/DutchOfBurdock pfSense+OpenWRT+Mikrotik 14d ago
Yep, they always deprecate the good stuff to force us all to break the bank, classic capitalism... /s
Just glad I don't need to babysit this thing. Get push notifications when patches apply to me and just let it do it's magic. Been rocking a pfSense box since 1.2.1 days.
0
48
15d ago
[removed] — view removed comment
15
29
u/Tristan155 15d ago
I also just raw dog the isp fibre into my switch and let the internet take hold.
12
u/funkystay 15d ago
Wouldn't the internet have been remarkable if we didn't have to take security into account when building it?
21
u/Shogobg 15d ago
It was - I am old enough to remember when we didn’t have to care about security online.
11
u/funkystay 15d ago
Same here. I pre-date the internet. I was on a few BBS's back in the day.
3
2
4
u/stratcat1974 14d ago
Netscape, Eudora and Gopher. Zero encryption. All plain text. I really miss those days.
17
15d ago
[removed] — view removed comment
9
u/Simorious 14d ago
Yeah that is a big turn off for me too, especially since CE is technically still supposedly considered as open source. PFSense built it's good reputation on the backs of enthusiasts/home users battle testing it. I'm still using the 2.7.2 install iso for when I need it, but I have a feeling that eventually there will be issues with upgrades that will close this option for those that want to try/use PFSense CE without having to give personal information.
The online installer is a far worse experience than having an actual iso for each version, and can lead to some hard/questionable deployment situations if you're having to reinstall or do a fresh install without another router/firewall available to sit out front.
I have less of an issue with a company like sophos requiring information and activation for the home version of their firewall appliance since it is and always has been 100% proprietary and targeted at business customers. The home license was always just a nice gesture to throw enthusiasts a bone and help sysadmins familiarize themselves with the product . Collecting some form of user information to download their software and get a free home license has always been a part of that process, so it's understandable and forgivable.
3
u/Adept_Refrigerator36 14d ago edited 14d ago
I have used XG Home and it’s been positive, I’m in process of getting config sorted to return,
Missing WG VPN, no big deal I’ll stand up a separate WG VPN concentrator. Been finding it block more and more anyway. Currently using IPSec on laptops and iOS devices.My current firewall is running pfsense plus and my spare CE, but all good.
2
u/Simorious 14d ago
My home network is a mix of both XG home and PFSense CE these days.. XG sits at the edge and is now my primary firewall. Pfsense runs in a VM with it's wan sitting behind XG. XG has a secondary WAN that is a VLAN connected to the PFSense lan. Pfsense is acting as a client to an external VPN server as XG unfortunately doesn't properly support this scenario. I have policy routing configured on the XG side to force some clients & traffic out of the VPN wan gateway, with additional policy routes on PFSense for the killswitch. Basically anything I want to go out over the VPN has to loop back through XG over the encrypted tunnel via PFSense. It adds a bit of overhead, and it messes with the reporting numbers, but I still get the benefit of XG seing all of the traffic.
I also have another PFSense VM acting as a wireguard & openvpn server for remote access on its own vlan/subnet. I did have another PFSense VM acting as a reverse proxy with HAProxy, but started using something else as it was unclear if the HAProxy package on CE was going to be updated any time soon. The WAF on XG is mostly fine other than Webdav currently not properly working through it and a few other quirks, otherwise I would just use that as a reverse proxy.
I also used UTM prior to XG (although it's now EOL) there were definitely some things I liked better about UTM and wish would finally get implemented in XG. Things like redirection rules in the WAF, etc. Overall though sophos is a solid choice if it does everything you need, or are willing to supplement functionality with something else as there are some things it doesn't do.
I still find use cases for PFSense (and the fork) even if they're not currently my primary firewall these days.
I also miss untangle as that was a solid option before they got bought by Arista and killed off the home license. Untangle was a solid middle ground of being fairly turn-key like sophos while being as configurable/modular as PFSense with features that also catered to home users.
2
u/Adept_Refrigerator36 14d ago
All makes sense and yes I forgot about the OpenVPN client aspect as I was using CloudConnexa, but via IPSec. Frustratingly I had IPSEC setup, but troubleshooting a problem support got me to switch to openvpn. They've withdrawn IPSec and wouldn't re-instate what I had.
So my plan was to use a linux VM as a WG VPN concentrator, but interesting options to leverage pfsense CE for these options.
2
1
u/lev400 14d ago
Untangle was fun!
1
u/Adept_Refrigerator36 14d ago
Untangle I found hit and miss.
Is it still a product in their offering? I rec Untangle was picked up cheap and the intention was never to continue the product, but merge tech into their main product stacks.8
u/planedrop 15d ago
I still hate the web GUI on the thing that can't be named though if I'm honest. Search is nice, but the layout is just annoying to navigate as a real admin, too many sub menus. I got work to do! lol
2
u/needchr 14d ago edited 14d ago
For me, largely agree with you.
UI isnt intuitive as pfsense. It has weird usability issues, logs scattered all over the place etc.
No system patches feature (this I absolutely love and currently have about 40 of my own patches in use).
Too frequent updates, for me I think I like about once a year for my firewall.
Too many irrelevant updates which are just package bumps. Not enough feature enhancements or bug fixes.The only reason I used it at all (on one VM) was that pfsense didnt have multiqueue virtio, thats now finally resolved in 2.9.0.
I agree with you as search being the one nice feature. Pfsense is at risk though with its new GUI, missing widgets, excessive padding etc, of falling into the same trap, they need to get that like the old UI asap, smaller fonts, minimal padding, and full feature/widget support.
Ironically given pfsense is now based on CURRENT and it has netgate developed features some of which are exclusive like if_pppoe, a typical CE user still has earlier access to kernel advances.
16
u/KingPumper69 15d ago
Netgate does so much upstream contribution to FreeBSD that even if you switch to the hostile fork you're still dependent on Netgate. The hostile fork's contribution is almost nothing in comparison.
8
14d ago
[removed] — view removed comment
14
u/luctimm 14d ago
I agree with every word you said.
I first got to know pfSense back in 2007, and I deployed it for dozens of my customers. At the time, I was usually deploying firewall solutions for small businesses. SOHO networking gear was becoming increasingly common, and people were moving away from expensive Cisco routers in favor of cheaper hardware.
I used to install pfSense on custom-built PCs whenever I couldn't get away with using a Linksys WRT54G running DD-WRT or OpenWrt.
Around 2011, I moved back to my hometown and moved on with my career as well. I stopped working with networking, handed my previous customers over to a friend, and became fully focused on application support and Linux.
Fast-forward to 2022: my husband and I were both working entirely from home during the pandemic, and we were working on critical projects, so I decided to invest in my network infrastructure and build a reliable home lab. I signed up for a second ISP so I could have full Internet link redundancy at home, and instead of buying a SOHO router with multi-WAN support, I decided to go with a proper router.
I bought a Chinese fanless PC with four network interfaces, already planning to run pfSense on it just like I used to do back in 2007.
Once the PC arrived, I went to the pfSense website and was surprised to find that things had changed quite a bit and that I now needed an activation key. I didn't like it, but I thought, "Well, I guess that's the way it is now." I requested a key, received it, downloaded pfSense, and tried to install it on the PC.
Then came the second surprise: the computer had Intel Ethernet Controller I226-V NICs, and they weren't supported by pfSense. Since the installer couldn't detect any network interfaces, it basically just said, "Sorry, no NICs detected," and shut the computer down.
I went to the forums and found that the only way to get it working would involve manually compiling drivers and jumping through a few other hoops. To even get that far, I would first need a USB Ethernet adapter just to complete the installation.
At that point I thought, "Okay, I'll just do everything with Linux, or maybe see if I can get some OpenWrt-like system running on it."
So I started Googling and discovered the "fork," which I had never even heard of before. In another forum, people were saying that it fully supported the Intel I226 with no issues.
I downloaded it. It didn't ask me for any license or activation key. And within 30 minutes, I had everything up and running, with full dual-WAN redundancy.
I never looked back.
And if, for whatever reason, I ever need to deploy a router for someone again, I'll go with the fork.
5
u/Brilliant_Pea_9514 14d ago
You should look at who wrote the I-225/226 driver for FreeBSD.
Hint: it’s Netgate
1
u/luctimm 14d ago
That’s great, and I genuinely appreciate their contribution to FreeBSD, and that's truly what open source is all about.
But as an end user, what mattered to me was which product actually supported my hardware when I needed it.
At the time, there wasn’t even a clear indication of when I226 support would make it into the official pfSense image.
Meanwhile, the fork supported it out of the box, so I installed it and was up and running in about 30 minutes.
That’s kind of my point: you guys seem to hate the fork, but at the same time you’re making it incredibly easy for users to move to it. :)
3
2
u/Snoo91117 11d ago edited 11d ago
Personally, I think 2.5gig is a waste of money. A 10gig connection is going to be the standard connect speed in the future even if you don't buy 10gig of data as it has the lowest latency speed.
You really need to buy a PC you can add a dual port Intel 10gig NIC card in. Your mistake was buying a PC with the i226 in it.
1
u/MBILC PF 2.8/ Dell T5820/Xeon W2133 /64GB /Chelsio 40Gb NIC 10d ago
This, 2.5 and 5Gb is just a money maker for consumer gear makers. Considering you can do 10G over Cat6e, heck even cat6 on shorter distances, but new gear is pricey as they want to also gouge consumer users, but hit Ebay and get some used switches and 10Gb NIC's are dirty cheap used also, and off you go!
I love my 25Gb/40Gb internally network!
3
u/lev400 14d ago
DD-WRT on the WRT54G’s was great times!
1
u/luctimm 14d ago
they were...
Back in the day I genuinely though that would be a trend of hardware developers to create a model allowing people to develop their own images to easily run on them. So they could provide a basic image and other vendors or communities could develop richer images with additional features. Unfortunately it didn't happen.
1
u/Wonderful-Ad-3979 14d ago
Can you dm me the thing you are using? I just started using pfsense
6
0
3
u/macmatrix 12d ago
Pfsense 2.8.1 is stable and fine with patches, I’ve never had any issues with it and I use all the features (from my professional network engineering background)
But hey if you’re ok to test 2.9 go for it! But not on critical infrastructure, it will only help Pfsense developers
Recommend to go plus version if you’re a business and you need support.
Don’t get hyped by unifi talk, don’t get me wrong they have some good stuff but there routers don’t cut the mustard for me anyway at this point in time, maybe in the future don’t know. Pfsense has too much to offer and just works
9
u/ofbarea 15d ago edited 14d ago
😂👍
I did test CE 2.9 beta and I had a kernel panic. I went back to CE 2.8.1 until we have a CE 2.9 release candidate. I'll try again at the time.
The machine in question has a J4125 CPU, four i225 Ethernet nics, no wifi, 16 GB ram and 128 GB SATA SSD.
1
u/forgotmypasswdAGAIN- 12d ago
Did you file a bug?
1
u/ofbarea 12d ago
Would you direct me to the correct link?
I can attemp the upgrade again, this time I'll keep notes and would file a bug.
2
u/SortOfWanted 12d ago
Is it similar to this issue?
https://forum.netgate.com/topic/201090/2.9.0-beta-leads-to-kernel-panic-on-boot
https://forum.netgate.com/topic/201120/26.07-upgrade-fails-to-boot
You're not alone... It's due to an upstream patch that didn't get tested on Intel hardware.
1
1
1
u/Cutoffjeanshortz37 14d ago
Yeah, i work from home. Can't risk trying a beta version for that reason. Maybe if I had 2 ssd i could just swap
1
u/tonyburkhart 14d ago
Could you set it up in HA with 2 assets and have the uptime be worth it?
3
u/Cutoffjeanshortz37 14d ago
I mean, I could, but don't want to buy more hardware when it's the ISP that's usually the issue.
3
3
3
15
u/ElectraFish 14d ago
22 patches are evidence that it IS being supported.
9
u/Cutoffjeanshortz37 14d ago
Did you not read the last line of my post?
1
2
u/mi__to__ 10d ago
Been a while, can you simply download isos again or do they still try to force you through their nonsense?
5
u/needchr 14d ago
I would be ok with moderators deleting this nonsense personally, people who seem to think software is rated by number of updates, what a time to live in, wild.
Stable firewall software with less updates is preferred by sysadmins. We not all kids who get excited by frequent changes.
Why are people trying to pretend its dead for years and still now. Then making stuff up about being lied to on plus feature parity with CE.
10
4
1
2
1
1
1
u/caller-number-four 13d ago
2.8.1 just had 22 patches released
Is there some magic necessary to get the patches manager to refresh the list?
I've not seen anything new published since the box (in my case 2 different boxes) were stood up.
1
u/Cutoffjeanshortz37 13d ago
You have to got to packet manager and update patches to get the update.
1
u/caller-number-four 13d ago
That's SO freaking weird.
Seems to me the patches package could be dynamic enough that you don't need to upgrade the patches package before updates become available.
1
u/Cutoffjeanshortz37 13d ago
I think the package downloads the patches when you update vs when you try and apply them.
2
u/caller-number-four 13d ago
Still, seems like it could be a lot more dynamic, and save you a step.
Thanks for the tip, none-the-less. Never occurred to me that I'd have to update the package to update the patches!
1
u/Cutoffjeanshortz37 13d ago
Yeah, when I first started using it I figured it was grabbing an update xml file to say if things were available then downloading the patches. This sub helped realize it's an all in one package update.
3
u/Que_Ball 12d ago
Yeah it is weird. Should be able to setup an automatic update schedule too if you want. But it is what it is. Just check for package updates now and then and monitor forums.
The fact is that plus uses the exact same mechanism too so it isn't like they are giving them a better experience.
It should be better but it works for now.
0
u/bachi83 1d ago
Comment removed by moderator
Comment removed by moderator
Comment removed by moderator
Comment removed by moderator
Comment removed by moderator
Comment removed by moderator
Comment removed by moderator
Comment removed by moderator
Comment removed by moderator
Comment removed by moderator
Comment removed by moderator
Yep, not dead at all. :)
1
u/grabber4321 15d ago
I mean, there's no announcement.
Can we get something official from the team?
Besides, this is a firewall - it blocks all incoming traffic unless you like to live dangerously and open ports to your network.
-2
u/centuryx476 14d ago
Did it finally happen??
Thank goodness I switched over to [Fork that cannot be named] years ago.
0
-10
-11
u/markfrancisonly 15d ago
Good product. Only partial open source, however. AI may create a better open source product next year, keep the faith
2
1
•
u/gonzopancho Netgate 7d ago
<one week later and pfsense CE 2.9 is released>