pfSense: FreeBSD-Based Firewall and Router

pfSense: FreeBSD-Based Firewall and Router

pfSense turns commodity hardware into a firewall and router with a feature set comparable to commercial appliances, managed entirely through a web interface.

Why self-host pfSense

Consumer routers ship limited firmware, stop receiving updates after a couple of years, and give you almost no visibility into your own traffic. pfSense replaces that with a real firewall: stateful filtering with pf, multiple WANs, VLANs, VPN termination, traffic shaping, and detailed logging, on hardware you choose and can upgrade.

What it does

pfSense falls into the Networking category of self-hosted software. It covers stateful firewalling and NAT, DHCP and DNS services, VLAN and multi-WAN routing with failover and load balancing, OpenVPN, IPsec, and WireGuard VPN termination, traffic shaping and captive portal, and high availability failover between two units. A package system adds intrusion detection with Snort or Suricata, pfBlockerNG for DNS and IP blocklists, HAProxy, and monitoring tools.

Community traction

pfSense has been developed since 2004 and is one of the most widely deployed open-source firewall platforms, common in small business and prosumer networks as well as homelabs.

Deployment

It installs as an operating system on dedicated hardware, typically a small multi-NIC appliance, or as a virtual machine. Netgate sells pre-built appliances and maintains the project. The Community Edition is free; Netgate also offers pfSense Plus, which is free for home and lab use on approved hardware and licensed for commercial deployments.

Alternatives

OPNsense forked from pfSense in 2015 and is the closest comparison, with a faster release cadence and a different UI philosophy. OpenWrt targets consumer router hardware. IPFire is another independent option.

License

pfSense Community Edition is released under the Apache License 2.0.

pfSense is the conservative choice for a serious home or small business network edge.