10 ms·
PSA: pfSense is closed-source [1]. It was discussed last month here on HN [2]. OPNsense is the equivalent FOSS alternative [3]. [1] https://github.com/rapi3/p
by freedom42 6y ago
PSA:
pfSense is closed-source [1]. It was discussed last month here on HN [2]. OPNsense is the equivalent FOSS alternative [3].
[1] https://github.com/rapi3/pfsense-is-closed-source https://github.com/rapi3/pfsense-is-closed-source
[2] https://news.ycombinator.com/item?id=25894420 https://news.ycombinator.com/item?id=25894420
[3] https://en.wikipedia.org/wiki/OPNsense https://en.wikipedia.org/wiki/OPNsense
- mig39 6y agoI don't think this is completely accurate, nor is it recent. Their "community edition" is open source and free: https://www.pfsense.org/download/ https://www.pfsense.org/download/ Also, they have https://github.com/pfsense/ https://github.com/pfsense/
- freedom42 6y agoThen idk what this comment [1] means. Maybe someone could clarify? [1] https://news.ycombinator.com/item?id=25915295 https://news.ycombinator.com/item?id=25915295
- k_roy 6y agoExcept it's not. The source that is provided doesn't actually build pfSense as shipped. Plus there are binaries that no source is provided for that "you don't need to worry about"
- tw04 6y agoCommunity Edition will diverge from Pfsense+ with the 2.6 release. They have also made no commitments there will be any releases after that - "it's up to the community". They will, however, gatekeep what features the community is allowed to add. Community Edition is more or less a dead man walking at this point, they just refuse to come right out and say that. Someone asked if they'd allow one of the REST API projects to be put into upstream and they gave some ridiculous answer about how they'd review any commit but alluded to the fact they won't actually accept it. Because what would they do if the maintainer left? Their suggestion was to fork it. Which, ironically, is exactly what OPNsense did and then Jim Thompson acted like a misbehaving 6 year old and created a website trying to bash them and didn't even have the spine to own up to it until there was a court order. https://opnsense.org/opnsense-com/ https://opnsense.org/opnsense-com/ I'm not sure why ANYONE would waste any effort on adding anything to pfsense at this point when they won't actually commit to accepting features upstream that competes with PFsense+.
- k_roy 6y agoI've been on the wrong end of the Netgate brigade/shills/apologists before due to a few blog entries, and it's not fun. I'm just glad others are seeing the darker side of them.
- WarOnPrivacy 6y agoIn my case, I don't readily find hostility toward a group that has busted tail to provide me tremendous value while I have contributed very little in return. My interactions over the years have been - perhaps not exclusively positive but overwhelmingly so. History says one day pfSense will no longer fill my needs. Okay. I'll raise an imaginary glass move on with gratitude.
- frankharv 6y agoWell instead of pfSense no longer fulfilling your needs than maybe its time to beam up to the mothership. FreeBSD can do everything pfSense does without a web interface.
- kbenson 6y agopfSense provided a real easy of use, at least back in the day. Given that the whole config synced over to a backup/HA failover system and updates to one could easily be confirmed synced to the other, there was a real ease of use in using pfSense (at least I thought so about a decade ago when I was using it). Spend enough time configuring HA firewalls and you start wishing you had something to take care of alerting about config differences and syncing changes automatically, and that's one of the things pfSense offered that was good. This wasn't a case of us not knowing how to configure stuff in the OS, we moved from configuring OpenBSD firewalls with pf+pfsync, ipsec+sasync and carp to pfSense because it just made it easier to deploy and configure, given we had about ten or more of these we maintained for customers. Even recently at a new job we were talking about upgrading or replacing some HA FreeBSD firewall pairs, and I was suggesting pfSense because it's simple to use, and just BSD underneath. Given what I've learned in this thread about the state of the project and company behind them now, I don't think I would recommend it anymore, but I still think a similar project with similar features has something to offer over vanilla BSD.
- jaytaylor 6y agoThe dramas [0] between PFSense, OPNsense, and IPFire [1] always seems to come up. I ended up going with PFSense and it works fine. It's open enough that you can always dive in to figure out what's going on. Perhaps philosophically suboptimal, but for all practical purposes it's worked great for my home! [0] https://www.reddit.com/r/homelab/comments/dg2wme/opnsense_vs_pfsense_2019_edition/f38q3ii/ https://www.reddit.com/r/homelab/comments/dg2wme/opnsense_vs... [1] https://www.ipfire.org/ https://www.ipfire.org/
- justaj 6y agoOh god I hate this so much about Reddit: > Why fuck netgate? > [deleted] > Exactly this. Well said. As a sidenote, can anyone recommend me a service which lets me see the contents of now deleted Reddit comments?
- croutonwagon 6y agoPushshift is the service. There’s a bunch of sites using their api. Like removeddit.com and ceddit.com where you can just edit the url and it will query pushshift
- justaj 6y agoThanks, it looks like Ceddit no longer works though.
- WarOnPrivacy 6y agoThe shade I occasionally see thrown toward pfSense is curious to me. This isn't push-back at the parent comment but me expressing a bit of confusion. I've used pfSense since 2009 or so. I was skeptical when Netgate entered the picture but since I've had no reason to complain. It's been a continuous and usually smooth timeline of serving me well. A relevant sidebar is that I've been part of different, stellar volunteer efforts - started by a core team that was trying to improve or fix something worthwhile. It is inevitable that core teams members will eventually run low on time/energy and changes must follow. Those changes can be anything and usually are.
- anfogoat 6y ago> The shade I occasionally see thrown toward pfSense is curious to me. Every last bit of it is deserved. They made a promise to keep pfSense open source and they broke it as soon as they could. I see them hiding behind it's the newly announced pfSense Plus that is closed source, not pfSense CE and it's pure weaseling. I still use pfSense but I feel bad for ever being excited about it and contributing to their popularity.
- WarOnPrivacy 6y agoHowever, you are directing your disdain (about pfSense) toward us. To what end? What is it you want to achieve?
- anfogoat 6y ago> However, you are directing your disdain (about pfSense) toward us. I don't think I am; who's us in that sentence? > To what end? What is it you want to achieve? I'm scratching an itch. If Netgate can screw the community that helped pfSense gain popularity then surely it is perfectly acceptable for a member of that community to express a little disdain.
- WarOnPrivacy 6y ago> who's us in that sentence? Everyone in this thread. > it is perfectly acceptable for a member of that community to express a little disdain. Okay. I never inferred otherwise. If venting is the total of your goal here are you okay we blow that off or is there something else you're hoping for? To be clear, I've no animosity toward your posts. My 'hidden' agenda is this: Because hostility takes a toll on the recipients (us), I'm curious if what you're getting in return is worth it. No judgment. We all do this.
- whalesalad 6y agoWoah, I have been using pfsense for quite a while but never knew it was closed source until now.
- croutonwagon 6y agoIt’s a fairly recent turn of events. First it was difficult to compile on 2.4 because three left out closed source dependencies that their build scripts relied on. With 2.6 they are basically diverging entirely. Albeit they are still trying to argue they are foss. The issue I have is if I’m going with an edge security appliance that has code that can’t be easily audited by security pros better than me, I’ll go with Pali Alto or Cisco who has entire branches and teams dedicated to security like Talos/snort. They are less succeptible to security errors and have a customer base that straight affects national security. So even Alphabet agencies will report exploits and 0days to them. With their wire guard shenanigans it’s clear they are a small team and closing off the code base means I’m now relying on people that act this way to criticisms for security. I don’t really care about internet drama and it’s a reason I’ve stayed with pfsense to now. But pragmatically their choices mean I have to change. Which is okay too. https://www.netgate.com/blog/painful-lessons-learned-in-security-and-community.html https://www.netgate.com/blog/painful-lessons-learned-in-secu... https://old.reddit.com/r/networking/comments/m6zjie/wireguard_netgate_pfsense_drama/ https://old.reddit.com/r/networking/comments/m6zjie/wireguar...
- hda111 6y agoI hope this will make a lot people contribute to OPNsense because I really prefer their GUI and over pfsense.