7 ms·
Agreed. I took action and migrated my firewall from pfsense to OpenBSD and couldn't be happier.
by hyperpl 5y ago
Agreed. I took action and migrated my firewall from pfsense to OpenBSD and couldn't be happier.
- na85 5y agoNice. What hardware are you running?
- hyperpl 5y agoStill pcengines apu2d4 since my WAN is still only 400mbps and this is able to route at that speed. If/when I upgrade to gigabit then I'll most likely invest in a protecli. Also, it helps that wireguard is firmly supported in OpenBSD as well.
- na85 5y ago>protecli Oh wow thanks for that, I was unaware of protecli and I'm not super happy with my edgerouterX. Thanks!
- user3939382 5y agoI’ve been using command-line only OpenBSD installs with pf as my default firewall for my clients for years. WebUIs always felt like unnecessary attack surface for a firewall.
- hyperpl 5y agoNot only the attack surface, but it wasn't until I tried migrating everything from pfsense to OpenBSD (firewall, dns, vpn, etc..) and started digging around did I realize how many scripts and processes are involved in managing pfsense's state. I ended up giving up and starting with OpenBSD from scratch and it didn't take me more than a couple of hours to get everything back and operational (wife tested and approved). I'm sure there's a rhyme to their reason for such a setup but I'm extremely content with the relatively few files I manage in vim with my own versioning, upgrade and backup methodology. I do admit that I sometimes miss the odd graph or html report but I'm getting more used to the logs.