5 ms·
Addressing Changes to PfSense Plus Home+Lab
- lousken 3y agoInformative and unfortunate. The only reason I upgraded from CE to plus home was because of boot envs.
- nilespotter 3y agoMassive influx of users to OPNsense
- oldbbsnickname 3y agoSadly, pfSense lost me a long time ago. I'm happily on my 2nd OPNsense business license on Deciso embedded Ryzen-based hardware with 10 GigE optical links. Even takes care of PKI and has 2FA. I'm happy and I don't have to worry about massive, arbitrary license changes or big corporate enshitification.
- magicalhippo 3y agoJust couldn't get IPv6 working with pfSense, as they had really limited support. Moved to OpenWRT a few years ago and been quite happy since.
- keep_reading 3y agoThe Deciso hardware is really nice! I also have a couple. Expensive but worth it.
- senectus1 3y agoI just installed my first last weekend. I'm pretty happy with the experience and the end result.
- radicality 3y agoHappy user of opnsense for two years. Using a box from Protectli, no issues.
- deadfece 3y ago"Home+Lab has been installed thousands of times in 2023 alone." This seems to indicate that nearly nobody was using it, even counting the illicit activities of the multiple appliance vendors. If I have a modest lab automation with solid bracketing of fw release versions on some network scenarios, I could easily account for thousands of on-install telemetry entries per week. I can imagine Hetzner alone would account for thousands upon thousands of installs. Just based on their phrasing, I doubt there will be a massive influx to opnSense.
- fostware 3y agoHome+Lab was always there to placate those users bent out of shape when Plus started diverging from CE, apart from just support. Now they're just applying the next step to limit those pesky freeloaders.
- deleted 3y ago[deleted]
- onetimeuse92304 3y ago[flagged]
- tbitrust 3y agoWe often confuse Free and Open Source with "free beer". We have been using pfsense for years without paying a dime; if we could we would gladly have done it. It's simple fairness.
- onetimeuse92304 3y agoAlso, what we forget is that if we are not paying, somebody else is paying. And somebody else is very likely not aligned with our interests. There is this conventional wisdom that a lawyer is not really your lawyer until it is you who is paying them. I think it has much broader application and you want to be paying for technology. It is naive to think you can accept services of say Facebook, not pay a dime for it and assume it is all done in your best interests.
- kortilla 3y agoThis is not the right mental model because: - software is copyable for free - contributing to open source doesn’t make the developers your agents like paying a lawyer does
- onetimeuse92304 3y agoIt is good mental model because whoever is producing the software is human. It does not matter if there is zero cost to copying the software. What matters is that somebody put an effort into doing something and now they are seeing lots of people using it for free. It is in human nature to try to benefit from it and most people have a mental model that they deserve to be compensated for doing something beneficial to another. Most people are not seeing incremental cost of adding another user (effectively zero or non zero), what they are seeing is total cost of producing the software divided by the number of users. Then they see that some users are paying and some users are not.
- LeoPanthera 3y agoI migrated to OPNsense during the wireguard fiasco. It was an extremely boring migration, and I mean that as compliment. It's been quietly doing its job ever since, with a minimum of fuss.
- geek_at 3y agoI have thought about moving from pfsense to opnsense but in my test install I had a feeling it has fewer features (and messy UI). For example something I use pretty heavily is pfblocker that automatically geo-blocks ips from different countries that most attack my homelab (Russia, USA, china ,etc..) from accessing my homelab Is there something like this on opnsense?
- alias_neo 3y agoThis is important for me too. From my searching, they have "GeoIP aliases" which is supposed to be their alternative to PfBlocker-NG; I have no idea if/how it functions as I haven't made the mode yet, but this is a deal breaker if it doesn't work the way I need.
- LeoPanthera 3y agoOPNsense supports blocklists in Unbound: https://docs.opnsense.org/manual/unbound.html#blocklists https://docs.opnsense.org/manual/unbound.html#blocklists However what you're saying doesn't make any sense. All incoming connections, from anywhere, are blocked by default. That's true in both pfSense and OPNsense. Are you saying that you allow all incoming connections, but then block specific countries? Because that's mad, and given the existence of VPNs, pointless.
- kortilla 3y agoHas Netgate provided any meaningful new features to pfsense over the last 5-10 years? Or is it just “support” for essentially what pfsense was a decade ago?
- ryan29 3y agoThey added boot environments to pfSense+. I think they use ZFS snapshots. You can take a snapshot, set it as the default boot environment, do some updates, and if things go bad you can reboot to get back to the snapshot you set as the default. I’d like to see some kind of more resilient upgrade process where a pre-upgrade snapshot is taken, the firewall updates and reboots, some kind of watchdog tries to hit a well known endpoint, and the whole thing automatically rolls back to the known good config if it goes X minutes without being able to connect after the update. That would mitigate the riskiest part of updating remotely. As for new features, once you have a reliable firewall, what more do you want? I wouldn’t complain about a better traffic shaper experience, but OpnSense did that and the “easier” traffic shaper in OpnSense isn’t as flexible IIRC. For licensing, I don’t hate the TAC-Lite approach. They could make it more clear it’s a lifetime thing (I hope I’m right about that) and I hate begging for installers, but at least they aren’t forcing subscriptions yet. I fear that’s coming one day since it would force us to switch to something else and pfSense is working ok for us ATM.
- throw0101a 3y ago> Or is it just “support” for essentially what pfsense was a decade ago? "Just"? I'm sure all of use nerds and geeks on HN think commercial support is often not important, but there are plenty of SMEs that need to de-risk some things when running their infrastructure.
- red-iron-pine 3y agoevery large org I've been at pretty much requires escalation contacts and vendor support. is one of the reasons we pay for RHEL and Docker licenses, etc.
- kortilla 3y agoYes, I didn’t say there wasn’t value in support. “Is this contractor responsible for the whole house or just the garage?” does not imply the garage isn’t important or that it’s trivial.
- ohcomments 3y agoHere we go again.... I've been resisting the change from pfSense to OPNsense for a while now but I start to really think I should just move on and get it done. All these f*ups with licensing and bs* from Netgate starts to be annoying. Just make a 50 or 100 license for home users who need / want to deploy a better router / firewall and get done with it! I moved from CE to this PeshPlus thing because supposedly CE was going to cease to exist... Now the PeshPlus is actually the one being discontinued! Wtf Negate!!! Get a grip.
- omnicognate 3y agoI briefly used pfSense before replacing it with a plain Arch installation (any distro would do just as well - I just use Arch for everything else so it's an easy choice). In a moderately complex home setup with wireguard to access my home network remotely, multiple VLANs/SSIDs (including one to firewall off IoT things and one that routes wan traffic to a vpn, again via wireguard), my own DNS server, a filtering web proxy for the kids, etc., I haven't encountered anything pfSense or similar would have made any easier for me. It's all achievable by editing relatively straightforward config files. The most complex bit is the firewall, but I have a terse, straightforward nftables config that does what I need and that I understand fully. I didn't really see the value in putting a layer of GUI stuff on top of it and then having to keep up with changes to that layer, and in the process obscuring what's actually going on.
- waynesonfire 3y agoThis seems like Netgate management is using Home+Lab as a scapegoat rather than acknowledging their own shortcomings. I'd like to see Netgate and OPNsense both thrive. The competition is good for the product and users.
- wtcactus 3y agoWell, I was still using pfSense over opnSense due to a bit more polish and having proper Tailscale integration. As soon as Tailscale has proper integration on opnSense, I'm definitively moving on. The CE version of pfSense has very outdated packages and that probably has an impact on security, which, for a Firewall, is a big no. BTW: Does anyone know why Tailscale doesn't provide a proper package (with graphical interface) for opnSense, like it does for pfSense? I was under the impression that it would need very few changes for it to work.
- wommy90 3y agoit's just 6 lines in the shell, I set it up yesterday opnsense-code ports cd /usr/ports/security/tailscale make install service tailscaled enable service tailscaled start tailscale up source: https://www.wundertech.net/how-to-set-up-tailscale-on-opnsense/ https://www.wundertech.net/how-to-set-up-tailscale-on-opnsen...
- user3939382 3y agoMy pf.conf files tend to be like 30-50 lines and easy to change so I never understood the allure of having a front end for it.
- martinmunk 3y agoI've been using pfSense on 4 private sites for years by now. Luckily I've not upgraded from CE. I think what pisses people off is the rugpull of them pushing people to get a free upgraded license and then removing it soon after. As for "but its free". I think its reasonable to expect the free offering to be promotional. I know I have bough Netgate HW and license for work because I was familiar with their free offering at home. But stuff like the recent move might make me reconsider.
- user7426528364 3y agoI mean, after what they did to OPNSense with the domain plus defamation, I don't know why would you trust a company with such behavior.
- anfogoat 3y agoThank you for the told you so, Netgate. And they knew they were going to do this the very moment they conceived of the idea of Plus but sure, if you must accompany this with a multiparagraph BS ridden sob story, go ahead. Expect nothing less from you lot.
- n8henrie 3y agoLots of comments about moving to OPNSense -- anyone using something Linux-based that they would recommend as a comparable alternative? My impression is that this might not exist yet (the currently available projects are significant lacking in either features or reliability), and that my odds of getting something user-friendly with tools like pfBlockerNG are even slimmer. I always feel so handicapped when something breaks on my router, due to being so much less familiar with BSD, and due to it being an older / limited FreeBSD release (many things missing from the pf repos). Just last week my pfsense upgrade resulted in a non-booting system, and I felt helpless (user error -- zpool upgrade but didn't upgrade something about the boot directory). I didn't have my usual tools, so I ended up having to install ZFS support to an old RPi3 running NixOS just so I could look around and get the ZFS parts sorted and figure out what happened. (Thankfully I eventually found an old mailing list thread with some obscure incantation that I ran from a pfsense installer usb and resurrected things.) The whole time I just really wished that I could have been on a Linux machine with my familiar GNU tools!
- lanman95 3y agoI am really happy with IPFire on my home network. It doesn't have all the advanced features that PF/OPNSense have, but it's suitable for my needs.
- bravetraveler 3y agoI use a Linux box with at least two fast NICs - why not try it out? The setup can be rough if one isn't that familiar/has high requirements... but making a router and so on is pretty basic stuff. Basic in the sense that it's easy to do both well and terrifyingly incorrectly. I'm curious about home users who truly need an interface because they're in there fiddling so much I use Ansible to manage the config of mine, but that's more for rebuilding. I look at the thing maybe twice a year
- neilv 3y agoI'm glad that my simple plastic OpenWrt router is sufficient right now, and I don't have to deal with changes/problems from Netgate, Ubiquiti, and other brands of fancier gear that once seemed appealing.
- kayson 3y agoWhat did Home+Lab have that CE didn't? I've been using CE for years now and it seems like it's got all the enterprise bells and whistles except support...
- davidee 3y agoI believe the only feature is “boot environments” at the moment. In fact they've diverged so little that, according to various sources online, one should be able to take a working 23.05.1 config (read: pfSense plus) and install it on 2.7CE without issue. In the Netgate world, it now seems that the CE edition is the most stable, inheriting changes/fixes after they've settled into the plus channel.
- dewbrite 3y agoI tried pfSense recently but I didn't love configuring my network through the UI. An API or something would make it amazing. But maybe that's the DevOps in me talking. I've been mostly happy with VyOS since then.
- btgeekboy 3y agoOPNsense is working towards that vision. They're rebuilding the car while it's driving down the road, so while some things aren't supported, many things can be done through the REST API. See https://docs.opnsense.org/development/architecture.html https://docs.opnsense.org/development/architecture.html and https://docs.opnsense.org/development/api.html https://docs.opnsense.org/development/api.html
- javier2 3y agoWhat kind of hardware do you run it on?