4 ms·
They added boot environments to pfSense+. I think they use ZFS snapshots. You can take a snapshot, set it as the default boot environment, do some updates, an
by ryan29 3y ago
They added boot environments to pfSense+. I think they use ZFS snapshots. You can take a snapshot, set it as the default boot environment, do some updates, and if things go bad you can reboot to get back to the snapshot you set as the default.
I’d like to see some kind of more resilient upgrade process where a pre-upgrade snapshot is taken, the firewall updates and reboots, some kind of watchdog tries to hit a well known endpoint, and the whole thing automatically rolls back to the known good config if it goes X minutes without being able to connect after the update. That would mitigate the riskiest part of updating remotely.
As for new features, once you have a reliable firewall, what more do you want? I wouldn’t complain about a better traffic shaper experience, but OpnSense did that and the “easier” traffic shaper in OpnSense isn’t as flexible IIRC.
For licensing, I don’t hate the TAC-Lite approach. They could make it more clear it’s a lifetime thing (I hope I’m right about that) and I hate begging for installers, but at least they aren’t forcing subscriptions yet. I fear that’s coming one day since it would force us to switch to something else and pfSense is working ok for us ATM.