pfSense CE 2.5.2
servethehome.com
servethehome.com
Ref: https://opnsense.org/opnsense-com/
From the link: “ Some of you may have come across OPNsense.com a domain that until September 21, 2017 was home to a controversial website with content targeted to harm our open source project.
On the fore mentioned date we filed a complaint with WIPO, the World Intellectual Property Organization to try and stop this website from being operated.
Until our legal action we were unable to determine the owner of the domains as it was registered using Domains By Proxy, LLC, however we believed the site was created by a pfSense enthusiast who had gone a step too far.
Much to our surprise we received an email on September 26, 2017 stating that the owner of this domain was in fact Jamie Thompson, Rubicon Communications dba Netgate also known for the competing pfSense project.”
> A full-stack PHP framework delivered as a C-extension!
I mean, I've can't even begin to imagine how insecure that awful combination of insecure by default languages is.
But, looking at: https://docs.opnsense.org/development/architecture.html It seems that it's mostly just the frontend that's php, or am I missing something?
> I mean, I've can't even begin to imagine how insecure that awful combination of insecure by default languages is.
What is inherently insecure about PHP? Or Phalcon? Do they have vulnerabilities that other C programs don't have?
C programs are often exposed to classes of vulnerability owing to weaker safety guarantees see[2]
[2] https://msrc-blog.microsoft.com/2019/07/22/why-rust-for-safe...
OPNSense also splits front-end into the MVC and control layer, as well as the back-end between the control layer and the configuration daemon which is written in python.
All of the actual packet processing and daemons are C or C++, essentially the standard packages you'd find in FreeBSD.
Whether PHP or C is more secure depends on who wrote it.
While I haven't really done any hardcode PHP work after PHP5 came out, there are plenty of ways to do it wrong, and a few ways to do it right. One thing is separation of concerns and encapsulation to the point where a fault in PHP can only mess up the PHP part and not the external system PHP calls into to ask for configuration changes.
Currently, a lot of the old pfSense code has been removed and replaced with code in the MVC framework, but it's a lot of work, and the team behind open-source OPNSense isn't huge. It will take time to cover it all.
My main reasons were that it did everything I wanted pfSense to do, something about the UI felt a bit smoother to me, and it didn't have the smarmy/wonky feeling that pfSense does (aggressive company behavior, closed-ish stuff, and then post-switch the Wireguard stuff happened).
I'm running this on a Protectli FW4B and have been quite happy. It's still doing exactly what I wanted, updates have been good, a bug I reported got fixed quickly, and it's... just working.
Also, by going to open hardware (and not the Netgate stuff I was originally thinking of) I can switch to another platform (eg: Untangle, OpenBSD) if desired.
But, for the forseeable future, OPNsense seems to be working just fine. <shrug>
I also had a very frustrating ARP bug where ARP broadcasts wouldn't work across mesh'd APs (https://www.reddit.com/r/UNIFI/comments/ghs4bg/arp_for_clien...).
Then there was just some various other quirkyness/weirdness, and I happened to get out just before the big security breach was disclosed.
I ended up going to a Ruckus R610 AP that I got via eBay running the Unleashed OS, and it's outstanding. Coverage is so good I no longer need my old AP + extra mesh'd one.
For switching I'm just using an old TP-Link that I had laying around.
UniFi seemed really neat at first, but then it just felt... overwraught. I don't need single-pane-of-glass monitoring of a ton of stuff for my home network. I don't want to run a management software server just for my home network. I do want something robust, but I don't want to worry about it, and I want to be able to piecemeal upgrade it. A small PC running OPNsense + a solid AP + just whatever for switching does exactly that.
(I'm not a homelab-type person... If I want that I use VMs, or my employer's hardware. I want my home network to be a solid, reliable utility that requires little maintenance. I don't want to be tweaking my home network after my day job.)
Note that Phalcon is a PHP extension (not a C extension) that provides new functionality available in the PHP runtime. This is roughly equivalent to a Ruby gem with a C extension, like Nokogiri.
Phalcon was at one point moderately well-regarded, though it's fallen out of favor for a wide variety of reasons, mostly the PHP development style moving on. I say this because as near as I can tell, Phalcon has had an entire single CVE in its entire decade plus of active development.
Casual anti-PHP bigotry isn't just uninformed, its harmful.
How does security patching compare?
Migration is really a complete reinstall and rebuild of your rules. I took a backup of my physical pfsense box and restored it to a VM then reinstalled opnsense on the physical hardware. With the pf box running in a vm I could just reference it while creating new rules.
I think someone made a script to load a pfsense backup onto an opnsense instance but I really think you’re better off with a clean slate.
Kind of a pain, sure, but I felt better knowing it was a fresh build and everything was where it should be.
Just means anyone who wants to try OpenBSD should spec something a little more powerful than that appliance.
Only issue I've had is that if it's a J1900 Celeron CPU, ensure you have the machine set to boot via UEFI before installing. (IIRC there's an open issue for FreeBSD installations failing to legacy boot on J1900 boards.)
In all cases I’d double check the individual chipset by doing a quick search on the forums whether you decide to go pf or opn.
PfSense offers a range of hardware they support, which disproves your assertion by itself without even mentioning companies like Apple and System76.
> one of the appliances that opnsense sells. Just expect to pay a premium to be lazy.
I'm totally willing to pay a premium to be lazy. Where did I imply otherwise? If OPNsense offers hardware these days then why didn't anyone just say so?
That disproves nothing. If you want to build your own system you need to research hardware if you want to have a pain free deployment.
> I'm totally willing to pay a premium to be lazy. Where did I imply otherwise? If OPNsense offers hardware these days then why didn't anyone just say so?
This forum is generally filled with people who want to build their own. As for why nobody mentioned they sell hardware: probably because they sold hardware from the beginning and it’s advertised all over their site?
Again, I said nothing about building my own.
> This forum is generally filled with people who want to build their own.
This forum is generally filled with people with a lot of qualities. For instance, there are a lot of people here who buy Apple products, which are very much not in the spirit of building one's own. Your assumption doesn't make a lot of sense to me.
> As for why nobody mentioned they sell hardware: probably because they sold hardware from the beginning and it’s advertised all over their site?
That's fair, I haven't looked at their site in ages because the last time I used OPNsense was after the very initial split and to my recollection there was no hardware then.
----
0: https://www.servethehome.com/buyers-guides/top-hardware-comp...
1: https://www.freebsd.org/cgi/man.cgi?query=cxgbe&sektion=4
Does the OPNsense project recommend or endorse any specific models of low-power all-in-one computer hardware for running OPNsense? And if no, is there any specific thing the community would recommend?
I don't want to spend hours on research or build something on Newegg. I want to by a complete piece of hardware that I install OPNsense on and know that I won't have to worry about hardware compatibility.
PS: Apparently OPNsense offers their own appliances these days just like PfSense does.
FYI, my observations as an outsider are the project went through three phases of owners:
BSD Perimeter is owner and starts open source fork creating open source releases = CMB and Scott as founders.
Electric Sheep Fencing ownership is a result of CMB taking more of the day to day while Scott bows out and Netgate starts funding things / sinking hooks in. Open source continues to be important and CMB is in charge for the most part.
Netgate ownership completes obtaining full ownership / gets their hooks into every bit of the project. We see annoying screen about licensing and they start nonsense with OPNSense to flex their tiny muscles.
FYI netgate hardware isn’t bad and you get stellar support for what is currently an open source product but they have worked hard to fracture the hard won trust CMB had been building up in the community.
https://marc.info/?l=pfsense-dev&m=139336551027270
https://forum.netgate.com/topic/66157/pfsense-tools-missing-...
With pfSense "plus" they published that they will only work on that paid product and mostly ignore the open source stuff, only do the essential requirements. It's essentially just a marketing gateway into their closed products. At that point you might as well buy any other mature closed product... there are many and from a closed source commercial product perspective they are all better than wat netgate produces, including commercial VyOS without a gui.
Why would someone use a router operating system with such strongly negative review from a respected security specialist?
A minimal Linux installation is an option, if your firewall is simple.
It's a perfect-balance of power and simplicity. It doesn't have a web interface but is just a nice way configure Linux' built-in networking features.
It doesn't consume any extra resources and will run anywhere Linux does.
I never much liked PFsense as a project. It feels very convoluted, and the hardware they sell (I was an early adopter of the then-new SG1000 appliance) is laughably exaggerated in its capabilities
But the Wireguard event is where they went from "incompetent" to "malicious" in my eyes
I ordered a Rasberry Pi 4 compute module and this accompanying ethernet breakout kit after seeing a review from Jeff Geerling (Raspberry Pi accessory mad scientist) and am currently waiting for it to arrive https://www.dfrobot.com/product-2242.html
I know I could just use something like OpenWRT, indeed I do have a lot of respect for the OpenWRT project. But I feel that the distro is more geared toward, well, routers. Devices with maybe 32 megs of flash storage and a slow MIPS CPU. Not a moderately powerful ARM machine with 8 gigs of RAM and gigabytes of SD or eMMC storage
For seven years, then, I've had a mini-ITX x86-64 box with a small SSD, 4GB RAM, and 5 gigabit NICs running Debian Stable. It's been upgraded in place and I see no reason why the upgrade to Bullseye in a month or two won't go as smoothly.
I think a Pi4 is roughly comparable in computation capacity, perhaps less so in I/O -- but what I've got is clearly overkill, anyway.
The Pi one can apparently saturate a gigabit iperf test without issue, so it sounds like a great replacement and rainy day project
https://www.pcengines.ch/apu2.htm
I've been using them for years w/out any issue. I just run standard Debian stable as well, with a few tweaks to make it more friendly for a read-only operating environment (to prevent wearing out the flash memory).
I had pfSense working before OpenWRT but wanted wireguard so I made the switch.
I appreciate the interest though!
I'm probably going to roll some sort of minimal Gentoo based system and then just augment it as-needed from there
I strongly recommend you to watch Jeff Geerling YouTube channel, you will see the why it is beneficial to use CM4 over Pi4.
The board I linked is the Pi's ethernet as eth0 and a Realtek gigabit NIC over PCI-E 1x as eth1 (instead of USB3 which is what the Pi 4 uses the PCI-E for)
As a result it can do a full gigabit of traffic with minimal overhead
The change now enables you to write firewall rules that use a placeholder for the ISP-assigned prefix. The rules should update automatically after a prefix change.
(What has always worked is using the fc00 or fd00 address spaces for local fixed assignments, but pfSense has had problems with that setup as well in my experience)
It’s not a great barrier, but I don’t want the bare minimum skills advertiser, hacker, MPAA consultant, web store, or whoever being able to easily rely on this IP being me.
Yes. There are tracking cookies, and fingerprinting, and whatever, but the bar being set this higher is better than lower.
The phone analogy makes sense until you realize you’re actively calling everyone all the time, and the callerid shouldn’t be easily readable. It’s not like phones at all really.
In residential connections, every marketer will just figure out that particular AS gives /64 (or /56 or /48) and bundle them up, like how they use IPv4 address to track families.
This is actually one of the use cases where 'private addresses' make sense: when you don't have a static assignment but need static addressing.
In the IPv4 it's very unlikely that you'll get a static address unless from ARIN/RIPE/etc (or pay US$ 25+/IP on the open market), so we have everyone using 10/8 with NAT. It's quite easy for someone to get a statically assigned IPv6… unless you're a home user. So if you want static address, use the IPv6 equivalent of 10/8, ULA:
* https://en.wikipedia.org/wiki/Unique_local_address
Then you NTPv6:
* https://en.wikipedia.org/wiki/IPv6-to-IPv6_Network_Prefix_Tr...
* https://datatracker.ietf.org/doc/html/rfc6296
* https://docs.netgate.com/pfsense/en/latest/nat/npt.html
The interface portion of the IPv6 address (right-most 64b) stays the same, and only the prefix (left-most 64b) gets shuffled as they pass through the gateway.
The creater of Wireguard said it was bad with buffer overruns and they got angry for being called out.
https://arstechnica.com/gadgets/2021/03/buffer-overruns-lice...
The software seems to be the default open source firewall / router network admins go to, but it seems like a ticking time bomb to me.
They also seem to be pivoting to a closed source firewall / router project so this will result in less work going in.
Unfortunately, the only time CLI wins out in networking is when there's a cert to dangle in front of people. As much as I want to do things the "right" way, part of that equation is handing projects off to other people to maintain...
I switched to OpenBSD/pf from pfsense and I have more peace of mind needing to maintain a small handful of commented config files.
Can you elaborate how GUI will be better ?
At least with CLI and plain text configs I have "#" so all configs are self documented and committed to git repository.
I'm not sure what world you live in, but in the Cisco world I don't know anyone who does anything beyond the trivial in the various 'GUIs'.
part of that equation is handing projects off to other people to maintain
Yes, and I don't know anyone who would hire a Cisco engineer that wasn't fully conversant with the CLI. The idea that something we've been doing, successfully, for decades (handing a text Cisco config to the next engineer) is "basically impossible" is...interesting...and unsupportable in my experience. As is the implied "GUIs are always easier to understand and reason about".
Point is still valid through. Especially compared to some overly-complicated implementations, the pfSense web UI for VLAN and IPSec can be a better alternative.
1.) Your firewall scripts are now atomic (if using nft as your interpreter instead of bash), so either the entire ruleset gets applied, or nothing does.
2.) There's a nice declarative form of the nft syntax which I prefer (vs a more imperative style which we're all used to with pf (in the BSD world), or iptables)...both forms are executed atomically when the nft interpreter is used.
3.) The presence of an actual 'include' statement makes it possible to break your fw scripts up into multiple files, for better organization and readability. This also all gets executed atomically.
Overall I found it to be an enjoyable experience.
Thanks to them, several years ago I swore off FreeBSD. The tech may be ok/good, the baggage of personalities and egos is not worth it though. After seeing this, and at least the two of them associated with pfSense, I've now started looking for replacements for pfSense.
I've been thinking of OPNsense, though the whole FreeBSD bit bugs me (code/OS is fine, personalities/egos less so). Linux "equivalents" sort of exist, though reading through the various fora for them suggests similar ego/personality issues.
I'm not sure its bad enough to go back to dedicated firewall/router appliances (most are terrible and closed source). If there is a simple way to convert my pfSense config to a OPNsense config, this is likely to be the first step I take.
I'd love to hear other people's experience converting away from pfSense.
Since one or more of these people are or have been core committers on FreeBSD, this makes me question that project's judgement.
There is. You just back up your pfSense config, and then restore it into OPNsense.
- https://www.netgate.com/blog/announcing-pfsense-plus
- https://www.netgate.com/blog/pfsense-plus-pfsense-ce-dev-ins...
If you're using pfSense CE you're using an EOL product, so you should move to OPNsense just for that reason alone.
Those two posts try to convince you that CE is still relevant and will still get releases, but read carefully and you realize any changes to CE will either be by third parties or those that were part of the base FreeBSD system and thus were upstreamed to FreeBSD anyway. All the actual development work will be for Plus, and the design of Plus is sufficiently divergent (UI backend rewritten from PHP to golang apparently) that you can't backport the work to CE either.
Plus will be free for home use (and hopefully remain so), but won't be open source. Not that CE is all that open source either, but at least you can read and modify the PHP scripts in your installation.
Another reason people stayed off OPNsense was that it was based on HardenedBSD instead of FreeBSD, however that changed a few months ago so that should no longer be a concern.
> There will be CE releases after 2.6, but unlike Plus, they’ll be done when they’re ready, not on a regular cadence.
pfSense currently just has a bit better support for packages. pfblockerng-devel, radius server for 2FA, Telegraf etc. Those are not available in OPNsense yet. Using pfblockerng-devel GeoIP lists, I can add an extra layer of security, allowing only certain countries to even reach my OpenVPN port.
There is no guarantee that OPNSense is any better, other than the mentality aspect. It is a critical project and I am hoping to make the hop as soon as possible. At the moment, given my use case, I still feel that there is some time.
It seems that all the big ones - Google, Facebook, Cloudflare...all use BPF on Linux for everything.
https://blog.cloudflare.com/cloudflare-architecture-and-how-...