Addressing Changes to PfSense Plus Home+Lab
netgate.com
netgate.com
It's been quietly doing its job ever since, with a minimum of fuss.
For example something I use pretty heavily is pfblocker that automatically geo-blocks ips from different countries that most attack my homelab (Russia, USA, china ,etc..) from accessing my homelab
Is there something like this on opnsense?
However what you're saying doesn't make any sense. All incoming connections, from anywhere, are blocked by default. That's true in both pfSense and OPNsense.
Are you saying that you allow all incoming connections, but then block specific countries? Because that's mad, and given the existence of VPNs, pointless.
Useful for if you're roaming around and need access to that service from your laptop/mobile without a VPN, but also prevents attacks from countries you're unlikely to access it from.
I use it to flat out block all incoming and outgoing connections to a certain small group of countries. More out of curiosity than necessity.
It's also got a Crowdstrike interface for more dynamic blocking.
I only have the one piece of hardware so I need a record of the configs somehow to refer to as I do the migration. Perhaps also some sort of backup so I can restore it in a pinch if I can't get OPNSense set up quick enough.
In older versions it was possible to import a PfSense backup - with a few glitches, but they're too different now. I think the slow way is the only way.
But also export your config because you will inevitably forget to screenshot a thing or seven and you can poke around the config export for that port number or IP address.
Worst case scenario, you can spin up a VM of pfsense quickly and reimport the config if you have to.
There's going to be a point soon where I have two fiber providers (and thus two WAN links) for a little while, I'll try move the existing pfSense off of my Protectli box to a VM, keep everything up for the family while I configure OPNSense on the Protectli, then if I do it right, I can move everything over with minimal reconfiguration.
It was anti-climactic and worked so well as to be boring, which is the absolute highest compliment that a replacement and cutover can have.
I doubt I have anywhere near the networking knowledge you have, so some of the more complex things I have set up; like my BGP routes for my Kubernetes clusters and my VLANs/trunks etc, that have taken a lot of tinkering might take me quite some time. I expect the way they're configured will be different, terminology might be different, and of course the UI will be different, so I can't just do it by reference.
I have no problem taking my time, so long as we have the basic networking we need for family and working from home.
Those things work the same way in opnsense. Most of my conversion was just data entry of the particulars.
I try to keep my main fws as simple as I can, for the benefit of the household, but I do get carried away with home automation and IaC/CM to my firewalls.
In a moderately complex home setup with wireguard to access my home network remotely, multiple VLANs/SSIDs (including one to firewall off IoT things and one that routes wan traffic to a vpn, again via wireguard), my own DNS server, a filtering web proxy for the kids, etc., I haven't encountered anything pfSense or similar would have made any easier for me. It's all achievable by editing relatively straightforward config files. The most complex bit is the firewall, but I have a terse, straightforward nftables config that does what I need and that I understand fully. I didn't really see the value in putting a layer of GUI stuff on top of it and then having to keep up with changes to that layer, and in the process obscuring what's actually going on.
I’d like to see some kind of more resilient upgrade process where a pre-upgrade snapshot is taken, the firewall updates and reboots, some kind of watchdog tries to hit a well known endpoint, and the whole thing automatically rolls back to the known good config if it goes X minutes without being able to connect after the update. That would mitigate the riskiest part of updating remotely.
As for new features, once you have a reliable firewall, what more do you want? I wouldn’t complain about a better traffic shaper experience, but OpnSense did that and the “easier” traffic shaper in OpnSense isn’t as flexible IIRC.
For licensing, I don’t hate the TAC-Lite approach. They could make it more clear it’s a lifetime thing (I hope I’m right about that) and I hate begging for installers, but at least they aren’t forcing subscriptions yet. I fear that’s coming one day since it would force us to switch to something else and pfSense is working ok for us ATM.
"Just"?
I'm sure all of use nerds and geeks on HN think commercial support is often not important, but there are plenty of SMEs that need to de-risk some things when running their infrastructure.
“Is this contractor responsible for the whole house or just the garage?” does not imply the garage isn’t important or that it’s trivial.
I'd like to see Netgate and OPNsense both thrive. The competition is good for the product and users.
I'm happily on my 2nd OPNsense business license on Deciso embedded Ryzen-based hardware with 10 GigE optical links. Even takes care of PKI and has 2FA. I'm happy and I don't have to worry about massive, arbitrary license changes or big corporate enshitification.
Moved to OpenWRT a few years ago and been quite happy since.
I'm pretty happy with the experience and the end result.
This seems to indicate that nearly nobody was using it, even counting the illicit activities of the multiple appliance vendors.
If I have a modest lab automation with solid bracketing of fw release versions on some network scenarios, I could easily account for thousands of on-install telemetry entries per week.
I can imagine Hetzner alone would account for thousands upon thousands of installs.
Just based on their phrasing, I doubt there will be a massive influx to opnSense.
As soon as Tailscale has proper integration on opnSense, I'm definitively moving on. The CE version of pfSense has very outdated packages and that probably has an impact on security, which, for a Firewall, is a big no.
BTW: Does anyone know why Tailscale doesn't provide a proper package (with graphical interface) for opnSense, like it does for pfSense? I was under the impression that it would need very few changes for it to work.
opnsense-code ports
cd /usr/ports/security/tailscale
make install
service tailscaled enable
service tailscaled start
tailscale up
source:
https://www.wundertech.net/how-to-set-up-tailscale-on-opnsen...As for "but its free". I think its reasonable to expect the free offering to be promotional. I know I have bough Netgate HW and license for work because I was familiar with their free offering at home. But stuff like the recent move might make me reconsider.
My impression is that this might not exist yet (the currently available projects are significant lacking in either features or reliability), and that my odds of getting something user-friendly with tools like pfBlockerNG are even slimmer.
I always feel so handicapped when something breaks on my router, due to being so much less familiar with BSD, and due to it being an older / limited FreeBSD release (many things missing from the pf repos).
Just last week my pfsense upgrade resulted in a non-booting system, and I felt helpless (user error -- zpool upgrade but didn't upgrade something about the boot directory). I didn't have my usual tools, so I ended up having to install ZFS support to an old RPi3 running NixOS just so I could look around and get the ZFS parts sorted and figure out what happened. (Thankfully I eventually found an old mailing list thread with some obscure incantation that I ran from a pfsense installer usb and resurrected things.)
The whole time I just really wished that I could have been on a Linux machine with my familiar GNU tools!
The setup can be rough if one isn't that familiar/has high requirements... but making a router and so on is pretty basic stuff.
Basic in the sense that it's easy to do both well and terrifyingly incorrectly.
I'm curious about home users who truly need an interface because they're in there fiddling so much
I use Ansible to manage the config of mine, but that's more for rebuilding. I look at the thing maybe twice a year
In the Netgate world, it now seems that the CE edition is the most stable, inheriting changes/fixes after they've settled into the plus channel.