So I’ve been using OPNsense for a few years. I have an extensive config inclduing vlans, plugins, policies, suricata, VPN, routes, gateways, HAProxy, etc.

Over the past few months, I’ve noticed certain bugs, weirdness, and slowness within OPNsense. I recently watched Tom Lawrence’s video on the licensing changes and he touched on the openssl vulnerability that OPNsense has yet to remediate.

The Plus license cost (per year) which entitles you to some limited support options is also appealing. Every time I get stuck figuring out something complex in OPNsense, I have to hope someone else has tried to do the same thing and posted about it so I can troubleshoot.

I also don’t like having to constantly update. A more “stable”/enterprise focused cycle like pfSense has seems like my pace. It broke on me last year with one of the upgrades and I had to clean install.

Don’t get me wrong, I love the UI (mostly), plugins, etc. in OPNsense, but these past few months have got me thinking.

I’ve also heard that people don’t like Netgate as a company, so that could definitely factor into not switching.

What are everyone’s thoughts?

  • TheHellSite@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    1 year ago

    I second this. No offense to OP!

    I never noticed any “slowing down issues” since any of the recent updates. Running OPNsense with a similiar setup to yours “vlans, plugins, policies, suricata, VPN, routes, gateways, HAProxy, etc”. Again no issues on 8+ sites, including SiteToSite WireGuard VPNs and with large corporate networks. Some systems running perfectly stable and performant since version 20.x (installed) and now running the latest update.

    Therefore I highly think your issues are user error / misconfiguration. Yet, I don’t mean to judge but it seems to me that you switching to pfSense will just bring your OPNsense issues with it.

    I can’t tell how much experience you have with networking/firewalls in general but a lack of that won’t bring you any further by switching to pfSense.