Switching from PFsense to OPNsense? Here's a basic setup

Поділитися
Вставка
  • Опубліковано 6 жов 2024

КОМЕНТАРІ • 82

  • @Techie4life
    @Techie4life 11 місяців тому +60

    Would love to see a full Opensense setup tutorial. Can't wait :)

  • @charlieblaclock9265
    @charlieblaclock9265 11 місяців тому +19

    After over 10 years on pfSense, our consulting firm have transitioned to OPNsense. The drama throughout the years with pfSense and its owner is just too much. Thanks for the final nudge pfSense management. There are alternatives which they don't understand.

    • @dabneyoffermein595
      @dabneyoffermein595 10 місяців тому +3

      Thanks for the tip. looks like transitioning off of it is over due

  • @LAWRENCESYSTEMS
    @LAWRENCESYSTEMS 11 місяців тому +7

    Good video and thanks for the mention! :)

    • @MactelecomNetworks
      @MactelecomNetworks  11 місяців тому +6

      No problem you’re the PFsense king had to mention you :)

  • @blademan7671
    @blademan7671 11 місяців тому +23

    Perfect timing of this video. I was searching for this exact process with all the changes from Negate licensing. It would be nice to see some typical services setup: installation process on bare metal, DHCP reservations, DDNS, UPS, config backups, software updates.

  • @bmcfa249
    @bmcfa249 11 місяців тому +6

    Great video. I would love to see you go more in depth with firewall configurations in a future video!

  • @jims261
    @jims261 11 місяців тому +5

    Yes great timing. Would love for you to go into more depth on firewall rules. Thanks for all the great videos.

  • @evilfootware
    @evilfootware 11 місяців тому +10

    Spot on video as per normal. Could you do a more in-depth one about opnsense firewall rules? I think that would be super helpful. Thanks again

  • @JavierPerez-fq2fi
    @JavierPerez-fq2fi 11 місяців тому +1

    Perfect timing too!!! Thanks for sharing this set up together with ubiquiti products

  • @BradleyHerbst
    @BradleyHerbst 11 місяців тому

    I really appreciated you making this video since what is currently going on. Thank you.

  • @JasonsLabVideos
    @JasonsLabVideos 11 місяців тому +4

    The Protecli box runs this SOOOO good ! Opnsense is nice !! Good video Cody !

    • @dabneyoffermein595
      @dabneyoffermein595 10 місяців тому

      whats better , a home EERO router/firewall (issued by my ISP) or a pfsense configuration for high protection home needs?

  • @jas9450
    @jas9450 11 місяців тому +1

    I'm so happy I went with UDM Pro then SE after PFsense started having on CE version 2.5 on my custom hardware. Your channel made the transition from PFsense to UDM super easy, thank you.

    • @jadamsnz
      @jadamsnz 11 місяців тому +1

      I had a pfSense box for a while, an old i5 SFF PC, and decided pfSense was total overkill for me and so went to a UDM Pro which also allowed me to set up a camera system.

  • @minigpracing3068
    @minigpracing3068 11 місяців тому +8

    A series of OPNsense videos would be nice. On the Lawrence Systems forum, several people mentioned the lack of tutorials for OPNsense, so many of us would like to see them. (edit) I'm hedging bets with pfsense, going to set up an OPNsense system just so I'm prepared. Another video I'd like would be installation and configuration of e2guardian on OPNsense, it's not horrible on pfsense, but I've read there is no gui for the settings on OPNsense.

    • @dabneyoffermein595
      @dabneyoffermein595 10 місяців тому

      Looks like pfsense is on its way out according to the description of this video (Lab-Version - in other words, the free version).

    • @minigpracing3068
      @minigpracing3068 10 місяців тому

      @@dabneyoffermein595 People keep telling me to calm down, pfsense CE will be fine... But I'm seeing that it no longer has feature parity, and I'm sure they are slowly working to remove the open code and replace it with closed code. People also keep telling me that OPN just isn't the same level, and part of that is they are not contributing as much code back to BSD so they are always behind, always waiting for a fix. All that said, I still haven't tested OPN yet, but it's on my (long) list of things to do. I did read about some of the sins of the past (pf), and see that same attitude in their recent news releases (go jump you freeloaders!), same thing that Redhat did and said about CentOS. I need to find time to learn OPN, really need to change my firewall at work this summer, big project considering e2guardian filters and Suricata tuning.

  • @ben.1
    @ben.1 9 місяців тому

    Thanks for this explainer video, Great video.
    I would love to see you go more in depth with firewall configurations in a video!

  • @JonathanRLight
    @JonathanRLight 11 місяців тому +1

    Timely video. If you setup interfaces via the console most of this is very fast; from install to updated basic working wan/lan is a few minutes.

  • @georgelza
    @georgelza 11 місяців тому +2

    Letting you know... deeper into firewall rules please.
    if you can also do a video covering truncing between opnSense and a Ubq switch, please.

  • @arthurtecpc
    @arthurtecpc 9 місяців тому

    I will loved show more rules for iot network. Thanks, great job.

  • @janstridh
    @janstridh 7 місяців тому

    Would have been nice to have some more firewall rules through OPNSense. Grouping and blocking other networks from accessing the gateway. Great educational channel. 👌

  • @philexel3007
    @philexel3007 11 місяців тому +2

    Defnitely would like to see a video on some more rules and setups, like VPN, ad blocking, and others. Great starting point though.

  • @rlocone
    @rlocone 11 місяців тому +2

    Thanks for all of your content. Please enable dark reader on browser presentations. Thank you.

  • @bokolobs1264
    @bokolobs1264 11 місяців тому

    Great video, Cody! Thanks! Would love to see a video on WAN failover setup.

  • @jardelainen8278
    @jardelainen8278 11 місяців тому

    Thanks for this, I would liketo see more opnsense videos

  • @MPHxthexLegend
    @MPHxthexLegend 11 місяців тому +4

    Nice video, it would be nice if you could show mDNS with IoT stuff and default LAN interactions.

  • @fordi_steve
    @fordi_steve 11 місяців тому

    Would also love to see a full review/tutorial. Thank you!

  • @defyiant
    @defyiant 11 місяців тому +2

    Full opnsense tutorial would be a help for a nooby like me running a firewall box similar to protectli

  • @darthkielbasa
    @darthkielbasa 11 місяців тому

    Glad I stumbled across this. May switch to OPN from pf. Not sure yet. I’m not impacted by the plus debacle but love jumping on bandwagons.

  • @l0pher
    @l0pher 11 місяців тому

    Yeah, would love some more OPNsense videos

  • @BillyDickson
    @BillyDickson 11 місяців тому

    Going to stick with pfsense but I entend to move to CE and see what happens in 6 months, I'll re-asses then. Thanks for the video, much appreciated.

  • @NecroMorrius
    @NecroMorrius 11 місяців тому +1

    I have had loads of issues with opnsense running it in a 50 site environment as a datacentre firewall. Mainly around IPsec tunnels and updating.

  • @bagassetiawan1478
    @bagassetiawan1478 11 місяців тому +3

    please make video about firewall rule in opn sense. tahnk you.

  • @thieuson
    @thieuson 11 місяців тому

    Very nice, im sưitching now

  • @JamesSturge
    @JamesSturge 11 місяців тому

    Oh nice, make more videos with full configuration and addons for IDS & IPS like Suricata.

  • @LordSaliss
    @LordSaliss 11 місяців тому +2

    Should do 2 follow-up videos, one with some firewall stuff and routing features built into OPNsense, and a second follow-up video with ZenArmor plugin that turns this into a layer 7 gateway like Unifi gateways are.

  • @chrisboyce3109
    @chrisboyce3109 11 місяців тому +3

    Hi Cody. With Bell and other providers pushing internet packages north of 1Gbps, I'm curious what you think about (or if you've tried) one of the Protectli 2.5Gbps NIC models and pairing that with say, Bell's 1.5Gbps plan? It seems like overkill, but I suspect they're going to keep sunsetting slower plans and forcing people into these crazy fast packages. I would want to try and take advantage of that on the custom firewall as much as possible. Thanks for the video.

  • @jamesclarity1077
    @jamesclarity1077 10 місяців тому

    Great vid!

  • @alonzosmith6189
    @alonzosmith6189 11 місяців тому

    Will give OPNsense a try again.

  • @jobapp7782
    @jobapp7782 11 місяців тому

    Thanks for the video. Maybe you could make a video on how to correctly configure the unifi dream machine with the Opnsense firewall. opnsense would be like an additional filter to the unifi dream machine. Opnsense firewall rules are also

  • @notta3d
    @notta3d 11 місяців тому

    Thank you!!

  • @notta3d
    @notta3d 11 місяців тому

    This seems to meet my needs. I don't use a lot of advanced features. I just need the VLAN's and the Firewall Rules. No sense paying $399 when this seems to do the job just as well.

  • @nospamallowed4890
    @nospamallowed4890 11 місяців тому +1

    Great video on how to setup OPNSense. But two things remain unclear to me:
    1) Why? I assume there in an advantage to OPNSense over PFSense. What is it?
    2) I see several people recommending Protectli hardware, and I see that it has better performance for the money. But isn't it a Chinese product? If so, isn't it risky to trust our whole security to hardware that could have been required to contain embedded spyware for the Chinese government?

    • @itchybear2162
      @itchybear2162 11 місяців тому +1

      Then you shouldn’t use any electronic devices/appliances. Most of the electronics whether it be the whole thing or parts of it is assembled or made in china.

    • @longbeach225
      @longbeach225 11 місяців тому

      Because Netgate is making PfSense a license and charging people. OpnSense is a fork from PfSense so the features are nearly the same for free.

  • @cjghvieira
    @cjghvieira 11 місяців тому

    Me too would love to see a full Opensense setup tutorial.
    Greetings from Portugal. :-)

  • @igornizambiev6836
    @igornizambiev6836 6 місяців тому

    Could you explain Firewall rules direction logic?:
    1) in ?
    2) out ?

  • @todoralexandrov1
    @todoralexandrov1 11 місяців тому

    Would like to see a detailed OpenVPN setup and test.

  • @angelln25
    @angelln25 11 місяців тому

    Would be good idea to do more content on firewall rules

  • @thorstenfricke3257
    @thorstenfricke3257 5 місяців тому

    Hi what should i buy today? pfsense or opnsense?

  • @shawnwait6207
    @shawnwait6207 11 місяців тому +1

    Hey Cody.. do you need a seperate firewall controller while using a UDM SE ?

  • @lkfng
    @lkfng 11 місяців тому

    Looks like I am reverting to pfSense CE and resume testing OPNsense as a solution for my customers.

  • @albertofelicianocolon51
    @albertofelicianocolon51 11 місяців тому

    Do you have the process of how you install OPNSense? And basic settings? Thanks.

  • @it-lehrling
    @it-lehrling 11 місяців тому

    More Videos about Opnsense Rules pls.

  • @giovannicoutinho5966
    @giovannicoutinho5966 11 місяців тому +2

    I got a mini pc with 4x intel i226 rj45 ports that is almost perfect for my use case, I had plans to add a mellanox cx3 sfp card on it so I can have 10GB throughput in the router but this wont be straightforward. My current setup is a UDM-Pro, USW-Aggregation and a USW-Pro-Poe 24 and they are connected through a dac cables. Is there a way I can use the udm pro for just cameras and network management, use the USW-Pro for intervlan routing and the minipc running opnsense as the router just for internet?

    • @giovannicoutinho5966
      @giovannicoutinho5966 11 місяців тому

      the reason for usw-pro being intervlan router is because of the throughput, I have a homelab network with 3 other minipcs for a proxmox cluster with 2.5G ports , a network for my storage that has a dac cable to the usw-aggregation and the main network where I have other 2 pcs over a 10gb link with fiber. also the cameras on its own network. Although 2.5GG throughput to the opnsense might be sufficient I will see bottlenecks when my pc on main network tries to write something in the nvme volumes of my storage so ideally the traffic would stay within USW-Pro and only go to the opnsense for internet. Is that possible?

    • @giovannicoutinho5966
      @giovannicoutinho5966 11 місяців тому

      I actually managed to get the mellanox cx3 sfp card working and using sata ssd as the opnsense disk. I will run some tests and will probably use it as intervlan router as well but I would love to get the intervlan routing on the switch if this is possible and keep using udm-pro to manage the usw-pro switch, all the flex switches and APs

  • @iamrage4753
    @iamrage4753 11 місяців тому

    Can you cover setting up a managenent vlan with suitable rules please

  • @msnippe3750
    @msnippe3750 11 місяців тому

    Lol i have 2 firewall boxes running opnsense and pfsense. I am trying to let them have the same functionality and i must say pfsense is the winner up to know. Basic functionality both score equally vlan lan etc etc. If you really want to make a difference then make a good video about adblocking, HAproxy and Acme licensing. That are the things that pfsense does better and there are more tutorials about that.

  • @lukey3030
    @lukey3030 11 місяців тому

    You must have had added some static routes on your primary router to your new vlan 11&12 subnets .
    You didn’t NAT your source traffic vlan 11 &12

  • @rowebil00
    @rowebil00 9 місяців тому

    The config has a similar appearance to Fortinet.

  • @moeunsoksovannary8506
    @moeunsoksovannary8506 11 місяців тому

    I would like to see Port forwarding on IP camera vlan.

  • @therus000
    @therus000 11 місяців тому

    Thanx for great video
    i tried to this before and everything fine except the dhcp not work on VLAN. i thought it was because the lagg.
    i used lagg before fo lan.
    i decide to do as you did in video.
    i delete the lagg and put the lan on igc1
    then i try to make the vlan from igc1
    everything as you do in video.
    the DHCP not work. i googled this problem before, someone said must change the setting on interfaces-settings-VLAN Hardware Filtering to default or disable. And Disable hardware checksum offload check this option
    but same. the DHCP doesnt work on vlan.
    maybe you got an ideahow to fix this problem.
    or can you share your interfaces settings

  • @szaboclaudiu
    @szaboclaudiu 10 місяців тому

    Hi. It's not better to connect AP directly into opnsense box in one dedicated port ? (I'm thinking that all wireless connected devices to not cross through a switch and after that to an uplink between sw and opnsense box (back and fw) - it's a useless traffic from my opinion)

    • @MactelecomNetworks
      @MactelecomNetworks  10 місяців тому +1

      It could be but the issues is you need to power the AP some how. You could always use a power injector

  • @Mieciu-xLx
    @Mieciu-xLx 10 місяців тому

    How to configure Traffic Shaping ?
    Greetings from Poland.

  • @murphybrown32216
    @murphybrown32216 5 місяців тому

    will opensense install and work on a cisco firewall asa 5520

  • @philipp5389
    @philipp5389 11 місяців тому

    Im missing a 16 Port pro Switch but I don’t think it will come

  • @RupertoCamarena
    @RupertoCamarena 11 місяців тому

    more from opnsense!!

  • @gonace
    @gonace 11 місяців тому

    I've lost all respect for Netgate and had little to begin with, to not be overdramatically but they've been closed-source for a long time but still say they're open-source.
    I don't get why they would like to annihilate thousands of beta testers who have been active in their community for years.

  • @ecotts
    @ecotts 11 місяців тому +1

    Im sick of Pfsense..

  • @psycl0ptic
    @psycl0ptic 11 місяців тому

    no fee...both are free. boot env and AWS VPN config are really the only two major things you don't get in CE. most don't need/use any of the Plus features anyway, and are just being overly dramatic as usual any time netgate makes any changes.

  • @perrenud8282
    @perrenud8282 11 місяців тому +1

    Would also love to see a full Opensense setup tutorial. Can't wait :)