Comparison conclusions:
pfSense offers paid options for additional support and features (pfSense Plus), a wider range of features and a larger community, but might have a steeper learning curve.
OPNsense provides a clean interface and built-in security features, but its community and documentation are smaller
The summary above is based on 40 interviews we conducted with pfSense and OPNsense users. To access the review's full transcripts, download our report.
"Initial setup is straightforward. There weren't too many issues with setting it up. It takes one hour or so."
"The network security and cloud security are most valuable."
"The features that we have found most valuable are the SSL VPN and the User Portal."
"The pricing is excellent. It's much less expensive than Cisco."
"Fortinet FortiGate appears to be scalable."
"The notable features that I have found most valuable are that it includes the antivirus, and also IPS, and even SD-WAN."
"The solution is easy to configure and maintain remotely."
"It has improved our organization with control data."
"For everyday tasks, we just get alerts. It's anything that's suspicious, including from our Netgate. So, it's part of how we maintain cybersecurity in our school. This is working alongside our endpoint security solution."
"The intrusion detection feature is the most valuable. It is an open-source firewall, so there is a lot of material on it. I also find the open VPN capability very nice. It is pretty customizable. The clustering and the high availability are the two biggest things to be able to get out of a firewall."
"It is much simpler than other solutions such as Fortinet."
"I had some outages in the network and we provide services for our company. We sell mobile credits. The terminal gets access to our own server inside the network and if one internet fails, then the other one is still up and we have a back-up link on the devices."
"I have found the most valuable features to be antivirus and malware protection."
"It is a stable solution. It is also easy to install and can be deployed and maintained by one team member."
"The built-in open VPN and the VPN Client Export are the solution's most valuable aspects."
"A very stable product that lasts over time, easy to understand, and administer."
"The graphic user interface is very good and it is user-friendly which makes the product easy-to-use."
"The DNS-level filtering is impressive for thwarting time scanners."
"The most valuable features in OPNsense are reporting and visibility."
"I feel that its valuable features are that it is simple and free."
"The solution has high availability."
"It's more secure and more reliable."
"The initial setup is easy. It only takes 15-30 minutes to deploy."
"The system in general is quite flexible."
"There can be more security in hybrid implementations. When a customer has a hybrid environment where some parts are in the cloud, we need a consistent security solution for such scenarios."
"Fortinet FortiGate could improve by having more storage in the hardware for log data."
"Fortinet FortiGate is not very easy to use. The navigation could be improved to make it easier to use."
"One of the problems I was having was with user mapping, and it is an issue for which I have escalated tickets with Fortinet support."
"The captive portal could be improved."
"I need user-behavior analytics, to find threat scenarios from inside the organization, insider attacks. That would be very helpful for us. In addition, I would like next-generation features for small and medium businesses. These businesses require UTM, all in one product. Fortinet must include it."
"The solution could have licensing fees reduced in the future."
"FortiGate is really good. We have been using it for quite some time. Initially, when we started off, we had around 70 plus devices of FortiGate, but then Check Point and Palo Alto took over the place. From the product perspective, there are no issues, but from the account perspective, we have had issues. Fortinet's presence in our company is very less. I don't see any Fortinet account managers talking to us, and that presence has diluted in the last two and a half or three years. We have close to 1,500 firewalls. Out of these, 60% of firewalls are from Palo Alto, and a few firewalls are from Check Point. FortiGate firewalls are very less now. It is not because of the product; it is because of the relationship. I don't think they had a good relationship with us, and there was some kind of disconnect for a very long time. The relationship between their accounts team and my leadership team seems to be the reason for phasing out FortiGate."
"If you want to take advantage of all of the solution's options, you need to have a bit of a technical background. It's not for a layperson."
"The hotspot and the portal feature in this solution are not stable for WiFi access. We use it at least once or twice every day and it crashes. Some modules can be better by improving detection and having new updates. Additionally, we have some issues with clustering and load balancing that could improve."
"The GUI could use improvements, though it is manageable."
"Also, simplifying the rules for the GeoIP. Making it simpler to understand would be an improvement."
"If a user doesn't have a large amount of experience in Linux systems, they will have problems using this solution. Users need to be highly skilled in troubleshooting competency. Users who do not have such skills will find the product difficult to use."
"I'd like to find something in pfSense that is more specific to URL filtering. We have customers who would like to filter their web traffic. They would like to be able to say to their employees, "You can surf the web, but you cannot get access to Facebook or other social media," or "You can surf the web, but you're not allowed to gamble or watch porn on the web." My technicians say that doing this kind of stuff with pfSense nowadays is not easy. They can implement some filters using IP addresses but not by using the names of the domains and categories. So, we are not able to exclude some categories from the allowed traffic, such as porn, gambling, etc. To do that, we have to use another product and another web filter that uses DNS. I know that there are some third-party products that could work with pfSense, but I'd like the native pfSense solution to do that."
"The Netgate forums and community don’t provide extensive discussions and topics related to every pfSense service."
"Reporting and real-time monitoring, since I'm used to Watchguard's reporting features, it would be nice to have an embedded solution for reporting."
"The support for OPNsense is good because we have documents available on the internet. The support could improve a little."
"On the customer-side, because I'm a small business, I need a cheaper or free solution option."
"I would like better documentation concerning the provided packages and their integration."
"The interface isn't so friendly user. But we have some technicians here who are quite confident with this tool. OPNSense could maybe add sets of rules so it's simpler to manage different groups with particular needs."
"In terms of improvement, the performance could be enhanced."
"You will need additional training before you can actually start to use it."
"I would like to see better SD-WAN performance."
"The reporting part could be better."
Netgate pfSense is ranked 1st in Firewalls with 128 reviews while OPNsense is ranked 3rd in Firewalls with 36 reviews. Netgate pfSense is rated 8.6, while OPNsense is rated 8.4. The top reviewer of Netgate pfSense writes "User-friendly, easy to manage the firewall, rule-wise and interface-wise". On the other hand, the top reviewer of OPNsense writes "Robust network security and management offering a user-friendly interface, open-source flexibility, and cost-effectiveness, with challenges regarding initial setup and the absence of official support". Netgate pfSense is most compared with Sophos XG, KerioControl, Sophos UTM, Cisco Secure Firewall and WatchGuard Firebox, whereas OPNsense is most compared with Sophos XG, Untangle NG Firewall, Sophos UTM, IPFire and WatchGuard Firebox. See our Netgate pfSense vs. OPNsense report.
See our list of best Firewalls vendors.
We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.