// Engineering Log
pfSense CE and Plus: an office firewall and how it differs from OPNsense
Published on 2026-09-22
// Fast route
This article belongs to the topic Networking and routing.
pfSense — a firewall and router on FreeBSD, one of the oldest open projects in this area. It is developed by Netgate, and today it exists in two editions: the open pfSense CE (Community Edition) and the commercial pfSense Plus. The tasks are the same as for OPNsense: a gateway between the office network and the Internet, VPN, multiple providers, network segmentation.
CE and Plus: what’s the difference
According to Netgate:
| pfSense CE | pfSense Plus | |
|---|---|---|
| License | open, allows commercial use | proprietary, under Netgate’s EULA |
| Where it runs | on any compatible hardware | preinstalled on Netgate devices; for other hardware and clouds (AWS, Azure) — by subscription |
| Cost | free | with TAC Lite support — $129 per year, TAC Pro — $399, TAC Enterprise — $799 |
| Support | forum and community | Netgate technical support, with higher tiers offering 24/7 support |
Current versions according to Netgate documentation as of August 2026: CE 2.8.1 and 2.9.0, Plus 26.03 and 26.07. CE releases are noticeably less frequent than Plus, and some new features often appear in Plus first.
For a Russian company it’s important that Plus is purchased from Netgate or via the AWS and Azure Marketplaces, so the realistic option is CE.
What it can do
- stateful firewall, rules by interface, aliases for address and port groups;
- multiple providers with gateway groups and failover switching;
- VPN: IPsec, OpenVPN, WireGuard (as a package);
- high-availability pair via CARP with configuration synchronization;
- packages from the built-in package manager: HAProxy, Suricata, pfBlockerNG and others.
Example: HAProxy on pfSense
HAProxy is installed as a package via System → Package Manager. There is a stable HAProxy package and HAProxy-devel, which follows the development branch. After installation settings appear in Services → HAProxy:
- in the Backend section you describe groups of servers where requests are forwarded and health checks for them;
- in the Frontend section — the addresses and ports on which HAProxy accepts connections, and rules for selecting the backend, including by domain name;
- certificates are taken from the pfSense certificate manager.
You don’t write the configuration file manually: the package assembles it from the interface settings. Netgate documentation notes a peculiarity: although the interface has separate tabs for frontends and servers, the final configuration consists entirely of listen sections. How HAProxy itself is organized and how to write its configuration manually is covered in the article about HAProxy.
Installation and updates
- A device with two network ports or a virtual machine.
- From the pfSense.org download page, CE and Plus are downloaded via the Netgate Installer, and the link to it leads to the Netgate online store.
- After installation the console asks to assign WAN and LAN, then the setup wizard in the web interface.
- Updates are installed from System → Update. Before upgrading between major versions you should export the configuration (Diagnostics → Backup & Restore) and read the release notes.
The first steps are the same as for any firewall: change the administrator password, restrict web interface access to the internal network, segment the network, set up configuration backups.
pfSense or OPNsense
OPNsense appeared in 2015 as a fork of pfSense, so their capabilities are close. The choice is usually determined not by features but by conditions:
- License and releases. OPNsense has a single open edition and releases twice a year. pfSense CE is updated less frequently, and new features often arrive in the commercial Plus first.
- Interface. The interfaces are different, and an administrator’s experience with one of them is a significant argument.
- Ecosystem. pfSense has more legacy guides and forum discussions, OPNsense has more frequent updates and a built-in REST API with access keys.
- Support. If you need paid vendor support and ready-made appliances, that’s Netgate and pfSense Plus.
For a new project without ties to Netgate, OPNsense is often chosen. If a company already runs pfSense and the administrator knows it, there’s no point in switching platforms just for the sake of change.
When pfSense is suitable
pfSense CE is suitable for an office that needs a full-featured firewall with VPN, a backup channel and packages like HAProxy without license payments. If such flexibility is not needed and you want a ready appliance, it’s simpler to get a router — MikroTik or Keenetic.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Networking and routing
MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.
Typical tasks behind this topic
- Set up VPN and secure access to office or cloud
- Fix routing, DNS, or unstable connectivity
- Configure MikroTik, firewall, and external links
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related