More shady stuff from pfsense

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

zer0sum

Well-Known Member
Mar 8, 2013
850
475
63
If you haven't already ditched pfsense for opnsense, now's the time!

It comes as no surprise to many that they are making changes without any communication at all. They pushed people from CE to a free Plus license for their homelabs, and then took it away, without a formal announcement of what exactly is changing.

The CE edition is still free, but updates are slow, and it seems to be dying a slow death.

If you go to their site and try to register for PFSENSE+ HOME OR LAB it shows as $0, but in reality you get redirected to a page with a $399 sub instead.

 
Last edited:

Dave Corder

Active Member
Dec 21, 2015
298
194
43
41
I migrated from pfSense to OPNsense a year or two ago. It was fairly straightforward. My Dell R210ii router has on-board Broadcom gigabit NICs and (at the time) a Chelsio dual-port SFP+ NIC - I ended up buying another Chelsio card and a 2-port PCIe Gigabit NIC with the same chipset as the R210ii and throwing them in an old spare PC so I could try out the pfSense export/OPNsense import process a couple times.

For the most part, all my rules and stuff transferred over fairly seamlessly. I do recall having to massage the XML file from pfSense in a couple areas before I could get OPNsense to import properly...possibly in the DHCP lease area and/or VLAN areas, which were the most important things for me to get migrated - I probably have over a hundred static entries for all my IoT devices, and keep them on a separate VLAN (along with my main VLAN, a management VLAN, and a guest VLAN).

Overall I'm quite happy with OPNsense as a whole, and am doubly-happy to have left the pfSense drama behind.
 

BlueFox

Legendary Member Spam Hunter Extraordinaire
Oct 26, 2015
2,098
1,515
113
If you go to their site and try to register for PFSENSE+ HOME OR LAB you get redirected to a page with a $399 sub instead of it previously being free.
Does say to contact sales@netgate.com to get a non-commercial license on the product page. If you could automatically generate licenses for free, their subscriptions would tank.
 

Sean Ho

seanho.com
Nov 19, 2019
774
357
63
Vancouver, BC
seanho.com
No problems routing my home network with OPN for many years now. With automatic config backups, I have no qualms about doing upgrades even in the middle of the workday. VLANs, Wireguard, IPv6, TFTP/PXE, DNSBL, haproxy, nginx, unbound overrides, WoL, NUT, etc.

Have always been curious to try out Vy, though.
 

Markess

Well-Known Member
May 19, 2018
1,166
783
113
Northern California
If you go to their site and try to register for PFSENSE+ HOME OR LAB it shows as $0, but in reality you get redirected to a page with a $399 sub instead.
Its super ironic that I finally said to myself, literally THIS MORNING, "Maybe I should stop putting it off and upgrade my Community Edition install to a Home Plus license while they're still free?"

Netgate still has the instructions to do this on their website. But, when I couldn't find the registration link where the instructions said it would be, a google search led me to a different Reddit page with the same Netgate response that @blunden posted above.

Sigh.

https://www.reddit.com/r/PFSENSE/comments/17fvtvv
 

marcoi

Well-Known Member
Apr 6, 2013
1,533
289
83
Gotha Florida
ill have to look into opensense with wpa_supplicant since i have ATT fiber. I think i setup switch to do vlan0 so i just need to figure out the wpa part. if anyone done it with opensense let me know steps if you got time.
 

zer0sum

Well-Known Member
Mar 8, 2013
850
475
63
ill have to look into opensense with wpa_supplicant since i have ATT fiber. I think i setup switch to do vlan0 so i just need to figure out the wpa part. if anyone done it with opensense let me know steps if you got time.
Which AT&T gateway do you have?

You can run the BGW-320 in a simple bridge mode without any need for supplicants. I tested it up to 5Gbps and it was very smooth for me
 

marcoi

Well-Known Member
Apr 6, 2013
1,533
289
83
Gotha Florida
Which AT&T gateway do you have?

You can run the BGW-320 in a simple bridge mode without any need for supplicants. I tested it up to 5Gbps and it was very smooth for me
i stopped using the GW a few years ago. running certs with wpa on pfsense CE as a VM now with vlan0 on virtual switch so i can vmotion pfsense to different box when doing updates etc.
 

RyC

Active Member
Oct 17, 2013
359
88
28
Wellp looks like the Home+Lab free Plus license is gone completely
 

mach3.2

Active Member
Feb 7, 2022
133
87
28
The disappearance of the $129 TAC lite can't be adequately explained by piracy/commercial thief too. Why not remove the discount and make it $129?

The whole thing feels like they are hurting for money and are trying to stop the perceived revenue leak by cutting all free licenses.
 
  • Like
Reactions: fohdeesha

zer0sum

Well-Known Member
Mar 8, 2013
850
475
63
i stopped using the GW a few years ago. running certs with wpa on pfsense CE as a VM now with vlan0 on virtual switch so i can vmotion pfsense to different box when doing updates etc.
I can update OPNsense and only lose 3-5 pings on the reboot. Not sure it's worth the trouble to do HA :)
 

das1996

Member
Sep 4, 2018
75
17
8
i stopped using the GW a few years ago. running certs with wpa on pfsense CE as a VM now with vlan0 on virtual switch so i can vmotion pfsense to different box when doing updates etc.
There's a wpa_supplicant on dslr for freebsd13 which should work with the current opnsense (as its still freebsd13 based?). Not sure if the current build of opn directly includes the patch. If not, you can get the binary here - OPNSENSE vlan0 supporting wpa_supplicant binary - AT&T U-verse | DSLReports Forums.

Commandline would be the same as on pf. You may need to play around with boot sequence to get it running properly at start up. Some basic instructions are included in the post.

And yes, was about to make the jump to pf, but not likely any more unless something changes, and quickly. This behavior is not acceptable. At least give some notice.
 
  • Like
Reactions: marcoi

ketiljo

New Member
Sep 7, 2022
16
7
3
I'm seriously considering switching to Opnsense now but I need an alternative to pfblockerNG. Any suggestions?
 

gb00s

Well-Known Member
Jul 25, 2018
1,196
603
113
Poland
Why is this shady behavior? Just because users want everything for zero doesn't mean businesses need to follow. If your supermarket tricks you every day no one calls it shady. If you run a business based on user subscription fees, you do what ever you can to suck money out of customers pockets.

Shady is to run something productive and requesting tools and services being run and maintained paying zero.
 

blunden

Active Member
Nov 29, 2019
492
155
43
Why is this shady behavior? Just because users want everything for zero doesn't mean businesses need to follow. If your supermarket tricks you every day no one calls it shady. If you run a business based on user subscription fees, you do what ever you can to suck money out of customers pockets.

Shady is to run something productive and requesting tools and services being run and maintained paying zero.
What can be considered shady is that they were pushing home lab users to pfsense plus and essentially stopped updating pfsense CE. They then made this change suddenly without any official announcement posted.

Now people might end up in a situation where they can't downgrade to CE because the configuration file format is too new. I don't know if that has happened yet, but for people who use the rest of their license period without reading this it's fairly likely to happen.

Obviously, misuse of the home lab issue is a problem. What they should've done is communicate this change ahead of time, and make sure that any changes to the configuration format is supported by CE too until the majority of users are likely to have migrated already.