/dev/null
[H]F Junkie
- Joined
- Mar 31, 2001
- Messages
- 15,182
i've used OpenBSD, FreeBSD, pfsense, and just had an ER lite die on me.
OpenBSD: I've used this since the 2.2 days. Super fast/stable, rock solid, not for n00bs. OpenBSD has a primary focus on networking and is "upstream" for pf. If you want the most solid, up-to-date, secure firewall, use OpenBSD.
PFsense: I only used up to 2.1. I ended up having weird problems with it and found the GUI unintuitive. Last I checked had problems with ipv6 in general (high cpu usage on dhcpdv6) and prefix-delegation broken. I'd avoid it right now. I ran it in KVM with emulated nics and I couldn't get more than about 60Mbit/s down on it on a 1090T in a vm. I could on an intel atom with real nice which is what I was using until I found out IPV6 was broken. Is it fixed in 2.2? don't know.
ER-lite: I had one of these & it died with light use in under 6 months. Flash corrupted. I received approval for an RMA,but am not going to send it in yet as I'm about to go on vacation & probably won't be home if they send it back to me. I like the OS. ipv6 works. They recently got ipv6 with PD working. Yay! Downside is GUI doesn't have all features that CLI has. Supports PBR (very cool!)
What I'm using now: VYOS. I needed a working firewall while pfsense was getting flaky (upgrades failing, weird firewall rule problems) and my er-lite was dead. This is linux based & a fork of vyatta. Because it's based on debian, you can use virtIO nic drivers so performance is good. On my 1090T ivm box I typically am using sub 10% cpusage. very nice, and free to download/use. I've found some bugs (port-group objects that are large error out when you try to use them), but i've found workarounds for that. CLI ONLY.
OpenBSD: I've used this since the 2.2 days. Super fast/stable, rock solid, not for n00bs. OpenBSD has a primary focus on networking and is "upstream" for pf. If you want the most solid, up-to-date, secure firewall, use OpenBSD.
PFsense: I only used up to 2.1. I ended up having weird problems with it and found the GUI unintuitive. Last I checked had problems with ipv6 in general (high cpu usage on dhcpdv6) and prefix-delegation broken. I'd avoid it right now. I ran it in KVM with emulated nics and I couldn't get more than about 60Mbit/s down on it on a 1090T in a vm. I could on an intel atom with real nice which is what I was using until I found out IPV6 was broken. Is it fixed in 2.2? don't know.
ER-lite: I had one of these & it died with light use in under 6 months. Flash corrupted. I received approval for an RMA,but am not going to send it in yet as I'm about to go on vacation & probably won't be home if they send it back to me. I like the OS. ipv6 works. They recently got ipv6 with PD working. Yay! Downside is GUI doesn't have all features that CLI has. Supports PBR (very cool!)
What I'm using now: VYOS. I needed a working firewall while pfsense was getting flaky (upgrades failing, weird firewall rule problems) and my er-lite was dead. This is linux based & a fork of vyatta. Because it's based on debian, you can use virtIO nic drivers so performance is good. On my 1090T ivm box I typically am using sub 10% cpusage. very nice, and free to download/use. I've found some bugs (port-group objects that are large error out when you try to use them), but i've found workarounds for that. CLI ONLY.
Last edited: