Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense Plus Multi-Instance Management Q&A - SNEAK PEEK

    Scheduled Pinned Locked Moved Messages from the pfSense Team
    9 Posts 8 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mwatch Administrator
      last edited by

      We're thrilled to share an in-depth Q&A session featuring our Lead Engineer, Leon, and our VP of Marketing, Glen. In this engaging conversation, they discuss the innovative Multi-Instance Management feature in pfSense and what it means for network administrators and businesses.

      Watch now: https://youtu.be/41gqqgA9zeM

      keyserK D 2 Replies Last reply Reply Quote 5
      • M mwatch pinned this topic on
      • keyserK
        keyser Rebel Alliance @mwatch
        last edited by

        @mwatch Very interesting.. Seems the MIM is a much more ambitious project than I thought. 300+ rest API commands from the getgo and templating functions… I Thought it would “just” be a automatic Mesh VPN setup and monitoring UI.

        Hope tp see the preview soon 😊

        Love the no fuss of using the official appliances :-)

        1 Reply Last reply Reply Quote 2
        • aaronsshA
          aaronssh
          last edited by

          This is great news. The one thing I really care about: can firewall aliases sync between devices? That would be a HUGE productivity gain.

          Sergei_ShablovskyS M 2 Replies Last reply Reply Quote 3
          • stephenw10S stephenw10 referenced this topic on
          • stephenw10S stephenw10 referenced this topic on
          • Sergei_ShablovskyS
            Sergei_Shablovsky @aaronssh
            last edited by

            @aaronssh said in pfSense Plus Multi-Instance Management Q&A - SNEAK PEEK:

            This is great news. The one thing I really care about: can firewall aliases sync between devices? That would be a HUGE productivity gain.

            Exactly this and a lot of other “small” things must be improved **BEFORE pfSense DevTeam start to spending a lot of resources (that already limited) to a significantly new product’s features!

            —
            CLOSE SKY FOR UKRAINE https://youtu.be/_tU1i8VAdCo !
            Help Ukraine to resist, save civilians people’s lives !
            (Take an active part in public protests, push on Your country’s politics, congressmans, mass media, leaders of opinion.)

            1 Reply Last reply Reply Quote 0
            • K
              kwangmien
              last edited by

              Hi,

              I am trying to find out what are the features supported by Multi-Instance Management.
              Can anyone advise where I can get the list of these features ?

              Thanks

              Regards
              Kwang Mien

              M 1 Reply Last reply Reply Quote 1
              • M
                michmoor LAYER 8 Rebel Alliance @kwangmien
                last edited by

                @kwangmien

                https://www.netgate.com/multi-instance-management-pfsense-plus

                Firewall: NetGate,Palo Alto-VM,Juniper SRX
                Routing: Juniper, Arista, Cisco
                Switching: Juniper, Arista, Cisco
                Wireless: Unifi, Aruba IAP
                JNCIP,CCNP Enterprise

                K 1 Reply Last reply Reply Quote 1
                • K
                  kwangmien @michmoor
                  last edited by

                  @michmoor Thanks for the info.

                  1 Reply Last reply Reply Quote 0
                  • D
                    detox @mwatch
                    last edited by

                    @mwatch Will you be providing a video on how it looks and what functions are avail?

                    Right now, I must remote into a local PC then log into the PfSense local dashboard... very cumbersome when managing 17 pfSense appliances.

                    1 Reply Last reply Reply Quote 1
                    • M
                      Morlock @aaronssh
                      last edited by

                      @aaronssh said in pfSense Plus Multi-Instance Management Q&A - SNEAK PEEK:

                      This is great news. The one thing I really care about: can firewall aliases sync between devices? That would be a HUGE productivity gain.

                      With an API and 300 commands, I don't think they skipped one to push aliases to the devices.

                      Certainly a very exciting development and improvement. However, like pfSense in general these days, it seems to be heavily inspired by developers' and marketing ideas and less by practical needs of network security professionals.

                      Some parts of the video call sound a bit far fetched, to be honest:

                      I never actually heard a complaint about a central management platform being too slow. Anyway, let's assume that a product out there is sluggish. Would it imply that you can move your enterprise firewalling from product x to pfSense, because Netgate's MIM is so much more responsive?

                      API vs. CLI: Outside of (mostly: cloud) environments that have a really mature, custom control plane, APIs of firewall appliances are rarely used, even on platforms that had them for years. CLIs are being used all the time, athough they are orders of magnitude slower than the slowest API, because they allow efficient manual changes as well as interfacing with a variety of third-party configuration managers with minimal adaptation. Whether a configuration change takes .4 or 78 seconds to apply is hardly relevant in a production environment. How many third-party vendors will support the pfSense API?

                      Scale: So far, it would have been very tedious to build infrastructures with thousands of pfSense instances. Hence, was it a real world need to support scaling into the tens of thousands, because so many clients with 15,000 instances each are urgently waiting for that feature? Or is it more about the many SMBs and SMB "MSPs" that maybe reach a two- or low three-digit number? The latter would have profited substantially from a CLI. With an API, they either do some very limited improvsation on the side, or have to use the Netgate platform right away.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.