Announcing Netgate Nexus: Multi-Instance Management for pfSense Plus
-
We're excited to announce the launch of Netgate Nexus, our new multi-instance management solution for pfSense Plus that enables you to securely manage hundreds of pfSense Plus instances through a single unified interface.
Key Features:
- Streamlined multi-instance management
- Comprehensive REST API for total automation
- Highly secure zero trust VPN architecture
Netgate Nexus comes bundled with pfSense Plus 25.11 and later versions. Licenses and entitlements are available on the Netgate store. Production license entitlements are sold on a per-managed device basis.
What specific use cases are you most interested in? We'd love to hear your feedback and answer any questions about this new solution.
Buy Now: https://shop.netgate.com/products/nexus-mim
Learn more: https://www.netgate.com/nexus
-
P pfGeorge pinned this topic on
-
@pfGeorge I’m really excited about this path forward, but right now - as far as I can see - the product is really only for developer heavy organisations as it does nothing other than open for API based automation. Yes, you can also individually manage each instance in the Nexus UI, but as far as I can tell, there is no UI “multimanagement” where simpler installations can automatically manage settings across all - or subsets of - instances like fx:
1: Establish a HUB/spoke or full mesh routed VTI Ipsec or wireguard infrastructure automatically.
2: Publish/Maintain common Aliases across all instances
3: Publish/maintain common Firewall rules across instances
4: Publish/Maintain common settings like installed packages, Advanced settings, certificates, service settings and so on.I’m sure some options will surface later on as third party maintained addons, but I was kind hoping some of it would be Nexus native so One could always rely on it from netgate at upgrade time :-)
-
@keyser said in Announcing Netgate Nexus: Multi-Instance Management for pfSense Plus:
Publish/Maintain common Aliases across all instances
3: Publish/maintain common Firewall rules across instancesI agree with items 2 and 3 in your list. Would be nice to have central aliases and rules to be able to use on our instances.
-
Nice work, please add fine‑grained RBAC to Netgate Nexus. We need a way to allow operators to manage all registered pfSense instances (view instances, use remote GUI/console) without giving them access to any Nexus controller settings or menus. A separation of “Instance Management” and “Controller Administration” privileges would enable proper role separation and significantly improve security in multi‑team environments.