pFSense vs Unifi gateway / firewall
-
I know this is a over saturated topic and I'm not here to start a "battle of the bands" disscussion becasue it's mute. pFSense is superior in so many ways. However what I would like to ask / say really is I found an articles where so many people are moving away from pFSense to unifi since the release of theire latest software release. The reviews are very positive and the promise of true security and ease of use. The hardware under the hood is lack luster, but, people dont seem to care since the specs are not advertised. However that does not stop the migration away form pFSense. Serious professionals are now migrating their environments to UniFi and recommending their customers to do the same. The reason, Simplicity and unification. One software to manage it all in a simplified way. No complicated configurations that require NASA level expertise. I get it and Netgate does not really compete in this space and neither do they want to. But, what I have read is UniFi is not as robust as pFSense and its audience are generally looking for a simple approach to network security.
So..that being said here is my question. Will Netgate ever consider a redesign of its web interface for pFSense? Keep the customization but make it easier to configure? I am not an expert so I do struggle at times with configuration. I am not even sure my instance of PFsense is configured correctly, but it does works and I tinker when things dont. I love the software for its security and highly configurability, but wish it was easier to manage. I wish Netgate provided better hardware. I also wish Netgate provided videos to demonstrate rule creation, log analysis, surricata configuration and a few more. Examples of rule sets or configuration and how it should work in practice would be very helpful rather than just describing what the configuration is. And yes I have RTFM. (read the %$#$!@*manual)
Unifi is compelling and I'm considering the switch because of all the hype, but not sure I want to trade the comfort of security for a pretty interface, which is all it is really. So your thoughts? Be gentle.
-
@zaphanathpaneah
moot*You may get biased answers here... :)
Unifi adds wireless. etc. management but needs a controller. We’ve set up Unifi but just for wireless. As I recall it doesn’t have a lot of custom configuration, add ons, etc.
AFAIK Netgate still has their “hangout” videos online, that may be what you’re looking for. Or https://docs.netgate.com/pfsense/en/latest/recipes/index.html ?
I worked on a new client’s Sonicwall the other day and found it doesn’t have host overrides. I could have solved an issue in like 10 seconds on pfSense.
-
Based on limited knoweledge of the Unifi firewall I am not impressed. The new version is said to be easier to use. Tom from Lawrence Systems did move to Unifi, although I am not sure if it is his home or business. Pfsense has come a long way from humble beginnings. While configuration can sometimes be complex it is very stable, and secure when correctly configured. Pfsense has passed the test of time continually proving it is a solid product.
-
@SteveITS said in pFSense vs Unifi gateway / firewall:
You may get biased answers here... :)
I would nominate this for the understatement of the week ;) hehehe
Last time I played with unifi for firewall was back when the usgp3 was a thing, had one for awhile - and my son was using it for a while (loaned him mine).. Which I admin remotely for him. Since I was only using it as a temp stop gap while waiting for my 4860. Was not impressed and could not get back pfsense fast enough - but was running pfsense as vm back then and when updated my internet speed the vm could not keep up. And the usgp3 couldn't really either unless turned off their ids/ips stuff.
I been using their APs forever, and the controller software has come a long way for sure - but I hate how they keep moving stuff. One version you do something in the gui here, then then they move it - and can't find it, etc.
I have a couple of their switches (flex mini) that I use for where I need a few more switch ports, in my guestroom, in the av cab, etc. They are teeny tiny, and they do switch ;)
But as my firewall/router - I don't think I would move to unifi.. I get the appeal of one pane of glass sort of thing.. But I will stick with pfsense and my cisco for my firewall/router and main switches. But yeah unifi has my vote for APs and misc switches. Not really a fan of their higher end switches - but do like the really small footprint of their mini switches. And the price point for those is good. And you can manage them easy enough for vlans, etc.
-
@johnpoz Yeah...thats kind of what I think. I have TP-Link APs because they were rated faster than UniFi and could had better range. However for the $$ theire mini switches are truly compelling. I do need a 10GB switch but my 4100 does not support 10GB so I need to look for a 6100 or 8200 on eBay. I need stability and that is something I am not sure UniFi has just yet. So this is my delimer. Do I continue to invest in pFsense or invest in UniFi echo system? I love the trouble shooting tools that comes with pFSense and I heard Unifi does not have them. So I would prefer to stay with pFSense. Also this forum in invaluable and a great help when I get stuck sometimes.
Thanks guys, Cheers. Oh...& BTW...I think I will get a Unifi AP and switch but keep pFSense.
-
Another person here using pfSense for firewall/router and UniFi just for wireless APs. I follow the community.ui.com forums, and there are lots of complaints all the time there about routing and network issues. But their wifi gear is pretty solid.
-
@johnpoz I would nominate this for the understatement of the week ;) hehehe
I second that comment!
This thread got me remembering the past and I was just wondering if Chris Buechler was still with Ubiquity and did a quick search.. appears not. Found this on the googley..
"Alta Labs is proud to announce Chris Buechler, Industry Legend and pfSense Co-Founder, has joined our team as Principal Architect. He will be primarily focused on the new Router and Switching product offerings we are developing."
Glad he is doing well.
-
@zaphanathpaneah said in pFSense vs Unifi gateway / firewall:
TP-Link APs because they were rated faster than UniFi
The omada line? Those are pretty much copies of unifi are they not? Sure was last time I looked at their controller. But yeah I think they come in cheaper - what I can tell you is recently updated my aging ac models to U7 lites - and for $99 they have been working great.. Pretty happy with their performance at that price point.
I don't really have a use case for 6ghz, and sure don't need 10ge for my APs - but having the 2.5ge as upgrade path was nice.. Not currently using it.. But at 99 bucks hey all for the ability to move to 2.5ge at some point.
They for sure are knocking the price point under 100 by not including the injector.. But lots of people have poe switches these days anyway. I ended up picking up the 2.5ge capable injectors for 20 bucks each for the 2 I got. I prob could of just kept using the one injector for the pro because it was normal poe. But the other 2 I had a lr and lite were passive models. And hey the injector was 10+ years old as well.
What tplink/omada AP(s) do you have? When I was toying with updating my old APs a while back I was looking at omada. But for what I was looking at - there was no reason to spend the money since really didn't have any need above the wifi 5 (ac) my mine could do.. But recently got new phones with wifi 7, and been reading some threads about the old models giving up the ghost.. And I was shit mine are 10+ years old. And to replace mine with new U7 lites it was only a couple hundred bucks - I went with 2 vs 3.. Since I had hard wired stuff I had in the guestroom - so an AP in that part of the house wasn't doing much anyway.
It gave me a new toy to play with - and the new ones can do 192 bit wpa3 enterprise.. No reason to run it - but I did it anyway ;) since now my new APs could do it. What is funny is using wpa3 enterprise without the 192 bit I couldn't get my phone to connect at wifi 7, it would if just wpa3 psk - but with enterprise only wifi 6. Until I enabled the 192 bit, changed out my certs to be of proper 192 bit strength.
I also recently picked up a UTR, man is the thing tiny.. I had no real use for it since I have gl.inet travel router.. But was like what the hell lets see what all the commotion is about. No use for its transport mode or even its wireguard - but its so tiny ;) It's performance is underwhelming - but was easy enough to setup, and it works from my testing. I will give it a go on a trip I have coming up in a few weeks.. But nice little bit of kit to throw into my bag.
I was also looking at their sfp wizard - and was almost going to pull the trigger.. Not so much to use their sfps or anything in equipment that locks sfps down. I was more interested in being able to pop a sfp in an get all the info about the sfp.. But it doesn't really seem to do that - just sort of copy paste firmware. I was hoping I could pop in a sfp and see on my phone the details - make, model number, etc.. My eyes are not as good as they were, and reading the small print on an sfp a pita.. But new phone with the macro camera is working great for that ;) If they add that feature in the future I might rethink.
Other thing that has been nice with updates lately - they are moving to their OS server for their software, and they finally made it drop dead simple to use your own cert for the interface. And the APs finally got an update to drop bear so the ssh is more up to date - even do pq (post quantum) key exchange.
One thing I wish they would add, maybe the omada/tplink does this? Is tell you what encryption a client uses, be it wpa2 or 3? I can see it on my phone if I install the developers diagnostic wifi profile. But would be nice to easy see if client used wpa 3 or 2 when you use the compatibility mode.. I mean I doubt my iot is going to ever support it.. But would be nice info to see on the controller.
-
One thing I look at and I like about pfSense is the infrequency of patches and upgrades. Software that does not need to be patched often if a good sign of quality control. While the way Netgate announces new releases needs an upgrade, the fact they are frequently late on releases is a sign they do real testing and real bug fixes.
Not being a follower of Unifi firewalls, patching required should be a high value point of comparison. Which one needs to patch more often?
A random person on the internet saying one is better than another may give you something to look at, but should be a low value comparison point.
As others have said, Unifi APs are good and I use them as well. -
@AndyRH to add to that - I have not run across a buglist or roadmap of any sort for unifi - not saying their isn't one but I follow the releases pretty closely, mainly for my APs - but since the controller is the same for both APs and their firewall/routers you see all the changes and reports when a new version is released..
I have never noticed any sort of listing of these issues, like redmine or anything.. Where you can see when something is reported or requested as feature when it is targeted for fix/release.
But I do notice a lot of posts about - yeah that was nice you added X or fixed Y.. But what about Z that has been asked for since version A, etc.
-
@AndyRH said in pFSense vs Unifi gateway / firewall:
Not being a follower of Unifi firewalls, patching required should be a high value point of comparison. Which one needs to patch more often?
Yeah, software churn is really UniFi's weakest point right now. They put out new versions often (every month or two) and they are constantly redesigning the GUI. I don't love that about them. It doesn't affect wifi-only installations so much, but if you have a complicated firewall setup you can expect periodic headaches along the line of "where did they move feature X to?" or "how am I supposed to do X now?". Of course, you don't have to accept every update right away ... but the more of them you skip, the more headaches you'll accumulate to be dealt with at once.
-
@tgl and even when they add a feature - like this new digital twin thing.. They are not clear on the requirements to use a feature.. I see where I can add generic stuff.. But doesn't seem to work how others with unifi routers are showing their screens, etc.
My current pet peeve is now that they moved to this OS Server thing - their stuff is getting some love on updates, 5.0.16, etc.. and 5.1 even but since I have OS Server just installed on a vm, seem to be stuck on 5.0.6..
Same thing when they added their wifi doctor, wasn't visible until I updated my APs to U7 line, etc.
And don't get me started how they said you need to move to OS Server because we not going to provide the network application on its own any more, then guess what they did and they are still are - but I can not seem to get to be able to use the update they list for the controller software that runs on OS Server to just update that portion.. Have to wait til the OS server sees the update for the network application to be able to update it..
Yeah there is no way I would move my whole network to them.. APs ok - don't really need any of the fancy stuff they love to play with like digital twin.. Just need to set the psk on the ssid and a vlan id for it ;)
-
@johnpoz My AP is blazing fast, especially if im standing right below it. (ceiling mounted). I had to get an injector as I did not have a POE switch. The thing is I like my network rack quiet and any tp link switch with POE currently has a loud fan attached which is anoying. I got a TP Link OMADA switch off ebay and thought i could swap the fan for a quiet one but the switch complained alot with beeps as it detected there was no fan installed even though there was. the electronics is designed to look for a specific fan.
I have a 2.5gb managed fanless switch and its great but editing videos or transfering large files is slow at times. So I need to get a 10gb switch which ill get from Unifi. TP Link switches are very $$$ and they are noisy. they are big andloud. I need SFP+ & 10gb rj45 on my router but my 4100 does not have it. i could go to a 4200, 6100 or 8200, or 8300 but they dont have 10gb rj45 either. So SFP+ will have to work.
-
@zaphanathpaneah said in pFSense vs Unifi gateway / firewall:
10gb rj45 either
Why would you not just use a fiber connection for 10ge? Pretty much any copper 10ge more than likely has a fan if it has more than a few ports - they run hot..
Normally you would uplink from your switch to your router with fiber. Sure something that has 10ge copper you could use into your switch..
Blazing fast doesn't tell me anything btw - what is the model number? Mine are blazing fast too - no where near it ;) blazing fast really isn't a technical term heheheh
I have a 2.5gb managed fanless switch and its great but editing videos or transfering large files is slow at times.
2.5ge is capable of about 280MBps - can your disks do more than that.. I use 5ge between my nas and pc and I see 400MBps - it can not sustain that forever, it burns through the cache, and then drops down to what the disks can do which are about 250MBps.. But when only moving a few GB file see 400..
Unless your using nvme on both source and destination - 10ge isn't going to be the upgrade you think its going to be.. Sure I would run 10ge too if wasn't cost prohibitive, but then I would have to spend money to be able to have the space I need all in ssd vs hdd, etc. etc. It can turn into a never ending cycle
-
@johnpoz All good points. I have NVMEs on one side but not both. So the speed will be limited to the cache size and HDD speeds. What I do is save to an local HDD and transfer between. I am working with hundreds of gigabytes of data so every second counts.
As for my TP Link APs, I'm using an older EAP and I'm currently getting close to 700mbps, which is not super great considering I have 1gb service from my carrier. However this is more than adequate for my smart tvs and kids online schools. I had 2.5gb service at first thinking it would increase bandwidth and I would see great speeds, but the bottle neck was always in my environment.
Cheers
-
@zaphanathpaneah if all you move the data between is your pc and your nas - you don't need to uplift the whole network for that. My network is only 1ge, but my pc and nas have a 5ge between them as SAN (storage area network) if you will.
My pc has its 1ge connection in the network via 192.168.9.0/24 and so does the nas. But there is a 192.168.10/24 network between the pc and nas - no gateways set no dns..
When I want copy files between my pc and nas I use the 192.168.10.x address.

That was a 2.5GB file - almost hard to catch the copy in a picture ;)
Got a 5ge nic for pc, few bucks.. And a 5ge usb nic for the nas, since can not install any actual network card in the nas.. This slows it down a bit, and only can do like 3.5gbps between.
$ iperf3.exe -c 192.168.10.10 Connecting to host 192.168.10.10, port 5201 [ 5] local 192.168.10.9 port 38204 connected to 192.168.10.10 port 5201 [ ID] Interval Transfer Bitrate [ 5] 0.00-1.01 sec 432 MBytes 3.57 Gbits/sec [ 5] 1.01-2.01 sec 416 MBytes 3.51 Gbits/sec [ 5] 2.01-3.01 sec 422 MBytes 3.53 Gbits/sec [ 5] 3.01-4.01 sec 423 MBytes 3.53 Gbits/sec [ 5] 4.01-5.01 sec 421 MBytes 3.52 Gbits/sec [ 5] 5.01-6.01 sec 420 MBytes 3.54 Gbits/sec [ 5] 6.01-7.00 sec 420 MBytes 3.54 Gbits/sec [ 5] 7.00-8.00 sec 416 MBytes 3.50 Gbits/sec [ 5] 8.00-9.01 sec 391 MBytes 3.26 Gbits/sec [ 5] 9.01-10.02 sec 422 MBytes 3.52 Gbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ ID] Interval Transfer Bitrate [ 5] 0.00-10.02 sec 4.08 GBytes 3.50 Gbits/sec sender [ 5] 0.00-10.02 sec 4.08 GBytes 3.50 Gbits/sec receiver iperf Done.Doing this would cost you a fraction of the $, and could use either fiber or copper this way.. Where is your nas in relation to your pc?
I would see prob a good 1gpbs more if was limited by the usb in the nas.
I move quite a bit of video between my nas and pc - for my plex server. Some days 100s of GB for sure. So I get where you are coming from.
-
@johnpoz Ahh.....brilliant!!! this is actually what I need. I have two NAS one for the family, a 2 bay Synology with 10gb and and home server with trunas running that has 16gb with more on the way. it has both 2.5gb and 10gb rj45 nics. I can run a connection between my pc and the nas itself and that would give me the bandwidth I need. thanks for the tip. The entire home does not need 10gb, just me so this is brilliant. I will be installing jellyfin soon so this will will come in handy also for transfering Blueray rips. I just need a cheap 10gb nic for my pc.
-
@zaphanathpaneah yeah it can be an easy solution if your pc and nas are in areas where you can run a new wire for the higher speed connection. If they are separate and you only have the 1 current network wire it can become a bit more difficult.
My pc sits right next to my rack where the nas.. So its a few feet of wire.

Normally not a fan of jumbo - but since this an isolated network with just the pc and nas on it, upping the mtu to jumbo got be about 20MBps more..
Let us know how it turns out - and what kind of speeds you can get on transfers.
My next nas will for sure be able to do 10ge, I don't have the disks to be able to actually saturate that.. Especially for really large transfers.. but normally if transfer a few GB at a time in a file or 2.. Not 100GB at once sort of thing - so pretty much most transfers are from my pc nvme drive to nas rust drive - but the cache on the nas works as a great buffer.. Bumping its ram from 8GB to 16 made for a drastic improvement with file copies..

I was thinking if I could use the nvme in the nas as sort of tiered storage where I transfer to there, and in the background it moves it to the rust drives I could get higher sustained transfers for more data.. But have not been able to work out a good way of doing it since synology doesn't actually support any sort of tiered storage.. But this works pretty good.. And not having to watch paint dry as a move a 4-5GB file from pc to nas, etc..
edit: just noticed - did I move 1TB from nas to pc in less than 24 hours? Wow ;) in the process of cleaning up the plex db showing impossible added dates, like 57 years ago sort of thing.. And it was messing up my storage graph..
I'm over the 50% mark on my space, so working out future plans of adding more.. Freaking drives are so crazy expensive currently..

-
I think I can provide some good feedback here, I've moved my entire (rather complex) homelab network between pfSense and Unifi like 5 times at this point. I keep coming back to pfSense, and for good reason.
I actually think there are important differences between the two, and there's also an impact from the low complexity of modern networks for most small businesses and homelabbers.
pfSense is far far far superior as an actual firewall and router, it has many more capabilities with rule flexibility, better default rule sets with no hidden BS rules (aside from ones clearly outline in documentation like IPsec), more custom settings, proper dynamic routing setups, the list goes on.
Where Unifi excels is in fancier features, a better looking (notably, NOT more functional) UI, and raw routing performance value.
As a firewall, Unifi has come a LONG way, but it's also still a LONG way behind higher end offerings like pfSense. What it does do though, is great flow tracking, it's IPS/IDS is far simpler to configure and manage, and it's content control features are better.
It's funny really, in a lot of ways UI has focused on "NGFW" features while having a pretty bad core for routing, VPNs, and firewalling.
To me, it's fun to have all the graphs to show traffic usage, where your traffic is coming from, etc... built into the firewall without the need for something more complex like ntopng or a SIEM with netflow data fed into it. But it's important to recognize those things are FUN, not necessities, and in the business world you'll have a SIEM anyway.
Another factor is VPN performance, Unifi is just terrible in this perspective, despite their routing performance value being so high. If you need fast IPsec you basically can't do it. I mean hell, their gateway that can do 12 gigabit throughput with IPS enabled can barely do half a gigabit for IPsec and just over a gigabit for other VPN protocols. My midrange 6100 can do 3x that.
The big reason I've gone back and forth is actually core routing performance though. My UDMP, a $300 ish device, can route my full 8 gigabit WAN, meanwhile my Netgate 6100, which was nearly $1000, can only push about 3.5 gigabit. But each time I do this swap, it only lasts for a few weeks (I always get the Unifi stuff matching my pfSense environment before making the swap, so it's usually several weeks of setup), then I miss all the stuff I could do with pfSense and importantly the reliability of it.
I guess my final point, in my already way-too-long comment, is that frankly, most businesses don't need more advanced features or high speed VPNs anymore. Many of what we would call small businesses need internet access, ideally with a few VLANs to keep IoT, guest, etc... traffic separate, and that's about it. Unifi makes those things really easy to manage at scale and their base firewalling has gotten good enough to not be a complete shit show now.
-
@planedrop Good summary, thanks. I don't have the sort of direct comparative experience you do, but what you wrote squares with what I've learned from reading the ui.com forums.
Privacy Policy · Cookie Policy