Concerns about Nexus as the future default GUI
-
've been running pfSense Plus on a Netgate 4100 for a while now — currently 26.07-RELEASE — and I've spent a decent amount of time poking at Nexus since it landed. I want to say up front that the performance story is real. It is noticeably faster than the PHP GUI, and I don't think anyone who has waited on a rules page to render is going to argue with rebuilding it in Go.
But Netgate has said the goal is for everyone to be on the new GUI by the end of the year, and from where I'm sitting Nexus still feels alpha. A few things concern me.
Dashboard widgets are a step backwards. The widget set in Nexus is very limited compared to what the PHP dashboard offers today. For a lot of us the dashboard is the first thing we look at every day, and right now moving to Nexus means giving up visibility rather than gaining it.
Packages aren't integrated. pfBlockerNG and Suricata have no Nexus UI. On my box those aren't optional extras — pfBlockerNG feeds the DoH blocklist that my IoT and CAST VLANs depend on, and Suricata sits on WAN. If the migration path means bouncing back to the PHP GUI for the packages that actually enforce policy, then Nexus isn't a replacement yet, it's a second interface to keep track of. I'd like to see a public roadmap for package integration before the PHP GUI starts being deprecated.
ThreatGate has bugs that fail silently. Two I've hit: remote feeds get truncated at 4999 entries with no warning, and refresh_interval doesn't actually trigger scheduled re-downloads, so feeds go stale in place. Both of those produce a UI that says everything is fine while the protection quietly isn't what you configured. For a security feature that's the worst failure mode there is — a loud error is fine, a wrong-but-confident status page is not.
Plus-only means a much smaller testing pool. Nexus isn't in CE, so nobody on CE can evaluate it, and Plus users can't kick the tyres without committing to an upgrade first. That's a big part of why the rough edges are surfacing slowly. It also makes it hard for those of us with fairly involved configs to sanity-check the new GUI against what we already run before we're carried into it.
Config fidelity. My ruleset leans on things like NAT redirect ordering, aliases from pfBlockerNG lists set to Alias Deny, and hand-placed rules that have to sit in a specific position relative to an RFC1918 block. I want confidence that Nexus represents all of that accurately — and that editing rules there won't quietly reorder or reinterpret anything — before it becomes the only way in.
None of this is "don't build Nexus". It's faster and the direction is right. What I'd like to see is a published parity checklist, a package integration timeline, and a firm commitment that the PHP GUI stays available and supported until parity is actually reached — not just through a transition window. Otherwise the practical effect for people running non-trivial configurations is being pushed onto an interface that can't yet express what they've built, and some of us will start looking at what else is out there instead.
Happy to be told I've got any of this wrong, and happy to file specifics on the ThreatGate issues if that's useful.
-
@junos I fully agree, and I would imagine most other users do as well. It really isn’t up to snuff yet - at all.
BUT:
We must remember Nexus can and will be updated out of band in relation to new pfSense+ releases. So it will very likely have a very quick improvement/fix cadence from now on.I have been debating with myself if Netgate should have great lashback for the announcement of the new UI this early in its “capabilities”, or if it’s a good idea because it’s the only way to get us to use it, find flaws, and getting it production ready.
My real gripe is with the bundling of other services “within” nexus, but thats for another thread.
EDIT: But I really miss a coordinated and effective way of reporting issues/problems with the new UI so they can get fixed asap. To much risk that genuine issue posts are missed in these long threads.
-
Privacy Policy · Cookie Policy