Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Concerns about Nexus as the future default GUI

    Scheduled Pinned Locked Moved Netgate Nexus
    3 Posts 3 Posters 241 Views 7 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      junos
      last edited by

      've been running pfSense Plus on a Netgate 4100 for a while now — currently 26.07-RELEASE — and I've spent a decent amount of time poking at Nexus since it landed. I want to say up front that the performance story is real. It is noticeably faster than the PHP GUI, and I don't think anyone who has waited on a rules page to render is going to argue with rebuilding it in Go.

      But Netgate has said the goal is for everyone to be on the new GUI by the end of the year, and from where I'm sitting Nexus still feels alpha. A few things concern me.

      Dashboard widgets are a step backwards. The widget set in Nexus is very limited compared to what the PHP dashboard offers today. For a lot of us the dashboard is the first thing we look at every day, and right now moving to Nexus means giving up visibility rather than gaining it.

      Packages aren't integrated. pfBlockerNG and Suricata have no Nexus UI. On my box those aren't optional extras — pfBlockerNG feeds the DoH blocklist that my IoT and CAST VLANs depend on, and Suricata sits on WAN. If the migration path means bouncing back to the PHP GUI for the packages that actually enforce policy, then Nexus isn't a replacement yet, it's a second interface to keep track of. I'd like to see a public roadmap for package integration before the PHP GUI starts being deprecated.

      ThreatGate has bugs that fail silently. Two I've hit: remote feeds get truncated at 4999 entries with no warning, and refresh_interval doesn't actually trigger scheduled re-downloads, so feeds go stale in place. Both of those produce a UI that says everything is fine while the protection quietly isn't what you configured. For a security feature that's the worst failure mode there is — a loud error is fine, a wrong-but-confident status page is not.

      Plus-only means a much smaller testing pool. Nexus isn't in CE, so nobody on CE can evaluate it, and Plus users can't kick the tyres without committing to an upgrade first. That's a big part of why the rough edges are surfacing slowly. It also makes it hard for those of us with fairly involved configs to sanity-check the new GUI against what we already run before we're carried into it.

      Config fidelity. My ruleset leans on things like NAT redirect ordering, aliases from pfBlockerNG lists set to Alias Deny, and hand-placed rules that have to sit in a specific position relative to an RFC1918 block. I want confidence that Nexus represents all of that accurately — and that editing rules there won't quietly reorder or reinterpret anything — before it becomes the only way in.

      None of this is "don't build Nexus". It's faster and the direction is right. What I'd like to see is a published parity checklist, a package integration timeline, and a firm commitment that the PHP GUI stays available and supported until parity is actually reached — not just through a transition window. Otherwise the practical effect for people running non-trivial configurations is being pushed onto an interface that can't yet express what they've built, and some of us will start looking at what else is out there instead.

      Happy to be told I've got any of this wrong, and happy to file specifics on the ThreatGate issues if that's useful.

      keyserK 1 Reply Last reply Reply Quote 1
      • keyserK Offline
        keyser Rebel Alliance @junos
        last edited by keyser

        @junos I fully agree, and I would imagine most other users do as well. It really isn’t up to snuff yet - at all.
        BUT:
        We must remember Nexus can and will be updated out of band in relation to new pfSense+ releases. So it will very likely have a very quick improvement/fix cadence from now on.

        I have been debating with myself if Netgate should have great lashback for the announcement of the new UI this early in its “capabilities”, or if it’s a good idea because it’s the only way to get us to use it, find flaws, and getting it production ready.

        My real gripe is with the bundling of other services “within” nexus, but thats for another thread.

        EDIT: But I really miss a coordinated and effective way of reporting issues/problems with the new UI so they can get fixed asap. To much risk that genuine issue posts are missed in these long threads.

        Love the no fuss of using the official appliances :-)

        SteveITSS 1 Reply Last reply Reply Quote 0
        • SteveITSS Offline
          SteveITS Rebel Alliance @keyser
          last edited by

          @keyser There’s a Nexus category on redmine

          To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
          Only install packages for your version of pfSense.
          Upvote 👍 helpful posts!

          1 Reply Last reply Reply Quote 1
          • First post
            Last post
          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
          Privacy Policy · Cookie Policy