TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

OPNsense - Open source FreeBSD based firewall and routing platform

3 pointsby fcambusover 10 years ago

4 comments

mariosover 10 years ago
Most of the features described come from the fact that FreeBSD ships with OpenBSD&#x27;s PF (among others). Why would you build it pick FreeBSD considering their PF version is <i>very</i> outdated ?<p>I think going with an OpenBSD base would make more sense for a &#x27;routing platform&#x27; as OpenBSD ships with various routing daemons and other network daemons that fit the description better (isakmpd&#x2F;iked for IPsec with IKE&#x2F;IKEv2, npppd for L2TP based tunnels ...). Obviously, you can install and use OpenVPN, pretty much any DNS implementation of your choosing to provide additional features. You also get a bunch of security features to mitigate attacks.[1] Most of them are enabled by default too, contrary to FreeBSD [2](though I have not checked if OPNsense enables them -- it makes sense to enable them, even more so on the network gateway)<p>AFAIK, FreeBSD has better MP support than OpenBSD (though that is a work in progress), and more actively developed wireless stack. Are there any other motivations for using FreeBSD ?<p>[1] <a href="http://www.openbsd.org/papers/ru13-deraadt/" rel="nofollow">http:&#x2F;&#x2F;www.openbsd.org&#x2F;papers&#x2F;ru13-deraadt&#x2F;</a><p>[2] <a href="http://networkfilter.blogspot.fr/2014/12/security-openbsd-vs-freebsd.html" rel="nofollow">http:&#x2F;&#x2F;networkfilter.blogspot.fr&#x2F;2014&#x2F;12&#x2F;security-openbsd-vs...</a>
评论 #8828671 未加载
feldover 10 years ago
They&#x27;ve beaten pfSense to a release on FreeBSD 10, have modernized the web interface (still PHP though), and will hopefully work on tightening up security while simultaneously cooperating better with their upstream BSDs.<p>I wish them the best.
评论 #8835391 未加载
feldover 10 years ago
test? last post didn&#x27;t work
feldover 10 years ago
test comment