Тёмный

Firewall Comparison: Ubiquiti EdgeRouter / Ubiquiti UniFi USG / Untangle / pfsense 

Lawrence Systems
Подписаться 340 тыс.
Просмотров 118 тыс.
50% 1

Connecting With Us
---------------------------------------------------
Hire Us For A Project: lawrencesystem...
Tom Twitter 🐦 / tomlawrencetech
Our Web Site www.lawrencesy...
Our Forums forums.lawrenc...
Instagram / lawrencesystems
Facebook / lawrencesystems
GitHub github.com/law...
Discord / discord
Lawrence Systems Shirts and Swag
---------------------------------------------------
►👕 lawrence.video...
AFFILIATES & REFERRAL LINKS
---------------------------------------------------
Amazon Affiliate Store
🛒 www.amazon.com...
UniFi Affiliate Link
🛒 lawrence.video...
All Of Our Affiliates that help us out and can get you discounts!
🛒 lawrencesystem...
Gear we use on Kit
🛒 kit.co/lawrenc...
Use OfferCode LTSERVICES to get 5% off your order at
🛒 lawrence.video...
Digital Ocean Offer Code
🛒 m.do.co/c/85de...
HostiFi UniFi Cloud Hosting Service
🛒 hostifi.net/?v...
Protect you privacy with a VPN from Private Internet Access
🛒 www.privateint...
Patreon
💰 / lawrencesystems
#pfsense #Firewalls

Опубликовано:

 

6 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 165   
@ashuggtube
@ashuggtube 2 года назад
Probably time for another one of these if that’s okay please Tom!
@ifneeded1
@ifneeded1 4 года назад
I discovered your channel about 2 weeks ago, and I can't thank you guys enough for everything that you share. I'm a computer consultant myself, but I love to learn from others all the time. Some of your experiences I've shared, and others were great to learn from. The demos that you do are great too, and are very useful in case I want to try out a product. I can't thank you guys enough, I hope that you continue to feel good about doing these videos and keep putting them out. -Max
@doom2125
@doom2125 4 года назад
Just wanted to give you a huge thanks for all your helpful content! Because of you I was finally able to ditch my horrible, unreliable modem/router that was provided by my isp. I'm now running a pfSense vm in Unraid with a UniFi AC Pro and Motorola MB8600 Modem. Now I'm diving deep into Suricata, ntopng and traffic shaping for my seedbox. What a cool (sometimes frustrating) learning experience this has been. It feels so great to have control over my network. Thank you very much!
@LorenzoFaletra
@LorenzoFaletra 4 года назад
thank you for your contribution to open source projects. it is very appreciated to hear that!
@myongpark
@myongpark 4 года назад
I really like that you fill the gap between Cisco/Palo Alto/Checkpoint and Linksys/Netgear. It’s such a wide world between them, and deserves to be covered.
@minigpracing3068
@minigpracing3068 4 года назад
The only thing I don't like about the Netgate hardware is the price. They are easily twice the price of a Supermicro server of similar performance, and that doesn't even include a year of support. With budgets being what they are right now, I have to build my own server and load PFSense. If the price included a year of support, then it would help justify the purchase.
@dennisdoherty1133
@dennisdoherty1133 4 года назад
I run a security gateway pro for layer 3, then i have another box running in a transparent bridge/vwire depending on the flavor of the month. Right now i'm running untangle on a atom in transparent layer 2 bridge behind the unifi security pro and in front of the switch. I've had pfSense, Palo Alto, etc.. etc.. running in this same configuration. Sort of gives you the best of both worlds.
@reza2251
@reza2251 3 года назад
I setup a dual pfSense router for no fear back in 2006 running on an alix2d3. Use to love that Os. I was doing all the pf work by hand before pfSense! Made sense to switch.
@charlesr.9414
@charlesr.9414 4 года назад
Thanks for being open and honest with your thoughts / comments!
@will16320
@will16320 4 года назад
Lmao "don't ask me to review consumer routers I don't use them" damn straight
@jeffburnett4397
@jeffburnett4397 4 года назад
Hey, Lawrence thanks for all the great videos especially the Pfsense routers. Thanks, Jeff
@miketarbox1190
@miketarbox1190 4 года назад
I ran PFSense for a few years, until the big AES-NI push, which didn't happen. I wasn't ready to upgrade the machine it ran on, so I found Untangle to be more to my liking. Sure, it cost me $50 a year, but I'm on year 2, and I thoroughly enjoy their product. I have the traffic separated into about 5 vlans, each with their own specific rules and policies. So I was really happy when you decided to review Untangle, and were good with it.
@aalvarez711
@aalvarez711 4 года назад
Waiting for that MikroTik review ;)
@alexwebster5311
@alexwebster5311 4 года назад
I hope he gives it an honest go. Frankly, I went away from pfsense to mikrotik for a couple of reasons. The QoS controls in Mikrotik are phenominal (Simple queues just work). They also auto update nicely with scripts so they stay current. MT releases updates very quickly and I have never had an update go bad. Tom, if you are reading this, please contact me if you have any questions on Mikrotik during a possible review. There is a lot of bad publicity out there, but it is mainly due to people leaving the admin access open to the internet...
@sitte24
@sitte24 4 года назад
Tom does not like the interface of mikrotik devices and as he also does not really have customers using them, he will not do a video about it because he does videos mainly "on the fly" if he has to do with that topic for some clients or so
@travistibbs1530
@travistibbs1530 4 года назад
I switched from Mikrotik to pfSense a couple of months ago bc while RouterBoard is an awesome router for the price, the interface *is* rough. But what turned me from fan to refugee was the discovery that I had left a gaping hole in my ACLs for over a year. While this is my fault, my experience with pfSense told me that this is much less likely to happen with decent organization of firewall rules and built in default deny rules. I’ve struggled with RouterBoard’s ACLs at several venues and will gladly go with pfSense, instead, from now on. Having well-packaged IDS/IPS was a pleasant sundae on my sundae. ;)
@karlbooklover
@karlbooklover 4 года назад
sameeeee
@Shane-Singleton
@Shane-Singleton 4 года назад
Not sure i'm ready to go with a MikroTik edge router. But their switches?? Oh yes..
@markchambers7147
@markchambers7147 4 года назад
I ha e the free sophos box in a small school for the web filtering and just to make sure no one hits porn ... works so well for me
@blackphidora
@blackphidora 4 года назад
Hello Lawrence, I don't have much time before I hit the road and listen to your video but decided to give a +1 to recommending taking a look at Vyos, I see other commenters have mentioned it but it is very similar to the EdgeOS cli. Ive been using Vyos in my Homelab and home network for about 2 years without any issues. they are running Wireguard and are doing NATS, Firewalling, and OSPF networking in both a protectli like device and a VM. Cheers!
@TK_Raz
@TK_Raz 3 года назад
imo Sophos should win hands down. It's by far the most feature packed, very very simple to use and manage, was rated in #1 cyber security (multiple times) and has true TLS/SSL DPI decryption.
@thevidco
@thevidco 4 года назад
Nice work, I would add that the ubiquiti usg is based on vyatta and can be configured for OpenVPN, IPSec, l2tp, all using the identical config commands as the vyatta. The config code can be added to the central configuration on the controller... the graphical interface is limited and disappointing when looking at all the functions and capabilities if this device ... adding extra interfaces is possible but again - cli same as vyatta ... Fully agree that pfsense is the easier to use solution .. .. however the central management of client environment I see as a major advantage .. thanks for the video .. factual and well presented .. I am not associated with any of the companies being commented on ..
@cwolf3116
@cwolf3116 4 года назад
The Sophos SG series was pretty good, but after a couple of years, issues with web filtering was a big problem. I will say, the SG gui was very good and the reports and config dumps were fantastic. Now, with either the Sophos SG or XG series, they tend to max out the CPU and make the system unusable. I have an old Sophos SG box that I installed the XG on, and it kept maxing out the CPU. So, I installed Untangle on it, and it is working great!
@jlficken
@jlficken 4 года назад
I still prefer Untagle over pfSense especially for home use as it is really simple to use.
@thomascasey8171
@thomascasey8171 4 года назад
VyOS is command line very similar to in feel to Junos. Works great and have it running on a protectli J1800.
@UpcraftConsulting
@UpcraftConsulting 4 года назад
I'm going to shout out to Watchguard for one specific use case I have all the time. High availability with DHCP or PPPoE provided ISP circuits. Watchguard is the only device I have run that supports this configuration. There may be others, but I suspect they are all in the same ballpark for pricing and closed source so I'm sticking with what I know. It's a great feature.
@ACGNY08
@ACGNY08 4 года назад
I like untangle because of the Dashboard and Support. Having support included when something hits the fan is pretty nice.
@jamesrockford5145
@jamesrockford5145 4 года назад
I called untangle today, there firewall was $329 and $50 for their software and if I wanted support $278 per year. NO free support, also no virus protection.
@ACGNY08
@ACGNY08 4 года назад
@@jamesrockford5145 They are doing away with the Home Licenses or Home License support (I forget what they said). I don't know much about the home license to be honest. I do know that you can download and install it and use the free version though it's limited it does work well. If you are just looking for a firewall for home use, things like PFSense and OPNSense would work well for you. They are free and have community based forum support.
@questionablecommands9423
@questionablecommands9423 4 года назад
Every time I install Untangle, I love it. Aside from pfsense and OPNsense, it's the only downloadable solution that I've found that supports NIC bonding from the UI, and they make it easier than anybody else. Then I promptly feel betrayed by needing to pay for running a caching DNS locally. I know, they also need to eat, but combine the facts that its so fundamental to a decent LAN with the fact that I'm willing to overlook a lack of local hostname resolution, and I feel like they fundamentally don't understand the home market.
@Zomby_Woof
@Zomby_Woof 4 года назад
The sophos hardware is great - for running pfsense. Sophos is barely closed source. Its an assortment of open-source modules in a gui that's pretty, but limited. Sophos has poor interop documentation. I finally did get a VPN tunnel working sophos-cisco, but it was a huge pain compared to pfsense. For whatever reason, the performance was abysmal once you started doing ips. Between performance, nerfed features, and them releasing a hideous fw version, I pulled the plug on that project and did not renew. Fortunately, my purchase was with a one year sub. Went with some short depth used servers, loaded pfsense, and never looked back. After the sophos boxes were no longer used, I figured out how to load pfsense on them. I have those powering a couple of smb installations. Once free of sophos licensing, I was able to swap cpu on the larger units, and upgrade ram on all of them. Even stock, the sg-115 is able to power a 200/20 connection with suricata without breaking a sweat
@onlyzach1
@onlyzach1 3 года назад
Great video! After doing some research on what I want, I think pfsense might be the way for me to go. Just scares the crap out of me (coming from a gen 1 eero router), if I ever do upgrade my network.
@canadianwildlifeservice8883
If you can put up with the registration process that Sophos makes you go through, it is a great product. You get pretty much every feature a home user could want for free and a polished GUI and it is relatively easy to configure. I haven't tried pfSense but I did briefly use Untangle but ever since since they put their premium version of NG home firewall behind a paywall I went with Sophos instead which offers most of the features of Untangle, for free, minus the Wireguard VPN. Honestly- sometimes I'd rather go with an Untangle appliance that has WiFi, but you can't argue with free and vote with your wallet.
@canadianwildlifeservice8883
sorry, I wanted to add to this without the post being too long. As a user of Sophos for the past 6 years I can say with ease that they take good care to release patch updates whenever there is an issue. After a month or two (after publishing the update for manual download on their site) it will be pushed to all users. Another reviewer said that security patches for pfSense take ages to be released. Not sure how true this is.
@stevewoodruff5872
@stevewoodruff5872 4 года назад
Thanks for all the great videos
@genns1679
@genns1679 4 года назад
A few years ago when I was just getting started I bought a couple of ap acl and a mikrotik router. I basically had to take the mtcna to learn how the heck to configure the darn thing. Once I learned and got everything right, it's been over 5 years with no issues. I've deployed over 20 of them to friends and a couple of of small businesses. No problems. I'm not saying they are better than pf sense. They are just different.
@mikesyr
@mikesyr 4 года назад
At home I use OpnSense, for home use I prefer it over pFsense due to Netgate being a bit slow to give hardware support to third party devices as opposed to their own solutions. That being said, if I were to roll it out as an IT professional and/or as an MSP, I'd probably just buy the Netgate devices.
@GameGeek128
@GameGeek128 4 года назад
I am interested to see your Take on WatchGuard newer gen firewalls
@_bodgie
@_bodgie 4 года назад
The USG is a pretty ordinary firewall IMHO. Limited DPI functionality and IPS seems pretty ordinary too from my limited testing. It's even difficult to understand how to configure the security rules.
@DaveIsbell
@DaveIsbell 4 года назад
spot on as usual. thanks
@LIVETANKREN
@LIVETANKREN 4 года назад
pfsense+UAP AC PRO=great combination
@NetITGeeks
@NetITGeeks 4 года назад
I have been using dd-wrt on my home Linksys router and now I am looking into running PFsene. I just need to find the most stable, power-efficient and cheap hardware I can find. I have an HP G7 server and I am not sure how stable PFsense going to be on a VM within the windows server.
@ramosel
@ramosel 4 года назад
I've run it VM and had a just few minor problems... really, your quest for cheap hardware is going to be good way to start out with pfSense and once you get proficient you can always try to move to a VM instance. It makes it easy to pop back and forth as you iron out initial configurations. Just be sure whatever hardware you choose supports AES-NI as the (ever) forthcoming ver. 2.5 is going to require it. I'd also shy away from Realtec NICs. pfSense really likes Intel NICs I run a SG-4860 just because I wanted something really low power consumption as I'm working towards "off grid" power. But I still run a hand full of DD-WRT boxes as APs and have one for client-bridge to my phone when my ISP goes down.
@theeclectic6015
@theeclectic6015 4 года назад
It needs to be pointedd out that while Ubiquit's security gateways are a bit behind, but they have made great strides in the last year.
@tomRX4878
@tomRX4878 4 года назад
Problem is that you don't find a could reseller for Netgate boxes in Europe. Especially in Austria.
@viecus
@viecus 4 года назад
I'm a fan of the Sophos XG's. Manage around 15 of them across different networks. Plugs into the rest of the Sophos ecosystem pretty well and the RED devices are pretty cool for small remote offices. Their biggest problem is logs.... The logging is shithouse. Apparently it's on the roadmap, but they're not the quickest when it comes to introducing features... Apart from that, I think they're great for a relatively cheap enterprise firewall.
@drreality1
@drreality1 4 года назад
I know that router os is not open source, but man is very powerful. Have you considered it?
@jasonflint88
@jasonflint88 4 года назад
drreality1 If you are talking about Sophos XG Home Edition, I think he really should test it out. It’s really is a powerful device and keeps my kids off of undesired sites without the need for me to point my AD Servers to the device for DNS Blackhole. I really like it and it is what I’m using for all of my clients as well (Subscription).
@rdsmith24
@rdsmith24 4 года назад
Why don't you review the Ubiquity Dream Machine?
@LordHog
@LordHog 4 года назад
Can you confirm a statement that I read. I read on a Amazon comment that vanilla pfSense can't be installed on Netgate boxes (e.g., SG3100). Thus one needs to load/install the version of pfSense controlled by Netgate??? Here are the Caveats listed by the commentator. Caveats: * The software is proprietary to Netgate. It will not run public distro of pfSense. You will need to contact support if you need a reinstall image. * The embedded eMMC flash is slow! If you are doing anything disk intensive plan to buy a M.2 SSD. If you are only using it as a basic firewall with no packages, eMMC is fine. Note: Installation of an SSD requires reinstall. * Only 2 GB RAM - only matters with certain packages. * Snort users: don't expect to get 1Gb/s throughput. Something more like 300 - 500 Mb/s is probably the limit. * Runs warm but Netgate says it's normal.
@GabrielLamounier-REZLAM
@GabrielLamounier-REZLAM 2 года назад
As my wife and I both work from home, I've contracted two ISPs, in order to account for outages. The problem is, now I've got two separate networks and one of them is always idle. I'd like to use a router to aggregate these two Internet connections. What router do you recommend?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 года назад
Only an SDWAN solution can bond/aggregate the connection together. With pfsense you can use policy routing to send some traffic out of each connection.
@jakekirby6438
@jakekirby6438 4 года назад
That Sophos box looks like the SG105 or SG115. I have actually installed pfSense on these and they work great. The later rev hardware can handle 6-8GB or RAM. Can't update the CPU though. You have to disable the "Port 60/64 Emulation" setting in BIOS, but then you can install pfSense!
@Daniel-ud6od
@Daniel-ud6od 4 года назад
Looks like a XG85, i did try pfsense on it also, but allways hangs after like 2 weeks
@xrekonx
@xrekonx 4 года назад
I started out with m0n0wall back in 2008, moved to pfSense a few years later. Never looked back for anything else for clients when I worked in a small MSP. Now I am stuck with CheckPoint :( $40,000 pile of @$%^
@TomBabula
@TomBabula 4 года назад
Moved from google WiFi to ER-X running vlans and custom firewall rules.
@mike.monkhouse
@mike.monkhouse 4 года назад
Will you be doing a review of the dream machine soon?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 года назад
if someone sends me one
@alexneustadter4498
@alexneustadter4498 4 года назад
Yah, I'm interested to what UI is gonna do with the software on the UDM and the other version still in EA, hopefully they add a bit more of the advanced stuff to it than what the usg had
@Bigsease30
@Bigsease30 4 года назад
Hello Tom. Thanks for all of your videos. Once I start on one, I usually get drawn down the rabbit hole to your others. Question: where did you get the Netgate rack mount enclosure?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 года назад
The link is in the video descrption
@namitkasliwal4438
@namitkasliwal4438 3 года назад
That was a lot of informative Video. I want to know if there is any Open Hardware available to install PFSense, which is not that costly as that of netgate hardware. If yes, do share the details
@Martin-ot7xj
@Martin-ot7xj 4 года назад
Hi there, it was one of your best tutorial video. Thnx
@sherifsafwats
@sherifsafwats 4 года назад
PFsense can filter (ssl -https) traffic also without installing certificate on client machines, using squid proxy , I used it for 2 years now and its working fine
@Ebrithil95
@Ebrithil95 4 года назад
Personally i really like VyOS. Once you figured out the CLI its by far faster to change configs then having to navigate through some 3 submenus on a web gui imho. Also i really like the commit/save style of changing configs. Not sure if PFSense supports that?
@AP-qc9hi
@AP-qc9hi 4 года назад
In these router/firewall comparisons, why do we hardly see mikrotik? I moved 4 sites from usg and usg pro to mikrotik and I could never go back. Mikrotik routers combined with unifi switches and ap is now my killer combination.
@JohanBernhardsson
@JohanBernhardsson 4 года назад
The USG and the edge do the same things. They have the same base in software. Yes you are limited in configuring the USG through the ui. But you can do loads with the json config file on the controller
@babakbanijamali5130
@babakbanijamali5130 4 года назад
Thank you for this. I was evaluating some routers/firewalls for use with our small office environment. We had narrowed down to EdgeRouter (now i know it's command line) and Ubiquity (but we need Wan2 for internet failover.. not an option apparently due to having to use an unsupported script).. so looks like we're back to pfsense. Any thoughts of building our own vs. getting netgate hardware with software built in?
@ClarkdeLeon
@ClarkdeLeon 4 года назад
Fortigate blames everything on you if there stuff don’t work. Even on hosted VOip issues. Does pFsense has a UMS?
@1988marksie
@1988marksie 4 года назад
Another issue with the usg is it takes forever to provision new configure, and can also cause outages when applying firewall rules, I bought one and now regret it... should have gone dual pfsense
@CarloRigoni
@CarloRigoni 3 года назад
What about centralized management solution for pfSense installed in different places?
@Nevexo287
@Nevexo287 4 года назад
Such a shame that multi-address is such as basic feature of Vyatta, but UBNT just can't be arsed to add it to the UniFi provisioning thing.
@reza2251
@reza2251 3 года назад
How is the programmability on these pfSense boxes now a days? Doing a bunch of ansible work with junos and it’s a dream
@edwardgreenjr167
@edwardgreenjr167 4 года назад
So if a build was primarily unifi- based, and would like that interface/management the USG provides, couldn't you have a pfSense box as the first point of entry on the network, with a USG behind it to give the best of both options? I apologize if that was asked before, or if it's just a general noob question. But other than cost, that would seem to solve the issue of keeping that interface for local management, and the pfSense box for the added features.
@1988marksie
@1988marksie 4 года назад
Edward Green, Jr that would be a nightmare to manage, you would need to double nat and loads of routing config, firewall rules in 2 places configuring twice as much for no reason. The only time I would ever do anything like this is if a client asked for double skin firewalls for compliance.
@YoungBud03
@YoungBud03 4 года назад
For some reason i have to reset the wireless connection on all wireless devices if left idle for a while, started happening once i switched to pfsencen AP AC LR + pfsence
@Feerab
@Feerab 4 года назад
Thanks a lot very instructive tutorial
@ricojacobs6530
@ricojacobs6530 4 года назад
What are your thoughts or experiences with ZyXEL firewalls and their USG series/line?
@Avrglife
@Avrglife 4 года назад
100% Agree!
@jasonflint88
@jasonflint88 4 года назад
To be honest, I clicked this video because I thought you finally tested out the Sophos XG... Please give it a try.
@rajilsaraswat9763
@rajilsaraswat9763 4 года назад
It would be interesting if you can do a site to site vpn tutorial using wireguard sitting behind pfsense. Wireguard on pfsense itself is still a controversial topic.
@O2C69
@O2C69 4 года назад
use sonicwall soho product for home & small business as well as enterprise sonicwall products.
@O2C69
@O2C69 4 года назад
m.firewalls.com/products/firewalls/sonicwall/sonicwall-tz/soho
@tomb3782
@tomb3782 3 года назад
Question about PFSence, you said it uses a command line's. I was wondering "Does it use standard Linux instructions" for its command line or does it have some unique set of instructions?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 3 года назад
It's BSD based, not Linux and uses the PF system in BSD.
@tomb3782
@tomb3782 3 года назад
@@LAWRENCESYSTEMS cool, i know nothing about that... Sorry, im just starting to get into this stuff as a hobby and i want to build my own router, im tired of verizon pinging my work machine and mining data.
@csparty11
@csparty11 4 года назад
I gotta say, you're not doing Sophos any justice!! i don't understand why you have so much reluctance against commercial products, sure they cost money (i hate that too lol) but ofcourse you have to put in a trial license to get it to work, how else will you be able to test all it, if they don't have a license system they can't make you pay for it.... And opensource fan's always seem have the same argument that all the code is audited, but are you sure about that? Because that almost never happens, also it would take a long time to check all that code. And if they did they are probably going to find tons of bugs which is good, then it can be fixed but don't think it has less bugs than commercial products. But honestly most opensource software are hobby projects which can go on for years and then just disappear because the developer does feel like it anymore, also support is often non existent. I'm not saying all opensource is like that but my experiences with opensource are frustrating. As for PFsense, i have been running it in a VM for years and testing with it on and off but i just HATE that damn interface, it's just not intuative at all. The dashboard is a joke (does not show me what i want to see, let alone have alerting) and simple stuff like putting in a firewall rule with a hostname doesn't even work, you have to make some alias for it. What a pain in the ass!!!! Most PFsense users don't even know what they are doing, they ask for help to get something to work but really they have no f-ing clue if they did it right. To me that is just bad practise and even unsafe!! Sure PFsense has some cool features but it's not mature enough especially if you compare it to other products which have much better interfaces. I suggest you also test and review some commercial products, you might like them and even love them at some point. Personally i like Kerio's interface, it's just easy and it think it was even free in the past 10+ yrs ago and ran on windows. Now it's all linux based and unfortunately expensive :-( But i gotta say, i immediately understand how to do something or make advanced firewall rules and the logs are great too.
@breakingcustombc2925
@breakingcustombc2925 4 года назад
I agree. Their NGFW is even more powerful and insightful when synchronized with Sophos Central endpoint. You won't get that type of insight and control with pfsense, etc.
@satamototo
@satamototo 4 года назад
You can pay attention to OPNsense too. It's NGFW with Sensei now.
@ForGood828
@ForGood828 4 года назад
How does the RackmountIT setup work for the SG-5100? I just got my box and I want it clean and rack mounted. I have a ventilated rack and it will be placed at the top by the fans so it will get plenty of air.
@commadore129
@commadore129 4 года назад
can you review IPFIRE?
@davidg4512
@davidg4512 4 года назад
Pfsense should implement zerotier to make something like a zerotier /SD-wan solution.
@TheTF01
@TheTF01 4 года назад
I wonder what your thoughts are on the edge routers for a wisp? They don’t need a lot of filtering. Mainly just good routing and nating. Any thoughts??
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 года назад
They are popular for that, it really comes down to what platform you are willing to learn.
@TheTF01
@TheTF01 4 года назад
Lawrence Systems / PC Pickup I appreciate your reply. That’s what I was thinking but I appreciate the confirmation. Love the work you do here, thanks!
@mitchellslot
@mitchellslot 4 года назад
Could you do a review of a cyberoam or fortigate firewall
@j.w.8663
@j.w.8663 4 года назад
Ubiquiti USG: I have two USG Site-Site VPNs extending from my office USG. BUT, it doesn't allow overlapping subnets, and forces me to use a different subnet for each remote site! Is there any way to allow all three to be on the same subnet?? Anything connected could be given a static IP and not use dhcp.... ?
@robinmordasiewicz
@robinmordasiewicz 4 года назад
Is it possible to use the small USG device for just DHCP ? I just need a cheap reliable dhcp server that the CK can manage. I don’t want the USG to be my gateway, I’ll keep my service provider gateway, but I want to control DHCP. I’m hoping I can just connect a single interface LAN port and manage it with CK and let it do DHCP ?
@toxicmunkii685
@toxicmunkii685 4 года назад
Hey Tom, is there any news on the second generation Unifi switches?
@sirusvirtus5885
@sirusvirtus5885 4 года назад
Pfsense awesome 👍
@orfeous
@orfeous 4 года назад
Wait.. pfsense and edgerouter has a dashboard. Ive used them
@jeffm2787
@jeffm2787 3 года назад
Dead video at this point, UDM line supports blocks of IP's today. Yes, long time coming.
@Hands-onNow
@Hands-onNow 3 года назад
Do u have a video on pfsense setup via virtual machine?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 3 года назад
>> ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-PTySV3ziPws.html
@Daniel-ud6od
@Daniel-ud6od 4 года назад
Do you know of any good tool to manage pfsense. Mostly to get status, health info?
@xm4rcell0x
@xm4rcell0x 4 года назад
what about OPNsense and IPfire?
@jcclark2060
@jcclark2060 3 года назад
Netgear is expensive and unreliable. I have pulled so many Netgear devices that are not operational. I am happy with the Edgerouter lineup and the ability to easily manage all of my devices from one interface which pfsense doesn't offer. Tried pfsense once and it was OK but I don't see any reason to spend 2x the money for an open source (ie FREE) software.
@SB-qm5wg
@SB-qm5wg 4 года назад
Could not get broadcast helper to work with the edge.
@jasonevenson3392
@jasonevenson3392 4 года назад
Is there a central management option for pfsense?
@strikesbac
@strikesbac 4 года назад
Have you tried any of the TP Link Omada stuff? Their little OC200 controller and APs work really well as an alternative to UniFi. Pure wireless at the minute.
@johnnybegood8049
@johnnybegood8049 4 года назад
Isn’t Sophos firewalls based on Astaro distro?! I use to work on Astaro’s firewall and they were based on Linux and very powerful.
@jfenning
@jfenning 4 года назад
XG is based on the Cyberoam product (BSD) . The older UTM is based on the Astaro product (Linux).
@Johnnyohne
@Johnnyohne 4 года назад
Ja
@SomeGuyInSandy
@SomeGuyInSandy 4 года назад
pfSense has a use case for my use case.
@MirkWoot
@MirkWoot 4 года назад
"some crappy opensource project", wow such sentences light me on fire, or well, turns on a switch saying that the person is so closed-minded, often not so easy to talk with, often not even willing to consider the possibility that it would work alright, or well, they say it's fine but that none would buy it, doesn't sell.
@Phil-D83
@Phil-D83 4 года назад
Pfsense lacks a proper certificate for squid +squid guard...
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 года назад
you have to create and install one.
@ramosel
@ramosel 4 года назад
I'd say Chris Buechler was more than just a "developer" at pfSense.... that moved to Ubiquiti.
@davidc5323
@davidc5323 3 года назад
Hi , wondering if Unifi end point is safe if you use it with pfsense would you need another ips /ids on the wifi end . thanks
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 3 года назад
Yes
@alexreta4116
@alexreta4116 4 года назад
Any thoughts on Palo Alto firewalls?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 года назад
plenty www.cvedetails.com/vulnerability-list.php?vendor_id=12836&product_id=26167&version_id=&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=0&month=0&cweid=0&order=1&trc=65&sha=878adabc690f67598b5002cb9562a9e488b1dc17
@breakingcustombc2925
@breakingcustombc2925 4 года назад
For small/medium businesses they are extremely overpriced. A place I used to work for was able to quote a similar Sophos solution for almost $30-50K cheaper. This also includes an active/active setup. The Palo Alto quote they had didn't include even passive HA.
@thesmylexfrontG
@thesmylexfrontG 4 года назад
Can’t view firewall logs. For 7 years. WTF Ubiquiti.
@rhdtv2002
@rhdtv2002 4 года назад
Do all of these allow to change the default IP for logging in. My current setup has a bunch of static IP for my devices - I wouldnt want to reconfigure all of them.
@colt1596
@colt1596 4 года назад
Pfsense does. I dont use the others
@StephenCunningham1
@StephenCunningham1 4 года назад
I could be wrong but I don't see how they could not let you, it's a feature of every router i've ever used.
@rhdtv2002
@rhdtv2002 4 года назад
@@StephenCunningham1 actually the USG at least of what of what I heard doesnt..maybe it does in CLI but not on the web interface
@Comeyd
@Comeyd 4 года назад
Rich Lo what do you mean? You define your networks (IP and subnet masks) and from there you have the gateway ip (first usable address within a subnet, just like the last ip in a subnet is the broadcast address). I've got 3 different networks configured on my USG and thus it has 3 addresses that it is accessible under. I've got 10.0.0.0/16 as my main LAN 10.0.10.0/24 as my "Internet of Shit" LAN for all the IoT devices that exist now, and is bandwidth limited to 5mbps down and 1mbps up And I've got 10.0.15.0/24 as my guest network. So my USG has 3 IPs in its LAN interface. 10.0.0.1, 10.0.10.1, and 10.0.15.1 Unless of course, he meant what address the controller is accessible on. That's wherever you choose to run it.
@JonathanAnez
@JonathanAnez 4 года назад
👌 ✌️
@dpscribe
@dpscribe 4 года назад
I understand some business don't want to use Open Source like OPNsense or PFsense, because they want to call support to do all the investigation to gather the information for troubleshooting. They don't want to pay an MSP, and some business believe Cisco, Sonciwall, Juniper, Palo Alto, Meraki, fortigate, and etc will have the answer if companies buy it from them. Businesses think just because they pay for the product/services somehow these companies will get the answer quickly for any problem the company encounters.
@tw3145wallenstein
@tw3145wallenstein 4 года назад
well there there is enterprise support for PFsenese directly from netgate so they offer the samething as the Cisco and Juniper.
@masterchef2408
@masterchef2408 4 года назад
Thanks :)
@RichardBuckerCodes
@RichardBuckerCodes 4 года назад
pfsense just works
Далее
pfSense vs UniFi Firewall: May 2024 Edition
23:30
Просмотров 84 тыс.
POLI и Маша - Сигма бой
00:20
Просмотров 420 тыс.
Dream Machine vs. Edgerouter
11:46
Просмотров 33 тыс.
Untangle Firewall Review
19:05
Просмотров 46 тыс.
UNIFI kann es DOCH... - UniFi Express im Test
14:37
Просмотров 33 тыс.
Firewall Comparison: Untangle VS pfsense
15:47
Просмотров 63 тыс.
UniFi Network BEGINNERS Configuration Guide | 2024
46:14
Unifi for Newbies - Securing with Firewall Rules
1:14:26