pfSense CE

pfSense CE

Free, open-source firewall and router distribution based on FreeBSD: stateful filtering, NAT, OpenVPN/IPsec/WireGuard, multi-WAN, VLANs, CARP high availability and add-on packages such as Suricata and HAProxy. Installs on amd64 hardware or a VM from a USB or ISO image.

OS: amd64 hardware / VM (FreeBSD-based appliance OS)
Size: —
Version: 2.9.0
FreeLatest version: 2.9.0Actively developed

pfSense CE (Community Edition) is a free, open-source firewall and router distribution based on FreeBSD, built for sysadmins who want enterprise-grade perimeter security on standard x86-64 hardware or in a virtual machine. A pfSense download replaces a consumer router or an ageing appliance with stateful packet filtering, NAT, VPN servers, traffic shaping, multi-WAN failover and a long list of add-on packages, all managed from a web interface.

pfSense started in 2004 as a fork of m0n0wall and is developed by Netgate (Rubicon Communications, LLC). The code is published under Apache-2.0. Netgate also sells pfSense Plus, a commercial edition preloaded on its own appliances and available for third-party hardware; this page covers the free CE release.

pfSense CE at a glance

Item Details
Latest version 2.9.0 (20 August 2026); the previous release was 2.8.1
Licence Free and open source, Apache-2.0
Platforms Dedicated amd64 (x86-64) hardware or a VM (Proxmox, VMware, Hyper-V, KVM, VirtualBox); installed from a USB memstick or ISO image
Developer Netgate (Rubicon Communications, LLC)
Official website pfsense.org (project) and docs.netgate.com (documentation)
Best for Branch and small-business edge firewalls, home labs, VPN concentrators and lab segmentation

What it does

  • Stateful firewall on pf with per-interface rules, aliases, schedules, floating rules and GeoIP or threat-feed aliases through pfBlockerNG.
  • NAT: port forwards, 1:1 NAT, outbound NAT with automatic or manual mappings, and (new in 2.9.0, experimental) endpoint-independent “port restricted cone” NAT for gaming and VoIP.
  • VPN: OpenVPN server and client, IPsec site-to-site and mobile clients, and WireGuard as a package.
  • Routing: static routes, multi-WAN with gateway groups for failover and load balancing, policy routing, and FRR (BGP/OSPF) as a package.
  • Network services: DHCP (Kea or ISC), DNS Resolver (Unbound) and Forwarder, dynamic DNS, NTP, captive portal with vouchers and RADIUS.
  • Traffic shaping with ALTQ and limiters, plus per-interface graphs and NetFlow/sFlow export through packages.
  • High availability with CARP, pfsync state synchronisation and XML-RPC configuration sync between two nodes.
  • Package system: Suricata or Snort IDS/IPS, HAProxy, Squid, ACME certificates, Zabbix agent, Telegraf, ntopng and more. 2.9.0 adds automatic renewal of self-signed and internal-CA TLS certificates.

How sysadmins use it

Publish an internal web server

  1. Go to Firewall > Aliases and create a host alias for the server, for example web01 = 10.0.10.20.
  2. Under Firewall > NAT > Port Forward, add a rule: interface WAN, protocol TCP, destination WAN address, port 443, redirect target web01 port 443. Leave “Filter rule association” on “Add associated filter rule”.
  3. Check Firewall > Rules > WAN for the auto-created pass rule and apply changes. Test from outside the network, not from the LAN, unless NAT reflection is enabled.

Set up remote access with OpenVPN

  1. Create an internal CA and a server certificate under System > Certificates.
  2. Run VPN > OpenVPN > Wizards: choose local user access, the CA and certificate, tunnel network (for example 10.8.0.0/24), the local networks to push, and let the wizard add the WAN and OpenVPN firewall rules.
  3. Install the OpenVPN Client Export package and export per-user configuration bundles for Windows, macOS and mobile clients.

Segment the network with VLANs

  1. Interfaces > Assignments > VLANs: create VLAN tags on the LAN parent interface, for example 20 (Servers) and 30 (Guests).
  2. Assign and enable each VLAN as an interface with its own static IP and DHCP scope.
  3. Write firewall rules per VLAN. Rules are evaluated top to bottom, first match wins, and the implicit default is to block; a Guests VLAN typically gets “pass to any, except RFC1918 networks” via an inverted alias.

Install and first run

Hardware. Netgate’s documented minimum is a 64-bit amd64 CPU, 1 GB of RAM, an 8 GB or larger disk and one or more supported network interfaces. For IDS/IPS, VPN throughput above a few hundred Mbit/s or many packages, plan for more RAM and a CPU with AES-NI. Intel NICs are the safest choice; some Realtek chips need a separate driver package.

Install. Download the installer image (USB memstick for VGA or serial console, or an ISO) from the official site; the installer is free, but downloads go through the Netgate store, which asks you to create a store account. Write the image to a USB stick, boot from it, accept the licence and choose Install. The installer asks which interface is WAN and which is LAN, lets you set WAN to DHCP, static or PPPoE, offers ZFS or UFS, and then fetches the release packages, so the WAN needs internet access during installation. Once the box reboots from disk, the LAN interface defaults to 192.168.1.1/24 with DHCP handing out 192.168.1.100–150.

  • First login: open https://192.168.1.1, log in with the default admin credentials shown in the documentation and run the setup wizard. Change the admin password immediately.
  • Virtual machines: on Proxmox or KVM use VirtIO NICs and disable hardware checksum offloading under System > Advanced > Networking if you see dropped traffic. On Hyper-V use the synthetic adapters, not legacy ones.
  • Upgrades: System > Update offers in-place upgrades between CE releases; take a configuration backup first. The 2.9.0 release notes warn that some hardware with a firmware problem, including certain Celeron J systems, may panic at boot.
  • Weak certificates: 2.9.0 ships OpenSSL 3.5, which rejects RSA keys shorter than 2048 bits for the web GUI and other services. Regenerate old certificates before upgrading.

Limitations

  • CE runs on amd64 only. The ARM images and some newer features (and Netgate’s TAC support) are limited to pfSense Plus, and Netgate openly encourages migration to Plus.
  • Getting the installer requires a Netgate store account, which some admins find an unnecessary step for open-source software.
  • CE releases arrive less often than Plus releases, so security fixes can take longer to reach CE.
  • Hardware support follows FreeBSD; new NICs and Wi-Fi adapters may not work, and Wi-Fi in general is not a strength.
  • Packages such as Suricata or Squid turn a small box into a busy one; sizing is your problem, not the installer’s.

pfSense CE vs alternatives

OPNsense is the best-known fork, with a more frequent release cycle and a different GUI; the feature sets overlap heavily and the choice is mostly a matter of preference and plugin needs. VyOS is a CLI-driven router OS for people who prefer configuration-as-code. For a Windows-side view of what traffic is doing, GlassWire shows per-application connections on the endpoint, while PRTG can poll pfSense over SNMP for interface graphs and gateway status. Logs from pfSense can be shipped by syslog to a SIEM such as Wazuh.

FAQ

Is pfSense free?

pfSense CE is free and open source under the Apache-2.0 licence. pfSense Plus is Netgate’s commercial edition for its appliances and third-party hardware.

pfSense vs OPNsense: which is better?

Both are FreeBSD-based firewalls with similar capabilities. OPNsense updates more often and has a different interface; pfSense has the larger body of documentation and a long package track record. Try both in a VM before committing.

Where is the pfSense download?

Installer images are published on the official website and delivered through the Netgate store after creating a free store account. Choose the amd64 memstick image for most hardware or the ISO for IPMI and optical boot.

What is the pfSense default password?

The documentation publishes the default admin username and password for a fresh installation. Log in at https://192.168.1.1 from the LAN side and change the password in the setup wizard.

What hardware does pfSense need?

A 64-bit x86 CPU, at least 1 GB of RAM, 8 GB of storage and supported network cards. Netgate’s hardware sizing guidance covers throughput, VPN and IDS requirements.

Does pfSense run on ARM or Raspberry Pi?

pfSense CE is amd64 only. The ARM builds exist only for Netgate’s own appliances running pfSense Plus. There is no Raspberry Pi image.

Last checked against official sources: 6 October 2026 (developer website: pfsense.org). Versions and licence terms change — confirm on the developer's site before deploying in production.

Other articles

Submit your application