OPNsense
Reddit take
AI summary of the Reddit excerpts below — not a quote
OPNsense is a highly regarded open-source firewall and routing platform frequently used by homelab enthusiasts and sysadmins to replace consumer-grade or ISP-provided hardware. It is praised for its flexibility, allowing users to run it on a wide range of hardware from repurposed 'e-waste' PCs to modern NUCs and dedicated mini-PCs. While it offers powerful features like VPN services, 10Gbps routing, and advanced security plugins, it is noted for a steep learning curve and a web interface that some find difficult to scale for very complex configurations.
Pros
- Extremely flexible hardware support, ranging from salvaged older computers to high-speed 10Gbps setups.
- Comprehensive feature set including VPN services, DNS integration, and advanced security options like Zenarmor and Suricata.
- Significantly more capable than standard consumer routers for tasks like WAN failover and granular traffic control.
- Well-documented and considered a stable 'edge device' for both home and remote site environments.
Cons
- The web UI can become counterproductive and difficult to manage when scaling to a high volume of networks or IPsec tunnels.
- Steep learning curve for beginners, often requiring significant time to master firewall rules and routing logic.
- Performance bottlenecks may occur in specific scenarios, such as PPPoE processes being limited to a single CPU core.
Caveats
- Hardware choice is critical; users frequently recommend Intel NICs for optimal stability.
- Running OPNsense as a virtual machine (e.g., on Proxmox) is common but typically requires dedicated NIC passthrough for best results.
- Initial configuration is often described as a 'rite of passage' that involves trial-and-error with firewall rules.
Best for
- Homelab users seeking enterprise-level networking features on a budget.
- Users looking to replace ISP routers with a more secure and customizable edge device.
- Advanced users requiring 10Gbps throughput or complex VPN and DNS configurations.
Avoid if
- You prefer a 'plug-and-play' consumer networking experience with minimal configuration.
- You are uncomfortable troubleshooting network settings and manual firewall rule sets.
This summary uses balanced time weighting with about a 6-month half-life. The evidence is older (median age of ~407 days), which may not reflect the most recent software updates or UI changes in OPNsense.
Sentiment
17 positive (63%) · 9 mixed (33%) · 1 negative (4%)
Trust + time weighted score: +59% · raw score 59%
What redditors said (10 of 27)
Have you replaced your ISP router with an opnsense/pfsense box yet? That, combined with swearing at firewall rules, is basically a rite of passage
I also use OPNSense in a different server.
Edge device, I prefer OPNSense
Working with OPNSense Firewall, Routing and DHCP and DNS Settings I found out the more you know you know you nothing in this topic 😅
I've had similar responses this year towards OPNSense (we use mainly to have WAN fail over and VPN on very remote sites, as well as force our internal DNS there and allow access to some of our VMs selectively, and we even have a more "advanced" setup in one place with a layer 2 bridge that we needed and it's been perfect)
Setup an alias in opnsense or pfsense with the Firehol list as the content....
and several VMs (OPNsense, Home Assistant, Windows 11 VM for Blue Iris) all running in a 2 node cluster via Proxmox later, I have a solution that nearly works. 😅
While troubleshooting those QoS issues, I shipped out a properly setup firewall with OPNsense to replace the SoHo FW/router they had from before = problem solved.
now every consumer router, regardless of the price, isn't as good as some salvaged 15 year old e-waste computer with an Intel NIC running Opnsense.
Also got a custom build router with opnsense.