1
23.1 Legacy Series / Re: Error with GPT partitions on VMWare ESXi 7.0
« on: March 06, 2023, 09:40:23 pm »
It's exactly as you say. It worked perfectly!
Thanks so much for the help!
Thanks so much for the help!
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Hi, did a quick search in the forums and on github but did not find an answer, is this FreeBSD/pfSense CARP problem also an issue in OPNsense?
https://redmine.pfsense.org/issues/6957
First of all, let me clarify that I have no relationship with OPNSense and that it is not my interest to have a discussion, but I think it’s a partial view to state that the product cannot be used in a large company. May be no the right product for you, sure.
We personally migrated a couple of old OpenBSD firewalls to OPNSense and it is working perfectly.
It is not so small. It has 3 internet access (separating different traffic for each one), several internal interfaces, plus several VPNs with OpenVPN and IPSec.
There are about 400 servers on the network and about 3000 users who use it. In adition 400 remote OpenVPN users.
Indeed we had some inconvenience (I don't remember which one now) with options that were not available in the VRRP administration interface.
We analyzed modifying the plugin and decided that it was simpler for us to use vrrp directly.
I have many years of Linux / Unix experience and I appreciate that FreeBSD is underneath.
We were also able to add external scripts and cron jobs for certain very specific things that were used in the old firewalls, such as upadate a dynamic DNS when an internet link stops working or parse some site to obtain a list of IP address, etc etc
We plan in the future add IDS/IPS or Sensei to the firewall.
It has limitations like any product, but its Open Source base allows it to be adapted with more or less effort. I thinks a closed product it’s not so versatile.
It is true that it is faster to edit pf.conf, but if the user (as is our case) is not a Linux / Unix specialist, he is deeply grateful to have a friendly interface to add a firewall rule or simply validate it. Or check the traffic or even add a VPN user, without needing to edit a single file.
Sure, it would be nice to be able to drag a ruler to place it in a given position or put a separator to facilitate reading, but for us it’s not the end of the world.
One last comment regarding the OpenBSD CARP active/active. It works perfect, but did you try to use it in a firewall? For us was a real headache to get it to work, and is related in the way OpenBSD select which cluster member takes the traffic. In fact already in OpenBSD we had switched to active/passive.
While OPNSense may have been originally intended for a small business environment, it is perfectly adaptable to a much more demanding one.
If we enter the cost into the equation (even paying for support from Deciso), the product goes from good to excellent.
Sorry for the long message and if something is not totally clear, explaining all this was a lot for my english.
Regards
Norberto