Hi,I'm looking at different options atm. I believe OPNsense is essentially Pfsense with a nicer UI?
Sophos is Sophos which has a UTM offering for home users, presumably so that you try it out commercially.
OPnsense also has the advantage of being able to be used commercially, and we could use that on our guest network with an air gap. Can you use OPnsense as a UTM solution?
I appreciate that you might have to download various packages instead of a unified dashboard in "one single pane of glass" to use the marketing terminologyThanks
Quote from: Solid-Profession on July 26, 2020, 02:16:54 pmHi,I'm looking at different options atm. I believe OPNsense is essentially Pfsense with a nicer UI?No, that might have been true in the past but the product diverged over the years and there are lots of things that have been rewritten from scratch. OPNsense has also more plugins in count but the core has almost the same functionality. The usually used plugins are in both systems but the implementation is likely different. In some regards, pfSense is better in others OPNsense if you need some special things, you need to test both separately. Here is a small comparison (note that an employee of that company is committing to opnsense):https://techcorner.max-it.de/wiki/Datei:2020-04-06_15_19_18-Window.pngQuote from: Solid-Profession on July 26, 2020, 02:16:54 pmSophos is Sophos which has a UTM offering for home users, presumably so that you try it out commercially. OPNsense is an UTM as well, especially if you add the Sensei plugin. It has a Firewall, WAF, Spam protection, malware scanning etc. if you use and combine the plugins correctly. Sadly not everything can be combined. For example the nginx plugin cannot make use of the local clamav service. Quote from: Solid-Profession on July 26, 2020, 02:16:54 pmOPnsense also has the advantage of being able to be used commercially, and we could use that on our guest network with an air gap. Can you use OPnsense as a UTM solution?As I said above, with the right plugins you have an UTM. The only thing is that commercial products often have better signatures and for that reason better detection. OPNsense also has no analysis engine for dynamic malware analysis. You only have a static scanner. So that depends on your needs. Quote from: Solid-Profession on July 26, 2020, 02:16:54 pmI appreciate that you might have to download various packages instead of a unified dashboard in "one single pane of glass" to use the marketing terminologyThanksThis paragraph confuses me.
You will find that OPNsense is more aligned with commercial UTM offerings than pfSense. Why? It was one of the reasons for forking it. This can also be witnessed by the mere existence of the TNSR offering that came later.
Only thing from Sophos I'm missing is the user portal to self-enroll certificates and VPN configs.
I didnt move, I offer my customers both of them, and it depends on the use case
Sophos is a commercial vendor with commercial virus scanner. And it offers a user portal and integrated WiFi. If a customer needs this, Sophos, if not, OPNsense
I think it's Limited to 50 devices