Skip to main content
Cloud / STACKIT / Products / Quick Deployment pfSense Firewall - Limited Availability

Quick Deployment pfSense Firewall - Limited Availability

pfSense as a quick deployment on STACKIT: firewall VM with IDS/IPS, GeoIP filtering, and VPN. Newer pfSense versions are unavailable due to licensing restrictions.

Network
Pricing Model The STACKIT infrastructure you use (server, network, floating IP) is billed via the STACKIT pricing calculator; pfSense is open-source software with no license fees
Availability Limited: according to STACKIT, newer pfSense versions are not available due to licensing restrictions
Data Sovereignty Operated within the STACKIT cloud; configuration and rule set stay inside your project
Reliability SLA as provided for the STACKIT infrastructure services used; pfSense is open-source software under customer responsibility SLA

What is the pfSense firewall quick deployment?

pfSense is an open-source firewall solution. STACKIT offers it as a quick deployment: a documented guide for setup, installation, and configuration of pfSense as a virtual machine on STACKIT infrastructure. This is third-party software on STACKIT infrastructure, not a managed service operated by STACKIT.

Notice: According to the official STACKIT documentation, newer versions of the pfSense firewall are not available for use due to licensing restrictions. STACKIT recommends considering the OPNsense firewall quick deployment instead. For new projects we recommend the same path.

Key capabilities

  • IDS/IPS: Intrusion detection and prevention to identify and block attacks
  • GeoIP filtering: Filtering traffic based on geographic origin
  • VPN: IPsec, OpenVPN, and WireGuard
  • Web interface: Configuration without UNIX command-line expertise
  • Free sizing: The hardware is defined by the size of the virtual machine
  • Open source: No license fees, continuously improved by a global developer community

Typical use cases

Keeping existing installations running: Teams already using pfSense can mirror their environment on STACKIT, taking the limited version availability into account.

Perimeter firewall: Traffic of a STACKIT project is routed through a central firewall instance with its own rule set.

Attack detection: IDS/IPS inspects traffic for known attack patterns.

VPN connectivity: Sites and clients connect via IPsec, OpenVPN, or WireGuard.

What to keep in mind

  • Version restriction: Newer pfSense versions are unavailable due to licensing restrictions
  • Vendor recommendation: STACKIT points to OPNsense as the alternative
  • Operational responsibility: Updates, rule set, and hardening remain with the customer
  • New projects: OPNsense is the future-proof choice for new environments

Working with innFactory

As an official STACKIT partner, innFactory supports you around pfSense on STACKIT: assessing existing pfSense environments, migrating to OPNsense, network and zoning concepts, building the rule set, and connecting sites via VPN.

Typical Use Cases

Continuing to run existing pfSense installations on STACKIT
Perimeter firewall in front of STACKIT workloads
Intrusion detection and prevention (IDS/IPS)
Site-to-site and client VPN via IPsec, OpenVPN, or WireGuard
GeoIP-based filtering of unwanted source countries

Technical Specifications

Administration Managed through a web interface; no UNIX command-line expertise required
Deployment model Quick deployment: STACKIT documents setup, installation, and configuration of pfSense on STACKIT infrastructure
Licensing Free, open-source software with no license fees, continuously improved by a global developer community
Recommended alternative STACKIT points to the OPNsense firewall quick deployment as an alternative
Security features Intrusion detection and prevention (IDS/IPS) plus GeoIP filtering
Sizing Freely selectable VM size to match your requirements
Version restriction According to STACKIT, newer versions of the pfSense firewall are not available for use due to licensing restrictions
VPN IPsec, OpenVPN, and WireGuard

Frequently Asked Questions

What is the pfSense firewall quick deployment?

STACKIT provides a quick deployment for the open-source firewall pfSense: a documented guide for setup, installation, and configuration of pfSense as a virtual machine on STACKIT infrastructure. pfSense is third-party software, not a managed service operated by STACKIT.

Why is pfSense only available with restrictions on STACKIT?

According to the official documentation, newer versions of the pfSense firewall are not available for use due to licensing restrictions. STACKIT therefore recommends considering the OPNsense firewall as an alternative.

Which alternative does STACKIT recommend?

In its pfSense documentation, STACKIT explicitly points to the OPNsense firewall quick deployment, which is also open source and covers the same feature set.

Which security features does pfSense provide?

The documentation lists intrusion detection and prevention (IDS/IPS), GeoIP filtering, and VPN via IPsec, OpenVPN, and WireGuard.

Are there any license fees?

No. pfSense is open-source software with no license fees; only the STACKIT infrastructure you use is billed. The restriction concerns the availability of newer versions, not the cost.

How is the firewall administered?

pfSense is configured through a web interface; UNIX command-line knowledge is not required. The hardware is defined by the size of the virtual machine.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.

STACKIT Partner

innFactory is an official STACKIT Partner. We provide consulting, implementation, and managed services for the sovereign cloud.

STACKIT Official Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

Google Cloud

Certificate Manager - Central TLS Certificate Management

Certificate Manager acquires, manages, and deploys TLS certificates for Cloud Load Balancing, Secure Web Proxy, and …

Pricing Pricing as published on the official …
SLA SLA as published by the provider
Compare →
Google Cloud

Cloud Domains - Domain Registration in Google Cloud

Cloud Domains lets you register and manage domains directly in Google Cloud, with billing through Cloud Billing and …

Pricing Per top-level domain pricing as …
SLA SLA as published by the provider
Compare →
Google Cloud

Data Transfer Essentials - Data Transfer Between Cloud Providers

Data Transfer Essentials provides cost-optimized data transfer between the services of an application that resides …

Pricing Currently offered at no charge when used …
SLA SLA as published by the provider
Compare →
Google Cloud

Secure Access Connect - Attach SSE Services to NCC Gateway

Secure Access Connect lets you connect security service edge products to NCC Gateway for security processing and secure …

Pricing Billed according to NCC Gateway pricing …
SLA SLA as published by the provider
Compare →
Google Cloud

Service Extensions - Custom Code in the Network Data Path

Service Extensions inserts custom code into the data path of Cloud Load Balancing, Media CDN, and Secure Web Proxy, as …

Pricing Billed per invocation: plugins on Cloud …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Telecom Network Automation - Cloud-Native Automation for Telecom Networks

Telecom Network Automation is Google's managed cloud implementation of the open source Nephio project for intent-driven …

Pricing Pay-as-you-go per automated vCPU per …
SLA SLA per provider / see official documentation
Compare →

70 comparable products found across other clouds.

Ready to start with Quick Deployment pfSense Firewall - Limited Availability?

Our certified STACKIT experts help you with architecture, integration, and optimization.

Schedule Consultation