What is the pfSense firewall quick deployment?
pfSense is an open-source firewall solution. STACKIT offers it as a quick deployment: a documented guide for setup, installation, and configuration of pfSense as a virtual machine on STACKIT infrastructure. This is third-party software on STACKIT infrastructure, not a managed service operated by STACKIT.
Notice: According to the official STACKIT documentation, newer versions of the pfSense firewall are not available for use due to licensing restrictions. STACKIT recommends considering the OPNsense firewall quick deployment instead. For new projects we recommend the same path.
Key capabilities
- IDS/IPS: Intrusion detection and prevention to identify and block attacks
- GeoIP filtering: Filtering traffic based on geographic origin
- VPN: IPsec, OpenVPN, and WireGuard
- Web interface: Configuration without UNIX command-line expertise
- Free sizing: The hardware is defined by the size of the virtual machine
- Open source: No license fees, continuously improved by a global developer community
Typical use cases
Keeping existing installations running: Teams already using pfSense can mirror their environment on STACKIT, taking the limited version availability into account.
Perimeter firewall: Traffic of a STACKIT project is routed through a central firewall instance with its own rule set.
Attack detection: IDS/IPS inspects traffic for known attack patterns.
VPN connectivity: Sites and clients connect via IPsec, OpenVPN, or WireGuard.
What to keep in mind
- Version restriction: Newer pfSense versions are unavailable due to licensing restrictions
- Vendor recommendation: STACKIT points to OPNsense as the alternative
- Operational responsibility: Updates, rule set, and hardening remain with the customer
- New projects: OPNsense is the future-proof choice for new environments
Working with innFactory
As an official STACKIT partner, innFactory supports you around pfSense on STACKIT: assessing existing pfSense environments, migrating to OPNsense, network and zoning concepts, building the rule set, and connecting sites via VPN.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is the pfSense firewall quick deployment?
STACKIT provides a quick deployment for the open-source firewall pfSense: a documented guide for setup, installation, and configuration of pfSense as a virtual machine on STACKIT infrastructure. pfSense is third-party software, not a managed service operated by STACKIT.
Why is pfSense only available with restrictions on STACKIT?
According to the official documentation, newer versions of the pfSense firewall are not available for use due to licensing restrictions. STACKIT therefore recommends considering the OPNsense firewall as an alternative.
Which alternative does STACKIT recommend?
In its pfSense documentation, STACKIT explicitly points to the OPNsense firewall quick deployment, which is also open source and covers the same feature set.
Which security features does pfSense provide?
The documentation lists intrusion detection and prevention (IDS/IPS), GeoIP filtering, and VPN via IPsec, OpenVPN, and WireGuard.
Are there any license fees?
No. pfSense is open-source software with no license fees; only the STACKIT infrastructure you use is billed. The restriction concerns the availability of newer versions, not the cost.
How is the firewall administered?
pfSense is configured through a web interface; UNIX command-line knowledge is not required. The hardware is defined by the size of the virtual machine.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.
