pfSense Documentation - Firewall and VPN Setup Guides

pfSense Documentation - Firewall and VPN Setup Guides

pfSense is an open-source firewall and router based on FreeBSD, used for perimeter security, NAT, VPN (IPsec, OpenVPN, WireGuard), and network segmentation. This documentation covers installing, configuring, and administering pfSense and is written for experienced network administrators, including those migrating from Cisco ASA, FortiGate, and MikroTik.

Sections

Installation and Upgrading

Firewall

  • Firewall Rules - rule creation, processing order, floating rules, state tracking
  • Aliases - grouping hosts, networks, ports, and URL tables
  • Schedules - time-based rule activation and deactivation
  • Best Practices - rule organization, common mistakes, migration from other platforms

NAT

VPN

Routing and Networking

High Availability

Traffic Management

Services

Management and Security

Monitoring

Packages and Extensions

Network Interfaces and Protocols

  • Interface Types - PPPoE, GRE, GIF, LAGG, QinQ, and wireless
  • Bridging - network bridges and transparent firewall
  • Captive Portal - authentication portal for guest networks
  • IPv6 - IPv6 configuration, dual-stack, DHCPv6, SLAAC, and NPt

Virtualization and Operations

System Configuration

Development and Automation

Reference Materials

Integrations

Frequently asked questions

What is pfSense?
pfSense is an open-source firewall and router based on FreeBSD for perimeter security, NAT, VPN, and network segmentation.
Which VPNs does pfSense support?
IPsec (IKEv2, site-to-site, and mobile clients), OpenVPN (remote access and site-to-site), and WireGuard.
Which packages does the documentation cover?
HAProxy, pfBlockerNG, Suricata, and others, plus the OpenNix package repository (AmneziaWG, Xray, Wazuh Agent, sing-box).
Can pfSense integrate with Wazuh SIEM?
Yes: the Wazuh Agent on pfSense forwards logs for security monitoring, including on Yandex Cloud and VK Cloud.
Does pfSense support high availability?
Yes, through CARP and Virtual IPs to build an HA cluster.
Who is this documentation for?
Experienced network administrators, including those migrating from Cisco ASA, FortiGate, and MikroTik.
Reviewed by OpenNix LLC · Last updated on