CRITICAL INFRA
Loading critical CVEs…
ALL EXPLOITED
Loading…

Fortinet vs pfSense vs OPNsense — Vergleich 2026

Fortinet FortiGate — Enterprise-Marktführer

Dedizierte ASIC-Hardware (FortiSP5/FortiSP6) liefert 100+ Gbps Durchsatz. Integriertes SD-WAN, FortiGuard Threat Intelligence, FortiAnalyzer für SIEM. Lizenzierung pro Gerät + pro Feature.

pfSense — Open-Source-Veteran

FreeBSD-basiert. CE (kostenlos) und pfSense Plus (Netgate kostenpflichtig). Ausgereifte Web-Oberfläche.

OPNsense — Post-Netgate-Alternative

pfSense-Fork aus 2015, europäische Community-Entwicklung (Deciso). Vierteljährliche Releases. Modernere UI.

Empfehlung nach Segment

Beispiel: dieselbe Regel, FortiGate vs pf

Dieselbe Richtlinie (HTTPS zu einem internen Server erlauben), auf jeder Plattform:

# FortiGate CLI — permite HTTPS spre un server intern
config firewall policy
    edit 1
        set srcintf "wan1"
        set dstintf "lan"
        set dstaddr "srv-web"
        set service "HTTPS"
        set action accept
    next
end

# OPNsense / pfSense (pf, sub capota) — echivalent
pass in on wan proto tcp to 10.0.0.10 port 443 keep state

IPsec-VPN: FortiGate vs strongSwan

Derselbe Site-to-Site-Tunnel, auf jeder Plattform:

# FortiGate (CLI)
config vpn ipsec phase1-interface
    edit "to-hq"
        set interface "wan1"
        set remote-gw 203.0.113.1
        set psksecret <secret>
    next
end

# strongSwan (Linux, /etc/ipsec.conf)
conn to-hq
    left=%defaultroute
    right=203.0.113.1
    authby=secret
    ike=aes256-sha256-modp2048
    auto=start

HA: Aktiv-Passiv-Cluster

Redundanz ueber zwei Geraete, auf jeder Plattform:

# FortiGate HA (CLI)
config system ha
    set mode a-p
    set group-name CLUSTER
    set hbdev "port3" 50
end

# pfSense/OPNsense: CARP VIP (concept) — un IP virtual flotant
# System -> High Availability: sync config + CARP pe interfata WAN/LAN

Logs an SIEM: auf jeder Plattform

Sie senden Ereignisse an Wazuh/syslog, egal welche Firewall:

# FortiGate
config log syslogd setting
    set status enable
    set server 10.0.0.5
    set port 514
end
# pfSense/OPNsense: Status -> System Logs -> Settings -> Remote Logging
#   Remote log server: 10.0.0.5:514 (firewall + system)

Regeln migrieren pfSense -> FortiGate

Wie Sie den Wechsel angehen, ohne Regeln zu verlieren:

# exporti config-ul pfSense (XML) si mapezi:
#   aliasuri  -> address/addrgrp objects
#   NAT       -> firewall vip / central-nat
#   reguli    -> firewall policy (pe srcintf/dstintf)
# pe FortiGate, obiecte intai, apoi politici:
config firewall address
    edit "LAN_NET"
        set subnet 10.0.0.0 255.255.255.0
    next
end