Fortinet FortiGate — enterprise leader
Dedicated ASIC hardware (FortiSP5/FortiSP6) delivers 100+ Gbps throughput. Integrated SD-WAN, FortiGuard threat intelligence, FortiAnalyzer for SIEM. Per-device + per-feature licensing.
Pros: performance, 24/7 support, FortiAnalyzer/FortiManager integration. Cons: expensive licensing, vendor lock-in.
pfSense — open-source veteran
FreeBSD-based. CE (free) and pfSense Plus (Netgate paid). Mature web UI. IPsec/OpenVPN/WireGuard VPN. CARP HA, multi-WAN.
Pros: mature, well-documented, large community. Cons: Netgate made Plus closed-source, single-thread throughput limit (BSD).
OPNsense — post-Netgate alternative
pfSense fork from 2015, European community development (Deciso). Quarterly releases. Modern UI, clean plugin system (Suricata, ZeroTier, NetData, native WireGuard).
Pros: 100% open-source, predictable releases, better UI. Cons: smaller community than pfSense.
Recommendation by segment
- Enterprise (1000+ users): FortiGate with FortiAnalyzer
- Mid-market (100-1000): FortiGate or OPNsense on dedicated hardware
- SMB (under 100): OPNsense or pfSense CE on NUC/Protectli
- Home lab: OPNsense (better UI for learning)
Example: same rule, FortiGate vs pf
The same policy (allow HTTPS to an internal server), on each platform:
# FortiGate CLI — permite HTTPS spre un server intern
config firewall policy
edit 1
set srcintf "wan1"
set dstintf "lan"
set dstaddr "srv-web"
set service "HTTPS"
set action accept
next
end
# OPNsense / pfSense (pf, sub capota) — echivalent
pass in on wan proto tcp to 10.0.0.10 port 443 keep state
IPsec VPN: FortiGate vs strongSwan
The same site-to-site tunnel, on each platform:
# FortiGate (CLI)
config vpn ipsec phase1-interface
edit "to-hq"
set interface "wan1"
set remote-gw 203.0.113.1
set psksecret <secret>
next
end
# strongSwan (Linux, /etc/ipsec.conf)
conn to-hq
left=%defaultroute
right=203.0.113.1
authby=secret
ike=aes256-sha256-modp2048
auto=start
HA: active-passive cluster
Redundancy across two devices, on each platform:
# FortiGate HA (CLI)
config system ha
set mode a-p
set group-name CLUSTER
set hbdev "port3" 50
end
# pfSense/OPNsense: CARP VIP (concept) — un IP virtual flotant
# System -> High Availability: sync config + CARP pe interfata WAN/LAN
Logs to SIEM: on each platform
You ship events to Wazuh/syslog, whichever firewall you run:
# FortiGate
config log syslogd setting
set status enable
set server 10.0.0.5
set port 514
end
# pfSense/OPNsense: Status -> System Logs -> Settings -> Remote Logging
# Remote log server: 10.0.0.5:514 (firewall + system)
Migrating rules pfSense -> FortiGate
How you approach the switch without losing rules:
# exporti config-ul pfSense (XML) si mapezi:
# aliasuri -> address/addrgrp objects
# NAT -> firewall vip / central-nat
# reguli -> firewall policy (pe srcintf/dstintf)
# pe FortiGate, obiecte intai, apoi politici:
config firewall address
edit "LAN_NET"
set subnet 10.0.0.0 255.255.255.0
next
end