pfSense CE 2.9.0 and pfSense Plus 26.07 are both out. Here is what changed in each, a walkthrough of the new Nexus GUI with ThreatGate and CoreDNS, and my honest assessment of where pfSense sits in 2026.
00:00 - Intro
00:35 - pfSense CE 2.9.0 Changes
02:33 - pfSense plus New GUI Announcement
03:28 - ThreatGate and CoreDNS Explained
04:18 - Enabling and Touring the Nexus GUI
07:05 - Zero Trust Egress Mode
09:18 - Where pfSense Sits in 2026
I can no longer support Netgate after the recent changes and what I view as a series of abrupt, reactionary decisions. Unfortunately, the way the situation was handled has significantly changed my perception of the company.
To be clear, I have no issue with Netgate generating revenue from its products and services. I understand that continued development, support, and maintenance require funding, and I would have been more than willing to pay a reasonable fee to support their work. However, I do not believe the $129-per-year pricing model represents good value, particularly when combined with the cost of Netgate’s hardware.
When comparing hardware pricing and performance against alternatives such as UniFi, I find the performance-to-cost proposition difficult to justify. The difference is substantial enough that, for my use case, Netgate is simply no longer competitive.
I ultimately moved to VyOS, and it has been working well for me. At this point, I am satisfied with the decision and have no intention of moving back.
I alternatively moved to opnsense for this very reason
For home use it also beats Unifi simply because I can run it on my own hardware. If I had Unifi at home and it developed a hardware fault, unless I had an expensive spare I would be down, with opnsense I can grab an old pc and be back up within an hour, whilst I arranged a replacement
Can you elaborate? I use a Netgate 2100 without any issues. You can install it for free bare metal on any hardware. Also, virtualization of pfsense (e.g. on Proxmox) is possible at no cost.
Since I have Netgate hardware I have never looked at Opensense. If I was unhappy with pfsene, I would probably have a closer look at Opensense.
Are you using the community edition or are you paying for it?
I don’t bother updating unless there is a security/actual issue relevant to the install
The tailscale addon is an important addin for me and available now due to Sheridan computers
I like q-feeds addon
Like the new rules interface was awkward at beginning but prefer it now
Rest is essentially the same
I recommend leaving pfsense fully otherwise your constantly “confusing” yourself via muscle memory
But big thing for me is, trust, you never know if negate do something which end ups creating a headache across your installed base, and I’d rather give opnsense monies in the future then negate if I have too
I like VyOS very much, but i dont use it. I know you are behind VyManager, but i dont like how you guys implemented that GUI solution via docker. But thats just me. Im not a fan of running containers on my router. However, thats not the primary reason i dont use it. Its systemd. Dont ask me why im against it, im not going to argue about it here. I use opnsense, while exploring other solutions like freebsd, openbsd or bsd router project.
@LTS_Tom you should really re-visit opnsense in 2026. A LOT has changed since you tried it last time. Sheridan Computers has implemented ZFS snapshots/boot environments and this is something that pfsense has behind paywall. The only thing i dont like are frequent updates. But i dont update for the sake of updating anyway. I treat opnsense like pfsense. I only update when there are critical CVEs fixed and new features added.
That is a fair point. Our original thinking was that many of the organizations using VyOS today are data centers, ISPs, and other environments managing multiple devices. Because of that, we chose to pursue a centralized “Site Manager” approach similar to UniFi.
That said, I agree with your perspective, and I appreciate the feedback. In hindsight, it would have made more sense to build the core management functionality directly into VyOS itself, while keeping Site Manager as a separate, optional deployment for centrally managing multiple VyOS instances.
I know there are users out there that don’t like systemd. No judgment there.
We are currently working on a project in VyProjects that I think users will like. But it does use systemd lol. I’m not talking about VyManager .
I’m not referring to pfSense’s functionality or technical capabilities; I’m referring to Netgate as a business and the direction they have taken. They built a great deal of trust as a community-oriented project, but in my view, a number of their recent business decisions have damaged the foundation and goodwill that helped make pfSense what it is today.
At this point, pfSense CE appears to be maintained largely to preserve community support, with development seemingly limited primarily to security and maintenance updates rather than meaningful feature advancement. That gives me concerns about the long-term direction of the project and Netgate’s commitment to the community edition.
Community edition. The cost is extremely high to pay for.
I think that a mute point Tom, if your managing a firewall and not locking down the internal interface as well as externally, then you should be using something like Unifi that hold your hand, not sarcastically said
The only plus point I’ll give negate is their support to openbsd, that is an undeniable fact, but also it is in their own self intrest, they’d be fecked if they didn’t
Undoubtedly opnsense are taking advantage here, but why not (there is zero trust between them) as I’m sure if negate went under or stopped, opnsense would step up, as well as the community around them built up over years of trust that netgate have destroyed…. You simply cannot buy trust like that no matter how much money u have
Opnsense has continued to support/add to BSD, while that has become more difficult due to politics, they continue to work forward on the base OS.
Opn also doesn’t hold much back from the free version, even the curated blocking list is now available to the CE users. There hardware was comparable to other enterprise choices, but supply and tariffs knocked it out, I recently bought a Protectli box because of the pricing.
Also, their appliances are much higher quality compared to plastic Netgate garbage. Does anyone remember Netgate devices with crappy eMMC storage that dies prematurely? Just terrible hardware in their low to mid segment.
Just read up on it, definitely been quite lively on the openbsd political side
I’ve also been pleasantly surprised how much engineering effort had been going on recently on enhancements, new features, but I do wish they had a more conservative LTS type version, although holding out on updates unless critical achieves the same
Most of the pfsense updates seem to be concentrating on the multi management side, I.e. concentrating on engineering effort to produce extra revenue streams
The sad thing is all negate had to do was be honest with the base that freely gave their time/trust to make the product as good as it is, instead of slyly deprecating its functionality.
I’d have been quite prepared to start paying for it if that was the problem, although I think it was the fact that peoples were repackaging their product in the east which got the manchild at the top in a hissy fit instead of just seeing it as a side of open source that will always be there
And if I recall properly, when I looked into buying pf, for the license I needed at work, it was at least twice the price compared to OPN. I haven’t checked in a while because I’m on OPN now and don’t really care to keep a comparison. If I suddenly had to change, I’d probably go to Unifi or spend some time with VyOS and see if I could pick it up. I have about 8 months left on my OPN Business, and plan to renew when the time comes. The only thing I don’t like about the OPN Business is that the clock starts ticking at purchase, not at install and activation. So I can’t buy the renewal now or I waste 8 months. I had money in last years’s budget but it would have wasted too much of my current license, hoping I have money in April to get this renewed.
This is a painful reality that many people dont want to admit. I cringe every time someone says “the open source community will take over”. No they wont. And even if they do, it will get abandoned before any serious works gets done. It looks like people are under the impression that open source software development takes just few hours of your time per day. The reality is much more cruel.