awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
pfsense avatar

pfsense/pfsense

0
View on GitHub↗
5,675 stars·1,594 forks·PHP·Apache-2.0·5 viewswww.pfsense.org↗

Pfsense

pfSense is an open-source operating system that turns a standard computer into a dedicated firewall and router with a web-based management interface. It runs on the FreeBSD kernel with the pf packet filter for stateful firewall and NAT processing, and manages all settings through a PHP-driven web interface that writes to XML configuration files.

The platform provides a comprehensive set of network security capabilities accessible through its browser-based control panel. Users can configure packet filtering rules to control traffic flow between network segments, manage network address translation to translate private IP addresses to public ones, and establish encrypted tunnels for remote access or site-to-site connectivity using IPsec, OpenVPN, WireGuard, or L2TP protocols. It also includes a captive portal engine that presents a login or acceptance page to users before granting network access on public or guest networks.

For advanced deployments, pfSense supports high availability through CARP failover protocol, pairing two firewalls in a failover cluster so one takes over seamlessly if the other goes offline. The system can be extended by installing third-party software packages through its built-in package manager, and provides real-time and historical performance monitoring through RRD-based graphing. Configuration can be backed up and restored to a file for disaster recovery.

Features

  • Firewall Router Distributions - An open-source operating system that turns standard hardware into a dedicated firewall and router.
  • Firewalls - Provides a stateful packet filtering firewall built on the FreeBSD pf kernel module.
  • Configuration Layers - Manages all firewall settings through a PHP-driven web interface that writes to XML files.
  • VPN - Creates and manages VPN tunnels through the web interface using IPsec, OpenVPN, WireGuard, or L2TP.
  • Multi-Protocol VPN Gateways - Provides a VPN gateway supporting IPsec, OpenVPN, WireGuard, and L2TP protocols.
  • Multi-Protocol VPN Servers - Configures VPN servers supporting IPsec, OpenVPN, WireGuard, and L2TP protocols.
  • Network Traffic Routing - Directs data packets between networks using configurable routing rules from the web interface.
  • Firewall Rule Configurations - Sets packet filtering rules to control traffic flow between network segments.
  • Virtual Private Networks - Establishes encrypted VPN tunnels using IPsec, OpenVPN, WireGuard, and L2TP protocols.
  • Network Address Translation - Provides NAT capabilities for translating private IPs to public addresses and port forwarding.
  • Integrated Security Appliances - Integrates packet filtering, NAT, VPN, and traffic shaping into a single security platform.
  • XML Configurations - Persists system state in a single XML file parsed at boot and reloaded on changes.
  • Firewall Management Interfaces - Manages all firewall settings through a browser-based control panel without command-line editing.
  • DHCP and DNS Services - Provides DHCP for automatic IP assignment and DNS for local hostname resolution.
  • Plugin Package Managers - Provides a PHP-based package manager for installing third-party software extensions.
  • Package Manager Installers - Installs and manages third-party software modules through a built-in package manager.
  • High Availability Cluster Deployments - Pairs two firewalls in a failover cluster using CARP for seamless high availability.
  • CARP Failover Implementations - Implements CARP protocol for stateful failover between paired firewall appliances.
  • Firewall Failover Clusters - Implements CARP-based failover clustering for seamless firewall redundancy.
  • Captive Portal Implementations - Ships a captive portal engine that intercepts HTTP traffic and redirects users to a login page.
  • Network Switching and Bridging - Directs traffic between subnets and connects separate network segments at the data link layer.
  • Firewall Package Extensions - Extends firewall capabilities by installing third-party software packages through a built-in package manager.
  • Managed Identity Authentications - Controls access to the web interface and VPN services through local accounts or external authentication.
  • Traffic Shaping and Prioritization - Supports traffic shaping and QoS to prioritize or limit bandwidth for critical applications.

Star history

Star history chart for pfsense/pfsenseStar history chart for pfsense/pfsense

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does pfsense/pfsense do?

pfSense is an open-source operating system that turns a standard computer into a dedicated firewall and router with a web-based management interface. It runs on the FreeBSD kernel with the pf packet filter for stateful firewall and NAT processing, and manages all settings through a PHP-driven web interface that writes to XML configuration files.

What are the main features of pfsense/pfsense?

The main features of pfsense/pfsense are: Firewall Router Distributions, Firewalls, Configuration Layers, VPN, Multi-Protocol VPN Gateways, Multi-Protocol VPN Servers, Network Traffic Routing, Firewall Rule Configurations.

What are some open-source alternatives to pfsense/pfsense?

Open-source alternatives to pfsense/pfsense include: opnsense/core — This project is the core management framework for a security appliance, providing the primary infrastructure for… getsurfboard/surfboard — Surfboard is a cross-platform network client and VPN manager that provides a graphical interface for establishing… raspap/raspap-webgui — This project is a wireless hotspot management interface for Debian devices. It provides a web-based controller for… systemsapproach/book — This project is a comprehensive computer networking textbook and instructional resource. It serves as a technical… oblique/create_ap — create_ap is a Linux network management script used to create wireless access points. It functions as a tool for… wireguard/wireguard-go — wireguard-go is a Go implementation of the WireGuard protocol that operates as a userspace tunneling engine. It…

Open-source alternatives to Pfsense

Similar open-source projects, ranked by how many features they share with Pfsense.
  • opnsense/coreopnsense avatar

    opnsense/core

    4,493View on GitHub↗

    This project is the core management framework for a security appliance, providing the primary infrastructure for firewall management, network intrusion prevention, and high-availability networking. It serves as the centralized system for controlling network security policies, filtering traffic, and administering a security appliance dashboard. The system is distinguished by its high-availability capabilities, which include synchronizing configurations and connection state tables across redundant nodes to enable automatic hardware failover. It also features a modular plugin architecture for ex

    PHPapibsdcaptive-portal
    View on GitHub↗4,493
  • getsurfboard/surfboardgetsurfboard avatar

    getsurfboard/surfboard

    8,419View on GitHub↗

    Surfboard is a cross-platform network client and VPN manager that provides a graphical interface for establishing secure tunnel connections. It functions as a multi-protocol proxy client and a rule-based traffic router, directing outbound requests to specific proxies or bypassing them based on domain and IP patterns. The application acts as a connection orchestrator, allowing users to import, organize, and switch between multiple virtual private network profiles and server configurations. It implements various proxy standards to route traffic through remote servers for privacy and access. Th

    View on GitHub↗8,419
  • raspap/raspap-webguiRaspAP avatar

    RaspAP/raspap-webgui

    5,184View on GitHub↗

    This project is a wireless hotspot management interface for Debian devices. It provides a web-based controller for managing wireless access points, wireless repeaters, VPN gateways, and DNS ad-blocking filters. The system includes a captive portal framework to intercept network traffic via customizable splash pages and a VPN controller that supports WireGuard and OpenVPN with kill-switch functionality. It further differentiates itself with a DNS ad-blocking filter using curated blacklists and the ability to operate in multiple network modes, including bridged access point and wireless repeate

    PHParmbiandebiandnsmasq
    View on GitHub↗5,184
  • systemsapproach/bookSystemsApproach avatar

    SystemsApproach/book

    3,298View on GitHub↗

    This project is a comprehensive computer networking textbook and instructional resource. It serves as a technical guide for the design and implementation of network layers, protocols, and hardware architecture, covering the spectrum from physical links to application-layer protocols. The content provides a detailed study of standards for congestion control, reliable data delivery, and internetwork routing. It includes specialized technical material on network security, public-key infrastructure, and the operation of modern cloud infrastructure and data centers. The material covers a broad ra

    Python
    View on GitHub↗3,298
  • See all 30 alternatives to Pfsense→