Network and Telecom

pfSense Installation and Configuration in Istanbul

On the right hardware and with regular maintenance, pfSense does most of what a commercial firewall does. We set it up so that whoever takes it over a year from now can still make sense of it.

CybUP TeamLast updated: 6 min read

In short

pfSense installation means putting the FreeBSD-based open-source firewall on a physical or virtual server and configuring its network segments, firewall rules, VPNs, intrusion detection packages and high availability. It suits SMEs that want to keep licence costs low and technical teams that want flexibility. CybUp chooses the hardware, installs pfSense, writes the rules and hands it over fully documented.

Who is pfSense a good fit for?

pfSense suits companies that want flexibility in their firewall and would rather put money into hardware and engineering time than into subscription licences. Routing, NAT, VLANs, multi-WAN, VPN and high availability come built in; IDS/IPS and IP list blocking are added through packages.

In return you have to accept a trade-off: there are no ready-made signature subscriptions and no single vendor to call, as there would be with a commercial appliance, and someone has to keep on top of updates and packages. For a 30-person software house, pfSense is an excellent choice. If the same office wants application control, SSL inspection and central management, FortiGate installation may be the better route. We go through the comparison with you during the review.

pfSense CE or pfSense Plus: what is the difference?

In January 2021 Netgate announced pfSense Plus and renamed the open-source project pfSense Community Edition (CE). The differences come down mainly to release cadence and extra features: Plus gets three major releases a year and includes some features that CE does not have (Netgate: What is pfSense Plus?).

  • Unicast mode for CARP (CE uses multicast only, which causes trouble in some virtual environments)
  • ZFS boot environments, so you can roll back after an upgrade
  • OpenVPN Data Channel Offload (DCO) and IPsec acceleration features
  • Settings optimised for Netgate hardware

What hardware do you need for pfSense?

pfSense hardware is sized by internet line speed, VPN traffic and the packages you plan to run, not by headcount. Netgate’s stated minimum is a 64-bit (amd64) CPU, 1 GB of RAM and 8 GB of storage, but the document itself says this will not suit every environment (Netgate: Minimum hardware requirements). Switch on an IPS package such as Suricata and the CPU and memory requirements rise sharply.

There are three options: Netgate’s own appliances, a mini server with known compatibility, or a virtual machine on your existing virtualisation platform. If you run it on your own hardware, the network card is the critical part; choose one that FreeBSD does not support well and you will see performance and stability problems. As a virtual machine, the virtual switch and VLAN design are what matter, and we plan those alongside VMware ESXi installation or Hyper-V.

How are pfSense firewall rules configured?

In pfSense, rules are written per interface, on the interface where traffic enters the firewall, and they are evaluated top to bottom with the first match winning. So we remove the default “allow LAN to any” rule on the LAN interface and replace it with explicit permissions between segments. Defining servers, ports and networks as aliases keeps the rule set both shorter and easier to read.

Say an office has its accounting database server, its guest network and its CCTV recorder all on the same flat network. As part of the pfSense installation we move them into separate VLANs, allow the guest network internet and DNS only, and let the camera network reach the recorder and nothing else. If a service has to be exposed to the internet, we set up the port forward with a source IP restriction and, wherever possible, put the service behind the VPN instead of opening it directly.

WireGuard, OpenVPN or IPsec on pfSense: which should you choose?

It depends on who the VPN is for. WireGuard is fast and simple to configure, but according to Netgate’s documentation it has no concept of user authentication and becomes cumbersome to manage with large numbers of peers (Netgate: WireGuard). On pfSense it is installed as a package. It works very well for a handful of administrators and for a tunnel between two sites.

For remote access with many users we prefer OpenVPN: users can be authenticated against Active Directory over LDAP or RADIUS, and certificates and a second factor can be added. To connect to another vendor’s device, such as a FortiGate at a branch or a cloud virtual network gateway, IPsec (IKEv2) is the standard choice. The full protocol comparison is on our VPN server setup page.

“Due to this simplicity, WireGuard lacks many of the conveniences of more complicated VPN types which can help automate large deployments. Thus, while its performance scales well, the management can become cumbersome for large numbers of peers.”

— Netgate — pfSense WireGuard documentation

What do pfSense packages such as Suricata and pfBlockerNG do?

The Snort and Suricata packages give pfSense intrusion detection (IDS) and intrusion prevention (IPS) (Netgate: IDS/IPS). Putting the rule sets straight into blocking mode can start cutting off legitimate traffic as well. So we run them in detection-only mode for a few days first, weed out the false positives and only then switch to blocking.

pfBlockerNG provides IP list and country-based blocking: it gathers lists into an alias and ties them to rules for inbound or outbound traffic (Netgate: pfBlocker-NG). A company that only serves customers in Türkiye, for example, can close its VPN port to other countries and see far less scanning traffic from the internet. Package updates and log volume are part of the maintenance plan.

How do you set up pfSense HA with CARP?

High availability in pfSense is built from three components: CARP for IP address redundancy, XMLRPC for configuration sync and pfsync for state table synchronisation. The two units run active/passive; if the primary fails, the secondary takes over and open connections are largely preserved (Netgate: High Availability).

CARP needs each unit’s own address plus a shared virtual IP on every network, so the IP plan has to be right from the start. If your provider has given you a single static IP, you may need extra addresses or a switch on the WAN side. If pfSense runs as a virtual machine, we allow for the fact that CE supports multicast CARP only.

“With this configuration in place nodes act as an “active/passive” cluster with the primary node working as the active node and the secondary node in a backup “hot standby” style role, taking over as needed if the primary node fails.”

— Netgate — pfSense High Availability documentation

What you receive

  • Hardware or virtual machine sizing recommendation
  • pfSense CE or Plus installed on the current release
  • Firewall rules organised around VLANs, an IP plan and aliases
  • WireGuard, OpenVPN or IPsec tunnels
  • Suricata/Snort and pfBlockerNG configuration (where needed)
  • CARP HA cluster and failover test (where needed)
  • Configuration backup and handover document

How we work

  1. 1

    Free review

    We look at your network layout, line speeds, VPN needs and current firewall, and tell you plainly whether pfSense is the right fit.

  2. 2

    Hardware and design

    We size the hardware or virtual machine and prepare the VLAN plan and rule matrix.

  3. 3

    Installation

    We install pfSense and configure the interfaces, rules, VPNs and packages.

  4. 4

    Go-live

    We swap out the old device out of hours and test user, server and VPN access.

  5. 5

    Handover

    We hand over the configuration backup and documentation, and propose a plan for updates and package maintenance.

Frequently asked questions

Is pfSense free?

pfSense CE is open source and has no licence fee. pfSense Plus comes with Netgate appliances; the licensing terms on other hardware and on virtual machines are set by Netgate, and we check the current position with you before installation.

How much does a pfSense installation cost?

We give a written quote once we have reviewed the scope, and the review is free. The number of VLANs, VPN users, an IPS package and any HA requirement determine the scope.

Can we install pfSense on a server we already have?

Yes, if the hardware is 64-bit and its network cards are well supported by FreeBSD. We check the network cards before installation and recommend an extra card if needed.

Is it safe to run pfSense as a virtual machine?

Yes, on a properly designed virtualisation platform. The WAN interface must sit on a separate physical NIC or an isolated virtual switch, and the hypervisor management network must not be reachable from the internet.

How long does it take, and will the internet go down?

For a single site, preparation takes a few working days and go-live is a window of a few hours out of hours. Downtime is limited to that window.

Who will keep pfSense up to date?

With a maintenance agreement, we plan and carry out release and package updates. If your own team will handle it, we include the update steps in the documentation.

Do you install pfSense remotely?

Yes. We work on-site in Istanbul; elsewhere in Türkiye we install remotely once your local staff have connected the device.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.