I co-founded pfSense. For the last year I've been building its successor. If you run pfSense today, you already know the reasons to look around: development you can't influence, a CE edition that feels like an afterthought, FreeBSD driver roulette on modern hardware, and a config workflow where one bad apply on a remote box means a drive. nfSensei is my answer. Built from scratch in Rust, on Linux, and designed around the things pfSense users actually complain about. Your config.xml imports. There's an importer that reads your pfSense config, shows you exactly what maps over and what needs attention, then applies it. You don't start from zero. You can't brick it from the couch. Changes stage as a candidate, diff before apply, validate through the real engines before anything is written, and auto-roll-back if you don't confirm in time. If a config ever fails at boot, the box falls back to the last good one on its own. The hardware works. Linux base means modern NICs and drivers just work — and the fast path compiles your rules to XDP at 40Gbps. Automation is native, not scraped. Everything the UI does is a documented API call — about 1,140 of them, with a built-in explorer. Your Ansible finally gets a real interface. The VPNs are current. WireGuard, IPsec, Tailscale, and self-hosted mesh — your own control plane, your keys — plus post-quantum key exchange where it counts. The experimental stuff has its own wing. Thirty-plus Labs features behind toggles: WAN bonding that fuses multiple cheap uplinks through a $5 VPS into one resilient pipe, per-flow SLA telemetry with tamper-evident audit chains, GeoDNS that steers traffic by live RTT and load, application-aware QoS, config push to a whole fleet of remote nodes, and an AI assistant on the box that reads your actual interfaces and logs using local models. Toggles are per-browser and can't touch your running config — flip things on, break them, tell me about it. Oh, and there is much more to mention here! Self-hosted, on your hardware, no cloud account, no subscription. It's NOW IN ACTIVE BETA (previously alpha) with about 40 testers, and bug reports typically get fixed in days. I want more people who know what pfSense does well and can tell me exactly where nfSensei falls short. If you are interested in testing please email me: sullrich@gmail.com. Tell me about your pfSense setup and I'll get you access. Note: Affiliates and employees of Netgate are not invited.

Last edited Jul 11, 2026 · 2:36 AM UTC

149
315
2,672
190,608
Sort replies: Relevant Recent Liked
Replying to @sullrich
Excellent news and a solid breakaway from a company comprised of toxic people who painted themselves into a corner with ossification — this is where some may consider OPNSense falling short, since it carried over a lot of cruft with it.
1
2
533
I have seen these toxic trends and promise that our community code of conduct is not going to allow for these types of behaviors. Interested to chat with any guidance you might have in making sure these things never happen again in the community!
1
5
456
Replying to @sullrich
the honest answer is most companies don't get past the initial excitement with open-source projects because of exactly these issues. pfSense has been a great tool for many but it's clear someone needs to pick up where they left off in terms of modernizing it.
1
1
1,021
This is my goal! Looking forward to the community helping driving it further!
3
851
Replying to @sullrich
Interested in checking this out! I loved pfsense back in the day but switched to opnsense years ago.
3
36
6,597
Hit me up! sullrich@gmail.com
6
6,131
Replying to @sullrich
I’ve been using pfsense since it was monowall. I actually love that it’s built on BSD instead of Linux but the development pace pushed my to opnsense. Tough ask to go to Linux , convince me
1
34
2,426
Not my job to convince you. Download the beta once its available and convince yourself?
8
483
Replying to @sullrich
You lost my support at rust. stop it already! I will use a juniper instead.
5
30
1,698
OK, boomer.
1
11
537
Replying to @sullrich
I'm not gonna lie, you have more apparel for sale than anything hardware based in the store. Your logo and your shirt artwork is 100% AI generated slop. Hardware is for an Rpi 5 Compute module... okay, I guess. Nothing innovative there really. The AI sloppage isn't exactly inspiring confidence...
5
26
3,642
You have not even been given access to the product and your judging the very limited info that is available currently. Have you even used pfSense? Do you know what it can do? Check yourself.
7
1,423
Replying to @sullrich
Long ago switched to OPNsense and the main thing is genuinely hate is the PHP management, so this sounds very attractive. If there's any way to become a beta tester, I'd love to. How do you deal with rather, ahem, frequent Linux root kernel exploits appearing very frequently in recent times?
1
1
15
2,593
Still a brand new project. I am sure we will at some point but appreciate bringing it up!
1
633
Replying to @sullrich
why would i use this instead of opnsense
3
12
2,243
Opnsense is great! If it works for you, stick with it! This would be more for advanced networking and features you do not have available currently in Opnsense.
2
3
840
Replying to @sullrich
Rust you say…. How many gb memory does it need ?
1
9
647
1GB stock install
1
151
Replying to @sullrich
Hopefully it isn't all AI slop like this post is.
2
8
938
Grow up.
2
364
Replying to @sullrich
> in Rust Fucking gay.
1
8
351
Grow up.
1
5
162
Replying to @sullrich
Full time OPNsense user here. It would be cool if there were some different VPN options. Amnezia or XRay or Rosenpass or so on. Tailscale sucks. The 4 you listed are already in OPNsense and it's not enough.
5
6
1,574
We have Netbird as well as a custom quic based vpn built from scratch in Labs gated.
2
2
339
Replying to @sullrich
pfSense CE user here for a long time, know all its quirks and workarounds so no major complaints except indeed the background development. If nfSensei will be able to run on a Pi, I'll use it.
2
1
4
2,194
It does. One of my primary test devices. RPI5 CPM plus custom boards are amazing.
1
396
Replying to @sullrich
Willing to entertain Linux, strongly prefer BSD, but Rust...Sorry, you lost me there. I'll continue to gripe with pfS+ and it's slow development. Hardware has never been an issue, I've found fantastic purpose-built hardware that runs it perfectly.
1
8
512
Do what you gotta do. Be you.
1
285