Submind YouTube summaries
Thumbnail for The State of pfSense in 2026

The State of pfSense in 2026

Watch on YouTube

Video summary

In August 2026, the pfSense ecosystem saw significant updates with the release of Community Edition version 2.9.0 and pfSense Plus 2607. The community edition focused primarily on security enhancements rather than visual overhauls, introducing post-quantum key exchange algorithms for SSH and deprecating weak TLS keys below 2048 bits to improve overall cryptographic strength. Additionally, a new experimental feature called endpoint independent port restricted cone outbound NAT was added to help resolve issues where multiple local clients share the same source port, alongside fixes for cross-site scripting vulnerabilities and a specific WireGuard CVE. While these updates are beneficial, administrators are reminded to check hardware compatibility notes before upgrading, as certain tunable settings may need adjustment prior to the update process. The major shift in this release cycle is centered on pfSense Plus, which introduces the Nexus interface—a unified management system designed for multi-instance environments. This new GUI integrates threatgate and core DNS components, offering a modernized dashboard that allows users to manage multiple pfSense instances from a single location without requiring extra licenses for the base system itself. The interface retains a layout similar to the legacy version to minimize the learning curve, though some advanced options in firewall rules are now hidden behind an "advanced" toggle. A standout security feature within this new ecosystem is the zero trust egress mode in core DNS, which restricts outbound connections to only those remote hosts that have been resolved via DNS, effectively preventing systems from initiating direct IP-based connections to suspicious command and control servers. Despite these technological advancements, the creator notes a decline in pfSense-related content production due to real-world shifts in their professional life. Having sold their managed services business in late 2025, they no longer manage large fleets of pfSense systems, which has reduced the practical, real-world experience that typically informs their video topics. Furthermore, since the community edition changes are relatively minor and the new pfSense Plus features are not yet deployed in their primary lab infrastructure for daily use, there is less incentive to produce immediate review content. The creator emphasizes a preference for demonstrating genuine, large-scale use cases over isolated lab tests, leading to a more selective approach to video creation that reflects the current state of the industry in 2026.
Read the full video transcript
It is August of 2026 and PFSense community edition version 2.9.0 has been released as well as pfSense plus 2607. I'm going to talk about the changes in these versions which there's not much for the community edition. There's a changes coming for the pfSense plus. They've added some features but there's some bigger changes with the way they're doing the new Nexus interface that I want to talk about and I'll also address the bigger picture overall status of PFSense as I see it. And too long didn't watch. I'm not telling anyone to stop using pfSense, but I'm also going to address why I don't make as many videos about pfSense in this video. So, let's get started. I want to start with the Netgate PFSense community edition 2.9.0. So, this is the community edition/opensource edition. And there's not a lot to visually show you here. They updated the SSH algorithms to have postquantum key exchange algorithms. So, better strength and security there. They are deprecating weak keys lower than 2048 bits. So that's good on TLS key certificates. You uh should note though if you're using an older less than 248 bit key. You'll get an error in the system. So easy enough to generate these for self-signed. And on the same topic of self-signed certificates, TLS certificate autorenew. Now this is separate from the Acme system that will do like let's encrypt and other automations for renewals. This is specifically to be able to autorenew a self-signed search. So that's great because some people would have that question of hey my self-signed certificates expiring. how do I fix it? And if you read the manual at all, it'll show you there's a little icon with a circle on it. You click it and it'll renew. Now, that can be done automatically. They have a new experimental feature called endpoint independent port restricted cone outbound NAT. It's kind of a mouthful, but for very specific use cases, this helps avoid issues with multiple local clients using the same source port and the same remote host. So, this is an experimental feature, not something I've done any testing on. I've also just not run into this as an issue, but I do know if you spend time in the forums, there's some discussion on this. There's a handful of minor really, but still important crossite scripting and a CVE 202658085 uh for wireguard fix. So once again, it was not, you know, hair on fire, but definitely things that need to be fixed. So this is a good update for anyone updating uh to the new version. No reason not to. Uh there is some hardware arata. If you happen to have some specific hardware, there's a specific tunable that they ask you to set prior to update. So always make sure to read through that. And there is a process, and I've covered this before and have videos on it, of how to update PFSense. That process really hasn't changed. Now, before we get to the PFSense Plus release, we do have to talk about what was released just before then, and it's the announcement of the new guey for PFSense Plus, which it's not exactly new. It's new, but not exactly new is because I covered it before. It's just the Nexus gooey. They're putting a lot more into that. Now, the Nexus system is the multi-instance management system, but also updated UI for PFSense. So, it's both at the same time. And I've covered this in the previous update that yes, if you're using multi-instance management, you do need for managing multiple pfenses a license for each pfSense. Now, not your pfSense plus license that comes with the hardware or that you can buy, but a separate multi-instant manage system, but you automatically get essentially one free license which is to manage that pfsense system itself. And I'll show that in a minute here, but this just lets you know that there is the new and updated guey and it also includes threatgate. We're going to talk about that in a moment. Um because if you're digging into Threatgate and they answer it very clearly here, Threatgate is the evolution of PF Blocker NG redesigned for modern threat landscapes and optimized for performance. So there's a couple components here and I'll leave links to all these so you can read through them. And uh let's actually jump over to that new release because the new features is core DNS and Threadgate. These two pieces work together to give you higher performance DNS and the ability to load really large groups together for massive amounts of block lists and still being performant even on a system that is not well resourced. So this is why they say it's an evolution of PF Blocker NG. By the way, this is nothing that's coming to PFSense CE. This is all functions only found in PFSense Plus. So they also have Snort version 3. And uh let's talk about using the new guey. So that's the big thing here. If we going to go to the tried true tested guey that I've done most of my videos on. If we go here to the advanced neck 8 Nexus, this is the same thing I showed when I showed how to set up Nexus uh in my previous video. And you just enable it. You can choose an port other than 8443 if you want. I'm going to leave it at 8443. And then you can access that URL. And it brings you to the Nexus dashboard. And if you haven't seen it before, you can open up the device management view. Even if you had multiple pfSenses added here, the way the multi-instant management works in PFSense is you choose your PFSense that you want to be the holder of all the other pfSenses essentially. And this is that bridging where you connect them all into Nexus and you add all of the systems in and then you would be able to control all your instances of PFSense in one place. It lets you pull up the console and this is the one local one. So I'm not needing any extra license for this. Uh here's the open the settings for it or let's click here and go to the new UI. Now the new UI is laid out very similar to the old UI. So you're not going to be too lost here. The firewall rules look very similar. So we go to rules. We have this little uh bar at the bottom that lets us add the rules, etc. So not really substantially different. There's not this huge learning curve to start using this interface. I will point out this. If we go over here to services and we want to look at like core DNS or if we look at the threat gate, they're both here. But let's jump back over and I want to make sure it's clear. Those are not in this same system under services. So they're new components are being added to the new UI but are not in the legacy UI. So I can still see those same firewall rules and changes are one and the same. So if I add or change something here, it's going to be the same over in the Nexus UI. But just for clarity, they're pushing to that new UI for management. And that is where you should be making changes and finding any challenges you may find and reporting them back so that this can be updated. But it's reaching a more featurelete uh way to do things. I don't know anything that's specifically not in here. I didn't go over it with a fine tooth comb, but it seems to be completely functional for the usual things you may do in pfsense such as firewall rules, VLANs, etc. all the features seem to be here and if any of them or something specific isn't uh head over to the old guey. I will say on the firewall rules something that may not be obvious immediately is when you're creating a new rule if we go here and we'll add to the rule list the extra options uh you just have to hit display advanced down here to get all those extra advanced options that are just kind of below the fold when you're doing it in the other UI. So all this seems to work perfectly fine. I didn't really do much in-depth testing but so far so good. I kind of like the new UI. Um, let me know in the comments down below if you do or not. Now, coming back over to Threatgate, I want to talk about this here. Configuring core DNS zero trust egress mode. Zero trust egress mode in core DNS enables administrators to restrict access to only the remote hosts that have resolved via core DNS. This is accomplished with connection tagging handled internally by core DNS and manual firewall rules. So, they have a whole write up on how this works. This is clever and I've heard it referred to as do not talk to strangers. And what that means is a host behind pfsense with this feature enabled reaches out and this would be the normal process. We resolve a website that website has to be turned into a IP address. So that DNS name launchsystems.com gets turned into an IP and then the system will go and resolve it and can go to the website launchystems.com. But what if you were to just go to an IP address? Well, ideally you don't want it to. And the reason for that is it is common and let me go all the way back to a old post here. Uh this is dating back to June 13th of 2017 when uh John Todd had posted this in the PFSense forums. There's a really common thread especially more so in 2017. It still exists here today. It's just a little bit less common but it's the idea that thread actors frequently use just IP addresses for command and control servers or you know random things that pe people may have set up that just reach out. it becomes suspicious. So you want to know why isn't it trying to resolve the DNS and you should have things resolving the DNS because you think things should be following the DNS and looked at a suspicious one or just going to an IP address. This is a way to block those and then you could always look through the block logs and try to figure out what's reaching out to IP only or why is it reaching out to IP only and solve that on a case-by case basis. So this is actually something in 2017, John T, if the name's not familiar, he is the CTO over at Quad9. and I've had them on the channel and talked about how much I like Quad9 a few times, but this is a cool security feature and as I said, it really probably was a much bigger deal in 2017, but you know, old attacks are still happening here in 2026. So, this can be an extra layer of protection that you can add by turning the feature on that now exists in PFSense Plus with Threatgate Plus Core DNS. And they have a right up here on how to do that. Now, to talk about why I don't make as many PFSense videos. For those of you that haven't been following the channel closely or any of the things that I do, I sold off the managed services side of my business in November of 2025. Therefore, I'm not managing a bunch of PFS systems anymore. That means there's not a lot of videos that are going to be based on my real world experience because I'm having less real world experience. I still offer consulting, but I've also just seen a decline in the consulting calls requested for PFSense. So, I still have people I talk to. I still have people I help in that realm. I still know a lot of people using it in the industry, but I just don't have as much interaction with it. Second thing is because and as I mentioned with PFSense CE, there's not really any big changes to talk about. That means a video on OpenVPN from several years ago outside of those old ciphers that I wasn't recommending then now not being available to choose. Well, that's the difference between a video done in several years ago and a video done today. And I don't make content just for the sake of making content. So, it's kind of led to a decline in the number of videos I produce. And that's just the reality of where we are here in 2026. I guess I could consider making some videos on the new Neckgate PFSense Plus version with the Threatgate and the Core DNS, but I'm not actively using it myself. Therefore, I have this set up in my lab only. And just showing you how to set something in a lab maybe of limited value because I want to know what the reality is. And I'm not swapping out all my stuff just to test it and see if I run into problems with that particular feature cuz it's not a feature that I'm excited to run out and implement and swap all of my network infrastructure over just to try. I can try it in a lab, but I think labs are well somewhat limited. I really try to bring on this channel realworld use cases for the things I do, not just some lab test. That's uh what you can get with a lot of other channels. I try to bring a little bit more in depth on that whenever possible, whenever reasonable from any of the videos or content that I make. But I love hearing from you. What are your thoughts on current status of PFSense here in 2026? Leave those thoughts and comments down below. Head over to my forums, forums. For a more in-depth discussion on this topic, or connect with me on the socials and reach out to me via lawsystems.com. Easy place to find me. I'm not that hard of a person to uh share your opinion with and send me an email if you like. All right. Intex. [music] [music] >> [music]