pfSense
Layer 3/4 corporate firewall on a proven open-source platform, for networks that demand robustness and flexibility.
Service overview
pfSense is ACT Tecnologia's corporate firewall platform for networks that demand robustness and flexibility at the network level, without the licensing cost of a proprietary appliance. Built on a hardened BSD system, it delivers stateful firewalling, corporate-grade VPN, segmentation, and advanced routing. For deep application-layer (layer 7) inspection, FortiGate is the recommended solution. The whole operation is run by ACT's NOC.
Robust firewall
Stateful firewall with granular policies by interface, alias, schedule, and per-rule bandwidth limiting.
Corporate VPN
IPsec, OpenVPN, and WireGuard VPN concentrator for site-to-site tunnels and remote access at scale.
Advanced routing
Static and dynamic routing (BGP, OSPF), multi-WAN with failover, and load balancing across carriers.
Firewall, routing, and networking
Layer 3 / Layer 4: complete traffic control and routing for multi-segment corporate networks. All features are configured, versioned, and monitored by ACT.
| Feature | Status | Description |
|---|---|---|
| Stateful firewall | Included | Rules by interface, alias, port, protocol, and schedule |
| Advanced NAT | Included | SNAT, DNAT, 1:1 NAT, and port forwarding with fine-grained control |
| Multi-WAN | Included | Failover and load balancing across multiple carriers, with configurable weights |
| 802.1Q VLANs | Included | Segmentation by department, environment, or trust level |
| Dynamic routing | Included | BGP and OSPF via add-on packages |
| Traffic shaping / QoS | Included | VoIP and critical traffic prioritization, per-rule limiters |
Available features depend on the appliance sizing.
Scope of coverage (layer 3/4)
pfSense is a stateful network firewall (layers 3 and 4). Deep application inspection (layer 7) is covered by the FortiGate line. The table below makes the scope explicit.
| Capability | Layer | pfSense |
|---|---|---|
| Stateful firewall (by port/protocol) | L3 / L4 | ✓ Covered |
| Advanced NAT, dynamic routing (BGP/OSPF) | L3 / L4 | ✓ Covered |
| VLAN, VPN, QoS, and multi-WAN | L3 / L4 | ✓ Covered |
| High availability in a redundant pair (CARP) | N/A | ✗ Not covered |
| IPS (intrusion prevention) | L7 | ✗ Not covered |
| Application control (App Control) | L7 | ✗ Not covered |
| Web filtering / content filtering by category | L7 | ✗ Not covered |
| Web proxy with caching | L7 | ✗ Not covered |
| Antivirus / anti-malware at the edge | L7 | ✗ Not covered |
| SSL/TLS inspection | L7 | ✗ Not covered |
| Anti-bot / C&C detection | L7 | ✗ Not covered |
For application inspection (layer 7), FortiGate is the recommended solution. ACT sizes the right tier for each operation's needs.
VPN and remote access
Enterprise-grade VPN concentrator, supporting the three main tunnel technologies and a hub-and-spoke topology to reach networks behind CGNAT, which requires a fixed IP at the hub.
| Technology | Typical use | Characteristic |
|---|---|---|
| IPsec | Site-to-site | Interoperable with other vendors, market standard |
| OpenVPN | Remote access at scale | Over TLS, traverses NAT, granular per-user control |
| WireGuard | High performance | Low latency and lower CPU overhead |
Tunnels are provisioned, documented, and monitored by ACT. Choice depends on scenario and required interoperability.
Security and access control
Layer 3/4 perimeter defense: pfSense protects the perimeter at the network level: rule-based traffic control, OS hardening, and administrative access governance, with logging and evidence for every change.
Traffic control
- Firewall policies by interface, alias, and schedule
- Geo-blocking and IP reputation list blocking
- Egress filtering to contain unauthorized traffic
- Protection against scanning and flooding at the edge
- Versioned rules with change history
Administrative access
- Hardened BSD system, reduced attack surface
- Management restricted to ACT's VPN
- Individual and certificate-based authentication
- Logging of changes and sessions
Network authentication
- RADIUS / FreeRADIUS integration
- LDAP / Active Directory integration
- Per-user VPN access authentication
- Policies by user group
Continuity
- Versioned configuration backup (XML)
- Fast restore on new hardware
- Configuration replicated after updates
- Critical changes in an agreed window
Management, monitoring, and continuity
Centralized administration by ACT's NOC, with continuous Zabbix-based monitoring, configuration backup, and fast restore; the client sees the health of the network without operating the firewall.
Continuous monitoring
- Zabbix-based collection: CPU, memory, links, tunnels, states
- Proactive alerts for link down and VPN failure
- Availability, bandwidth, and session dashboards
- History for capacity and trend analysis
Continuity and backup
- Automatic, versioned configuration backup (XML)
- Fast restore on new hardware
- Customizations replicated after every update
- Critical changes in an agreed maintenance window
ACT's operational care.
Firmware changes and customizations are documented and replicated after every update, preventing loss of adjustments. Every critical change is preceded by a backup and executed in an agreed window.
Specifications
| Form factor | Desktop or rack appliance, sized by throughput |
| Interfaces | Multiple Gigabit ports; SFP/10G depending on model |
| Operating system | Hardened BSD system, maintained and updated by ACT |
| High availability | Not available on this platform; for HA/redundancy, FortiGate is recommended |
| Monitoring | Zabbix integration, 24x7 alerts |
| ACT support | Support via ACT's central desk, with SLA per contract (managed models) |
The network core ACT watches for you.
In managed models, ACT takes on end-to-end operation of pfSense: firewall, VPN, routing, monitoring, and response. Network health stays visible to decision-makers, with evidence and backup before every change.
Recommended use cases
Central corporate network
- Main firewall at headquarters
- Multi-WAN with failover
- Segmentation by VLAN and policy
VPN concentrator
- Many site-to-site tunnels
- Remote access for employees
- Hub for networks behind CGNAT (fixed IP at the hub)
Robust network
- Robust routing and multi-WAN
- Granular segmentation and policies
- 24x7 monitoring by ACT
Want to know if pfSense solves what your operation needs?
Talk to ACT and understand, with clarity, how this solution fits your environment.
Talk to ACT