faq123
Нуу, тебе это крутить, я бы софос оставил, раз уже есть, вполне хорошие утм, пфсенс настраивать задолбишся
А в чём ещё разница для SOHO?
"
I left pfsense years ago for Sophos SG UTM (the old version). IMHO, The new Sophus UTM (XG) isn't quite fully baked just yet, but is getting close. Have a look at the Sophos forums to see which would be right for you.
Which is better is subject to what you want. If you want a full featured firewall with intrusion detection and application control, Sophos is the way to go. If you want a hot-rod where you control every nut and bolt, go pfsense.
There probably isn't anything that Sophos does that pfsense can't be made to do, but with Sophos, getting something done is one or two mouse clicks. With pfsense, anything other than basic firewall functionality requires lots of research, installing third party packages, then trying to figure out how to make it all play together using probably outdated documentation.
Think of pfsense as a homemade bucket-T roadster with a Chevy 350 engine. Great performance, but the driver's seat is an aluminum lawn chair, and when it rains, you get wet.
Another way to look at it is that Sophos has a task oriented menu system. With pfsense, the web menus are essentially just a front end for the myriad of configuration options that each component requires.
An example of this is creating client access VPN. With Sophos, you enter a few details, click a few buttons, and Sophos builds all of the needed pieces for you including a web portal where clients can download their certificates and client software.
With pfsense, you first have to make pfsense a certificate authority which requires you to configure a dozen options that require a masters degree in certificates to understand. To make matters worse, 90% of those options have reasonable default values that could have been used instead of making the user figure out what needs to go there. Then you have to configure certificates for the users. Then you have to set up the networking. Then you have to set up DHCP. Then you have to get the client cert and the client software to the user.
Last thought: If you decide to go with pfsense, check out OPNSense and research why you might want to choose it instead of pfsense.
" (c) легально стыбзино с Reddit