Netgate pfSense firewalls: a UK business guide
Sizing, pfSense Plus vs Community Edition, high availability and a practical migration checklist.
By the Telappliant team

Netgate appliances running pfSense Plus give UK businesses enterprise-grade routing, segmentation and VPN without per-feature licensing. This guide covers editions, sizing, resilience and how to migrate from an existing firewall cleanly.
pfSense Plus vs Community Edition
pfSense Community Edition is the free, open-source build maintained by the project. pfSense Plus is the commercially supported edition that ships on Netgate hardware, with validated firmware, additional features and vendor support. For production business networks we deploy pfSense Plus on Netgate appliances so there is a supported path when something breaks at 2am.
How to size an appliance
- Internet throughput today and the circuit you expect in 24 months
- VPN throughput, which is usually the real constraint on smaller units
- Concurrent sessions, driven by user count and application mix
- Number of VLANs and physical ports, including out-of-band access
- Whether you need a high availability pair rather than a single unit
Designing for resilience
Two patterns cover most UK sites. A CARP high availability pair protects against appliance failure with state synchronisation, so sessions survive a failover. Multi-WAN protects against circuit failure, load balancing or failing over between a leased line, FTTP and 4G/5G backup. Head offices and anything running voice usually justify both.
Segmentation that stands up to an audit
- Separate corporate, guest, voice, CCTV/OT and payment traffic into VLANs
- Default-deny between zones, with documented exceptions
- Restrict management interfaces to a dedicated admin network
- Log inter-zone denies and export logs off the appliance
- Keep an owner and review date against every firewall rule
Migration checklist
- Export and audit the existing rule base, then delete rules nobody can justify
- Map VLANs, routes, NAT entries and VPN peers before touching hardware
- Rebuild policy on pfSense rather than importing accumulated drift
- Stage the appliance and test VPN tunnels out of hours
- Cut over in a planned window with the old firewall kept ready for rollback
- Back up the configuration and schedule the first rule review at 30 days
When an NGFW is the better answer
pfSense is strong on routing, segmentation, VPN and multi-WAN. If your requirement is deep layer-7 threat prevention, cloud sandboxing, SSL inspection at scale or vendor threat intelligence, a next-generation firewall from Fortinet, Palo Alto or Cisco fits better. Hybrid designs are common: pfSense at the edge of smaller sites, an NGFW where inspection earns its cost.



