SohoLab by Conram.it
Hardware, software, infrastructure experiments and notes on systems that actually run here.

A Firewall Journey

Protecting your Lan

Over the past few years, my firewall setup has been on its own little odyssey. It’s been a mix of curiosity, necessity, and sometimes just the sheer fun of trying something new—abiding the need for a safe solution.

In 2023, I arrived at IPFire after spending time with OPNsense and MikroTik. I was tired of wrestling with interfaces that felt like they were built for a certification exam rather than for the person actually running the network. IPFire was a breath of fresh air: practical, straightforward, and not buried under layers of abstraction.

By spring 2024, I took a leap. I swapped IPFire for UniFi, chasing that promise of more automation, more built‑in “intelligence,” and a management platform that could take a bit of the day‑to‑day burden off my shoulders. At the time, I couldn’t find any other on‑premises firewall that offered that kind of unified, polished control out of the box. And for a while, it delivered exactly what I wanted.

But over time, the more I used UniFi, the more I realised it simply wasn’t going to work as expected. My requirements hadn’t changed, my network did not grow in complexity, but the reality of daily use exposed several shortcomings I couldn’t ignore:

  1. The automation that first seemed like a convenience often overrode or limited the precise control I needed.
  2. Its “intelligence” was surface‑level—good for (very) small, simple networks but not enough for detailed, policy‑driven segmentation.
  3. Firewall rules were locked behind a simplified interface that hid or abstracted critical options.
  4. VLAN‑centric design made true isolation cumbersome without workarounds.
  5. Troubleshooting tools were too shallow—summarised logs and metrics instead of the raw data needed for fast, accurate diagnosis.
  6. Device and manufacturer identification was unreliable or outright wrong, making it harder to inventory, track, and manage connected equipment accurately.

Core Requirements for My Firewall

These aren’t nice‑to‑haves; they’re dealbreakers for me:

  • Granular firewall rules at both L3 and L4
  • A policy‑first design with object‑based rules
  • No enforced cloud dependency
  • Honest, raw observability for troubleshooting
  • Flexibility to mix and match hardware vendors
  • Ability to run on my own server hardware, hence bare-metal installation of the firewall OS.

Where UniFi Fell Short for Me

  • Firewall rules abstracted behind a simplified UI
  • VLAN‑first design instead of true, policy‑driven isolation
  • Limited ability to group and manage hosts or services logically
  • Architecture that leans toward the cloud even when self‑hosted
  • Summarised logs and metrics that hide the finer details
  • Inaccurate or inconsistent device/manufacturer identification

Considering Alternatives

When it was time to move on, I didn't just jump back to IPFire blindly. I looked at pfSense, OPNsense, and others. They all have strengths—pfSense with its rich feature set, OPNsense with its modern interface. But IPFire matched my current needs without overcomplicating things, and I already knew its quirks from my time with it in 2023.

IPFire vs UniFi

IPFire setup
A picture from a typical setup of IPFire

IPFire gives me full custom L3/L4 rules, logical grouping of hosts and services, root shell access, no cloud tie‑ins, and clear, enforceable isolation policies. UniFi, while polished, limits firewall granularity, ties grouping to VLANs, hides advanced settings, and depends more on its ecosystem. Troubleshooting in IPFire means direct access to logs and counters; in UniFi, you get summaries. Device identification in IPFire is whatever I configure; UniFi's guesses are often wrong.

When it was time to move on, I didn’t just jump back to IPFire blindly. I looked at pfSense, OPNsense, and others. They all have strengths—pfSense with its rich feature set, OPNsense with its modern interface. But IPFire matched my current needs without overcomplicating things, and I already knew its quirks from my time with it in 2023.

Migration Blueprint

  1. Define zones by trust level (WAN, LAN‑core, User LAN, IoT, Guest, Services)
  2. Create host and service objects to make policy rules human‑readable
  3. Write rules that state your intent clearly and log what matters
  4. Default‑deny between zones; document every exception and why it exists

Closing Thought

I didn’t leave UniFi because it’s a bad product—it’s not. I left because, despite my initial optimism, it didn’t meet the same requirements I had from the start. Firewalls should bend to your policy, not the other way around. Whether it’s IPFire, pfSense, OPNsense, or something else entirely, the best choice is the one that matches your requirements today, with the freedom to change when tomorrow arrives.

Get IPFire, you too!