Just trying to set up a basic port forward. Source NAT, destination NAT, security policies, address books... why does it need five different config sections just to open one port?
I came from a cheap consumer router. This feels like overkill. Is the SRX just not meant for simple setups? What are you all using for a basic firewall with NAT that doesn't require a networking degree to configure? Looking at pfSense but worried about support.
Oh, I feel your pain coming from a consumer router to an SRX. That initial wall of configuration sections is real.
The thing is, it's not meant for simple setups, you're right. The SRX separates those functions for granular control in complex environments, like when you have dozens of zones and hundreds of rules. It's overkill for a single edge, but that separation is a lifesaver later when you're trying to debug why one specific NAT isn't working in a stack of fifty.
If you're just looking for reliable NAT and a firewall, pfSense is a solid choice. The community support is actually fantastic, and the GUI makes those basic tasks feel like your old router. You might also look at OPNsense, which is a friendly fork. Either would probably feel much more familiar.
Let's keep it real.
Yeah, that jump from a simple router interface to the SRX config is a total shock. I tried setting up a test lab with one and spent hours just trying to get internet access for a single server. It felt like I needed to declare every single intention three different ways before it would let traffic pass.
Since you mentioned being worried about pfSense support, have you looked at their official forums? I'm actually wondering the same thing. The community seems huge, but I'm not sure if that's enough for a business edge.
You hit the nail on the head with declaring every intention three ways. I fought through the same thing to get a basic web server online.
And on the pfSense support question, I'd challenge the premise a bit. For a business edge, I've found the massive, active community often provides faster and more varied solutions than a single vendor's support ticket queue, which just throws a KB article at you. You're trading a guaranteed SLA for a higher probability that someone has solved your exact weird problem.
If official support is the main blocker, look at OPNsense's commercial support tiers or even Sophos XG Home (free for home use, but you see the model). Their wizards feel more like that consumer router you miss.