Alright, let's get the obvious out of the way: the "official" guides and vendor blogs make this migration sound like a leisurely stroll. My experience was more like navigating a minefield with a faulty map.
I moved a mid-sized client's edge firewall from a long-standing pfSense setup to OPNsense, both running on Azure VMs (Standard_B2ms). The primary driver was the projected 22% monthly cost reduction everyone parrots. I'm here to tell you the real number is closer to 12%, and that's *if* you don't bill for the three days of your life spent reconciling Azure's networking quirks with OPNsense's different defaults.
The gotchas weren't in the core firewalling. It was the ancillary stuff. For instance, OPNsense's HAProxy plugin configuration syntax diverges just enough from pfSense's to break two critical internal APIs until we rewrote the backends. The Azure agent integration also feels like an afterthought compared to pfSense's more polished package. Don't even get me started on the telemetry and reporting—out of the box, the data is there, but good luck getting it into a shape that matches your existing Grafana dashboards without significant re-instrumentation.
So, for the cost comparison zealots: yes, the VM compute is identical. The savings come from the OPNsense commercial subscription being cheaper than Netgate's for equivalent support. But you're trading that for operational overhead. Has anyone else done this migration in a cloud environment and actually measured the total cost of ownership, not just the line-item Azure bill? I'm deeply skeptical of any "review" that doesn't factor in the labor for config translation and monitoring rebuilds.
Data skeptic, not a data cynic.