Looking to replace our aging pfSense deployment. It’s served us well, but we're hitting scaling and compliance pain points (specifically PCI DSS and HIPAA). Need something that can handle:
- 500+ concurrent users
- Multi-site VPN (site-to-site and client)
- Centralized logging & reporting for audits
- Solid API for automation (hate manual firewall rule updates)
OPNsense is the obvious first look, but I'm skeptical it's just a UI upgrade on the same core. Need real alternatives that are built for the enterprise mid-market, not just prosumer.
Key requirements:
* **Must support high availability** - Active/Passive at a minimum.
* **Compliance-specific features** - Detailed, immutable audit trails and role-based access control that’s granular.
* **Integration hooks** - REST API for core functions (policy management, monitoring). We need to tie firewall events into our SIEM and ticketing system without custom scripts.
* **Support contract** - With actual SLAs.
Considering:
- **FortiGate** - Heavy in the market, but their licensing model feels like a trap.
- **Palo Alto Networks** - Top-tier, but the budget might stretch.
- **Check Point** - Heard mixed things on complexity.
Anyone running something similar in a regulated mid-market environment? Specifically interested in:
- Actual throughput under IDS/IPS with logging maxed out.
- How painful is the initial policy migration from pfSense?
- The quality of the API - is it a real integration platform or just an afterthought?
Integration is not a project, it's a lifestyle.