The Gateway vs pfSense and OPNsense
Short answer
Section titled “Short answer”Choose pfSense or OPNsense for a mature, general-purpose firewall appliance with a broad UI and package ecosystem. Choose The Gateway when the central problem is programmable per-device routing across multiple privacy paths on Linux.
Choose pfSense or OPNsense when
Section titled “Choose pfSense or OPNsense when”- You need a conventional edge firewall with extensive interface, VLAN, NAT, HA, and package controls.
- You depend on their established ecosystem, documentation, or support options.
- You require an open-source base.
- Your team already operates one successfully and does not need The Gateway’s policy model.
Choose The Gateway when
Section titled “Choose The Gateway when”- Devices and groups need different tunnel, bridge, DNS, and direct-routing policies.
- Protected paths must fail closed and reconcile after restarts.
- Multiple WireGuard or OpenVPN exits need per-connection splitting.
- Policies must be pushed or pulled across several Linux gateways.
Coexistence
Section titled “Coexistence”The products can be layered: pfSense or OPNsense can remain the perimeter firewall while The Gateway serves a routed segment that needs its privacy-policy model. Keep ownership of DHCP, NAT, and default routes unambiguous and test failure modes at the boundary.
Important trade-off
Section titled “Important trade-off”pfSense and OPNsense are broader and more mature firewall platforms. The Gateway is private, Linux-only software with a smaller ecosystem. It should be selected for its specific policy and privacy-routing capabilities, not as an automatic replacement for a working firewall.
Sources and next steps
Section titled “Sources and next steps”- pfSense documentation — official Netgate documentation.
- OPNsense documentation — official OPNsense documentation.
- The Gateway comparisons overview — capability matrix and other alternatives.
- Threat model — intended protections and non-goals.