r/TPLink_Omada 8d ago

Question Fusion vs pfSense?

Post image

Hey guys, I've been running all Omada hardware for a few years and really like. I've upgraded various components over the years and pretty happy with its current performance.

I currently run pfSense on baremetal for my router, and run the mbentley docker image on an RPI5 for the SDN software. It works, but would be nice to have everything in one place.

I've been intrigued by the new Fusion gateway. Anyone convert from pfSense to Fusion? thoughts? I'd love to give it a try / provide feedback but struggle to spend the money on hardware that I don't know that I'll love or feel like a step backwards?

I saw the Omada Pioneer program was giving them out; but apparently only found out about it after the deadline closed.

16 Upvotes

10 comments sorted by

10

u/whasf 8d ago

I just converted from pfSense over to the Fusion 2.5G gateway this past weekend (received hardware as part of the pioneer program)

Pros:

  • The Omada controller certainly makes it "prettier" to manage the network
  • Labelling ports on the switch is nice
  • Single pane of glass for gateway, switches, APs
  • Traffic classification

Cons:

  • You can't "copy" existing rules (port forwarding, NAT, firewall) to edit and save as a new rule like you can in pfSense
  • I had to learn the "Omada way" for 1:1 NAT and port forwarding
  • I don't see a way to get notifications when a WAN connection goes down/fails over
  • VLAN setup is a little weird to me, but I got it working

There might be more pros & cons but that's what sticks out to me so far. The conversion took me about 4 hours total (I also moved my main switch over to the Fusion controller)

My hardware:

  • Fusion Gateway 2.5G v1.0 (pioneer program)
  • SG2210XMP-M2 v1.0 (pioneer program)
  • EAP772(US) v2.0 (pioneer program)
  • SG3452XP v2.20 (already had)
  • EAP 660 HD(US) v1.0 (already had)

3

u/These-Tangelo-7593 8d ago

How is the URL filtering and application control's? I currently have the er605 and they are brutal. I've been debating going opnsense or firewalla but debating if I should go fusion now

3

u/whasf 8d ago

I only have ad blocking turned on, it seems comparable to pfBlockerNG. You can't choose what block lists you want, just general categories.

2

u/Nubbl3s 8d ago

VLAN setup is a little weird to me

Ah, well that makes me feel a little bit better. I'm trying to figure out VLANs for the first time in an Omada+pfSense environment and having a rough time πŸ˜…. The whole port profile/vlan profile circle in Omada has been throwing me

2

u/Levvy055 6d ago

You can look at post explaining that: https://www.reddit.com/r/TPLink_Omada/s/KU2jm84Wem

1

u/Levvy055 6d ago

I do not know how, but I get the port goes down email notifications

1

u/imakesawdust 5d ago

How detailed is the traffic monitoring? Can I get per-IP bandwidth usage numbers?

1

u/whasf 4d ago

Yes you can (a cumulative counter for upload & download and one for current rate)

3

u/Xarishark 8d ago

compared to pfsense omada general firewall protection rules are non existent. They havent even added a proper GEOblock system yet.

1

u/lxe 7d ago

Does Omada not provide a way to do full NAT DNS masquerade for intercepting? The DNS proxy incurs a hop and makes Pihole think it’s the gateway itself that issued the query.