01
Identify the pfSense edition and installer first
Tungsto lists pfSense without identifying Community Edition or Plus, version, installer, or support. Netgate treats the editions as distinct. Confirm edition, supported release, architecture, checksum, eligibility, and update path.
pfSense Plus activation and Netgate support can require eligibility, registration, or subscription. A generic OS selection does not include them. Check current Netgate documentation and the applicable license and trademark terms.
02
Verify network interfaces, drivers, and throughput needs
Netgate requires compatible x86-64 hardware and one or more supported NICs, while warning that minimums do not fit every environment. VPNs, intrusion detection, packet size, rules, and packages can change throughput needs.
The catalogue does not prove NIC count, chipset, drivers, or separation. Confirm them first; a public port is not evidence of separate WAN, LAN, management, sync, or private-server links.
03
Define WAN, LAN, and routing outside the OS label
Draw the traffic path before installation: gateway, management source, WAN, LAN, VLANs, prefixes, NAT, VPN peers, and downstream systems. Interface labels cannot create physical connectivity or provider routing.
An address-block description does not reveal usable addresses, gateways, VLANs, or routing for other servers. Do not place pfSense in their path until private links, routing, MAC behavior, and recovery are confirmed.
04
Preserve recovery access before changing the network
Selecting pfSense records an intended OS. Accepted, Provisioning, or Queued does not confirm installation or a working firewall. The installer formats target disks, so preserve configuration and data elsewhere. Verify media origin and checksum.
Interface or routing mistakes can remove remote access. Arrange recovery before changes. KVM and custom ISO requests are queued; neither guarantees an immediate console, mounted image, or progress view.
05
Operate and test the firewall as a customer-managed system
You manage firewall rules, access, certificates, VPN keys, packages, logging, updates, backups, monitoring, and recovery. Test the traffic path and fail safely. Tungsto does not manage pfSense or redirect other customer traffic through it.
One server is not HA. Netgate HA needs multiple nodes, CARP, synchronization, matching interfaces, addresses, and suitable connectivity. OS selection creates none of these; verify every dependency.
Direct answers
Questions before you order
Does selecting pfSense deliver a working firewall?
No. It records the intended OS. Installation, interface assignment, routing, rules, access, and validation must complete before the server can be treated as a firewall.
Can pfSense automatically route traffic for my other servers?
No. That requires a confirmed network path, routing model, interfaces or cross-connects, address plan, and recovery design. The OS choice alone provides none of them.
Is pfSense high availability included?
No. HA requires multiple compatible nodes, addressing, CARP, synchronization, suitable connectivity, matched interfaces, and failure testing. These are separate design and service requirements.