
VLOG Thursday 503: pfsense, UniFi and the "Cloud", Homelab Q&A
Source: YouTube · Lawrence Systems · published Aug 27, 2026 · 1:48:08
Tom discusses why he's producing fewer pfSense videos, noting the community edition hasn't changed much in years while pfSense Plus is moving toward a closed-source, feature-split model 2:04-2:25. He argues that for many businesses—especially those managing distributed locations—UniFi's unified ecosystem without recurring licensing has become a more practical choice than standalone firewall solutions 7:22-8:05. He also emphasizes that endpoint security, not firewalls, is where modern threats are actually handled, and that the "move fast and break things" mentality is wrong for infrastructure 13:00-13:15.
Key Takeaways:
• pfSense Community Edition remains a solid open-source packet-pushing firewall, but the new Nexus UI and features like Core DNS are exclusive to the closed-source pfSense Plus, creating an effective fork 5:59-6:43.
• UniFi's edge-first architecture keeps the control plane local, meaning if the cloud goes down, firewalls keep passing packets—addressing a common criticism about cloud dependency 15:14-16:03.
• Firewalls alone don't stop modern threats; encrypted traffic limits their effectiveness, and most attacks now originate through browsers and endpoints, making EDR tools far more critical 12:05-12:53.
• Enterprise firewall pricing is inflated by sales pipelines, commissions, market development funds, and reseller lock-in—not just product development costs 44:00-46:06.
• Tom recommends revisiting products rather than forming permanent opinions based on first impressions, noting UniFi corrected its earlier cloud-registration requirement and now explicitly documents its edge-first philosophy 1:34:16-1:38:32.
Tom encourages a pragmatic, goal-oriented approach to tool selection—whether for firewalls, hypervisors, or hardware—rather than tribal loyalty to any single platform.
Sources:
- 2:04-2:25 Tom explains why he's making fewer pfSense videos and the Plus/Community split
- 5:59-6:43 New Nexus UI and Core DNS are pfSense Plus-only, not in Community Edition
- 7:22-8:05 Client with 2,000 locations moving to UniFi to escape subscription costs
- 12:05-12:53 Why endpoint security matters more than firewall inspection with encrypted traffic
- 15:14-16:03 UniFi's edge-first architecture keeps firewalls working when cloud is down
- 44:00-46:06 How sales commissions, MDF, and reseller lock-in inflate enterprise firewall pricing
- 1:34:16-1:38:32 UniFi's edge-first philosophy page and why revisiting products matters
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 2 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right, it says it's live. Oh, it it worked on the first click. Yay. [laughter] It's the little things in life, like when it works on the first click. I like that. Welcome to Vlog Thursday number I didn't pull that up. I'm pretty sure it's 502. 503. It was one of those two. I was close. I was in the 500s. So, welcome. Uh PFSense. Boy, I was recording a video on PFSense. I had a lot of things come up. Therefore, I got distracted and did not finish said video on pfSense. Um, I'm trying to decide if I'll redo the video. And I might. Sometimes I actually make videos and redo them before they ever get published. You're welcome because I realized I may have babbled a bit. And as much as I enjoy live streams, there is a much more concise version of me that makes videos. So, I've thought about …