Skip to content
Beta

pfSense Firewall Connectivity Pattern

Last updated on

This asset describes how the STACKIT Quick Deployment pfSense firewall can be used as a reusable connectivity control point in migration landing zones.

It is especially relevant for hub-and-spoke network designs where multiple projects connect through a central security and routing layer.

  • Network Area governance: A shared enterprise network is centrally governed and projects are attached in a controlled way.
  • Routing Tables design: Routing behavior between projects is explicitly steered through approved route patterns.
  • Connectivity controls: Security domains, inspection points, and north-south / east-west flow controls are defined before onboarding workloads.

Review the STACKIT deployment inputs before using the appliance in a migration landing zone. Protect service-account key files and review the required permissions against your automation policy. Deployment preparation does not replace route design or firewall-rule approval.

From the STACKIT docsSetup pfSense › PreparationSource updated 27.07.2026 · copied 06.10.2026

For the pfSense installation please download the GitHub repository containing the deployment scripts for Terraform.

Terraform is going to create these networks vpc_network and wan_network the subnets for the VPC and WAN network get provisioned automatically.

In the file [01-config.tf](http://01-config.tf/) are settings such as the Availability Zone, Network ranges or the VM size (Machine Type) which can all be changed.

Configuration options:

  • Project ID (required)
  • Availability Zone
  • Machine Type
  • Network Range & IP Address

To create a service account and grant admin permissions refer to the Service account documentation.

You also need to Create a service account key as described and save the output as JSON into the secrets.json (overwrite all the content in the file).

The versions can be retrieved from the image repository: https://pfsense.object.storage.eu01.onstackit.cloud/index.html

What is this?

This section is copied from the STACKIT docs automatically, several times a day. It cannot be changed here. Changes belong in the STACKIT docs.

  • Central firewall requirement: You need an explicit inspection and control point between spokes and shared services.
  • Migration phase isolation: Different migration waves require controlled inter-project communication.
  • Hybrid integration path: Connectivity to external environments must be structured and auditable.

Use this asset as a connectivity building block within the broader landing zone network architecture, together with Network Area, Routing Tables, DNS, and VPN standards.

Asset historyActive 5 of the last 12 weeksTMUpdatedNo updates · 1 bar = 1 week i
Maintainers
TMTobias M.Head of STACKIT Cloud Framework · STACKITOwnerActive 12 of the last 12 weeks · 168 updatesSTACKITwww.linkedin.com/in/tobias-müller-011304172LWLukas WeberrußHead of STACKIT Cloud Migration Framework · STACKITOwnerActive 10 of the last 12 weeks · 47 updatesSTACKITwww.linkedin.com/in/lukas-weberruß-a360b081Contributed in STACKIT
Show full history (4 more)