---
title: "pfSense Firewall Connectivity Pattern"
description: 'Guidance for using the STACKIT Quick Deployment pfSense firewall as the central control point in hub-and-spoke network area architectures on the STACKIT Cloud.'
sidebar:
  badge:
    text: "STACKIT"
    variant: success
scfAsset:
  managed: false
  category: "software"
  external: true
  tags: ["design-and-mobilize", "landing-zone", "network", "network-area", "routing", "firewall", "vpn"]
  maintainers:
    - user: "lukas.weberruss"
      role: true
      website: true
source_url: "https://framework.stackit.cloud/migration/assetcontainer/stackit/pfsense-firewall-connectivity-pattern/"
source_file: "docs/migration/assetcontainer/stackit/pfsense-firewall-connectivity-pattern.mdx"
---

## Overview

This asset describes how the STACKIT Quick Deployment pfSense firewall can be used as a reusable connectivity control point in migration landing zones.

It is especially relevant for **hub-and-spoke** network designs where multiple projects connect through a central security and routing layer.

## Primary use context

- **Network Area governance**: A shared enterprise network is centrally governed and projects are attached in a controlled way.
- **Routing Tables design**: Routing behavior between projects is explicitly steered through approved route patterns.
- **Connectivity controls**: Security domains, inspection points, and north-south / east-west flow controls are defined before onboarding workloads.

## Product reference

- **STACKIT Quick Deployments pfSense firewall**: <LinkChip href="https://docs.stackit.cloud/products/quick-deployments/pfsense-firewall/">Documentation</LinkChip>

Review the STACKIT deployment inputs before using the appliance in a migration landing zone.
Protect service-account key files and review the required permissions against your automation
policy. Deployment preparation does not replace route design or firewall-rule approval.

> From the STACKIT docs: [Setup pfSense › Preparation](https://docs.stackit.cloud/products/quick-deployments/pfsense-firewall/how-tos/setup-pfsense/#preparation) (Source updated 27.07.2026, copied 06.10.2026)

For the pfSense installation please download the GitHub repository containing the deployment scripts for Terraform.

Terraform is going to create these networks `vpc_network` and `wan_network` the subnets for the VPC and WAN network get provisioned automatically.

In the file `[01-config.tf](http://01-config.tf/) are` settings such as the Availability Zone, Network ranges or the VM size (Machine Type) which can all be changed.

Configuration options:

- Project ID (required)
- Availability Zone
- Machine Type
- Network Range & IP Address

To create a service account and grant admin permissions refer to the [Service account documentation](https://docs.stackit.cloud/platform/access-and-identity/service-accounts/).

You also need to [Create a service account key](https://docs.stackit.cloud/platform/access-and-identity/service-accounts/how-tos/manage-service-account-keys/#create-a-service-account-key-generate-new-key-pair) as described and save the output as JSON into the secrets.json (overwrite all the content in the file).

The versions can be retrieved from the image repository: https://pfsense.object.storage.eu01.onstackit.cloud/index.html

## When to use

- **Central firewall requirement**: You need an explicit inspection and control point between spokes and shared services.
- **Migration phase isolation**: Different migration waves require controlled inter-project communication.
- **Hybrid integration path**: Connectivity to external environments must be structured and auditable.

## Implementation note

Use this asset as a connectivity building block within the broader landing zone network architecture, together with Network Area, Routing Tables, DNS, and VPN standards.
