Softwr

Cloud · head to head

Infracost vs pfSense

Infracost logo

Infracost

Cloud

Cloud cost estimates in pull requests, with governance in the paid tier

From
Free
Rated
-
pfSense logo

pfSense

Networking

Open source firewall software with a free Community Edition and a separate commercial Plus edition sold by Netgate

From
Free
Rated
-

The short version

  • Each has a real cost: Infracost usage-based resources such as object storage, serverless functions and data transfer have no cost without monthly usage figures supplied by hand, and the documentation warns plainly that engineers otherwise read them as free.; pfSense pfSense CE and pfSense Plus are not simply the same software with a support contract layered on top; Plus is a separately developed edition with its own feature set, and moving between them is a migration, not a toggle
  • They diverge on capability: Infracost covers Pull request cost diffs, pfSense covers Stateful firewall and NAT.
  • Prices and features above were last checked on 1 September 2026.

Where they differ

Only the attributes on which Infracost and pfSense actually diverge.

Attributes where Infracost and pfSense differ
AttributeInfracostpfSense
Pricing modelFree open source tool, then per month by run volumeOpen source Community Edition, free; commercial Plus edition sold separately by Netgate
PlatformsWeb, macOS, Linux, Windows, DockerLinux
CategoryCloudNetworking

Identical on both: starting price (Free), free tier (Yes), user rating (Not yet rated).

What each one covers

Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.

Only in Infracost

  • Pull request cost diffs
  • Multi-format parsing
  • Apache-2.0 CLI
  • FinOps policies
  • Automated remediation
  • IDE integration

Only in pfSense

  • Stateful firewall and NAT
  • VPN support
  • Traffic shaping and QoS
  • Package ecosystem
  • CE and Plus editions

What people use each for

The jobs each tool is most often brought in to do.

Infracost

  • Teams that want an expensive infrastructure change questioned at review rather than discovered on an invoicenot pfSense
  • Platform groups enforcing tagging so cloud spend can be attributed to a team at allnot pfSense
  • Organisations adopting FinOps practice without buying a full cloud management platformnot pfSense
  • Engineers who want a cost figure in the editor while writing the Terraformnot pfSense

pfSense

  • A home user or small business wanting a free, fully-featured firewall on commodity hardware with no licence costnot Infracost
  • A business wanting an integrated firewall appliance with vendor support, typically buying a Netgate appliance bundled with pfSense Plusnot Infracost
  • A team wanting to evaluate advanced features like real-time threat intelligence before committing to Netgate hardware or a Plus migrationnot Infracost
  • An organisation replacing an expensive commercial firewall with an open source alternative while retaining the option to add commercial support laternot Infracost

Where each one falls short

Documented limitations, not opinions. Every one is a constraint you would hit in normal use.

Infracost

  • Usage-based resources such as object storage, serverless functions and data transfer have no cost without monthly usage figures supplied by hand, and the documentation warns plainly that engineers otherwise read them as free.
  • Splitting production from non-production usage assumptions is not supported in the free usage file, which the docs attribute to a missing project filter, so that separation requires the paid product.
  • The step from 250 to 1,000 dollars a month is large and the Cloud tier includes only ten admin seats, with developer seats charged at a figure that is not published, so the cost for a large organisation cannot be computed from the pricing page.
  • Estimates are list price. Negotiated agreements, committed use discounts and reserved instance economics require SKU-level overrides available only on Enterprise, so the number in the pull request is not the number on the bill.
  • The share of the product covered by the Apache-2.0 licence is shrinking. Checks, automated fixes, policies and agent integrations are all hosted-only, so the permissive licence increasingly protects the estimation engine rather than the product.

pfSense

  • pfSense CE and pfSense Plus are not simply the same software with a support contract layered on top; Plus is a separately developed edition with its own feature set, and moving between them is a migration, not a toggle
  • Running Plus on non-Netgate hardware depends on Netgate's current migration terms, which have changed over time, so a buyer planning to use white-box hardware with Plus should verify current eligibility rather than assume it works as it did previously
  • CE has no official vendor support channel; a business relying on it for production firewalling without a support contract is self-supporting on community forums
  • Some newer features and threat intelligence integrations are Plus-only, so CE users do not get feature parity going forward even though both editions remain under active development
  • Netgate's own appliance pricing and the terms of the CE-to-Plus migration path are not always clearly presented in one place, requiring some digging to understand the real total cost of a Plus deployment on non-Netgate hardware
  • As with any self-managed firewall, security depends on the operator applying updates and correctly configuring rules; there is no managed security operations layer included even in Plus

Pricing, plan by plan

Infracost

Free
  • FreeFree
    • 1,000 runs a month
    • Terraform, CloudFormation and CDK estimates
    • Community support
  • Starter$250/month
    • 10,000 runs a month
    • Email support
  • Cloud$1000/month
    • Ten admin seats, developer seats charged separately
    • FinOps policies and cost guardrails
    • Dashboards and audit trails
  • Enterprise$undefined/year
    • SKU-level price overrides for negotiated rates
    • Business unit reporting
    • SSO with SAML group mapping

pfSense

Free
  • pfSense CEFree
    • Full firewall and routing functionality
    • No vendor lock-in to hardware
    • Community support
  • pfSense Plus (via Netgate appliance)$undefined/one-time
    • Bundled with Netgate hardware appliances from around $189
    • Threat intelligence feeds
    • Certified support tiers

Which should you pick?

Choose Infracost if

  • You need pull request cost diffs.
  • You want to start without paying.
  • You work on Web, macOS, Linux, Windows, Docker.
  • You also want multi-format parsing.

Choose pfSense if

  • You need stateful firewall and nat.
  • You want to start without paying.
  • You work on Linux.
  • You also want vpn support.

Questions people ask

Is Infracost or pfSense better?
Neither clearly leads. Infracost starts at Free and pfSense at Free, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
Which is cheaper, Infracost or pfSense?
Infracost starts at Free and pfSense at Free.
Does Infracost or pfSense run on more platforms?
Infracost runs on Web, macOS, Linux, Windows, Docker. pfSense runs on Linux.
Can I use Infracost for free?
Both have a free tier, so you can try either at no cost before committing.
What is Infracost best used for?
Infracost is most often used for teams that want an expensive infrastructure change questioned at review rather than discovered on an invoice, platform groups enforcing tagging so cloud spend can be attributed to a team at all, organisations adopting finops practice without buying a full cloud management platform, engineers who want a cost figure in the editor while writing the terraform. Of those, teams that want an expensive infrastructure change questioned at review rather than discovered on an invoice and platform groups enforcing tagging so cloud spend can be attributed to a team at all are not what pfSense is typically brought in for.
What can Infracost do that pfSense cannot?
Infracost covers Pull request cost diffs, Multi-format parsing, Apache-2.0 CLI, FinOps policies. pfSense covers Stateful firewall and NAT, VPN support, Traffic shaping and QoS, Package ecosystem.

Answered from the vendors’ own pages

Infracost: Is the open source version genuinely useful on its own?

Yes, for estimation. It parses your definitions and produces breakdowns and diffs locally. What it does not do is comment on pull requests, enforce policy or report across an organisation, all of which are hosted-only.

pfSense: What is the difference between pfSense CE and pfSense Plus?

CE is the free, open source edition installable on any compatible hardware; Plus is a commercial edition from Netgate with additional features and support, typically bundled with Netgate appliances.

Infracost: Will the estimate match my cloud bill?

No. It is list price. Committed use discounts, enterprise agreements and reserved instances need SKU-level overrides that sit in the Enterprise tier.

pfSense: Can I run pfSense Plus on my own hardware?

It is possible through a migration from a CE installation via Netgate's official channel, but the terms and availability of that path have changed over time and should be confirmed directly with Netgate.

Infracost: Why do my S3 and Lambda resources show no cost?

Usage-based resources need monthly usage values supplied in a usage file or defined centrally. Without them they estimate at zero, which is the documented behaviour and the most common way the tool misleads.

pfSense: Is pfSense CE really free with no catch?

Yes, CE has no licence fee and no hardware lock-in, though it comes with community rather than vendor support.

Infracost: Has the licence ever changed?

No. The command line tool has been Apache 2.0 throughout, with no Business Source or AGPL episode, which is unusual in this category.

Infracost: What is a run?

Not defined on the public pricing page, and the run allowance is what separates the free and Starter tiers, so establish the definition before choosing between them.

Share

Related pages

Other head to heads