Best Hardware for OPNsense in 2026: Protectli and Mini-PCs
How to size CPU, NICs, and RAM for OPNsense in 2026, with picks across three tiers: fanless Protectli vaults, mini-PCs, and refurbished enterprise gear.
Affiliate disclosure: Some links below are Amazon affiliate links. We may earn a small commission at no extra cost to you. Hardware is selected based on performance data, not commission rates.
OPNsense runs on any x86-64 hardware with two NICs. The question is which hardware fits your throughput needs, noise tolerance, power budget, and expansion plans. This guide spans the full range, including used NUCs, rackmount servers, and refurbished enterprise gear. If you have already settled on a fanless mini PC, the narrower best mini PC for an OPNsense homelab covers current-generation boxes model by model.
At a glance
| Box | CPU | NICs | Cooling | Suricata inline headroom | Typical price | Best for |
|---|---|---|---|---|---|---|
| Protectli FW4C | J3160, 4c @ 1.6 GHz | 4x Intel GbE | Fanless | ~250 Mbps | $180–220 used | Sub-500 Mbps WAN, no IPS |
| Used Celeron NUC | Celeron, gen 7–9 | 1x onboard + add-in | Fan | Light duty | $80–150 | Cheapest route, extra I/O work |
| Protectli VP2420 | J6412, 4c @ 2.0 GHz | 4x Intel 2.5GbE (i225) | Fanless | ~600 Mbps | ~$350 new | 1 Gbps WAN with Suricata on |
| Topton/Cwwk N5105 | N5105, 4c | 4x Intel, GbE or 2.5GbE by SKU | Quiet fan | ~500–600 Mbps | $200–260 | Value multi-gig, tolerant of fan noise |
| Protectli VP4630 | i3-10110U, 2c @ 4.1 GHz turbo | 6x Intel 2.5GbE | Fanless | 1 Gbps+ | $600+ | Power homelab or small office |
| Refurb Supermicro | Xeon, varies | 10GbE SFP+ / add-in | Fan, loud | High | Varies used | 10GbE, ECC, lab experimentation |
Read the table by column, not by row: NIC vendor decides whether inline IPS runs at all, cooling decides whether the box can live in a room you occupy, and the Suricata column is the number that actually separates the tiers. Everything below expands on those three.
The Suricata figures are planning estimates for a mid-sized ET Open ruleset, derived from CPU class and the published specifications listed under each box — not bench measurements, and not a promise. Ruleset size swings them by a wide margin: trimming to high-confidence categories can roughly double what a given box sustains, and turning on every category can halve it. Treat the column as tier ordering, and size with headroom.
How to size it (do this before buying)
Work backwards from three numbers:
- WAN throughput. Match to your ISP plan, with headroom. Plain NAT routing is light — even low-power Atom-class CPUs route a gigabit. The cost explodes when you add inline IDS/IPS with Suricata, which is single-flow-CPU-bound and can cut usable throughput by half or more on a given box.
- Feature load. Plain firewall + DHCP + DNS is trivial. Add inline Suricata, a VPN with many concurrent tunnels, traffic shaping, or Netflow/reporting, and CPU and RAM demands climb. Be honest about what you’ll actually enable.
- Single-thread performance. OPNsense’s packet path and Suricata benefit more from strong single-thread performance and AES-NI than from many slow cores. A 4-core chip with good per-core speed beats an 8-core chip of weak cores for this workload.
A practical rule: size for the feature set you’ll enable within a year, not just today’s link speed. Under-provisioning shows up as latency under load and a saturated CPU exactly when you need the firewall most.
NIC choice matters more than the CPU badge
Use Intel NICs (igb/em/ix drivers). Realtek NICs work for casual use but have a long history of throughput and stability issues under sustained load on FreeBSD, and inline Suricata (netmap/IPS) often won’t run on them. If a mini-PC only ships Realtek, budget for an Intel-based add-in or pick a different box. Confirm AES-NI is present (it is on essentially all modern Intel/AMD) for fast VPN.
If the box you are adapting is a desktop or a server with a free PCIe x8 slot and you want 10GbE over copper, the Intel X550-T2 is the reference dual-port choice: a genuine Intel part on the mature ix driver, which is the difference between a NIC that FreeBSD treats as a first-class citizen and one that produces forum threads. It is the wrong purchase for a fanless appliance — there is no slot to put it in — and overkill if your LAN is gigabit end to end. For a 1 Gbps repurpose, any Intel igb-class dual or quad card does the job for a fraction of the price.
Tier 1: Entry-level (sub-$200, up to ~500 Mbps IDS-off)
Protectli FW4C (~$180–220 used)
- CPU: Intel J3160 (quad-core, 1.6 GHz, 6W TDP)
- NICs: 4×Intel GbE
- RAM: 4–8 GB DDR3L
- Storage: mSATA SSD slot
- Fan: Fanless
- Verdict: Best entry point. Runs cool and quiet. IDS/IPS (Suricata) will saturate the CPU around 250 Mbps on ET Open rules. Fine for <500 Mbps WAN without IPS.
Used Intel Celeron NUC (Gen 7–9) (~$80–150)
- Works but requires an external USB NIC or PCIe NIC adapter. More I/O hassle than a purpose-built device.
Tier 2: Mid-range (200–400, up to ~940 Mbps IDS-off, ~600 Mbps IDS-on)
Protectli VP2420 (~$350 new)
- CPU: Intel Celeron J6412 (quad-core, 2.0 GHz, 10W TDP)
- NICs: 4×Intel 2.5GbE (i225)
- RAM: 8 GB DDR4 (upgradeable to 16 GB)
- Storage: M.2 NVMe + 2.5” SATA slot
- Verdict: Significant leap from the J3160. 2.5GbE on all ports future-proofs for multi-gig WAN. Suricata ET Open handles ~600 Mbps comfortably.
Topton/Cwwk N5105 mini-PC (~$200–260)
- Intel N5105, 4×Intel GbE or 2.5GbE, fan-cooled but quiet.
- Slightly louder than Protectli but significantly cheaper for equivalent throughput.
Tier 3: High-end (500+, 1 Gbps+ with IDS, 10GbE inter-VLAN)
Protectli VP4630 (~$600+)
- CPU: Intel Core i3-10110U (dual-core, 4.1 GHz Turbo)
- NICs: 6×Intel 2.5GbE
- RAM: up to 64 GB DDR4
- Storage: dual M.2 NVMe
- Verdict: Handles 1 Gbps IDS/IPS throughput. Overkill for most homes; appropriate for a power homelab or small office.
Refurbished Supermicro SuperServer (used)
- Overkill in power draw (35–65W idle) but gives you 10GbE SFP+ and ECC RAM. Worth it if you’re also running pfSense BGP/OSPF experiments.
Key buying criteria
| Criterion | Recommendation |
|---|---|
| WAN speed | Match NIC to your ISP tier (GbE for ≤1G, 2.5GbE for multi-gig) |
| IDS/IPS | J6412 minimum if enabling Suricata inline |
| Power | Fanless < 10W for always-on closet install |
| Expansion | Pick hardware with extra NIC ports for future DMZ/IoT VLANs |
| Used vs new | Used FW4C is the best value entry — OPNsense doesn’t need warranty |
The power number nobody checks
A firewall runs every hour of every day, so idle draw is the spec that compounds. A fanless 10W appliance costs roughly a fifth of what a 50W refurbished server costs to run, and over a five-year life that gap can exceed the price difference between the two boxes. Vendor “TDP” figures describe the CPU, not the system, and say nothing about the PSU’s efficiency at the 10–20% load a router actually sits at.
The honest way to settle it on hardware you already own is to measure at the wall with a plug-in meter such as the Kill A Watt P3 P4400, which reports watts and accumulated kWh so you can convert directly against your utility rate. Measure the candidate box idle, then again with Suricata enabled and traffic flowing — the delta between those two numbers is what enabling IPS actually costs you per year, and it is usually smaller than people expect on modern silicon.
RAM and storage guidance
- RAM: 4 GB is a workable floor for routing + basic services. Run Suricata, Zenarmor, or heavy reporting and you want 8 GB; 16 GB is comfortable headroom and cheap. If you use the ZFS install (recommended for boot environments/rollback), give it more RAM rather than less.
- Storage: use a real SSD (SATA or NVMe), not a USB stick or low-endurance SD card. Suricata, Netflow, and the reporting database write continuously and will wear out cheap flash. 20 GB+ is sensible if you enable logging/reporting; the OS itself is small. ZFS on a single SSD is fine and gives you snapshot/rollback before firmware updates.
Buying used safely
Used Protectli/mini-PC boxes are the best value in homelab firewalls. A quick checklist:
- Confirm the exact NIC chipset (ask the seller or check the model spec) — you want Intel, not Realtek.
- Verify the unit accepts the RAM/storage you plan to add (DDR generation, M.2 vs mSATA, SATA bay).
- Check it has the port count for future VLAN/DMZ growth — adding a NIC later is often impossible in a fanless case. A trunk to a managed switch is the alternative, and the OPNsense VLAN configuration guide covers what that costs you in tagging complexity.
- Factory-reset and re-flash OPNsense yourself; never trust a pre-installed firewall image from a stranger.
When this is the wrong purchase
Don’t buy a high-end 6-NIC box “to be safe” if you have a 300 Mbps connection and won’t run IPS — a quiet fanless dual/quad-core unit will idle near silent, sip power 24/7, and do the job. Conversely, don’t try to run inline Suricata at multi-gig on an entry Atom box; it will be the bottleneck and you’ll blame the software. And if you only need basic routing for a small flat network, repurposing an existing low-power PC with an Intel dual-NIC card is often the most economical path — buy purpose-built hardware when fanless operation, low idle power, port density, or appliance form factor genuinely matter to you. One repurpose that does not work is the ARM single-board computer sitting in a drawer: OPNsense publishes amd64 images only, and what a Raspberry Pi can and cannot do for an OPNsense build covers the supporting roles it still fills.
Two adjacent decisions worth settling before you spend anything. If you want a box built for the job rather than adapted to it, the best OPNsense hardware appliance for home covers purpose-built Protectli and Deciso units and what separates them from a repurposed mini PC. And if the platform itself is still open, OPNsense vs pfSense for homelab is the decision to make first, because it changes which hardware compatibility lists apply to you.
Comparing OPNsense vs pfSense hardware compatibility? FirewallCompare hardware guide has side-by-side appliance spec sheets.
Related
Best OPNsense Hardware Appliance for Home: Protectli, Deciso, and What to Skip
The best OPNsense hardware appliance for home use comes down to NIC chipset, AES-NI, and honest sizing. Here are the purpose-built picks across three price tiers.
Best Mini PC for OPNsense Homelab 2026: NIC and CPU Sizing
Choosing the best mini PC for an OPNsense homelab comes down to dual Intel NICs, AES-NI, and enough CPU headroom for Suricata. Here is what works.
OPNsense on Raspberry Pi: What Actually Works
OPNsense ships amd64-only images, so it will not boot on a Raspberry Pi. Here is what the Pi can still do for your firewall, and what to buy instead.