pfSense hardware 2023 (3 router recommendations) (2024)

This article was last updated onDecember 29, 2022

We sell quite a lot of open-source hardware. Most of our customers are fans of pfSense, the most popular open-source operating system for routers. The question we often get is, "What hardware should I get for pfSense?".

The hardware recommendation will depend on your needs. For example, your hardware needs are lower if you are using pfSense "just" as a router or firewall without more advanced packages. On the other hand, if you need to run your traffic through a VPN tunnel, the CPU needs to be able to handle it. If you need to use IDS (Intrusion Detection) or IPS (Intrusion Prevention), such as Snort or Suricata, you will want to have more memory.

pfSense 2.6 hardware requirements

Not everyone is the same, but there are some common requirements that any hardware must fulfil.

  • CPU should support AES-NI
  • CPU must be powerful enough to route your internet traffic
  • RAM - you must have enough for the packages you want to run.
  • NICs - LAN ports should be coming from Intel. pfSense still doesn't perform great with Realtec Network Interfaces.
  • WiFi - pfSense supports a minimal number of WiFi adapters. If you plan on using WiFi, make sure you get the right adapter.

If you must use older VPN technology, such as OpenVPN or IPSec, you will want a CPU with AES-NI support to improve cryptography performance.

What is AES-NI?

AES-NI (AES New Instructions) is a new encryption instruction set baked right into the CPU that dramatically speeds up cryptography tasks such as encryption/decryption for VPN or SSL. AES-NI was developed by Intel, but most modern AMD CPUs also support it now.

There are a lot of routers sold online that claim to be pfSense compatible and don't support AES-NI.

Cheap pfSense box - APU2E5

APU is a well-known, reliable hardware manufactured by the Swiss company PC Engines. APU2, APU3 and APU4 routers are the most popular hardware firewalls we sell at TekLager. This is the cheapest pfSense router we sell but don't be deceived; it's a very capable firewall for a home or small office.

Tip: in most applications, this box will perform just as well as the more expensive versions.

  • CPU:4 core, 1Ghz AMD GX-412TC (with AES-NI)
  • RAM: 4GB ECC DDR3-1333 DRAM
  • NIC: 3x GigabitIntel i211AT
  • Storage:16GB mSata SSD
  • Routing throughput: 1Gbit on pfSense using multiple connections. 550Mbit/s using single connection.
  • VPN: ~100Mbit over OpenVPN, ~500Mbit over WireGuard.
  • Cooling: Passive, fanless cooling.
  • Power consumption:6-10W - very low power consumption

See the full specification here:APU2E5 router

This hardware is definitely good enough for home usage. It's passively cooled, so it's completely silent.

Our favorite thing about APU routers is that they are 100% silent, cheap, powerful enough and super reliable.

( about $248 USD)

TLSense J4125

For those who would like to have a bit better CPU or moteLAN ports, we recommendTLSense J4125, which is one step up from APU. It has 5x intel 2.5Gbps NICs, more storage, a more performant Intel Celeron J4125 CPU and4-16GB of RAM.

  • CPU:4 core, Intel J4125 Quad Core 2.7Ghz (with AES-NI)
  • RAM: 4-16GB DDR4-2400 DRAM
  • NIC: 5x 2.5GbpsIntel i225-V rev 3 (supported by pfSense)
  • Storage:16GB mSata SSD
  • Routing throughput: 2.5Gbps on pfSense
  • VPN: ~600Mbpsover OpenVPN, ~1.5Gbps over WireGuard.
  • Cooling: Passive, fanless cooling. 0 noise
  • Power consumption:~8-10W - very low power consumption

See the full specification here:TLSense J4125

This configuration is very popular. This CPU and 2.5Gbps network interfaces ensure that this hardware will last you for a long time.

( about $304 USD)

​TLSense - the high-end performance

TLSense 10210U is a powerful box. It's great if you plan to use IDS/IPS packages such as Suricata or Snort for Intrusion detection and prevention. It's also a perfect choice for a VPN gateway.

This hardware is popular with customers who have a 1Gbps or 2.5Gbps internet connection and want to utilize the full throughput over OpenVPN or IPSec. This hardware is also suitable for Proxmox or VMware to run multiple Virtual Machines.

It has a powerful 10th-generation Intel Core 10210U CPU, 16-64GB of RAM, and up to 1TB NVMe SSD. In addition, it comes with 6x 2.5Gbps Intel LAN ports and an HDMI port.

If you are looking for 10Gbit hardware, see fanlessTLSense D2123ITor the rackTLSense 1U W-1290.

If you are looking for something else, see other models.

If you are looking for a pfSense WiFi router read this article we wrote about pfSense wireless support.

Cheers!

pfSense hardware 2023 (3 router recommendations) (2024)

FAQs

PfSense hardware 2023 (3 router recommendations)? ›

Current versions of pfSense software are compatible with 64-bit (amd64, x86-64) architecture hardware and Netgate ARM-based firewalls. Alternate hardware architectures such as Raspberry Pi, other Non-Netgate ARM devices, PowerPC, MIPS, SPARC, etc.

What hardware to use with pfSense? ›

Current versions of pfSense software are compatible with 64-bit (amd64, x86-64) architecture hardware and Netgate ARM-based firewalls. Alternate hardware architectures such as Raspberry Pi, other Non-Netgate ARM devices, PowerPC, MIPS, SPARC, etc.

What is the best processor for pfSense? ›

If you wish to go with a pfSense box that features excellent performance in terms of its processor power, then the Qotom pfSense Boxes is the perfect option for you. This is primarily due to the reason that it uses the Intel Core i3 4005U processor inside.

What is the best option for pfSense? ›

Best pfSense VPNs:
  • NordVPN: Our top recommendation for pfSense. ...
  • Surfshark: A secure and private service that doesn't limit connections.
  • ExpressVPN: This fast, secure VPN comes with an easy-to-follow guide for pfSense setup.
  • PureVPN: This VPN is fast and secure and has a great selection of server locations.
Jan 9, 2023

What size is recommended for pfSense? ›

A pfSense installation requires at least 1 GB of disk space. If you are installing on an embedded device, you can access the console either by a serial or VGA port.

How much RAM should I have for pfSense? ›

pfSense Hardware Requirements and Guidance
General Requirements:
MinimumCPU - 500 Mhz RAM - 512 MB
RecommendedCPU - 1 Ghz RAM - 1 GB
Requirements Specific to Individual Platforms:
Full InstallCD-ROM or USB for initial installation 1 GB hard drive

Can you put pfSense on any router? ›

pfSense can be installed on any hardware - your old computer may become your new router. This is a great way to get started if you have a computer with at least 2 network cards.

What is the disadvantage of pfSense? ›

Disadvantages. One potential disadvantage of using PfSense is that it can be complex to configure, particularly if you're not familiar with firewall configuration.

Is a pfSense router worth it? ›

pfSense is the #3 ranked solution in best firewalls. PeerSpot users give pfSense an average rating of 8.4 out of 10. pfSense is most commonly compared to OPNsense: pfSense vs OPNsense. pfSense is popular among the large enterprise segment, accounting for 51% of users researching this solution on PeerSpot.

Do I need a router with pfSense? ›

If you want to connect your home or business LAN to another network or the Internet, you will need at least one router.

How many ports do you need for pfSense? ›

The hardware requirements for using pfSense is relatively simple, you need two network ports (the community prefers Intel I-450s, but there are many, MANY more that fit the bill).

Should I use OpenWRT or pfSense? ›

OpenWrt vs.

Supported devices: OpenWrt is designed to be used on a wide range of embedded devices, including routers, access points, and network-attached storage devices. pfSense, on the other hand, is primarily intended for use on firewall and router devices.

Is Raspberry Pi good for pfSense? ›

To sum it up, using a Raspberry Pi as a security device on your device is a great idea, but the software is not there yet. pfSense is not available on the ARM architecture and the other alternatives are not perfect.

How many interfaces can pfSense have? ›

Should a particular environment require more than 128 interfaces, consider alternate designs that do not involve using all of the interfaces on the firewall directly. If the firewall must handle large numbers of interfaces, be wary of potential performance and GUI concerns.

Does pfSense work out of the box? ›

Out of the box, pfSense software does not log any passed traffic and logs all dropped traffic.

How much RAM does a firewall need? ›

For a network firewall, any new Intel dual-core hardware (Core i3) will do, even at 6x 1 Gbit/s. For an application firewall, I'd recommend a quad core (Core i5). 4 GB RAM will be enough for both uses. Disk storage doesn't matter, but you need at least 5 GB.

Is 32GB RAM overkill for work? ›

32GB of RAM is considered high and is generally overkill for most users. For most everyday use and basic tasks such as web browsing, email, and basic office work, 8GB of RAM is more than enough. Even for gaming or video editing, 16GB is typically sufficient.

Why is pfSense better than router? ›

It is highly expandable

Unlike most router software, pfSense has a package management system (think plugins) that allows users to add features like IDS/IPS systems, proxies, traffic monitors, VPN support, and much more. Here are some of the customizations and packages I recommend.

Does RAM matter for pfSense? ›

1 GB should be considered a minimum but some configurations may need 2 GB or more, not counting RAM used by the operating system, firewall states, and other packages.

Can you put pfSense on a Netgear router? ›

The pfSense firewall software protects your internal network from hackers. To use this software with the Netgear VPN router, you must configure the pfSense software to allow for Netgear VPN user access. You do this procedure in the pfSense management utility software.

Can you use a laptop for pfSense? ›

You might be wondering if using an old laptop as a pfSense router is a good idea. In many respects, laptops are good candidates for being repurposed into routers. They are small, energy efficient, and when the AC power shuts off, they run on battery power, so they have a built-in uninterruptable power supply (UPS).

Can pfSense monitor traffic? ›

Firewall Analyzer for pfSense provides you a unique way to monitor the Internet traffic of the network in near real-time. pfSense firewall traffic data is collected and analyzed to get granular details about the traffic across each firewall.

Do companies use pfSense? ›

Around the world in 2023, over 240 companies have started using pfSense as perimeter-security-and-firewalls tool. Companies using pfSense for perimeter-security-and-firewalls are majorly from United States with 231 customers. 39.22% of pfSense customers are from the United States.

Is pfSense a router or firewall? ›

pfSense is a firewall/router computer software distribution based on FreeBSD. The open source pfSense Community Edition (CE) and pfSense Plus is installed on a physical computer or a virtual machine to make a dedicated firewall/router for a network.

Does pfSense have antivirus? ›

Anti-virus Filtering

pfSense Plus software can be configured to function as an anti-virus proxy using the HAVP package. Antivirus proxies act like traditional web proxies, except they scan all content passing through the proxy for virus or malware signatures.

Can pfSense run WIFI? ›

pfSense supports Wi-Fi standards up to 802.11na (2.4Ghz and 5Ghz), if you have an adapter that works well. Some 802.11n adapters are detected as 802.11g and won't work at full speed. In addition, some cards will work only as a client, while you want to use them as an access point.

Is MikroTik better than pfSense? ›

As a final point, MikroTik offers more granular flexibility at the cost of usability, while pfsense offers a smoother yet rough user interface. And at the end, reviewers decided to do business with pfsense at the end of the day. They felt that pfSense obviates the needs of their business better than other products.

Why is pfSense the best? ›

It as scalable capacities, with functionality for SMBs. As a firewall, pfSense offers Stateful packet inspection, concurrent IPv4 and IPv6 support, and intrusion prevention. Within its VPN capabilities, it provides SSL encryption, automatic or custom routing, and multiple tunneling options.

Does pfSense act as a firewall? ›

Overview. The pfSense project is a free network firewall distribution, based on the FreeBSD operating system with a custom kernel and including third party free software packages for additional functionality.

Do I need a firewall if I have a router? ›

Fortunately, most people don't need to buy a firewall. Many devices come with free software firewalls, and many routers automatically have a firewall and additional security protections built in. If you have an older router, however, a separate hardware firewall or an upgrade might be a good idea.

Is pfSense still free? ›

pfSense® software is a free, open source customized distribution of FreeBSD specifically tailored for use as a firewall and router that is entirely managed via web interface.

What is the IP range for pfSense? ›

By default, the LAN IP address of a new installation of pfSense software is 192.168. 1.1 with a /24 mask ( 255.255. 255.0 ), and there is also a DHCP server running.

What is the maximum throughput of pfSense? ›

Routing throughput: 1Gbit on pfSense using multiple connections. 550Mbit/s using single connection.

Is pfSense a next gen firewall? ›

Palo Alto next-generation firewalls classify all traffic, including encrypted and internal traffic, based on application, application function, user and content. Users can create security policies to enable only authorized users to run sanctioned applications.

Is pfSense better than FortiGate? ›

Comparison Results: Based on the parameters we compared, it seems that pfSense is the more favorable solution because it is open source and also offers great features. To learn more, read our detailed Fortinet FortiGate vs. pfSense Report (Updated: May 2023).

Do professionals use Raspberry Pi? ›

"For IT professionals, you can do a lot of coding and development with the Raspberry Pi, making it a great tool for when you want to make something and don't know where to start.

What Linux does pfSense use? ›

Oracle Linux 7.1/pfSense

pfSense is an open source distribution of FreeBSD specifically for use as a firewall and router.

Does pfSense use multiple cores? ›

Background information. APU2, APU3 and APU4 motherboards have four 1Ghz CPU cores, pfSense by default uses only 1 core per connection. This limitation still exists, however, a single-core performance has considerably improved. APU2*4 have very performant Intel I210-AT Network Interfaces.

Does pfSense require two NICS? ›

PfSense is a firewall, if you put your router in bridged mode, Pfsense becomes your router and takes on the public IP, but you would need two NIC.

Can pfSense have multiple DHCP servers? ›

Yes, PFSense ca do DHCP for each VLAN.

Can you access pfSense remotely? ›

Several ways exist to remotely administer a firewall running pfSense® software that come with varying levels of recommendation. They all work, but their use may vary for any number of reasons (Client restrictions, corporate policies, etc.)

Should I use pfSense appliance as my access point? ›

Using pfSense software as an access point can work quite well with the right card and configuration. In general, the best practice is Using an External Wireless Access Point, especially if clients require 802.11ac or newer standards.

Does pfSense do deep packet inspection? ›

The types of attack prevention that make sense at the network edge include: Intrusion detection and prevention. Network traffic analysis. Deep packet inspection.

Is 8GB RAM enough for cybersecurity? ›

How Much RAM is Needed for Cyber Security? Storage and RAM are probably the two most significant aspects to consider when purchasing a laptop. As a result, 8 GB of RAM is sufficient for most people, but if you are a cyber security professional, we recommend at least 16 GB of RAM to run the device smoothly.

What is the lifespan of a firewall? ›

Firewalls, Switches, & Wireless Access Points: Your typical firewall, access point, and switch last about five to eight years.

Is 16GB RAM enough for a home server? ›

To have healthy breathing room for modern and future games, I recommend at least 16GB of DDR4 RAM or better for a home gaming server.

Can I run pfSense on a PC? ›

Navigate to the download page on pfsense.org in a web browser on a client PC. Select an Architecture: AMD64 (64-bit) For 64-bit x86-64 Intel or AMD hardware.

Can I install pfSense plus on my own hardware? ›

Some customers prefer to source their own hardware, and that is fine. There are plenty of options. If you are using pfSense Plus on your own hardware, just be aware that CPU, memory, NIC, BIOS settings and disk configurations can affect performance.

Does pfSense work with WiFi? ›

pfSense supports Wi-Fi standards up to 802.11na (2.4Ghz and 5Ghz), if you have an adapter that works well. Some 802.11n adapters are detected as 802.11g and won't work at full speed. In addition, some cards will work only as a client, while you want to use them as an access point.

Is pfSense still the best? ›

pfSense is the #3 ranked solution in best firewalls. PeerSpot users give pfSense an average rating of 8.6 out of 10. pfSense is most commonly compared to OPNsense: pfSense vs OPNsense. pfSense is popular among the large enterprise segment, accounting for 51% of users researching this solution on PeerSpot.

Is pfSense just a firewall? ›

The pfSense project is a free network firewall distribution, based on the FreeBSD operating system with a custom kernel and including third party free software packages for additional functionality.

What is the disadvantage of PfSense? ›

Disadvantages. One potential disadvantage of using PfSense is that it can be complex to configure, particularly if you're not familiar with firewall configuration.

Can you install PfSense on Netgear router? ›

The pfSense firewall software protects your internal network from hackers. To use this software with the Netgear VPN router, you must configure the pfSense software to allow for Netgear VPN user access. You do this procedure in the pfSense management utility software.

Should I use OpenWrt or PfSense? ›

OpenWrt vs.

Supported devices: OpenWrt is designed to be used on a wide range of embedded devices, including routers, access points, and network-attached storage devices. pfSense, on the other hand, is primarily intended for use on firewall and router devices.

Is it OK to run pfSense in a VM? ›

PfSense is known for its reliability and comes with many features that only commercial firewalls offer. PfSense is included in many third-party free software packages. You can install PfSense on both physical and virtual machines.

Top Articles
Latest Posts
Article information

Author: Nicola Considine CPA

Last Updated:

Views: 6413

Rating: 4.9 / 5 (49 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Nicola Considine CPA

Birthday: 1993-02-26

Address: 3809 Clinton Inlet, East Aleisha, UT 46318-2392

Phone: +2681424145499

Job: Government Technician

Hobby: Calligraphy, Lego building, Worldbuilding, Shooting, Bird watching, Shopping, Cooking

Introduction: My name is Nicola Considine CPA, I am a determined, witty, powerful, brainy, open, smiling, proud person who loves writing and wants to share my knowledge and understanding with you.