OPNsense hardware requirements - Thomas-Krenn-Wiki-en (2024)

In many use cases it is sufficent to operate a OPNsense firewall with smaller server configurations. The OPNsense creators give some recommendations for sizing the firewall server hardware.[1] We have summarised these for you here.

OPNsense hardware requirements - Thomas-Krenn-Wiki-en (1)

  • 1 Suitable hardware for your application
  • 2 Component selection
    • 2.1 Impact of special functions
  • 3 Firewall Performance Tests
  • 4 Hardware compatibility list
  • 5 References

Suitable hardware for your application

The following overview shows the recommendations issued by the OPNsense makers.

Important Hint: For an exact sizing of your hardware please contact our sales department, we will find the right hardware for you.

Component selection

The following table shows the minimum configurations recommended by OPNsense:

Scope of applicationEquipmentSample system
Network throughput (Mbps)Number of users/networksCPURAMDisc capacity
Minimum

(OPNsense standard features,
without disk writes as for caching proxy (cache)
or Intrusion Detection & Prevention (Alert Database))

11 - 15010 - 301 GHz Dual-Core2 GB4 GB SD or CF card

Edge 4L

Reasonable

(OPNsense standard features,
all functions can be used,
but possibly only for fewer users or lower loads)

151 - 35030 - 501 GHz Dual-Core4 GB40 GB SSD

LES network 6L /
RI1102D-F /
RI1102D-F Ver.2

Recommended

(OPNsense standard functions,
meets most use cases)

350 - 750+50 - 150+1,5 GHz Multi-Core8 GB120 GB SSD

RI1101-SMXEFH /
RI1102H+ Scalable

Impact of special functions

Although most functions have no particular influence on the hardware selection, the following functions can have extensive effects:

  • Squid Proxy cache for controlling Web content: high influence on CPU (higher loads) and disk writes (cache).
  • Captive portal:[2] several hundred users require more CPU performance than listed in the table above.
  • State transition tables: OPNsense logs as firewall with Stateful Packet Inspection[3] the state of all active network connections (Connections/Sessions) going through the firewall. This information is stored in a state table. Two entries are stored for each individual connection (one for the outgoing connection and one for the incoming connection). Each entry in this table occupies approximately 1 KB of RAM.

Firewall Performance Tests

We perform our own in-house Performance Tests with various OPNsense-compatible servers. The test scope includes among others a firewall throughput test, IDS/IPS test, OpenVPN, IPsec and WireGuard VPN test.

Hardware compatibility list

Because OPNsense is based on FreeBSD, it supports at least the same hardware as the respective FreeBSD version:

References

  1. Hardware sizing & setup (docs.opnsense.org)
  2. Captive portal (en.wikipedia.org)
  3. Stateful firewall (en.wikipedia.org)

OPNsense hardware requirements - Thomas-Krenn-Wiki-en (2)

Author: Werner Fischer

Werner Fischer, working in the Knowledge Transfer team at Thomas-Krenn, completed his studies of Computer and Media Security at FH Hagenberg in Austria. He is a regular speaker at many conferences like LinuxTag, OSMC, OSDC, LinuxCon, and author for various IT magazines. In his spare time he enjoys playing the piano and training for a good result at the annual Linz marathon relay.

OPNsense hardware requirements - Thomas-Krenn-Wiki-en (3)

Author: Thomas Niedermeier

Thomas Niedermeier working in the product management team at Thomas-Krenn, completed his bachelor's degree in business informatics at the Deggendorf University of Applied Sciences. Since 2013 Thomas is employed at Thomas-Krenn and takes care of OPNsense firewalls, the Thomas-Krenn-Wiki and firmware security updates.

OPNsense hardware requirements - Thomas-Krenn-Wiki-en (2024)
Top Articles
The Key To Successful Investing Is Asset Allocation
Private Equity as an Asset Class - (Wiley Finance) 2nd Edition by Guy Fraser-Sampson (Hardcover)
Devotion Showtimes Near Xscape Theatres Blankenbaker 16
Play FETCH GAMES for Free!
Was ist ein Crawler? | Finde es jetzt raus! | OMT-Lexikon
Dricxzyoki
Midflorida Overnight Payoff Address
Top Financial Advisors in the U.S.
Blairsville Online Yard Sale
Ktbs Payroll Login
454 Cu In Liters
What to do if your rotary tiller won't start – Oleomac
Summoners War Update Notes
Lancasterfire Live Incidents
Craighead County Sheriff's Department
Effingham Bookings Florence Sc
Indiana Wesleyan Transcripts
Raz-Plus Literacy Essentials for PreK-6
How to Grow and Care for Four O'Clock Plants
Marion City Wide Garage Sale 2023
THE FINALS Best Settings and Options Guide
Wisconsin Volleyball Team Boobs Uncensored
Engineering Beauties Chapter 1
8000 Cranberry Springs Drive Suite 2M600
Jordan Poyer Wiki
Plost Dental
A Christmas Horse - Alison Senxation
Miles City Montana Craigslist
Anesthesia Simstat Answers
Ocala Craigslist Com
A Man Called Otto Showtimes Near Carolina Mall Cinema
Till The End Of The Moon Ep 13 Eng Sub
N.J. Hogenkamp Sons Funeral Home | Saint Henry, Ohio
Hannah Jewell
My Dog Ate A 5Mg Flexeril
Eero Optimize For Conferencing And Gaming
Quality Tire Denver City Texas
Frostbite Blaster
Delaware judge sets Twitter, Elon Musk trial for October
Devon Lannigan Obituary
Mathews Vertix Mod Chart
Costco Gas Foster City
Catchvideo Chrome Extension
Gander Mountain Mastercard Login
Naomi Soraya Zelda
Cryptoquote Solver For Today
Kenmore Coldspot Model 106 Light Bulb Replacement
Tamilblasters.wu
Salem witch trials - Hysteria, Accusations, Executions
7 National Titles Forum
Latest Posts
Article information

Author: Trent Wehner

Last Updated:

Views: 5380

Rating: 4.6 / 5 (76 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Trent Wehner

Birthday: 1993-03-14

Address: 872 Kevin Squares, New Codyville, AK 01785-0416

Phone: +18698800304764

Job: Senior Farming Developer

Hobby: Paintball, Calligraphy, Hunting, Flying disc, Lapidary, Rafting, Inline skating

Introduction: My name is Trent Wehner, I am a talented, brainy, zealous, light, funny, gleaming, attractive person who loves writing and wants to share my knowledge and understanding with you.