• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Hardware recommendation for pfSense install

amrogers3

Gawd
Joined
Nov 7, 2010
Messages
663
I built a system about 15 years ago using a SuperMicro X7SPA-HF-D525. I am looking to upgrade my system and was looking for something to replace my old unit.
I am not familiar with the new tech and if these mobos have changed significantly from back in the day.
What would you guys recommend for a low profile unit that won't get too hot or be too loud?
I plan to run pfSense with VPN and pfBlocker for now.
Would SuperMicro be the way to go? I am looking for something that will last another 15 years if possible.
Also, I would like to get something with Nvme if possible.
 
Last edited:
What's the environment, # of clients, bandwidth to support, etc.?

WAG based on your existing system, it looks to me that this is for a typical home install. I'd say most anything based around a N100/300 CPU with 2+ NICs will work fine.
 
Any reason for 4 NICs? Typically for pfSense, you only need one in and one out.
 
From personal experience, avoid realtek 1g nics if possible. They often work most of the time, but some weird shit happens sometimes and it's not worth the hassle when it does.

I've heard good things about realtek 2.5g nics, but I haven't used them with FreeBSD yet. People say the intel 2.5g nics are bad too (i225?). I like intel 1g and 10g though.

Does your old system limit you, or is it just old? I think most people could use a modern potato to fill their firewall needs, if the D525 fits your needs, I don't know how you would find something new that doesn't. Other than if you still need six sata ports... 4 is more common these days :(
 
Just buy a Netgate appliance. I got tired of playing the games and did just that. Netgate 4200 should hold you for a long time.
 
Just buy a Netgate appliance. I got tired of playing the games and did just that. Netgate 4200 should hold you for a long time.
This may be the way brother. What you think about the hardware on these, haven't these units not been updated for some time?
 
This may be the way brother. What you think about the hardware on these, haven't these units not been updated for some time?
The 4200 came out 2 years ago. It supports multi-gig speeds and has 2.5Gb Intel Ethernet ports. It's their "lowest" model with Intel so you don't have to deal with ARM processors and you get PfSense Plus, so preferential updates over the community edition.

I went through the same thought exercise after I wanted to update my home grown pfSense box, but I couldn't build one better than this with 4 ports, low power usage, no noise, etc. Yeah, it's a slight upcharge in the bundle versus rolling your own, but if you started from scratch and needed a mini-itx case, PSU, RAM, SSD and equivalent Supermicro motherboard, it's not that bad.
 
The 4200 came out 2 years ago. It supports multi-gig speeds and has 2.5Gb Intel Ethernet ports. It's their "lowest" model with Intel so you don't have to deal with ARM processors and you get PfSense Plus, so preferential updates over the community edition.

I went through the same thought exercise after I wanted to update my home grown pfSense box, but I couldn't build one better than this with 4 ports, low power usage, no noise, etc. Yeah, it's a slight upcharge in the bundle versus rolling your own, but if you started from scratch and needed a mini-itx case, PSU, RAM, SSD and equivalent Supermicro motherboard, it's not that bad.
Those are some very good points. It even has Nvme which is nice. 4GB Ram seems small. Do you know if that is upgradable? I don't think it is, at least it doesn't say it is in the description.
 
I haven't opened it up to check, but 4GB is plenty. I added some pretty big IP lists in pfBlockerNG and my memory usage is 39%. Before that it was negligible.

What's your current usage now?
 
I had a N150 fanless 4x2.5GbE Topton computer I got from Aliexpress. Worked great until I moved to Firewalla.
 
What's your current usage now?

Here is a snapshot of my current usage

Screenshot 2026-06-11 at 5.35.34 PM.png
 
I will second the Netgate appliance thing. We've bought small ones at work for various uses and they work well. It's just convenient having a small unit that does it all. Like you can totally build a PC that'll do the same or better... but why bother? They are also fanless until you get to pretty large units so that's nice.
 
Buy a used Dell/HP SFF with an open PCie slot, i3 8th gen for longer term performance, with 4-8GB of ram and then buy a PCIe Intel NIC and off you go, more power than what a netgate device will give you for the prices they charge.
 
Buy a used Dell/HP SFF with an open PCie slot, i3 8th gen for longer term performance, with 4-8GB of ram and then buy a PCIe Intel NIC and off you go, more power than what a netgate device will give you for the prices they charge.

That is true, however, you get the pfSense Plus for free with a Netgate device vs. $129/yr. with 3rd party hardware. From what I've seen Netgate certainly doesn't seem to care much about the CE version and rarely updates it. If you're going to go 3rd party hardware, I'd probably get opnsense instead. I used them both, and I kind of liked opnsense better.
 
That is true, however, you get the pfSense Plus for free with a Netgate device vs. $129/yr. with 3rd party hardware. From what I've seen Netgate certainly doesn't seem to care much about the CE version and rarely updates it. If you're going to go 3rd party hardware, I'd probably get opnsense instead. I used them both, and I kind of liked opnsense better.
CE gets updated as needed, you could say it is almost better because it tends to get the stable updates, and it gets security fixes as well. People keep saying netgate doesnt care about CE version, but it still fully works and gets updates?

And the PFSense + is just include in the price of the hardware..
 
CE gets updated as needed, you could say it is almost better because it tends to get the stable updates, and it gets security fixes as well. People keep saying netgate doesnt care about CE version, but it still fully works and gets updates?

And the PFSense + is just include in the price of the hardware..
OPNsense gets updated all of the time & more so than I observed with pfSense CE. There's definitely pros & cons to any of them though.

I managed to get the free perpetual license for pfSense Plus before they killed that off. I just need the right hardware to make use of it as a firewall eventually.
 
Getting updates all the time is not always a good thing, for my firewall, I prefer stability over constant updates that do not fix actual issues or security related things.
 
stability

Over the past ~20 years I have had two separate pfsense updates fail to come back up on reboot, these were CE editions back then but still inexcusable IMO.

I'd love to switch from Netgate but what a pain. Ubnt isn't an option, maybe opensense someday.
 
Getting updates all the time is not always a good thing, for my firewall, I prefer stability over constant updates that do not fix actual issues or security related things.
I'm looking for security updates over absolute 99.9999% uptime. With all of the new vulnerabilities by AI code scanning agents, I prefer that they actually do something than nothing at all.
 
I'm looking for security updates over absolute 99.9999% uptime. With all of the new vulnerabilities by AI code scanning agents, I prefer that they actually do something than nothing at all.
You need to look at actual risk for being exploited though.

Most exploits, unless you leave your management interface(s) open on the internet, which is a fail off the bat, are not exploitable. Why CVE ratings can be flawed as a very very very small % of most CVE's are not even close to being easily exploitable unless something is already compromised, human or AI.

Most recent CVE is May 2026....
https://app.opencve.io/cve/?vendor=pfsense

As noted, requires Admin rights already to access the API as it is required to work with the APIs. Many other CVE's are via 3rd party packages, so would be the same for OPSense if using said same packages.

longblock454 I've been running PFSense for personal/work for....almost 20 years now, I personally, can not recall a single time an update hosed my pfsense. I know it does and can happen, as I follow netgate forums and reddit pfsense, just seems to be more related to hardware a system was on, or packages that were installed and upgrade steps not followed (like removing all packages before doing a major update) vs wide scale "Update ABC bricked everyone's pfsense installs"
 
Last edited:
I'm definitely aware of the CVE severity levels... tracked such like that for a long time gov't side. I was pointing out that I dislike patch stagnation for what actually applies when a certain situation with a setup can be exploited.
 
I'm definitely aware of the CVE severity levels... tracked such like that for a long time gov't side. I was pointing out that I dislike patch stagnation for what actually applies when a certain situation with a setup can be exploited.
Also is a little downtime for a reboot really a big deal? Schedule that shit when you are asleep and just roll with it. I've never understood people who are opposed to patching because of uptime. In almost all cases, you have time when it doesn't matter, do it then. That is for sure true of a home router. I guarantee there's plenty of hours a day you aren't using your home Internet. Just do it then and patch often. Don't scour over CVEs and worry if they are applicable or not, just patch and move on.

If it really is a situation where uptime is critical then the answer is, as it always is, redundant systems. Have two in a failover config (PFSense supports this) and patch one, then patch the other.
 
I'm definitely aware of the CVE severity levels... tracked such like that for a long time gov't side. I was pointing out that I dislike patch stagnation for what actually applies when a certain situation with a setup can be exploited.
For sure, if something is vulnerable and could be exploited easily, get that sh*t patched vendors!

Also is a little downtime for a reboot really a big deal? Schedule that shit when you are asleep and just roll with it. I've never understood people who are opposed to patching because of uptime. In almost all cases, you have time when it doesn't matter, do it then. That is for sure true of a home router. I guarantee there's plenty of hours a day you aren't using your home Internet. Just do it then and patch often. Don't scour over CVEs and worry if they are applicable or not, just patch and move on.

If it really is a situation where uptime is critical then the answer is, as it always is, redundant systems. Have two in a failover config (PFSense supports this) and patch one, then patch the other.

Agree, the days of "My uptime is years" is not a brag, patch often. My point was more about having constant "updates" is not always a good thing, stability should be priority for a perimeter device vs adding shiny new bells and whistles. Comparing OPNSense vs PFSense because OPNSense gets updates more often isn't a good comparison, as it depends on what those updates actually are..

Too many people just want shiny new features added all the time that they wont even use but just see "Well this thing got a new patch while their competitors didn't, so they suck"
 
Agree, the days of "My uptime is years" is not a brag, patch often. My point was more about having constant "updates" is not always a good thing, stability should be priority for a perimeter device vs adding shiny new bells and whistles. Comparing OPNSense vs PFSense because OPNSense gets updates more often isn't a good comparison, as it depends on what those updates actually are..

Too many people just want shiny new features added all the time that they wont even use but just see "Well this thing got a new patch while their competitors didn't, so they suck"
I wasn't implying the last part when I mentioned OPNsense. I was pointing out that OPNsense has a better release cycle than pfSense CE. pfSense Plus & above see way more updates than CE does from my own personal experience. If that has changed, I gladly welcome it from Netgate.
 
Now that it's a bit older, there are lots of used options with C3000 class chips which are very capable and basically designed for this application. I've scored a few for 100$ or less. Even the older netgate SG2xxx are still running great although they're only dual core.
 
Back
Top