
A business with a 100 Mbps connection might reasonably assume that any firewall rated above 100 Mbps will be sufficient. That figure is useful, but it says very little about how the firewall will perform once it begins handling the actual workload of the network.
Netgate's own sizing guidance identifies required throughput and the features running on the firewall as the primary factors in hardware selection. Real-world traffic patterns, VPN usage, and security services can all change the resources required from the appliance.
Sizing a Netgate appliance therefore requires looking beyond the WAN speed and considering what pfSense Plus will actually be expected to do.
The Internet connection establishes a useful baseline.
If the organization has a 1 Gbps Internet service, the firewall should be capable of processing that traffic comfortably under the conditions in which it will actually operate. The same applies when there are multiple WAN connections or when an upgrade to a faster service is already planned.
The important distinction is between headline throughput and workload throughput.
Netgate publishes several performance figures for its appliances, including L3 forwarding, firewall throughput and IPsec VPN performance. It also publishes results using both large-packet iPerf3 traffic and IMIX traffic, which represents a mixture of packet sizes closer to what may be encountered in real networks.
A firewall capable of moving several gigabits of straightforward routed traffic will not necessarily deliver the same throughput when inspecting traffic or encrypting it through a VPN.
Sizing should therefore begin with the traffic path: What traffic will pass through the firewall, and what will pfSense Plus need to do with it?
That question is considerably more useful than simply asking how many megabits the ISP provides.
It is common to describe firewall requirements in terms of the number of users:
“We have 100 users. Which firewall do we need?”
The problem is that 100 users can represent very different networks.
A professional-services office using cloud applications and ordinary web traffic may place a relatively modest load on the firewall. Another organization with the same number of users could be moving large files between sites, maintaining several VPN tunnels, or generating large numbers of concurrent connections.
pfSense Plus also maintains a state table for connections passing through the firewall. Netgate notes that each network connection consumes states and that environments handling very large numbers of concurrent connections need sufficient resources for the resulting state table.
User count should therefore help describe the environment, but it should not determine the appliance by itself.
VPN usage deserves particular attention during sizing because encryption and decryption place additional demand on the firewall processor.
Consider a company with headquarters in Nairobi and several branches. Its firewall may need to process normal Internet traffic while simultaneously carrying site-to-site VPN traffic between locations. Remote employees may also be connecting through encrypted tunnels.
The question is no longer whether the appliance can handle the organization's Internet connection. It must also deliver the required encrypted throughput while continuing to perform its other firewall duties.
Netgate specifically advises sizing VPN deployments primarily around expected VPN throughput rather than simply counting the number of VPN connections. Hardware acceleration also has a major influence on encrypted performance. Netgate publishes dedicated IPsec performance figures for each appliance for precisely this reason.
For organizations where VPN traffic forms a significant part of the network architecture, those figures can be more relevant than the headline routing number.
A basic stateful firewall workload and a firewall running additional traffic-processing packages do not impose the same hardware requirements.
Netgate notes that packages which intercept or inspect network traffic can consume additional processor and memory resources. Snort and Suricata, for example, can materially affect hardware requirements depending on how they are configured.
The sizing exercise should therefore account for the intended pfSense Plus configuration before the appliance is selected.
A business deploying straightforward firewalling and VPN connectivity may have considerably different requirements from one expecting the same appliance to perform more extensive inspection.
Planning those services also avoids selecting hardware based on today's configuration only to discover that there is little room to introduce additional functionality later.
Firewall sizing is also a physical network design problem. The appliance needs to connect to the infrastructure around it.
A business may require 2.5 GbE connectivity internally even though its current Internet connection is slower. Another organization may want SFP+ interfaces because its firewall connects directly into a 10 GbE switching environment. Dual ISPs may introduce additional WAN interface requirements.
Netgate's current appliance range reflects these different deployment profiles.
The Netgate 4200 provides four independent 2.5 GbE interfaces and supports multi-WAN and high-availability configurations. Netgate positions it for branch, small-business and medium-business environments.
The Netgate 6100 expands the connectivity options significantly, providing 10 GbE SFP+, 2.5 GbE RJ45 and 1 GbE combo interfaces. That flexibility can make it better suited to environments where the firewall needs to integrate into faster LAN infrastructure or support more varied WAN connections.
For larger deployments, the Netgate 8200 moves into a 1U rack-mount platform with an eight-core processor, 16 GB of memory and interfaces supporting connectivity up to 10 GbE. Netgate positions it across branch, medium-business and large-business use cases.
At the upper end, the Netgate 8300 is aimed at more demanding enterprise, data-centre and service-provider environments, with significantly greater processing resources and expansion options including 25G and 100G connectivity.
The correct appliance is therefore influenced by both how much traffic needs to be processed and how the firewall needs to connect to the rest of the network.

Sizing a firewall exactly for today's workload can create another problem: business networks rarely remain static.
Internet services are upgraded. New branches are opened. More applications move to the cloud. VPN traffic increases as systems become distributed between offices and data centres.
A firewall expected to remain in service for several years should have enough capacity to absorb reasonable growth without forcing an early hardware replacement. That does not mean automatically buying the largest appliance available.
Oversizing increases project cost without necessarily improving the network. Undersizing creates a more expensive problem later when the firewall becomes the constraint on an otherwise capable infrastructure. The objective is appropriate headroom.
If a business currently operates a 500 Mbps Internet connection but expects to move to 1 Gbps within the deployment lifecycle, the future connection should form part of the sizing exercise now.
The same applies to planned branch expansion or a migration toward heavier VPN use.
Once the workload and network requirements are clear, the differences between Netgate platforms become more useful.
|
Appliance |
What typically drives the selection |
|
Netgate 4200 |
Business firewalling and VPN requirements where 2.5 GbE connectivity is sufficient |
|
Netgate 6100 |
Greater interface flexibility, including 10 GbE connectivity, or a workload that requires more capacity than the 4200 |
|
Netgate 8200 |
Higher firewall and VPN workloads, rack-mounted deployment, and greater headroom for larger network environments |
These are not fixed tiers based on company size.
A branch carrying substantial encrypted traffic may require more firewall capacity than a larger office with relatively simple Internet access. Interface requirements can also determine the platform before raw throughput becomes the limiting factor.
Bottomline: The appliance should follow the workload and architecture.
A useful Netgate firewall sizing exercise should establish the current WAN capacity and expected growth before examining how much traffic will actually cross the firewall. It should also account for VPN requirements, pfSense Plus services and the physical interfaces needed to integrate with the network.
Only then does it make sense to choose the appliance.
That distinction is particularly important when the firewall forms part of a larger project involving branch connectivity, network segmentation or Internet resilience. In those environments, selecting the hardware independently of the network design can create limitations that only become apparent after deployment.
As an Authorized Netgate Value-Added Reseller in Kenya, Optace Networks can work with customers to size the Netgate platform around the actual network requirement rather than treating appliance selection as a simple specification comparison.
For organizations planning a new firewall, replacing an existing gateway, or preparing for a network upgrade, talk to Optace Networks about Netgate firewall sizing and designing the appropriate Netgate and pfSense Plus deployment for your environment
.jpg)
-(1).png)


In this article, we delve into the principles of OFDMA, the defining principle of the 802.11ax standard, its applications, and its impact on wireless broadband.

© 2026 PoweredbyOptace Networks Limited. All Rights Reserved.