← EuroFirewalls

Guides · Sizing

Which Netgate to choose: sizing by bandwidth, VPN and services

There is no single “best” Netgate. The right appliance matches your Internet bandwidth, the number of concurrent VPN users, the security services you enable and the physical format you need. This page explains how to read those requirements — without invented benchmarks.

Get a free sizing reviewBrowse Netgate appliances

What actually determines the choice

Four questions decide most installations:

Scenarios and typical models

Starting points, not rigid rules — the selector on the homepage refines them with your numbers, and we review the result free of charge.

ScenarioTypical modelWhy
Home and micro officeNetgate 1100 · 2100Compact, all-Gigabit ports, light VPN use.
Small business, up to 1 GbpsNetgate 2100 BASE · MAXFive ports with combo uplink, VLANs, a few VPN users.
Growing business, 2.5 GbE, IDS/IPSNetgate 4200 MAXFour 2.5 GbE ports, NVMe storage for logs and packages.
Fibre and 10 GbE, branch officesNetgate 6100 BASE · MAX2× 10GbE SFP+ plus 2.5 GbE ports for heavier VPN workloads.
Enterprise edge, rackNetgate 8200 MAX1U rack, SFP+ 10G, hardware crypto acceleration.
Mission critical, data centreNetgate 8300 BASE · MAXEnterprise platform; dual hot-swap PSU on the MAX version.

What affects performance — honestly

Real throughput depends on traffic mix, rule set, VPN encryption and enabled packages. We deliberately publish no benchmark numbers: they change with every configuration. What is safe to say:

BASE or MAX?

Same platform, different storage: BASE uses eMMC, MAX adds faster and larger SSD/NVMe. MAX is recommended when logs, Suricata or package data grow locally; if you only ship logs to an external system, BASE is often enough.

Let us review the sizing before you order

Send us the line bandwidth, expected VPN users, enabled services and format requirements. We confirm the model — or suggest the right step up — before you buy.

Frequently asked questions

How much headroom should I plan?

A common practice is to size for the line you expect in two or three years, not only today. Upgrading later means replacing the appliance; headroom is cheaper.

Does a bigger model make the network more secure?

No. Security comes from rules, updates, segmentation and monitoring. A larger appliance adds capacity for VPN, inspection and logging — not security by itself.

Can I start small and grow?

Yes, within a model family. When requirements outgrow the appliance the usual path is the next tier; Netgate Nexus can manage several instances centrally.

One appliance or a redundant pair?

For mission-critical connectivity a redundant pair with CARP is the robust answer — see our high-availability guide. For a single office, one correctly sized appliance is the common choice.

Sources

Last verified: 2026-08-29. Orientation guide, not a performance guarantee: throughput varies with configuration and traffic. Verify the model choice with FRAOS before purchasing.