Guides · Sizing
Which Netgate to choose: sizing by bandwidth, VPN and services
There is no single “best” Netgate. The right appliance matches your Internet bandwidth, the number of concurrent VPN users, the security services you enable and the physical format you need. This page explains how to read those requirements — without invented benchmarks.
What actually determines the choice
Four questions decide most installations:
- Bandwidth: the WAN ports must keep up with the line, with headroom for growth.
- Concurrent VPN users: encryption is CPU work; remote users and site-to-site tunnels add up.
- Security services: IDS/IPS inspection and intensive logging need CPU and fast storage.
- Physical format: desktop, 1U rack, redundant power supply.
Scenarios and typical models
Starting points, not rigid rules — the selector on the homepage refines them with your numbers, and we review the result free of charge.
| Scenario | Typical model | Why |
|---|---|---|
| Home and micro office | Netgate 1100 · 2100 | Compact, all-Gigabit ports, light VPN use. |
| Small business, up to 1 Gbps | Netgate 2100 BASE · MAX | Five ports with combo uplink, VLANs, a few VPN users. |
| Growing business, 2.5 GbE, IDS/IPS | Netgate 4200 MAX | Four 2.5 GbE ports, NVMe storage for logs and packages. |
| Fibre and 10 GbE, branch offices | Netgate 6100 BASE · MAX | 2× 10GbE SFP+ plus 2.5 GbE ports for heavier VPN workloads. |
| Enterprise edge, rack | Netgate 8200 MAX | 1U rack, SFP+ 10G, hardware crypto acceleration. |
| Mission critical, data centre | Netgate 8300 BASE · MAX | Enterprise platform; dual hot-swap PSU on the MAX version. |
What affects performance — honestly
Real throughput depends on traffic mix, rule set, VPN encryption and enabled packages. We deliberately publish no benchmark numbers: they change with every configuration. What is safe to say:
- IDS/IPS inspection reduces the throughput available to normal traffic.
- VPN encryption costs CPU; larger models include hardware crypto acceleration.
- Intensive logging and packages benefit from MAX storage (SSD/NVMe).
- When in doubt, size one step up: headroom costs less than a replacement.
BASE or MAX?
Same platform, different storage: BASE uses eMMC, MAX adds faster and larger SSD/NVMe. MAX is recommended when logs, Suricata or package data grow locally; if you only ship logs to an external system, BASE is often enough.
Let us review the sizing before you order
Send us the line bandwidth, expected VPN users, enabled services and format requirements. We confirm the model — or suggest the right step up — before you buy.
Frequently asked questions
How much headroom should I plan?
A common practice is to size for the line you expect in two or three years, not only today. Upgrading later means replacing the appliance; headroom is cheaper.
Does a bigger model make the network more secure?
No. Security comes from rules, updates, segmentation and monitoring. A larger appliance adds capacity for VPN, inspection and logging — not security by itself.
Can I start small and grow?
Yes, within a model family. When requirements outgrow the appliance the usual path is the next tier; Netgate Nexus can manage several instances centrally.
One appliance or a redundant pair?
For mission-critical connectivity a redundant pair with CARP is the robust answer — see our high-availability guide. For a single office, one correctly sized appliance is the common choice.