Nicholas TongNetgate 1100 pfSense+ appliance
42 / 46
the firewall my parents run is smarter than the one I run
The ISP modem at my parents' house died on a Sunday in April, right before a storm cell came through, and my dad called me the way he calls me about anything electrical: as a fact, not a request. "The internet is off." I drove over with a Netgate 1100 in my backpack, swapped it in, and the whole install took about forty minutes, thirty of which were the ISP's activation page refusing my browser. That box has been there since. It has survived two outages, one firmware update I did over the phone, and my dad's opinion that it is "too light for a machine that does a job." He spent thirty years as a machinist. He judges hardware by mass. I have stopped arguing.
Here's the thing. Read the forums about the 1100 and you will find two camps arguing past each other. One camp says it is underpowered and slow. The other says it is the best $289 you can spend on a home network. Both are right, because they are reviewing two different products. The 1100 is not a homelab toy with a support contract. It is a supported appliance that happens to be small, and the product you are buying is the update pipeline, not the silicon.
what it actually is
A small fanless box with an ARM processor, 1GB of RAM, and three 1GbE ports. One port is WAN. The other two hang off an internal switch. pfSense Plus is installed on it, licensed to it, and supported by Netgate, which means the factory images, the tested upgrade path, and a support channel are all part of the price. Netgate rates it around 900 Mbps of routing, which matches what independent reviewers measured back when the box launched at $159. In 2026 it lists at $289, and the store page now says the price includes fluctuating memory and component cost, which is the most honest sentence on any vendor page I have read this year.
The spec sheet reads thin because it is thin. That is the design. Every dollar went into the boring parts: the power supply, the case, the software build, the warranty.
the part everyone gets wrong
People buy it, install Suricata and pfBlockerNG and thirty aliases and a traffic shaper, get 300 Mbps and a hot chassis, and leave a one-star review. I want to be careful here, because the anger is real and the expectation is wrong. IDS at gigabit on an ARM chip with 1GB of RAM is not a configuration choice, it is a category error. The 1100 is a firewall that routes. It filters, it NATs, it runs a VPN tunnel or two at usable speed, and it keeps state. That is the job. The Reddit thread that says "don't expect to be running pfBlocker" is correct and rude about it, which is the forum way.
The counterintuitive part is that the thinness is the security feature. A router that cannot run packages does not run packages. Every package on an edge device is attack surface, and the history of consumer routers is a history of web-admin CVEs exploited from the LAN side of the world. CVE numbers are boring on purpose, and the most important property of this box is not any single CVE. It is that Netgate ships tested updates for this exact hardware, and the appliance refuses to become a project unless you force it.
the mechanics, in ops terms
Three ports, two jobs. WAN is its own interface. The two LAN ports are switched together in the factory config, so if you want different firewall rules between port two and port three, you are editing the switch configuration, which trips up about everyone once. My parents' setup does not care: port two is the desktop, port three is the TV, same rule set, done.
Day to day it draws a handful of watts, runs silent, and mounts on a wall, which matters more in a hallway closet than any throughput number. Config backup is the one habit that carries the whole deployment. The config file is tiny. Mine, for my parents' box, fits in an email and I have actually emailed it to myself, which is not the approved method but is a method.
where it breaks
RAM, first and hardest. 1GB is a ceiling you will feel the moment a table of aliases grows or you enable anything with a state table appetite. The box will not warn you politely. It will just get slow, and then the dashboard will tell you what you did.
Package selection, second. The pfSense package ecosystem is built for amd64 first, and on ARM hardware you are downstream of what has been built and tested for this platform. Some things are simply absent. Treat that as a feature.
Gigabit, third. There is no 2.5GbE anywhere on this box, and if your ISP plan or your NAS traffic wants more, no amount of tuning gets you there. Buy the next appliance up and skip the grief.
And price, fourth. $289 in 2026 buys a lot of x86 mini PC. The honest math is this: the mini PC route is cheaper in dollars and more expensive in hours, because you become the QA team for your own firewall images. I built both kinds. I run the overkill build at my own house, because my job is the network and I like the project. I put the appliance at my parents' house, because nobody there is on call, and the only person on call is me, four exits away.
what to do
- Decide which product you want. Project: build x86 and have fun. Appliance: buy the 1100 and leave it stock.
- Keep packages at zero or near it. Everything the box does for you should be in the base image.
- Back up the config off the box, on a schedule, and restore it once on purpose so you know it works.
- Turn off the admin interface from the WAN side, forward nothing you do not need, and put anything untrusted on a separate interface or a VLAN behind it.
- Update quarterly, not instantly. Read the release notes. They are short, which is itself a sign of a maintained product.
One useless detail to end on: the only outlet in my parents' hallway closet is behind a box of Christmas lights, so the 1100 currently sits on top of a stack of phone books from 2019, held level by the wall bracket and one folded coupon. It has been there for a year. It will be there after the next storm.
I got the IDS urge out of my system years ago, and it cost me a weekend I do not want back. The 1100 will never teach you anything, and that is the point.
The best firewall is the one nobody has to log into.