Nicholas TongProtectli VP2420 firewall appliance
21 / 46
the fanless box that stands between my house and everything else
The SSD in my old firewall died on a Tuesday at 1:15am. I know the time because that is when the ping monitor gave up and my phone lit up with six alerts that all said the same thing in six ways. I keep my home network on a monitoring stack I built myself, which pages me for things no normal person gets paged for. That was a choice I made, and that night it worked exactly as designed, which means I was awake in my kitchen at 1:20, holding a USB stick with an installer on it, while the air conditioner ran like it was angry at me.
The old box was a desktop from 2016 with a consumer SSD in it, because I was in a hurry in 2022 and in a hurry is where my worst infrastructure decisions are born. The replacement is a Protectli VP2420, a fanless four-port appliance built for exactly this job. I have run it as my edge firewall for about eight months. This post is the honest version of that, including the storage mistake I made and the evening it cost me.
It lists at $369 before you add memory or storage, so let me say the usual thing plainly: this is not a purchase recommendation. I paid for it myself, with bug bounty money, and you should read every number here as one person's invoice, not advice.
the part everyone gets wrong
People shop for firewall hardware by comparing CPU benchmarks, and that is mostly wasted effort. The appliance is not the firewall. The config is the firewall. Put a $369 box on your line and leave it at factory defaults and you have the same security posture as a $60 router from the airport store, minus one interface you might use correctly.
Here's the thing about what you are actually buying. The value of a box like this is in what it does not have. No cloud account. No mobile app. No telemetry stream with your DNS history in it. No subscription that silently converts your router to a paperweight when the vendor loses interest. It runs OPNsense, an open source firewall I can read the source of, and the only traffic it sends upstream by default is a periodic check for updates, which you can turn off. Eight years of reading breach reports has taught me to price the absence of features at least as high as the features.
the mechanics
The VP2420 is a small gray aluminum box, 146 by 127 by 50 millimeters, that doubles as its own heat sink. Inside: an Intel Celeron J6412, four cores at 2.0 GHz with a burst to 2.6, and four Intel I226-V ports at 2.5 gigabit each. Maximum power draw is about 24 watts, which means the thing idles around ten and my UPS does not notice it exists.
Ports are the whole point. My VLAN plan lives in the interfaces, not in my head:
- igc0: WAN, straight to the cable modem
- igc1: trusted LAN, the laptop and desktop
- igc2: IoT, where the cameras and the TV go to be watched
- igc3: guest and lab, things I do not trust and need to rebuild anyway
I bought the coreboot option instead of the standard AMI firmware. Coreboot is an open source BIOS replacement, and the vendor's image cuts down the Intel Management Engine, the always-on subsystem that ships with basically every Intel consumer board and sits below your operating system with its own network reachability. I am not saying the ME is how you get breached. I am saying it is an attack surface I can reduce for free at checkout, so I do.
Install time, from USB stick to a working firewall with my VLANs rebuilt: about forty minutes, most of which was me typing rules I had already written down. The J6412 handles my full gigabit line without breathing hard. With Suricata inline I lose some throughput and gain a rule feed, and I keep it off the guest VLAN because I got tired of tuning it.
where it breaks
The storage. The board has one M.2 slot for an SSD, and it is SATA only, not NVMe, which the datasheet will tell you and I will repeat because it cost me an evening. The box also has 16GB of eMMC soldered on board. I originally booted OPNsense off that eMMC because it was there and it worked. Then I read the note in the vendor's own description recommending a real SSD for demanding installs, and I moved the install to an M.2 SATA drive and rebuilt from backup.
Here is what that taught me, again: backups are not real until you have restored from them. The restore worked. The forty minutes of extra typing did not, because two of my rules had been edited since the backup and nobody wrote down the edits. That gap is on me, not Protectli, but it is exactly the kind of thing the product page never mentions and the postmortem always does.
Other honest complaints. One SO-DIMM slot, capped at 32GB, so plan the memory once and be done. Fanless is silent, and it is also a thermal gamble in a Houston July; mine lives in a closet that hits the mid eighties when the sun is on that side of the house, and the aluminum case does its job but I check it the way you check on a sleeping kid. There is a strip of painter's tape on the bottom of the case with the install date written on it in pencil, which does no rhetorical work at all, I just like knowing. The I226-V ports have a history of driver and firmware quirks across platforms, so update the NIC firmware story on your platform before you blame the cable. And the VP2420 has been replaced by the VP2420e, which is the same machine minus the eMMC, so if you buy new today you are buying the e.
what to do
If you want a dedicated firewall box, the shape of the decision matters more than the brand:
- Install on a proper SSD. Never boot your edge device from the eMMC someone left lying on the board.
- Export the config, then import it once on purpose, so the backup is real.
- One interface per trust level. Cameras do not talk to your laptop. Enforce it in rules, not in vibes.
- Turn off every service you are not using. Every one of them is an open door you forgot you had keys to.
- Schedule config backups off-box, and update the firewall on a Saturday morning with coffee, not at midnight with adrenaline.
A $369 aluminum box that runs software you can read is not exciting. That is the endorsement. The most important part of my network is the part that never makes noise, never asks for an account, and never calls anyone about me.
Restore your firewall config from backup this week, once, on purpose.