IWILLUNITED STATES

Firewall appliances for business

OPNsense and pfSense firewall appliances for business

Open-source firewall hardware for multi-WAN, VPN, and segmented networks, without per-device subscription licences.

9 IWILL platforms, from compact fanless desktops with 10G SFP+ to 1U and 2U rackmount units with LAN bypass. The range is built for OPNsense and pfSense, and every configuration is validated by an engineer for your chosen software and release before you receive a written quotation.

IWILL Nano-N3261 fanless firewall appliance with four Intel 2.5GbE ports and two 10GbE SFP+ ports

The range

Choose your appliance

All 9 models in our firewall appliance range, grouped by throughput tier. The tier reflects the processor class, not a benchmark: use it as a starting point, then let our engineers confirm the fit for your traffic.

IWILL firewall appliances compared by processor, ports, memory, form factor, cooling and tier
ModelCPULAN portsSFP / SFP+RAM maxForm factorFanlessTier
IWILL N1342 firewall applianceN1342Intel Twin Lake N150 (4 cores, 4 threads, up to 3.6GHz)2× 2.5GbE (Intel i226-V)2× 10GbE SFP+ (Intel 82599)16GB DDR5DesktopNot specifiedBranch
IWILL Nano-N3061 firewall applianceNano-N3061Intel i3-10110U / i5-10210U / i7-10810U (Comet Lake, up to 4.2GHz)6× 2.5GbE (PoE option on ports 3–6)None64GB DDR4DesktopYesSMB
IWILL Nano-N18 firewall applianceNano-N18Intel i4205U / i5-8265U / i7-8565U (8th Gen Whiskey Lake)6× 1GbENone32GB DDR4DesktopYesSMB
1U8L-B75Intel Core i3-3220 / i5-3450 / i7-3770 (3th Gen, LGA1155)6× 1GbE (Intel 82583V)Optional 2× 1GbE SFP (Intel i350)16GB DDR31U rackmountNoSMB
IWILL Nano-N3281 firewall applianceNano-N3281Intel Core Ultra 5 125U / Ultra 7 155U (12-16 cores, up to 4.8GHz)8× 2.5GbE (1 vPro, 7 with PoE option)None64GB DDR5DesktopYesMulti-site
IWILL Nano-N3161 firewall applianceNano-N3161Intel i3-1215U / i5-1235U / i7-1255U (Alder Lake, up to 4.4GHz)6× 2.5GbE (PoE option on ports 1–4)None64GB DDR4DesktopYesMulti-site
IWILL Nano-N3261 firewall applianceNano-N3261Intel Core i5-1235U / i7-1255U (10 cores, 12 threads, up to 4.7GHz)4× 2.5GbE (Intel i226)2× 10GbE SFP+ (Intel 82599)64GB DDR5DesktopYesMulti-site
IWILL 1U6L-ADL firewall appliance1U6L-ADLIntel i3-12100 / i5-12400 / i7-12700 (Alder Lake, 4-8 cores)6× 1GbE (2 bypass groups)None128GB DDR41U rackmountNoData-center edge
IWILL 2U6L-ADL firewall appliance2U6L-ADLIntel i3-12100 / i5-12400 / i7-12700 (Alder Lake)6× 1GbE (2 bypass groups)None128GB DDR42U rackmountNoData-center edge

“Not specified” means our product data does not state it; we confirm it on enquiry. Configuration options (processor variant, memory, storage) are agreed per order.

Sizing guide

Which size do you need?

Port count is the easy part. A firewall is sized by its users, the sites and VPN tunnels it terminates, and whether it runs IDS/IPS inspection. Encryption and inspection load the CPU far more than routing.

Branch

Branch office or single small site

One internet connection, a handful of VLANs, remote-access VPN for a small team, and a few site-to-site tunnels back to head office. Routing, DNS filtering, and light traffic shaping run comfortably here.

Efficiency-class Intel processors. Models: N1342

SMB

Small business with several departments

A single site with more users, more internal segments (staff, guest, voice, cameras, servers), two WAN links for failover, and a steady number of remote-access VPN users. Six physical ports make it easy to give each zone its own interface instead of relying entirely on VLAN tagging. Light IDS/IPS on the WAN interface is realistic; inspecting every internal segment is where you step up.

Earlier-generation Intel Core processors. Models: Nano-N3061, Nano-N18, 1U8L-B75

Multi-site

Multi-site networks and hub firewalls

Head-office hubs that terminate many site-to-site tunnels, multi-WAN load balancing, and IDS/IPS (Suricata) or Zenarmor inspection across several interfaces at once. 12th-gen Intel Core and Core Ultra processors, memory up to 64GB, and 2.5GbE or 10GbE SFP+ ports leave headroom for packages that run alongside routing.

12th-gen Intel Core and Core Ultra mobile processors. Models: Nano-N3281, Nano-N3161, Nano-N3261

Data-center edge

Data-center, MSP, and campus edge

Rack-mounted perimeters in server rooms and colocation, MSP-managed customer edges, and deployments that need LAN bypass groups (traffic keeps flowing if the system halts), console access, memory up to 128GB, or, on the 2U model, a redundant power supply option.

Socketed 12th-gen Intel Core desktop processors in rackmount chassis. Models: 1U6L-ADL, 2U6L-ADL

These tiers are guidance only. Final sizing is confirmed by our engineers once we know your WAN speeds, user and site counts, tunnel numbers, and the packages you plan to run.

Software

OPNsense or pfSense?

Both are mature, FreeBSD-based firewall platforms with stateful filtering, multi-WAN, VLANs, CARP high availability, and IPsec, OpenVPN, and WireGuard VPN. Our hardware runs both, so the choice is about your team's preferences rather than the box; we confirm compatibility for the exact model and release you plan to deploy.

Licensing

OPNsense is open source under a BSD licence, with an optional paid Business Edition. pfSense is offered as the open-source Community Edition and as pfSense Plus from Netgate. Check current licensing terms for your use case.

Update cadence

OPNsense follows a fixed schedule of two major releases a year with frequent minor updates. pfSense releases are less frequent and not tied to a fixed calendar. Both publish security advisories.

Plugins and packages

Both offer Suricata IDS/IPS, HAProxy, and many other add-ons. Zenarmor (application-aware filtering) is available as a plugin on both. Package availability differs by version, so confirm the ones you need.

Interface

OPNsense has a modern, menu-driven web UI with a built-in API. pfSense has a long-established UI familiar to many administrators, with extensive community documentation. Try both on the same hardware if your team is undecided.

Hardware comparison

IWILL vs Netgate and white-label boxes

Looking for a Netgate alternative? Compare hardware you can verify. Where we cannot state another vendor's specification, the table says “varies”.

Hardware attributes of IWILL firewall appliances compared with Netgate appliances and white-label firewall boxes
AttributeIWILLNetgate appliancesWhite-label boxes
Intel network controllersStated in our data for N1342, 1U8L-B75, Nano-N3261 (Intel i226, 82599, 82583V, i350); controller confirmed per model on enquiry for the othersVaries by modelVaries
AES-NI hardware cryptoStated for Nano-N3061, 1U8L-B75, Nano-N3281, Nano-N3161, 1U6L-ADL, 2U6L-ADLVaries by modelVaries
TPM 2.0Stated for N1342, Nano-N3281, Nano-N3261, 1U6L-ADLVaries by modelVaries
Warranty lengthStated per model on your written quotationVariesVaries
OPNsense / pfSense pre-installAvailable on request, or shipped without an OSVariesVaries
SupportUS-based technical presales in EnglishVariesVaries

Netgate and pfSense are trademarks of their respective owner. IWILL is not affiliated with Netgate.

Services

Pre-configured on request

A pre-configured OPNsense or pfSense appliance saves your team a bench session per site. These options are discussed on enquiry and agreed in writing; bare hardware is also available.

  • OS installation

    OPNsense or pfSense installed on the agreed storage, at the version you specify.

  • Interface and VLAN plan

    WAN, LAN, guest, voice, and camera segments mapped to ports and VLAN IDs from your plan.

  • VPN profiles

    Site-to-site and remote-access tunnels (IPsec, OpenVPN, or WireGuard) prepared from your addressing scheme.

  • Baseline hardening

    Default credentials changed, management access restricted to a chosen interface, and unused services disabled.

  • Backup configuration

    An exported configuration file supplied with the unit so you can restore or clone it.

  • Matched HA pairs

    Two identical units prepared for a CARP pair, with a sync interface agreed in advance.

United States

For US organizations

Network segmentation is a common supporting control in environments that handle Controlled Unclassified Information under NIST SP 800-171 and CMMC Level 2: separating CUI systems, guest Wi-Fi, OT, and management networks limits what an attacker can reach. A multi-port OPNsense or pfSense appliance with VLANs, per-zone rules, and logging can help implement that design. It is one part of an assessed program, not a compliance guarantee: your assessor and your system security plan decide what satisfies each requirement.

IWILL US is operated by Global Natural Imports LLC in Orlando, Florida. Technical presales is US-based and in English.

Support hours and shipping origin are confirmed on your quotation. Quotations are issued in USD for US delivery.

Enquiries for multiple sites, MSP rollouts, or HA pairs are welcome. Include the quantity and the delivery ZIP code so we can quote the full rollout.

Frequently asked questions

What firewall throughput can I expect?

Throughput depends on the software, rule set, and enabled packages: routing, VPN encryption, and IDS/IPS load the CPU very differently. We do not publish a single figure; our engineers size the model and memory against your WAN speeds, tunnel count, and inspection plans, and confirm the recommendation in writing.

How many VLANs can I run?

VLANs are defined in OPNsense or pfSense rather than by the hardware, so every model supports 802.1Q VLAN tagging on its LAN ports. The practical limit is the traffic and rule complexity between segments, which is part of the sizing conversation. Models with six or eight physical ports let you keep critical zones on dedicated interfaces.

Which models support SFP or SFP+?

The N1342 and Nano-N3261 each have two 10GbE SFP+ ports on an Intel 82599 controller. The 1U8L-B75 offers an optional pair of Intel i350 SFP ports. The other models in the range use copper RJ45 ports only. Tell us your optics or DAC cables and we will confirm compatibility.

Can I build a high-availability (CARP) pair?

Yes. OPNsense and pfSense both support CARP failover with configuration and state synchronization. An HA pair needs two identical appliances and, ideally, a dedicated sync interface, so a model with a spare port is the easiest fit. Ask for two matching units on your enquiry and we will plan the port layout with you.

What warranty do the appliances carry?

Warranty length and coverage depend on the model and are stated on your written quotation. See our warranty policy page for the general terms. Warranty policy →

What is the lead time?

Lead time is confirmed on quotation, once the configuration (processor, memory, storage, and any pre-installation work) is agreed.

Can you ship without an operating system?

Yes. Many customers deploy their own OPNsense, pfSense, or other image. We can supply the hardware without an OS, or with an install prepared to your specification.

Do you offer rack-mount options?

The 1U6L-ADL and 1U8L-B75 are 1U 19-inch rackmount appliances and the 2U6L-ADL is a 2U rackmount unit. The compact Nano and N-series models are desktop units; mounting for these is discussed on enquiry.

Tell us about your network

Share your WAN links, user and site counts, VPN needs, and preferred software. An engineer will recommend the model and configuration, and send a written quotation with lead time and warranty terms.

We store your analytics preference locally. Optional analytics loads only with your permission. See our Privacy Policy.