All articles
Engineering reference for pfSense router hardware sizing, Snort/Suricata inspection memory, VPN cipher throughput, and the CE versus Plus release cadence.
-
Snort vs Suricata on pfSense: Which IPS to Run in 2026
Pick Suricata for most pfSense firewalls: a multithreaded engine and Suricata-native ET Open rules. Snort 2.9.20 still suits OpenAppID users.
-
pfSense CE vs pfSense Plus: What Actually Differs
The two pfSense editions share a lineage but not a release cadence. Netgate's own version table shows where they diverge and where they re-converge.
-
Workload Sizing for pfSense: VPN, IDS and State Tables
Plan pfSense capacity around VPN traffic, IDS rules and peak state counts. Separate memory allowances from packet-rate limits before choosing a build.
-
pfSense Slow Speeds: Find the Real Bottleneck
A diagnostic order for slow pfSense throughput, from where to measure first to the network buffer, PPPoE and inspection settings that actually cap it.
-
pfSense Throughput Bottlenecks: Routing, VPN and IDS
Identify pfSense throughput bottlenecks in packet processing, VPN encryption and IDS workloads. Match CPU, NIC and memory limits to the traffic you run.