Loading...
Loading...
Open-source firewall hardware for UK organisations, without per-device subscription licences: Intel-based appliances from branch to data-centre edge, supplied ready for OPNsense or pfSense.

All 15 IWILL network-security appliances, grouped by tier. The tier reflects the processor class: Branch for low-power Celeron and N-series, SMB for earlier Intel Core, Multi-site for current Core U and Core Ultra, and Data-centre edge for rack-mounted desktop-class Core. Select a model for full specifications.
| Model | CPU | LAN ports and speed | SFP / SFP+ | RAM max | Form factor | Fanless | Tier |
|---|---|---|---|---|---|---|---|
| Intel Celeron J1900 | 4x Gigabit Ethernet RJ45 | None | 8GB | Desktop | Yes | Branch | |
| Intel Processor N100 | 4x Gigabit Ethernet RJ45 (Intel i210 / i211) | None | 16GB | Desktop | Yes | Branch | |
| Intel Celeron J6412 | 4x Gigabit Ethernet RJ45 (Intel i210 / i211) | None | 8GB | Desktop | Yes | Branch | |
| Intel Twin Lake N150 | 2x Intel i226-V 2.5GbE | 2x 10GbE SFP+ (Intel 82599) | 16GB | Desktop | Not specified | Branch | |
| Intel Celeron N5095 | 2x Intel i225-V 2.5G LAN | None | 16GB | Desktop | Yes | Branch | |
| Intel Celeron N5095 | 4x Intel i225-V 2.5G LAN | None | 16GB | Desktop | Yes | Branch | |
| 1U8L-B75 | Intel Core i3-3220 / i5-3450 / i7-3770 | 6x Intel 82583V Gigabit LAN | Optional: 2x Intel i350 SFP | 16GB | 1U rackmount | No | SMB |
| Intel i4205U / i5-8265U / i7-8565U | 6x 1000M LAN | None | 32GB | Desktop | Yes | SMB | |
| Intel i3-10110U / i5-10210U / i7-10810U | 6x 2.5G LAN (3-6 PoE option) | None | 64GB | Desktop | Yes | SMB | |
| Intel Core i5-1235U | 6x 2.5 Gigabit Ethernet RJ45 | None | 64GB | Desktop | Yes | Multi-site | |
| Intel i3-1215U / i5-1235U / i7-1255U | 6x 2.5G LAN (1-4 PoE option) | None | 64GB | Desktop | Yes | Multi-site | |
| Intel Core i5-1235U / i7-1255U | 4x Intel i226 2.5GbE | 2x 10GbE SFP+ (Intel 82599) | 64GB | Desktop | Yes | Multi-site | |
| Intel Core Ultra 5 125U / Ultra 7 155U | 8x 2.5G LAN (1 vPro, 7 with PoE option) | None | 64GB | Desktop | Yes | Multi-site | |
| Intel i3-12100 / i5-12400 / i7-12700 | 6x 1000M LAN (2 bypass groups) | None | 128GB | 1U rackmount | No | Data-centre edge | |
| Intel i3-12100 / i5-12400 / i7-12700 | 6x 1000M LAN (2 bypass groups) | None | 128GB | 2U rackmount | No | Data-centre edge |
Processor, memory and port options are shown as listed in our product data; the exact build is agreed on quotation. “Not specified” means our data does not state it for that model.
Four things drive firewall sizing: how many users and devices sit behind it, how many sites and VPN tunnels it terminates, how many WAN links it balances, and whether IDS/IPS or application inspection runs on the traffic. Use the tiers below as a starting point.
Small offices, shops, clinics and remote branches
A handful to a few dozen users on a single site, one or two internet connections, a small number of site-to-site or remote-access VPN tunnels and light filtering such as DNS blocking. IDS/IPS can run on a small ruleset. Low-power Celeron and N-series processors keep these units compact, and the N1342 adds 10G SFP+ uplinks.
Models: MC-41, MC-74, MC-74J, N1342, SPC-N5095-2L and SPC-N5095-4L
Established small and medium businesses
Several dozen users, a handful of VLANs (staff, guest, VoIP, CCTV, IoT), dual-WAN failover and a steady load of remote-access users. Six gigabit or 2.5G ports give room to separate each segment physically as well as by VLAN. Suitable where Suricata runs on selected interfaces rather than everything.
Models: 1U8L-B75, Nano-N18 and Nano-N3061
Head offices that terminate many branch tunnels
Larger user counts, many concurrent IPsec or WireGuard tunnels, multi-WAN load balancing and IDS/IPS or Zenarmor inspection across most interfaces. Current-generation Intel Core U and Core Ultra processors, DDR5 on the newer models and, on the N3261, 10G SFP+ uplinks to the core switch.
Models: MC-76, Nano-N3161, Nano-N3261 and Nano-N3281
Server rooms, hosting and MSP racks
Rack-mounted desktop-class Intel Core processors with memory headroom to 128GB for large state tables, heavy inspection and HA pairs. LAN bypass groups keep traffic flowing through a failed unit where the design requires it, and the 2U chassis offers a redundant power supply option.
Models: 1U6L-ADL and 2U6L-ADL
These tiers are guidance, not a guarantee of throughput. Final sizing is confirmed by our engineers once we know your WAN speeds, VPN load and inspection policy.
Both are mature, FreeBSD-based firewalls with stateful filtering, multi-WAN, IPsec, OpenVPN and WireGuard. OPNsense began in 2015 as a fork of pfSense, and the two have developed differently since. Neither is the wrong choice.
| Attribute | OPNsense | pfSense |
|---|---|---|
| Licence | BSD 2-Clause open source. The community edition is free for any use. | pfSense CE is Apache 2.0 open source. pfSense Plus is Netgate’s commercial edition; its terms on third-party hardware are set by Netgate. |
| Update cadence | Two major releases a year on a published schedule, with regular minor updates in between. | pfSense CE and pfSense Plus are released on separate schedules set by Netgate. |
| Inspection plugins | Suricata IDS/IPS built in; Zenarmor (application-aware DPI) and CrowdSec available as plugins. | Suricata and Snort packages; pfBlockerNG for IP and DNS blocklists. |
| User interface | Modern MVC-based interface; most functions are also exposed through a built-in API. | Long-established interface familiar to many engineers, with extensive community documentation. |
| Best fit | Teams wanting a predictable release cycle and plugin ecosystem. | Teams already standardised on pfSense configs, scripts and training. |
Our hardware runs both. 10 of the 15 models list OPNsense and pfSense support in our product data; the 2U6L-ADL lists pfSense, and we confirm OPNsense compatibility for it on enquiry.
A like-for-like look at hardware attributes only. Where we cannot state another supplier’s specification for every model, we show “varies”: check the specific model you are comparing.
| Attribute | IWILL | Netgate | White-label mini PCs |
|---|---|---|---|
| Intel network controllers | Specified in our data on MC-74, MC-74J, N1342, SPC-N5095-2L, SPC-N5095-4L, 1U8L-B75 and Nano-N3261 | Varies by model | Varies |
| AES-NI for VPN acceleration | Listed on SPC-N5095-2L, SPC-N5095-4L, 1U8L-B75, Nano-N3061, Nano-N3161, 1U6L-ADL and 2U6L-ADL | Varies by model | Varies |
| TPM 2.0 | Listed on N1342, Nano-N3281 and 1U6L-ADL | Varies by model | Varies |
| 10G SFP+ option | N1342 and Nano-N3261 | Varies by model | Varies |
| 1U / 2U rackmount | 1U8L-B75, 1U6L-ADL and 2U6L-ADL | Varies by model | Varies |
| Warranty | 3 years standard, extendable to 5 years | Varies | Varies |
| Pre-install and hardening | On request, agreed at enquiry | Varies | Varies |
| Local support | UK-based team, warranty service within the UK | Varies | Varies |
Arrive with a firewall that is ready to rack or plug in. The options below are discussed and agreed when you enquire, so the build matches your network rather than a template.
OPNsense or pfSense CE installed and updated to the current release, or shipped with no OS for your own image.
WAN, LAN and OPT ports assigned, with VLANs for staff, guest, VoIP, CCTV or IoT segments to your plan.
Gateway groups for failover or load balancing across two or more internet connections.
IPsec, WireGuard or OpenVPN site-to-site tunnels and remote-access profiles prepared for your users.
Default credentials replaced, management access restricted to a dedicated interface, and unused services disabled.
An exported configuration file handed over with the unit, so you can restore or clone it later.
Cyber Essentials expects a boundary firewall, default-deny inbound rules and changed default passwords. A dedicated appliance with separate VLANs for staff, guests and devices supports those controls. It helps you meet the requirements; it does not certify you.
Delivery to UK addresses is arranged with your order and confirmed on quotation. Our London-based team handles pre-sales questions and support in English, and warranty service is provided within the United Kingdom.
Orders are supplied with a VAT invoice for your accounts team, and quotations are issued in writing before you commit.
It depends on the processor, the number of firewall rules, whether IDS/IPS or Zenarmor is inspecting traffic and which VPN protocol and cipher you use. We do not publish a single headline figure because it would not reflect your ruleset. Tell us your WAN speeds, VPN load and inspection needs and our engineers will size the model and confirm it on the quotation.
OPNsense and pfSense both support 802.1Q VLANs across the full ID range of 1–4094, and neither charges per VLAN. In practice the limit is your design and the inspection load, not a licence. Many businesses separate staff, guest, VoIP, CCTV and IoT networks on a single trunk port.
N1342: 2x 10GbE SFP+ (Intel 82599); 1U8L-B75: optional 2x Intel i350 SFP; Nano-N3261: 2x 10GbE SFP+ (Intel 82599). All other models use RJ45 copper ports.
Yes. Both OPNsense and pfSense support high availability with CARP virtual IPs, pfsync state synchronisation and configuration sync. You need two matching units and a spare port on each for the sync link. We can supply matched pairs and discuss the failover design on enquiry.
IWILL products are supplied with a 3-year warranty from the date of purchase, with warranty service provided within the United Kingdom. An extended warranty of up to 5 years is available on request.
Lead time depends on the model, configuration and quantity, and is confirmed on quotation.
Yes. We can supply units with no operating system, with memory and storage fitted but no OS, or with OPNsense or pfSense CE installed. Choose whichever suits your deployment process.
1U8L-B75, 1U6L-ADL and 2U6L-ADL are 19-inch rackmount units. The other models are desktop enclosures; if you need them in a cabinet, ask us about shelf options when you enquire.
Share your user count, sites, WAN links and VPN needs. We will recommend a model, agree the configuration and send a quotation with the lead time confirmed.
info@iwilltech.co.uk