Hey everyone! 👋 I've been lurking here for a while, picking up tons of great insights on NGFW setups. Big thanks to the community for that.
We're running a SonicWall NSA 3700 for our ~500 person office (mix of on-prem and remote). It's... fine? But the licensing costs are starting to feel heavy, and I'm not thrilled with some of the UI/management quirks. I've been hearing more and more buzz about OPNsense in the open-source space, especially for its flexibility and robust feature set.
I'm really curious if anyone has made a similar jump at this scale. My main questions are:
* **Performance in Reality:** We push about 1.5 Gbps sustained with all services (IPS, AV, filtering) turned on. Can OPNsense on decent commodity hardware (thinking Supermicro, maybe) handle this reliably? I'm less concerned about datasheet numbers and more about real-world throughput with threat prevention enabled.
* **High Availability:** A smooth HA setup is non-negotiable for us. How straightforward is it to get a stable CARP/HA configuration running? Any major pitfalls during failover?
* **Management & Logging:** Our team is used to a certain workflow. How is the day-to-day rule management and, crucially, log analysis compared to a traditional vendor box?
* **The Ecosystem:** I know the community and plugin system is a huge strength. For an office our size, what are the must-have plugins for web filtering, VPN (we use Global VPN Client a lot), and deep packet inspection?
I'm optimistic about the potential for better control and cost savings, but I want to go in with eyes wide open. If you've run OPNsense at a similar scale, I'd love to hear your migration lessons, hardware specs, and whether the team's overall experience was positive.
Happy benchmarking!
Always testing.