Skip to main content
Appliance Builder

Build Your Firecradle Appliance

Tell us about your network. We'll recommend the exact firewall hardware you need, and explain why. You can override any recommendation if you know better.

Mode:
1

What's Your Network?

Enter the number of users and devices per category.

LAN Users & Devices
Workstations, laptops, VoIP phones
25devices
Remote / Road-Warrior VPN Users
IPsec, WireGuard, or OpenVPN clients
5users
Guest & IoT Devices
Guest Wi-Fi, cameras, badge readers
10devices
Servers / DMZ Hosts
Publicly-reachable or heavy-throughput hosts
3hosts
Branch / Site Locations
Remote offices via site-to-site VPN
1sites
Total users & devices51
When in doubt, round up. Servers and DMZ hosts count more than desktop users, since they usually drive more inspected traffic. Switch to Advanced if you'd rather enter your total user count and bandwidth per user directly.
2

Traffic & Inspection Requirements

How much throughput do you need? How deep should inspection go? Deeper inspection uses more CPU.

Throughput Target
★ Most common target for small business networks
Inspection Depth
Firewall plus IPS covers most small business setups. Full deep packet inspection plus SSL inspection uses more CPU, but it catches encrypted threats.
Peak Traffic Window
This is how many hours a day traffic stays near its peak. It shows the steady throughput your appliance must handle.
Firewall + IPS (~15%) at a Moderate traffic profile adds up to 204 Mbps of demand across 51 users and devices. After inspection overhead and burst headroom, plan for 288 Mbps of appliance capacity during your 16 hrs peak window.
3

Interface & Redundancy Configuration

We work out the port count you need from your throughput target. You can override any value.

Port Speed
Faster ports mean you need fewer of them for the same total throughput. SFP+ modules need matching switch optics.
Port Count
Recommended: 2 ports × 2.5GbE
2.5 Gbps effective
You need 288 Mbps of usable throughput. That covers peak demand, inspection overhead, and 20% burst headroom. Active-Backup bonding only sends traffic on one link at a time (2.5 Gbps per port). The second port is a hot standby, not extra capacity. We recommend 2 ports, giving 2.5 Gbps effective.
Link Bonding Mode
With 2 ports, Active-Backup is the simplest choice. One link carries traffic while the other stays idle as a hot standby. It takes over right away if the main link or switch port fails.
Secondary WAN Uplinks
Independent ISP circuits for internet-edge failover
No secondary WAN uplink configured. A single ISP circuit is a single point of failure. If it drops, every user and site loses internet access until it's fixed. Adding a secondary uplink is a common upgrade.
4

Performance & Security Goals

Set your failover target and traffic level. This picks your hardware tier and shapes the analysis on the right.

Traffic Profile
Session target: 25,000. This shapes the hardware tier we recommend.
Failover Target
How fast must you recover after an appliance failure? Targets under 5 seconds need an Active-Passive HA pair.
Peak Concurrent Sessions
10k
Session capacity: ~960,000 ✓ sufficient
Thousands of simultaneous connection-table entries at peak (up to 500k).
5

VPN & Remote Access

How many VPN tunnels or users do you need at once? We'll recommend the right crypto tier.

Concurrent VPN Tunnels
5
IPsec / WireGuard / OpenVPN, combined
Crypto Performance Tier
Recommended: Standard (multi-core crypto)
For 5 concurrent tunnels at your traffic profile, AES-NI hardware crypto offload keeps IPsec, WireGuard, and OpenVPN close to full speed, without slowing down inspection.
6

High Availability & Fleet Management

Pair two appliances for automatic failover. Optionally manage every site from one console.

No HA Pair Configured
If this appliance fails, you must replace the hardware and restore your saved settings. That usually takes hours, not seconds. Your selected failover target requires an HA pair to hit reliably.
Active-Passive HA pairs typically fail over in ~1-3 seconds with existing sessions preserved.
Centralized Cloud / Fleet Management
This appliance is standalone, managed locally through its own admin console. Switch to Fleet-Managed once you run more than a couple of locations, or manage several customer accounts.
Your Recommended Spec
All values are recommended for your network
Throughput Requirements
Aggregate demand204 Mbps
After inspection overhead240 Mbps
Burst headroom (20%)+ headroom applied
Total capacity needed288 Mbps
Network Interfaces
2× 2.5GbE ports
Active-Backup (1-link fault tolerance)
Effective: 2.5 Gbps
No secondary WAN uplink
✓ Meets your throughput target
Threat Detection / IPS
Firewall + IPS (~15%)
Rule/signature-based inspection engine
ET Open/Pro, VRT, and custom rule sources
Inline drop mode, per-rule tuning supported
Processor
8 cores / 16 threads minimum
2.4+ GHz base clock · Est. TDP ~45W
AES-NI (crypto offload) required
Handles 2.5 Gbps inspected traffic + 5 VPN tunnels
Memory (RAM)
16 GB DDR4/DDR5 ECC
ECC required for connection-table integrity
Session capacity: ~960,000 concurrent
VPN headroom: 5 tunnels
VPN & Remote Access
5 concurrent tunnels (Standard (multi-core crypto))
AES-NI, multi-core
IPsec (strongSwan) · WireGuard · OpenVPN
✓ Tier supports your tunnel count
High Availability & Management
Standalone appliance
Failover: Manual (hardware swap + config restore)
Locally managed console
Component Summary
2× 2.5GbEIPS / Threat Detection8-core CPU16 GB ECC RAM5 VPN tunnels
Power & Environment
Load draw
~91W
Annual energy
~797 kWh
Power cost/yr
~$104
Noise level
28–36 dB
Failover after appliance failure
Manual (hardware swap + config restore)
high risk
no HA pair configured
No secondary WAN uplink - single ISP circuit is a single point of failure
Quiet enough for a wiring closet, reception desk, or small-office rack. Power at $0.13/kWh. Breakdown: Ports 6W + RAM 3W + CPU ~45W.
Expected Performance
Aggregate Throughput✓ Target met
2.5 Gbps effective · 288 Mbps needed (16 hrs peak window)
Failover Speed⚠ Misses target
~300 sec achieved · target: < 30 sec
Concurrent Sessions (Moderate)✓ Sufficient
960,000 available · 10,000 needed
Optimal Bonded Pair Layout
1× 2-port bonded group✓ Optimal
Ports per group: 2 (even ✓)
This is one bonded group - add another group to separate failure paths
Effective throughput: 2.5 Gbps
Cost Estimate - Gross Approximation
Hardware (one-time est.)~$794
Hardware amortized /yr~$117/yr
Annual power cost~$104/yr
Total annual operating~$221/yr
Prices are rough estimates, based on typical hardware costs. They can vary a lot by vendor, region, and market. This is not a formal quote.
This is a minimum spec. Adding 20-30% headroom, like more RAM or faster ports, extends its life and covers unexpected growth. Firecradle can help you finalize your hardware.