I know we're all about the overkill here at STH, but my little opnsense box for gigabit fiber is just a $35 m73 tiny (Haswell) plus a $10 mPCIe RTL8111 NIC. Runs a bit hot but works just fine including wireguard, haproxy, and DNSBL; no suricata though. I try to design my network to minimize...