I'm in the market for a firewall to place in a small rack at a data center to access backup storage and a few NVME backed VMs. My current firewall is a DIY 2U firewall 2013 AMD AM1 Kabini with a 4 port NIC running Sophos XG but this setup struggles with my 1 Gbps connection prior to VPN. I'm assuming the lack of hardware acceleration for IPsec is causing the performance issues. I like the Sophos OS but it requires 2nd system for Netflow monitoring. I would be happy to if I can find one device to do both.
Here are options I'm considering:
Constraints:
I'm asking for any suggestions on models or brands to consider for this use.
Here are options I'm considering:
- MikroTik options (CCR2004-1G-12S+2XS The Connectivity Router)
- Requires 2nd system to monitor bandwidth
- The routerboard UI leaves a lot to be desired but I have few complaints about my MikroTik APs.
- Juniper SRX300
- The higher-end models (Juniper SRX 650s) that provide 1 Gbps VPN throughput are hard to find on the secondary market.
- Fortinet FortiGate 60E
Constraints:
- I'm looking for low-cost options as I'm looking to buy a pair. ($500 - $700/each)
- I'm open to used hardware from the secondary market and I don't require support but I would like easy access to upgrades and security patches.
- Rackmountable
- Energy efficiency
- Similar to the Kabini (15w TDP) system or better
- Open to wireguard or other VPN technology to gain energy efficiency
I'm asking for any suggestions on models or brands to consider for this use.