Quick answer

Build it, on OPNsense, with Intel NICs. UniFi’s real limit is the IDS/IPS throughput Ubiquiti publishes per gateway: 1 Gbps on the Cloud Gateway Ultra, 3.5 on the Dream Machine Pro, 5 on the Cloud Gateway Fiber. Switch threat management on and that ceiling, not the WAN port, is your speed.

On this page

Turning on threat management costs you throughput. Ubiquiti publishes how much. It just does not print the number anywhere near the toggle.

That is the thing to understand before you buy UniFi, and it is the reason I would build instead. I have run both an appliance and a box I put together myself, and the appliance is the one where a spec you did not read becomes your internet speed.

The ceiling is published, one page away

Ubiquiti’s own help page for intrusion detection is direct about the cost. Enabling it “increases CPU and memory utilization,” and “since traffic is being actively inspected, maximum routing performance may be reduced” — then it sends you to techspecs.ui.com for the figure (Ubiquiti Help Center). The setup steps on that same page walk you to Settings, CyberSecure, Protection, and a switch. No number.

Here is what is on the other site. These are the gateways worth cross-shopping rather than the whole catalogue — every figure is Ubiquiti’s published spec for that model, and every price is from Ubiquiti’s store:

GatewayDefault WAN portsIDS/IPS throughputStore price
Cloud Gateway Ultra (UCG-Ultra)2.5 GbE RJ451 Gbps$129
Cloud Gateway Max (UCG-Max)2.5 GbE RJ452.3 Gbpsfrom $199
UniFi Express 7 (UX7)10 GbE RJ452.3 Gbpsfrom $199
Dream Router 7 (UDR7)10G SFP+, 2.5 GbE RJ452.3 Gbps$279
Cloud Gateway Fiber (UCG-Fiber)10G SFP+, 10 GbE RJ455 Gbps$279
Dream Machine Pro (UDM-Pro)10G SFP+, 1 GbE RJ453.5 Gbps$379
Dream Machine SE (UDM-SE)10G SFP+, 2.5 GbE RJ453.5 Gbps$499
Dream Machine Pro Max (UDM-Pro-Max)10G SFP+, 2.5 GbE RJ455 Gbps$599
Dream Machine Beast (UDM-Beast)25G SFP28, 10 GbE RJ4525 Gbps$1,499
Enterprise Firewall (EFG)25G SFP28, 2.5 GbE RJ4512.5 Gbps$1,999

Read the first two columns against each other. A UniFi Express 7 has a 10 GbE WAN port and inspects at 2.3 Gbps. A Cloud Gateway Ultra has a 2.5 GbE WAN port and inspects at 1 Gbps. The port tells you what the gateway will accept. The other column tells you what it will actually move once you switch on the feature you bought a security appliance for.

The pricing does not climb with it either. The $279 Cloud Gateway Fiber inspects at 5 Gbps — faster than the $379 Dream Machine Pro at 3.5, and level with the $599 Dream Machine Pro Max. If inspection speed is what you are shopping for, the model order on the store page is not the order you want.

Multi-gig is where you find out by accident

At 1 Gbps almost nothing here bites. Most of the line-up inspects at or above a gigabit, threat management goes on, the speed test looks the same, and you never think about it again.

Then the fiber gets upgraded. Two gig, five gig, whatever the ISP is selling this year. The gateway is fine — it has the ports. What happens is that your speed test stops matching your bill, and the reason is a specification on a different website that you had no reason to open when you were choosing between a Dream Router and a Dream Machine.

This is a quiet failure. Nothing errors. Nothing alerts. You get the inspection ceiling and a vague sense that the ISP is overselling.

If you are on multi-gig and you want IPS on, the inspection number is the only spec that matters. Pick the gateway from that column and work backwards.

Rule granularity is the second limit

The other thing an appliance costs you is control. Current UniFi has moved on this, so here is where it stands.

UniFi Network 9.0 brought zone-based firewalling, and it is a real firewall. Custom zones on top of the built-in six, to a ceiling of thirty zones in total, policies matched on device, network, IP, MAC, port, application, domain or region, plus protocol, connection state, scheduling and rule reordering (Ubiquiti Help Center). That is a long way past what UniFi gateways used to hand you.

What has not changed is that the shape is fixed. The six built-in zones carry a lock icon and cannot be removed. The built-in policies carry the same lock and “cannot be modified or removed” — you write a policy above one to beat it rather than editing it. A network belongs to exactly one zone.

That is a different arrangement from a pf-based ruleset, where nothing is implicit and every default is yours to set. On OPNsense the ruleset is the whole story; on UniFi there is a layer underneath your rules that you override rather than own. Whether that matters depends entirely on whether you have ever needed to change something in that layer. If you have, you already know. If you have not, the zone matrix is easier to reason about than a page of interface rules.

Why a new build starts on OPNsense

Both are FreeBSD, both filter well, and my OPNsense versus pfSense comparison settles the feature-by-feature version. My reason for starting new work on OPNsense is about Netgate rather than about packet filtering.

The licensing. Netgate discontinued the free Home+Lab download of pfSense Plus, saying the decision “was made in order to align Netgate’s business model to better serve our worldwide customer base and partners,” and citing appliance vendors reselling boxes with the free commercial build on them (Netgate, October 26, 2023). pfSense Plus on hardware you supply now starts at $129 a year. pfSense CE stayed free, and stayed good — this is a direction, not a cliff.

The WireGuard episode. Netgate shipped a kernel-mode WireGuard implementation, quality concerns surfaced, and it came back out: “Given that kernel-mode WireGuard has been removed from FreeBSD, and out of an abundance of caution, we are removing WireGuard from pfSense software pending a thorough review and audit” (Netgate, March 18, 2021). It returned later as a package. The handling is the part I remember.

The domain. In 2017 a WIPO panel ordered opnsense.com transferred away from Jamie Thompson of Rubicon Communications dba Netgate, to OPNsense’s maintainer Deciso — “the Panel orders that the disputed domain name <opnsense.com> be transferred to the Complainant” (WIPO case D2017-1828, November 12, 2017).

None of that makes pfSense a bad firewall. It is why, given a blank machine, I start somewhere else.

Realtek is the DIY instability

Almost every “my OPNsense box randomly drops the WAN” story ends at the network card, and the vendors say so in their own documentation.

Netgate’s pfSense hardware documentation: “The best practice is to use Intel NICs because they have solid drivers in FreeBSD and they perform well,” and of the alternatives, “some work fine, others may suffer from instability or poor performance” (pfSense docs). OPNsense’s hardware page lands in the same place: “Intel® network interface cards (NIC) for LAN connections are reliable, fast and not error-prone” (OPNsense docs).

Both platforms sit on FreeBSD, so this is one piece of advice, not two. Use Intel and most of the mystery problems disappear. A cheap box with a Realtek chip is the single most common way a DIY firewall earns its reputation for being flaky, and it is a hardware choice rather than a software one.

Build it, on OPNsense, with Intel NICs

That is the recommendation. Commodity x86, Intel networking, OPNsense on top.

You give up the single pane of glass, and that is a real thing to give up. Someone who has only ever run the appliance usually re-buys the appliance, and having run both I understand exactly why — one interface for the gateway, the switches and the access points is worth something, and a build does not offer it. What you get back is a firewall with no inspection ceiling except the CPU you chose, no locked policy layer under your rules, and no vendor deciding next year what tier your feature lives in. For hardware to put it on, the homelab firewall and router stack comparison has bench numbers by box.

Buy UniFi instead if you want integrated Wi-Fi and switch management in one place. That is the case for it, it is a good case, and it is the whole case. If that is you, buy on the inspection column: pick a gateway whose IDS/IPS figure is above your WAN speed, not one whose ports are.

Do not buy UniFi if you want granular firewall control, or full-rate inspection on a multi-gig line without buying up the stack. Five gigabits of inspection starts at $279, and past that the ladder stops making sense — the $1,999 Enterprise Firewall inspects at 12.5 Gbps while the cheaper $1,499 Dream Machine Beast inspects at 25. On a build, that number is a CPU choice.

Prices and specifications move. Both columns above came off Ubiquiti’s own pages on September 7, 2026 — check them before you order.

Frequently asked questions

Does turning on UniFi threat management slow your internet?
It caps it. Every UniFi gateway has a published IDS/IPS throughput figure that is lower than what the box routes with inspection off, and once threat management is on that figure is your ceiling. A Cloud Gateway Ultra inspects at 1 Gbps behind a 2.5 GbE WAN port. A Dream Machine Pro inspects at 3.5 Gbps behind a 10G SFP+ WAN port. If your line is faster than the inspection number, the inspection number is your speed.
Which UniFi gateway inspects fastest for the money?
The Cloud Gateway Fiber, for anything short of rack gear. It is $279 on Ubiquiti’s store and rated at 5 Gbps IDS/IPS — more inspection than the $379 Dream Machine Pro at 3.5 Gbps, and the same figure as the $599 Dream Machine Pro Max. Price and inspection speed do not climb together across the line, so read the spec page rather than the price tag.
Should I build on pfSense or OPNsense in 2026?
OPNsense, for a new build. Netgate discontinued the free Home+Lab download of pfSense Plus in October 2023, and pfSense Plus on hardware you supply now starts at $129 a year. pfSense Community Edition is still free and still a good firewall, so an existing pfSense box with tuned rules is not a problem to solve. It is the direction of travel that would keep me from starting there.
Why do DIY firewall builds go unstable?
Realtek network cards, most of the time. Netgate’s own pfSense hardware documentation says the best practice is Intel NICs because they have solid drivers in FreeBSD, and that other cards may suffer from instability or poor performance. OPNsense’s hardware page says the same thing in different words. Both platforms sit on FreeBSD, so the advice is the same on either. Put Intel in the box and most of the mystery problems never happen.

Evidence ledger

Last updated
Methodology
This networking guide was written and edited by Lowell K. Wood IV in St. Louis County, MO. Specs and prices verified against vendor and project documentation current on the date above. Full editorial standard: methodology.
Update log
  • 2026-09-07 — Last reviewed and updated.
Corrections
Spotted an error or a stale number? Email hello@techfuelhq.com. Confirmed corrections are added to the update log above.

About the author

Written by Lowell K. Wood IV, who builds and runs TechFuelHQ from St. Louis, Missouri.