Build it, on OPNsense, with Intel NICs. UniFi’s real limit is the IDS/IPS throughput Ubiquiti publishes per gateway: 1 Gbps on the Cloud Gateway Ultra, 3.5 on the Dream Machine Pro, 5 on the Cloud Gateway Fiber. Switch threat management on and that ceiling, not the WAN port, is your speed.
On this page
Turning on threat management costs you throughput. Ubiquiti publishes how much. It just does not print the number anywhere near the toggle.
That is the thing to understand before you buy UniFi, and it is the reason I would build instead. I have run both an appliance and a box I put together myself, and the appliance is the one where a spec you did not read becomes your internet speed.
The ceiling is published, one page away
Ubiquiti’s own help page for intrusion detection is direct about the cost. Enabling it “increases CPU and memory utilization,” and “since traffic is being actively inspected, maximum routing performance may be reduced” — then it sends you to techspecs.ui.com for the figure (Ubiquiti Help Center). The setup steps on that same page walk you to Settings, CyberSecure, Protection, and a switch. No number.
Here is what is on the other site. These are the gateways worth cross-shopping rather than the whole catalogue — every figure is Ubiquiti’s published spec for that model, and every price is from Ubiquiti’s store:
| Gateway | Default WAN ports | IDS/IPS throughput | Store price |
|---|---|---|---|
| Cloud Gateway Ultra (UCG-Ultra) | 2.5 GbE RJ45 | 1 Gbps | $129 |
| Cloud Gateway Max (UCG-Max) | 2.5 GbE RJ45 | 2.3 Gbps | from $199 |
| UniFi Express 7 (UX7) | 10 GbE RJ45 | 2.3 Gbps | from $199 |
| Dream Router 7 (UDR7) | 10G SFP+, 2.5 GbE RJ45 | 2.3 Gbps | $279 |
| Cloud Gateway Fiber (UCG-Fiber) | 10G SFP+, 10 GbE RJ45 | 5 Gbps | $279 |
| Dream Machine Pro (UDM-Pro) | 10G SFP+, 1 GbE RJ45 | 3.5 Gbps | $379 |
| Dream Machine SE (UDM-SE) | 10G SFP+, 2.5 GbE RJ45 | 3.5 Gbps | $499 |
| Dream Machine Pro Max (UDM-Pro-Max) | 10G SFP+, 2.5 GbE RJ45 | 5 Gbps | $599 |
| Dream Machine Beast (UDM-Beast) | 25G SFP28, 10 GbE RJ45 | 25 Gbps | $1,499 |
| Enterprise Firewall (EFG) | 25G SFP28, 2.5 GbE RJ45 | 12.5 Gbps | $1,999 |
Read the first two columns against each other. A UniFi Express 7 has a 10 GbE WAN port and inspects at 2.3 Gbps. A Cloud Gateway Ultra has a 2.5 GbE WAN port and inspects at 1 Gbps. The port tells you what the gateway will accept. The other column tells you what it will actually move once you switch on the feature you bought a security appliance for.
The pricing does not climb with it either. The $279 Cloud Gateway Fiber inspects at 5 Gbps — faster than the $379 Dream Machine Pro at 3.5, and level with the $599 Dream Machine Pro Max. If inspection speed is what you are shopping for, the model order on the store page is not the order you want.
Multi-gig is where you find out by accident
At 1 Gbps almost nothing here bites. Most of the line-up inspects at or above a gigabit, threat management goes on, the speed test looks the same, and you never think about it again.
Then the fiber gets upgraded. Two gig, five gig, whatever the ISP is selling this year. The gateway is fine — it has the ports. What happens is that your speed test stops matching your bill, and the reason is a specification on a different website that you had no reason to open when you were choosing between a Dream Router and a Dream Machine.
This is a quiet failure. Nothing errors. Nothing alerts. You get the inspection ceiling and a vague sense that the ISP is overselling.
If you are on multi-gig and you want IPS on, the inspection number is the only spec that matters. Pick the gateway from that column and work backwards.
Rule granularity is the second limit
The other thing an appliance costs you is control. Current UniFi has moved on this, so here is where it stands.
UniFi Network 9.0 brought zone-based firewalling, and it is a real firewall. Custom zones on top of the built-in six, to a ceiling of thirty zones in total, policies matched on device, network, IP, MAC, port, application, domain or region, plus protocol, connection state, scheduling and rule reordering (Ubiquiti Help Center). That is a long way past what UniFi gateways used to hand you.
What has not changed is that the shape is fixed. The six built-in zones carry a lock icon and cannot be removed. The built-in policies carry the same lock and “cannot be modified or removed” — you write a policy above one to beat it rather than editing it. A network belongs to exactly one zone.
That is a different arrangement from a pf-based ruleset, where nothing is implicit and every default is yours to set. On OPNsense the ruleset is the whole story; on UniFi there is a layer underneath your rules that you override rather than own. Whether that matters depends entirely on whether you have ever needed to change something in that layer. If you have, you already know. If you have not, the zone matrix is easier to reason about than a page of interface rules.
Why a new build starts on OPNsense
Both are FreeBSD, both filter well, and my OPNsense versus pfSense comparison settles the feature-by-feature version. My reason for starting new work on OPNsense is about Netgate rather than about packet filtering.
The licensing. Netgate discontinued the free Home+Lab download of pfSense Plus, saying the decision “was made in order to align Netgate’s business model to better serve our worldwide customer base and partners,” and citing appliance vendors reselling boxes with the free commercial build on them (Netgate, October 26, 2023). pfSense Plus on hardware you supply now starts at $129 a year. pfSense CE stayed free, and stayed good — this is a direction, not a cliff.
The WireGuard episode. Netgate shipped a kernel-mode WireGuard implementation, quality concerns surfaced, and it came back out: “Given that kernel-mode WireGuard has been removed from FreeBSD, and out of an abundance of caution, we are removing WireGuard from pfSense software pending a thorough review and audit” (Netgate, March 18, 2021). It returned later as a package. The handling is the part I remember.
The domain. In 2017 a WIPO panel ordered opnsense.com transferred away from Jamie Thompson of Rubicon Communications dba Netgate, to OPNsense’s maintainer Deciso — “the Panel orders that the disputed domain name <opnsense.com> be transferred to the Complainant” (WIPO case D2017-1828, November 12, 2017).
None of that makes pfSense a bad firewall. It is why, given a blank machine, I start somewhere else.
Realtek is the DIY instability
Almost every “my OPNsense box randomly drops the WAN” story ends at the network card, and the vendors say so in their own documentation.
Netgate’s pfSense hardware documentation: “The best practice is to use Intel NICs because they have solid drivers in FreeBSD and they perform well,” and of the alternatives, “some work fine, others may suffer from instability or poor performance” (pfSense docs). OPNsense’s hardware page lands in the same place: “Intel® network interface cards (NIC) for LAN connections are reliable, fast and not error-prone” (OPNsense docs).
Both platforms sit on FreeBSD, so this is one piece of advice, not two. Use Intel and most of the mystery problems disappear. A cheap box with a Realtek chip is the single most common way a DIY firewall earns its reputation for being flaky, and it is a hardware choice rather than a software one.
Build it, on OPNsense, with Intel NICs
That is the recommendation. Commodity x86, Intel networking, OPNsense on top.
You give up the single pane of glass, and that is a real thing to give up. Someone who has only ever run the appliance usually re-buys the appliance, and having run both I understand exactly why — one interface for the gateway, the switches and the access points is worth something, and a build does not offer it. What you get back is a firewall with no inspection ceiling except the CPU you chose, no locked policy layer under your rules, and no vendor deciding next year what tier your feature lives in. For hardware to put it on, the homelab firewall and router stack comparison has bench numbers by box.
Buy UniFi instead if you want integrated Wi-Fi and switch management in one place. That is the case for it, it is a good case, and it is the whole case. If that is you, buy on the inspection column: pick a gateway whose IDS/IPS figure is above your WAN speed, not one whose ports are.
Do not buy UniFi if you want granular firewall control, or full-rate inspection on a multi-gig line without buying up the stack. Five gigabits of inspection starts at $279, and past that the ladder stops making sense — the $1,999 Enterprise Firewall inspects at 12.5 Gbps while the cheaper $1,499 Dream Machine Beast inspects at 25. On a build, that number is a CPU choice.
Prices and specifications move. Both columns above came off Ubiquiti’s own pages on September 7, 2026 — check them before you order.
Frequently asked questions
Does turning on UniFi threat management slow your internet?
Which UniFi gateway inspects fastest for the money?
Should I build on pfSense or OPNsense in 2026?
Why do DIY firewall builds go unstable?
Evidence ledger
- Last updated
- Methodology
- This networking guide was written and edited by Lowell K. Wood IV in St. Louis County, MO. Specs and prices verified against vendor and project documentation current on the date above. Full editorial standard: methodology.
- Update log
- 2026-09-07 — Last reviewed and updated.
- Corrections
- Spotted an error or a stale number? Email hello@techfuelhq.com. Confirmed corrections are added to the update log above.