Networking & Security

Hardened OPNSense Gateway with Multi-WAN Failover, WireGuard & Suricata

1. Hardware Sizing

Running Suricata Intrusion Detection with Hyperscan pattern matching and WireGuard site-to-site tunnels at multi-gigabit speeds requires Intel i225/i226 2.5GbE NICs with hardware offload disabled.

Ready to assemble this blueprint?

Launch our interactive configurator to load verified components tailored for this architecture.

Open in Lab Builder →