Quote from: Stormscape on February 03, 2026, 11:59:00 AMFor what it's worth, the i5-8500 in my Optiplex 3060 I use for OPNsense easily handles my 2100/200 connection. I usually peak at around 2.40 for CPU usage when downloading. Now granted I'm not doing any sort of IDS, but hopefully that should give you a good idea of what to pick.
QuoteDo not enter static routes for networks assigned on any interface of this firewall. Static routes are only used for networks reachable via a different router, and not reachable via your default gateway.
Allow "out" quick from any to 192.168.100.0/24
Block "out" quick from any to RFC1918
Quotepass in quick on igc3 reply-to ( igc3 100.87.0.1 ) inet from {any} to {192.168.100.0/24} keep state # Allow ONT access
block out log quick on igc3 reply-to ( igc3 100.87.0.1 ) inet from {any} to $RFC1918 # Never expose internal IPs
Allow "out" quick from any to 192.168.100.0/24 with disable reply-to
Block "out" quick from any to RFC1918 with disable reply-to
10.0.0.0/8
172.16.0.0/12
192.168.0.0/18
192.168.64.0/19
192.168.96.0/22
192.168.101.0/24
192.168.102.0/23
192.168.104.0/21
192.168.112.0/20
192.168.128.0/17
Block "out" quick from any to RFC1918_WITHOUT_ONT