UK to EU Shipping: We will dispatch all EU orders from Belgium. NO HASSLE, NO TAX, NO DUTY, NO EXTRA CHARGES UK to USA Delivery, No Hassle, Directly from the manufacturer. UK to Australia & New Zealand Shipping: We will dispatch all Orders from Australia. NO HASSLE, NO TAX, NO DUTY, NO EXTRA CHARGES UK to EU Shipping: We will dispatch all EU orders from Belgium. NO HASSLE, NO TAX, NO DUTY, NO EXTRA CHARGES UK to USA Delivery, No Hassle, Directly from the manufacturer. UK to Australia & New Zealand Shipping: We will dispatch all Orders from Australia. NO HASSLE, NO TAX, NO DUTY, NO EXTRA CHARGES

Categories

Open-Source Firewall Appliances

Product Code: NSHO-002

(1)

Intel® 5205U 6 LAN 1 COM 4G/5G Firewall 1U Rackmount Server

$507.49

-11.11%

Product Code: NSHO-005

Intel® Core™ i7-9700 8 LAN 4 10Gig SFP+ 4G 1U Rackmount Server SD-WAN Netw...

$1,159.99

$1,304.99

-12.66%

Product Code: NSHO-006

Intel® Core™ i5-9600 8 LAN 4 10Gig SFP+ 4G 1U Rackmount Server SD-WAN Netw...

$1,000.49

$1,145.49

-14.71%
-25%

Product Code: NGHC-241

14th Gen Intel i7 NGHC Hypervisor Mini Server/Workstation with vPro 5G/Wif...

$956.99

$1,275.99

-24.46%

Product Code: NGHC-242

14th Gen. Intel i5 NGHC Hypervisor Mini Server/Workstation with vPro 5G/Wi...

$761.24

$1,007.74

-24.37%
-11.67%

Open-Source Firewall Appliances 

One rugged platform. Your choice of security OS. 

Vendor-neutral network security 

Enterprise-grade network protection without vendor lock-in. Deploy pfSense, OPNsense, Untangle or Sophos on purpose-built hardware — engineered for 24/7 mission-critical edge, from a fanless branch box to a redundant-PSU datacenter appliance. 

The platform 

Most security appliances tie you to a single vendor's software, one licensing model, and one upgrade path. When the subscription lapses or the hardware reaches end-of-life, you are forced into a costly refresh on the vendor's terms. 

We flip that model. You get a hardened, purpose-built hardware platform — and you choose the firewall operating system that fits your stack, your budget, and your compliance requirements. Run the same trusted hardware across every site, switch operating systems when your needs change, and redeploy units freely without licensing penalties. 

Every appliance is built around Intel hardware with AES-NI encryption acceleration and VT-x / VT-d virtualization, so you get line-rate VPN throughput and the option to virtualize your firewall on a hypervisor such as Proxmox VE — consolidating routing, security, and monitoring on one box. 

Why it matters 

No vendor lock-in 

Own the hardware outright and pick the OS. No forced subscriptions, no licensing traps, no vendor dictating your refresh cycle. 

Deploy anywhere 

One hardware family scales from a silent fanless branch unit to a redundant-PSU rackmount — same management, same images, every site. 

Lower total cost 

Open-source firewall OS options eliminate per-seat licensing. Re-image or repurpose any unit at no extra cost as needs evolve. 

How it works 

The appliance sits at the network edge between your internet uplink and your internal networks. All traffic passes through the firewall OS, where it is filtered, routed, encrypted, and inspected before reaching any internal zone — your LAN, a public-facing DMZ, or remote branch sites connected over VPN. 

Security at every layer 

  • Filter — Stateful firewall & NAT: Every packet is checked against your rule set. Only authorized traffic crosses between zones, with full network address translation and port control. 

  • Encrypt — VPN connectivity: Site-to-site and remote-access VPN (WireGuard, IPsec, OpenVPN) tie branches and remote workers into the network over hardware-accelerated tunnels. 

  • Inspect — IDS / IPS & filtering: Built-in intrusion detection and prevention (Suricata / Snort), application-aware filtering, and content control catch threats in real time. 

One platform, every industry 

Because the platform is vendor-neutral and scales across form factors, the same hardware secures radically different environments — from a factory floor to a hospital network to a multi-site retail chain. One core, many deployments. 

  • Manufacturing & OT: Segment IT from operational technology, protect legacy PLCs and SCADA systems, and create secure conduits between the factory floor and the enterprise network. 

  • Healthcare: Isolate medical devices on dedicated VLANs, support HIPAA-aligned segmentation, and keep patient-data networks separate from guest and admin traffic. 

  • Retail & Multi-site: Maintain PCI-DSS compliance across stores, link every branch back to HQ over VPN, and isolate guest Wi-Fi from point-of-sale systems. 

  • Finance & FinTech: Enforce a zero-trust perimeter, run encrypted tunnels between offices, and capture audit-grade logs for regulatory reporting and incident response. 

  • Media & Studios: Protect high-value footage with isolated, high-throughput production networks and tightly controlled access between editing, render, and archive zones. 

  • Branch & SMB: Deploy an affordable all-in-one gateway with firewall, VPN, and content filtering — managed remotely, with plug-and-protect simplicity. 

Hardware tiers 

Desktop Small — SOHO & branch edge 

  • Fanless, silent aluminium chassis 

  • 4× 2.5GbE (Intel i226-V) 

  • Quad-core, dual-SIM 4G/5G ready 

  • Compact, DC-powered footprint 

Model: MNHO-095 

1U Rackmount — Core firewall 

  • 6–8× Gigabit LAN (Intel i211) 

  • Optional 4× SFP / SFP+ 10G fiber 

  • Core i3 / i5 / i7 & Pentium options 

  • Up to 64GB RAM, dual storage 

Models: NSHO-002 / 005 / 006 / 007 / 147 

1U High-Availability — Mission-critical 

  • Redundant power supply (1U RPSU) 

  • 8× GbE + 10/25/40G SFP+/QSFP+ (optional) 

  • 11th-gen Core, up to 128GB RAM 

  • RAID 0/1/5/10, M.2 NVMe, 5G/Wi-Fi 

Models: NSHO-009 / 011 / 012 

Compute Node — Virtualized UTM / SIEM host 

  • 14th-gen Core, up to 20 cores 

  • DDR5 ECC, up to 96GB 

  • Dual 2.5GbE, NVMe RAID, vPro 

  • Ideal as hypervisor or log host 

Models: NGHC-241 / 242 / 243 

Choose your security OS 

pfSense (Open source) 

Battle-tested FreeBSD firewall with rock-solid stability and an enormous community. Best for: core routing & VPN concentration. 

OPNsense (Open source) 

Modern fork with rapid updates, a clean UI, and built-in IDS/IPS and reporting. Best for: security-first deployments. 

Untangle (Commercial) 

Application-aware filtering, content control, and simple, friendly dashboards. Best for: SMBs needing easy management. 

Sophos (Commercial) 

Enterprise-grade UTM with deep threat intelligence, sandboxing, and cloud management. Best for: distributed enterprise fleets. 

Platform highlights 

  • Intel server-grade NICs (i210 / i211 / i226) 

  • AES-NI · VT-x / VT-d hardware acceleration 

  • 1G–40G SFP / SFP+ / QSFP+ fiber options 

  • Up to 128GB RAM 

  • RAID 0/1/5/10 

  • 4G / 5G ready 

  • PXE / Wake-on-LAN 

  • Watchdog timer 

  • CE / FCC / UKCA / RoHS compliance 

Specifications are typical and may include optional configurations. Contact PicoPC for tailored build-to-order quotes. 

🍪 Cookies Notice

We use cookies to ensure you get the best experience. See our Privacy Policy.