Service status & availability Crypto-only billing · No-KYC signup

Installable system

pfSense installation on dedicated hardware

Verify whether a Tungsto server fits the intended pfSense topology. Confirm edition, installer, NIC compatibility, routing, management access, and licensing. Selecting pfSense creates no private LAN, route for other servers, or completed firewall.

Installation

pfSense can be selected during checkout. Confirm the image release, hardware compatibility, disk layout and access method before installation. SSH-key support depends on the image; the order request alone is not proof that imaging has completed.

Licensing and updates

Licensing depends on the selected product, edition and deployment. Confirm the image and current upstream terms. Required commercial licenses, subscriptions and guest rights are not included unless the order explicitly states otherwise.

Recovery access

IPMI/KVM and custom ISO are listed control capabilities. Confirm console access and the supported rescue or reinstall workflow for the order. A queued control request is distinct from a completed hardware action.

Suggested hardware

Start with these configurations.

ProcessorCoresMemoryStorageWeeklyMonthlyAction
Ryzen 5 3600Ryzen bare metal
6c/12t
64 GB DDR4
2×512 GB NVMe
$17per week
$55per month
Configure →
Xeon E-2276GXeon bare metal
6c/12t
32 GB ECC
2×1 TB NVMe
$19per week
$63per month
Configure →
Ryzen 7 5800XRyzen bare metal
8c/16t
64 GB DDR4
2×1 TB NVMe
$22per week
$71per month
Configure →
Xeon E-2388GXeon bare metal
8c/16t
64 GB ECC
2×1 TB NVMe
$26per week
$87per month
Configure →

Before you choose

Confirm compatibility before installation.

3 min guide

Identify the pfSense edition and installer first

Tungsto lists pfSense without identifying Community Edition or Plus, version, installer, or support. Netgate treats the editions as distinct. Confirm edition, supported release, architecture, checksum, eligibility, and update path.

pfSense Plus activation and Netgate support can require eligibility, registration, or subscription. A generic OS selection does not include them. Check current Netgate documentation and the applicable license and trademark terms.

Verify network interfaces, drivers, and throughput needs

Netgate requires compatible x86-64 hardware and one or more supported NICs, while warning that minimums do not fit every environment. VPNs, intrusion detection, packet size, rules, and packages can change throughput needs.

The catalogue does not prove NIC count, chipset, drivers, or separation. Confirm them first; a public port is not evidence of separate WAN, LAN, management, sync, or private-server links.

Define WAN, LAN, and routing outside the OS label

Draw the traffic path before installation: gateway, management source, WAN, LAN, VLANs, prefixes, NAT, VPN peers, and downstream systems. Interface labels cannot create physical connectivity or provider routing.

An address-block description does not reveal usable addresses, gateways, VLANs, or routing for other servers. Do not place pfSense in their path until private links, routing, MAC behavior, and recovery are confirmed.

Preserve recovery access before changing the network

Selecting pfSense records an intended OS. Accepted, Provisioning, or Queued does not confirm installation or a working firewall. The installer formats target disks, so preserve configuration and data elsewhere. Verify media origin and checksum.

Interface or routing mistakes can remove remote access. Arrange recovery before changes. KVM and custom ISO requests are queued; neither guarantees an immediate console, mounted image, or progress view.

Operate and test the firewall as a customer-managed system

You manage firewall rules, access, certificates, VPN keys, packages, logging, updates, backups, monitoring, and recovery. Test the traffic path and fail safely. Tungsto does not manage pfSense or redirect other customer traffic through it.

One server is not HA. Netgate HA needs multiple nodes, CARP, synchronization, matching interfaces, addresses, and suitable connectivity. OS selection creates none of these; verify every dependency.

Direct answers

Questions before you order

Does selecting pfSense deliver a working firewall?

No. It records the intended OS. Installation, interface assignment, routing, rules, access, and validation must complete before the server can be treated as a firewall.

Can pfSense automatically route traffic for my other servers?

No. That requires a confirmed network path, routing model, interfaces or cross-connects, address plan, and recovery design. The OS choice alone provides none of them.

Is pfSense high availability included?

No. HA requires multiple compatible nodes, addressing, CARP, synchronization, suitable connectivity, matched interfaces, and failure testing. These are separate design and service requirements.