Router & Firewall Hardware Engineering
OPNsense State Table Calculator
Calculate pf state table RAM allocation, Suricata threat detection overhead, and WAN interface throughput for OPNsense appliances.
State Table RAM Usage
500 MB
Recommended System RAM
8 GB
Min CPU Cores Required
4 Cores
How this is calculated
- State table memory uses the figure published in the OPNsense hardware sizing documentation: roughly 1 kB per state entry, so 1,000 tracked connections occupy about 1 MB.
- A 2 GB allowance is added for the base system, and the ruleset selector adds the approximate resident footprint of an intrusion detection engine at that scale.
- The result is floored at 4 GB, which is the tier the documentation describes as reasonable for every standard feature to be functional.
- Core count steps up with WAN speed, active tunnel count and ruleset size, because those are the three workloads that scale past a single core.
This is a planning estimate built from published sizing guidance, not a measurement of a specific machine. Size with headroom.
Read next
- OPNsense hardware requirements - the official CPU, RAM and disk tiers, NIC chipset guidance, and why ARM boards are out of scope.
- WireGuard site-to-site tunnel - a persistent link between two networks, and the routes each side needs.
- WireGuard vs OpenVPN vs IPsec - which protocol benefits from AES-NI and which does not.
- WireGuard troubleshooting - when the tunnel count is right but the tunnel is not up.