The question comes up in almost every first conversation with a new SMB customer: is the FritzBox enough, or do we really need a proper firewall? And if so — OPNsense, Sophos, Fortinet? What is realistic for a shop with 12 employees, what for a law firm with 40 users across three sites?
We look after firewalls in exactly that size range across Bavaria, from 5 to 50 users. This article is the comparison we use internally — with honest limits and without benchmarks nobody can reproduce.
What a business firewall must deliver in 2026
A pure packet filter with NAT and a few port forwards is no longer a business firewall in 2026, it is a router with a filter feature. What customers actually need today boils down to six items:
- Network segmentation via VLAN, at minimum for guests, office, servers, VoIP and possibly production
- VPN for home office and site-to-site, ideally WireGuard and IPsec in parallel
- DNS filtering and blocklists to block phishing and malware domains
- Intrusion detection or prevention with well-maintained rulesets
- TLS inspection or L7 filtering where compliance or cyber insurance require it
- Central logging with a retention window that matches NIS2 and insurance terms
The FritzBox covers maybe half of it — and the other half only with crutch solutions. That frames the actual comparison.
FritzBox as a business firewall — honest limits
The FritzBox is an excellent consumer router and a workable micro-business router for one to five users. Limited VLANs, a simple packet filter, WireGuard since FRITZ!OS 7.50, MyFRITZ! as DDNS and a solid VoIP stack. For a trade business with three workstations and a bit of home office, that is often enough.
But for anything that needs segmentation, IDS/IPS, clean logs or multiple WAN uplinks it is the wrong tool. No Suricata, no serious GeoIP blocking, no granular NAT rule, no central logging with syslog fan-out. Using a FritzBox as a business firewall for 15 employees does not save money, it defers cost to incidents that get much more expensive later.
Rule of thumb: up to about five users without compliance the FritzBox can stay. From the sixth workstation or as soon as GDPR-sensitive data, legal work or tax advisory come in, something larger belongs in front. The migration path is in our post on replacing the FritzBox with OPNsense.
OPNsense as a business firewall 2026
OPNsense is our default recommendation in the 5 to 50 user range. The reasons are pragmatic: open source under 2-Clause BSD, no per-user licence, a mature plugin ecosystem and a hardware choice from small fanless mini-PCs to full HA clusters.
Feature-wise it covers our opening list in 2026: WireGuard and IPsec in the kernel, Unbound with blocklists, Suricata IDS/IPS with ET-Pro categories, ClamAV integration, HAProxy as a plugin, CARP for high availability, MFA with TOTP and WebAuthn. For L7 filtering there is Zenarmor as a paid plugin, and the Free Edition covers many SMB projects.
The honest caveat: OPNsense needs operational know-how. Without a service provider and without in-house networking experience, do not run it self-managed. That is where our OPNsense managed service comes in — hardware, setup and operation including updates and rules, with price ranges named individually per project.
pfSense Plus in an SMB context
pfSense Plus is still technically mature, but Netgate made it clear with the 2024 licensing model that the Community Edition is no longer a feature target. For fresh SMB projects, pfSense makes sense only in two cases: existing installations with clean documentation, or Netgate hardware customers deliberately choosing the whole-stack path.
Details are in our OPNsense vs. pfSense comparison. Short version: for new SMB projects in 2026 we pick OPNsense — clearer licensing, more active plugins, more predictable update cadence.
Sophos XGS — the classic business firewall
Sophos XGS is the “we have always done it this way” pick in many systems house offers. Boxes are solid, Sophos Central as a management console is mature, and for customers already running Sophos Endpoint there is a real benefit through Synchronized Security.
Also honest: Sophos XGS is a subscription product. Without an active licence, IDS/IPS, web filtering, app control and sandbox features are dead. The base hardware still runs as a packet filter, but the point of buying it is gone. Xstream Protection is the typical SMB tier and we deliberately do not print EUR figures because they vary by model, term and distributor.
Sophos XGS fits when a customer already lives in the Sophos ecosystem, when head office and branches need unified management and when a named vendor contact matters. For a classic 10-person business without an existing Sophos footprint, it is rarely the best pick in 2026.
Fortinet FortiGate — enterprise looks in an SMB dress
FortiGate 40F, 60F and 80F are the small models typical in SMB proposals. The hardware is good, FortiOS offers a broad feature set, the Security Fabric is well thought through. Catch same as Sophos: without active UTM bundles the firewall is functionally halved.
Two 2026 realities: Fortinet has seen several serious zero-days in recent years that demanded fast, active patching — you need to cover that internally or through a provider. And migrating away from FortiGate is entirely feasible — the workflow is in our post on migrating from FortiGate to OPNsense.
FortiGate fits best for customers with multiple sites already using or building SD-WAN, and those with an existing Fortinet contract framework. For a classic single-site mid-market business, licence cost plus patching discipline rarely deliver the best value for money.
Size classes: which firewall fits how many users
The following matrix is our lived recommendation from SMB projects. It is deliberately rough because reality always knows the details, but it helps with the initial framing.
| Size | Realistic options | What we typically do |
|---|---|---|
| 1 to 5 users | FritzBox, small OPNsense appliance | FritzBox often enough; OPNsense if VPN/compliance |
| 5 to 15 users | OPNsense standard appliance, Sophos XGS 116/126 | OPNsense in 90 percent of cases |
| 15 to 30 users | OPNsense, Sophos XGS 136/2100, FortiGate 60F | OPNsense or Sophos depending on environment |
| 30 to 50 users | OPNsense HA cluster, Sophos XGS 2100/3100, FortiGate 80F/100F | OPNsense HA or Sophos depending on compliance |
What we deliberately do not do: name fixed EUR prices in a blog article. Hardware moves between distributors, licences are calculated differently by term, and HA is a different animal than a single node. A realistic quote comes from a short scoping conversation.
Licence honesty: where the money actually goes
A point that often gets lost in firewall comparisons: the biggest cost item is not the hardware but the recurring licences and operational effort. A FortiGate 60F without a UTM bundle is a different device than one with a full bundle. A Sophos XGS without Xstream Protection is worth a fraction of what the marketing slide promises.
OPNsense is simple here: no user licences, no feature bundles. Anyone who wants Zenarmor Premium pays for Zenarmor. Anyone who wants ET-Pro rules pays for the ET-Pro subscription. That is it. That makes the total-cost calculation over four to five years of operation far more predictable than closed systems.
Our practical recommendation by segment
- Trade business, 3 to 8 users, single site, no forced home office: FritzBox unless compliance says otherwise. OPNsense as soon as VPN or VLAN is required.
- Law firm or medical practice, 5 to 20 users, GDPR and professional-code sensitive: OPNsense with DNS filter, Suricata and WireGuard. For medical practices see also our post on the regulation for medical practices.
- Mid-market, 20 to 50 users, one or two sites, mixed home office: OPNsense HA or Sophos XGS depending on existing ecosystem.
- Multi-branch business with SD-WAN ambitions: OPNsense with HAProxy and multi-WAN, or FortiGate where a Fortinet contract already exists.
For implementation we are your contact in Bavaria — details on our firewall service are at OPNsense support by DATAZONE.
FAQ on business firewalls in 2026
Is a FritzBox enough as a business firewall for 10 employees?
Short answer: probably not. Up to five users without compliance requirements it is defensible. From ten employees onwards segmentation, IDS/IPS, clean logs and multiple WAN uplinks are missing — and none of that can be cleanly retrofitted on a FritzBox.
What does an OPNsense firewall cost for an SMB?
We deliberately avoid fixed EUR figures because hardware, bandwidth, HA needs and support scope dominate the picture. Price ranges for standard projects span from “small fanless appliance with setup” up to “HA cluster with managed service” — you get a concrete quote after a short scoping call.
Does open source make sense in a business environment at all?
Yes, if a professional operation stands behind it. OPNsense is developed by Deciso and has an active community. For SMBs the deciding question is not “open vs. closed source” but “who runs the firewall reliably”. That is exactly what we deliver as a managed service.
Sophos or Fortinet — which is better for SMB?
Both are mature products. Sophos fits better when Sophos Central is already in use or Sophos Endpoint is deployed. Fortinet fits better when SD-WAN or multi-site needs exist. For new projects without prior investment, in 2026 we often pick OPNsense because the cost structure is more predictable.
How often does a business firewall need to be replaced?
For OPNsense appliances we typically plan five to seven years of hardware life. Sophos and Fortinet depend heavily on the licence model — often the hardware is technically viable longer than vendor support lasts. What matters is an annual review of the ruleset, IDS rules and VPN config.
Does a 15-employee shop really need IDS/IPS?
Yes, in almost all cases. Cyber insurance now actively asks for intrusion detection and logging, and NIS2-adjacent supply chains pass requirements down. Suricata on an OPNsense with ET Community rules is the simplest way to cover that point cleanly — without extra licences and without vendor lock-in.
More on these topics:
More articles
pfSense Plus vs. OPNsense 2026: Current Feature Comparison
pfSense Plus vs. OPNsense 2026 technical comparison: WireGuard, Zenarmor, HAProxy, Suricata, MFA and HA -- licensing, community and migration paths.
OPNsense HA with CARP: 3 Real-World Pitfalls
OPNsense HA with CARP in SMB environments: the three most common pitfalls -- config drift, sync-interface saturation and DHCP failover -- with fix procedures.
Replacing the Fritzbox with OPNsense: When SMBs Should Switch
When does the Fritzbox stop being enough? OPNsense as the SMB successor: VLANs, real firewall rules, VPN concentrator and SNMP monitoring.