Bespoke hardware · pfSense or OPNsense · your choice · 10G SFP+ & 2.5G copper · Wi-Fi 7 radios · 250+ clients
Davidsons IT Agency · Custom Router Builds

Custom-Built
High-Performance Routers

Bespoke networking hardware engineered for maximum bandwidth, minimal latency, and robust traffic management, specifically designed for high-demand, tech-heavy households. Built on pfSense or OPNsense, your choice.

Hand-selected silicon pfSense or OPNsense 10G SFP+ uplinks 2.5G copper ports Enterprise firewall OS
inside the build · click a component
DVB-RTR-PCB / REV 3 pfSense · OPNsense CPU / SoC 8-core · 3.8 GHz C-01 Memory DDR5 · 32 GB C-02 Storage 1 TB NVMe C-03 Wi-Fi radios Wi-Fi 7 tri-band C-04 10G uplinks 2x SFP+ · 10 Gbps C-05 2.5G ports 4x RJ45 · PoE passthrough C-06 Cooling Dual maglev · < 22 dBA C-07 Firewall OS pfSense / OPNsense C-08 HAND-BUILT · BENCH-TESTED · pfSense OR OPNsense DAVIDSONS IT AGENCY
Four things we build around

Every layer between the line and your devices

A fast line is only the beginning. What sits between the fiber and your laptop decides whether the whole household actually feels fast, at the same time, under real load.

01 / SILICON
HARDWARE NAT OFFLOAD · x86
Silicon chosen for load

A CPU with hardware offload for NAT and QoS, so routing stays at line rate even when the whole house is busy and pfSense or OPNsense is doing deep inspection.

02 / FIREWALL OS
pfSense NETGATE · CE · + OPNsense DECISO · FREEBSD OR ENTERPRISE FIREWALL · YOUR CHOICE
pfSense or OPNsense

Every build ships with pfSense or OPNsense, your choice. Both are enterprise-grade FreeBSD firewalls with IDS/IPS, VPN, native SFP+ support and no telemetry.

03 / THERMALS
COOL SILICON · NO THROTTLING
Thermal engineering

Big heatsinks and maglev fans keep the silicon cool under sustained load. No thermal throttle, no fan whine, and pfSense or OPNsense always at full speed.

04 / TRAFFIC
INGRESS P1 · VOICE P2 · GAMING P3 · STREAM P4 · BULK QUEUES · NOT JUST PRIORITIES
Traffic management

Real queue disciplines with fair sharing, configured in pfSense or OPNsense. Calls, gaming and streaming keep their lanes, and bulk traffic waits its turn.

Two firewall platforms · one custom build

pfSense or OPNsense, your choice

Both are enterprise-grade open-source firewalls, both run on the same hardware we build, and both come with full support from us. We help you pick the one that fits the way you want to run your network.

Platform · pfSense

Battle-tested, widely documented, huge community

Netgate's pfSense is the most widely deployed open-source firewall in the world. Millions of installations, a mature package ecosystem, and a community that has already solved almost every problem you will encounter.

  • ✓Largest documentation and community knowledge base of any open-source firewall
  • ✓Official Netgate-backed releases with long-term support options
  • ✓Mature package ecosystem, including Suricata, pfBlockerNG and HAProxy
  • ✓Widest compatibility with tutorials, guides and third-party integrations
BaseFreeBSD
StewardNetgate
Best forBattle-tested reliability
CommunityLargest in class
Platform · OPNsense

Modern UI, hardened, frequent releases

OPNsense is a fork of pfSense maintained by Deciso, with a cleaner modern interface, a hardened base system, and a faster release cadence. A great fit if you want the security-first philosophy to be visible in the day-to-day UI.

  • ✓Modern, mobile-friendly UI that is easier to hand over and maintain day to day
  • ✓Hardened by default, with a security-first release philosophy
  • ✓Frequent releases and a fast-moving upstream, always on current FreeBSD
  • ✓Strong commercial backing from Deciso, with a growing plugin ecosystem
BaseFreeBSD
StewardDeciso
Best forModern UI · hardening
CadenceFrequent releases

Still not sure? · We walk through both during the survey · You pick · We build

Before and after

What changes when the router is built for the load

Most households already buy good internet. The bottleneck sits in a plastic box the provider gave away, doing a job it was never designed for.

Before · stock ISP router

Free plastic box, single chip, one job

The provider hands over a router that barely covers its own cost. One small CPU, 512 MB of RAM, gigabit ports and firmware you cannot see into.

  • ✕Connection table fills up and new sessions get dropped
  • ✕Bufferbloat adds hundreds of ms of latency under load
  • ✕CPU throttles and wireless starts to stutter
  • ✕No real QoS, no packet capture, no per-device stats
Throughput~900 Mbps
Latency under load200+ ms
Concurrent sessions~4 k
VisibilityNone
After · custom build · pfSense / OPNsense

Purpose-built silicon, tuned for the whole house

Every component picked for a reason. Multi-core CPU, 32 GB of RAM, 10G uplinks, and pfSense or OPNsense with real queue disciplines that keep latency flat.

  • ✓Hardware offload keeps routing at line rate, no session drops
  • ✓pfSense or OPNsense queue disciplines keep latency flat, even during big transfers
  • ✓Runs cool under 24/7 load, no thermal throttle, no fan noise
  • ✓Full visibility: logs, per-device stats, packet capture if needed
Throughput24 Gbps NAT
Latency under load+0.4 ms
Concurrent sessions1.2 M
VisibilityFull stack
Measured, not promised

The numbers every build ships with

Every router leaves the bench with a signed spec sheet. These are the numbers a typical whole-home build produces, measured under real load with pfSense or OPNsense at the helm.

NAT throughput
24 Gbps

Single-flow routing capacity with hardware offload. The line will saturate long before the router does.

Added latency under load
+0.4 ms

Measured while the link is saturated. Stock routers add 100 to 300 ms in the same test.

Concurrent connections
1.2 M

pfSense and OPNsense state table capacity. Handles every browser tab, IoT device and container in the house at once.

IDS / IPS throughput
10 Gbps

Suricata or Zenarmor running at line rate on the 10G uplink, without dropping packets or throttling the line.

Built around how you live

Every device in the house, at the same time

A home that runs at once, every hour of the day. Games, calls, 4K, backups, IoT. The build is designed so the busiest room never notices the rest of the house.

Silicon chosen for the workload

Every part picked for a reason

Nothing off the shelf, nothing overspecced, nothing underbuilt. The CPU handles routing and QoS in hardware. The RAM holds the state table for pfSense or OPNsense. The storage keeps the logs. The cooling keeps the silicon at full speed. All of it documented on a spec sheet you actually get.

Traffic that never queues

Latency stays flat, even during a backup

Real queue disciplines in pfSense or OPNsense, not a priority checkbox. A game keeps its lane while a 500 GB backup runs, and a video call stays clean while the rest of the house streams.

Queue discipline
Active
Home lab & NAS

10G where the storage lives

The NAS sits on its own 10G uplink, on its own VLAN, with its own QoS class. Backups finish at line rate and never touch the gaming latency. pfSense and OPNsense both handle the VLAN routing natively.

NAS link speed
10 Gbps
Working from home

Calls that hold, all day

Voice and video are their own queue, not just a checkbox. The uplink is shaped so no download can starve the outbound stream that keeps the call clean. Both firewall platforms support this out of the box.

Voice stability
Measured
Built to be upgraded

Future-proof by design, not by sticker

Everything that matters is socketed and swappable. When Wi-Fi 8 lands or 25G becomes standard, we swap the module, not the whole router. The chassis, the CPU and the pfSense or OPNsense configuration stay. The upgrade path is part of the design, not an afterthought.

Swappable modules
Wi-Fi · storage · WAN
Firewall config
Version-controlled
Isolation by default

One network, many separated worlds

IoT devices, guests, work laptops and the NAS each get their own VLAN. pfSense and OPNsense both handle inter-VLAN firewall rules natively, so everything shares the uplink and nothing shares the blast radius.

VLAN segmentation
Enforced
Component choices

Every part chosen for the household, not for the spec sheet

Two households with the same internet line can need very different builds. We pick components around your devices, your rooms and the way you actually use the network.

CPU platform

x86 with hardware offload, or a high-end ARM SoC for lower power. We match the platform to the workload, not the other way around.

Memory & storage

DDR5 in capacities far above what the routing table needs, plus real NVMe storage for pfSense or OPNsense logs, config backups and IDS rule sets.

Network interfaces

A mix of 10G SFP+ cages and 2.5G copper ports, sized to the household. Both firewall platforms see them as standard interfaces.

Enclosure & cooling

Desktop, small rack, or fanless. Metal enclosures, quiet thermal design, and a form factor that fits where the network actually lives.

Build tiers

Pick the build that fits the household

The tiers below are examples to give you an idea. Within each one, the CPU, storage, wireless and port layout are adapted to your devices, your rooms and your existing infrastructure. pfSense or OPNsense, your choice, on every tier.

01 Apartment · up to 100 devices

Compact build

For a single-floor home with a modest device count. A compact desktop chassis, quiet cooling, and enough silicon headroom for years of use.

  • CPU4-core x86 offload
  • Memory16 GB DDR5
  • Ports1x 10G SFP+ · 4x 2.5G RJ45
  • FirewallpfSense or OPNsense your choice
Lead time2 to 3 weeks
03 Estate · home lab

Rack build

For larger homes, home labs and outbuildings. Rack-mount chassis, redundant power, multiple 10G uplinks and enough state table for anything you throw at it.

  • CPU8 to 16-core x86 multi-tenant
  • Memory64 GB DDR5 · mirrored NVMe
  • Ports4x 10G SFP+ · 8x 2.5G RJ45
  • FirewallpfSense or OPNsense + HA pair
Lead timeProgram-based

Examples only · Every build is adapted · pfSense or OPNsense on every tier

How we work

From the first conversation to a signed spec sheet

A short, evidence-first process. We measure, we build, we bench, and you get the numbers before the router goes live.

01

Requirements & survey

We look at your devices, rooms, existing cabling and the way you actually use the network. Every assumption gets written down before anything is bought.

02

Component selection & build

CPU, memory, storage, radios and ports, all chosen for the workload. The build itself is done by hand, with cable routing and thermal paste done properly.

03

pfSense or OPNsense

We install and configure pfSense or OPNsense, your choice. VLANs, firewall rules, queue disciplines, IDS/IPS and VPNs, all configured and version-controlled.

04

Bench test & handover

A 24-hour soak at full load, thermal and throughput tests, and a signed spec sheet. Then the router ships, we install it, and hand over the documentation.

A common situation

Four gamers, two home offices, one home lab, one stock router

This is the household we see most often at the top end. Fast fiber line, plenty of devices, and a plastic box that was never meant to keep up.

Typical scenario · high-demand household · 200+ devices

Good line. Overloaded router. Latency in every room.

The line came in at 1 Gbps symmetrical, and speed tests looked fine. But the moment the household actually used the line together, everything fell apart. Video calls jittered, game pings doubled, and the NAS backup crawled overnight. Nothing was wrong with the internet. Everything was wrong with the box sharing it.

What the diagnostics found
  • State table ceiling. The stock router maxed out around 4,000 concurrent connections. A single browser tab can open 30 on its own, and the household had over 200 devices.
  • Bufferbloat everywhere. When the line was busy, latency added 150 to 300 ms. Voice and video had no way to jump the queue, because there was no real queue to jump.
  • Single-core CPU pegged. Routing, NAT and Wi-Fi all shared the same core. Under load, everything slowed down together and wireless clients started dropping.
  • Thermal throttling. The plastic case had no airflow. Sustained load pushed the SoC past 90 °C, and the router quietly halved its own performance.
  • No visibility. No logs, no per-device traffic, no packet capture. pfSense and OPNsense would have exposed all of it. The stock firmware exposed nothing.

The fix was not a bigger line. It was a router with the silicon, the memory and pfSense or OPNsense to handle what the household actually did. Same internet, completely different experience.

Silicon matters more than sticker specs

A router with hardware offload routes at line rate. A router without it relies on a CPU that was never designed for this.

Queue, do not just prioritise

Priorities alone do not help when everything arrives at once. pfSense and OPNsense both ship real queue disciplines, and we tune them.

Cooling is performance

A router that runs hot throttles itself. Real heatsinks and quiet fans keep the silicon at full speed, all day, every day.

Visibility is the last mile

Without logs, per-device stats and packet capture, every future problem is a mystery. pfSense and OPNsense give you back the tools.

“

The line was always fine. It took one custom build to prove that the router was the problem all along.

Multi-floor household
“

Game pings stopped spiking the moment someone else started a download. That alone justified the whole build.

Gaming household
“

The NAS backs up at 10G now, and I can finally see per-device traffic. It feels like getting the network back.

Home lab build
Common questions

Before we start a build

The things people usually ask us before the first conversation.

Why a custom build instead of a consumer router?

Consumer routers are built to a price. They are designed for a household of twenty devices, not two hundred. A custom build starts with the silicon the workload actually needs, then adds pfSense or OPNsense, cooling and ports to match. The result is not more expensive in the long run, because it lasts longer and does not need replacing every eighteen months.

pfSense or OPNsense, which one do I get?

Your choice. Both are enterprise-grade FreeBSD firewalls. pfSense has the largest community and the widest documentation. OPNsense has a more modern UI, a hardened base system and a faster release cadence. If you already use one, we build on that. If you do not, we walk through both during the survey and pick the one that fits the way you want to run your network. Either way, we build, configure and support it.

Do I need to know anything about pfSense or OPNsense?

No. We configure everything, document it, and hand it over with a plain-language guide. If you want to tinker later, both platforms are well-documented and we are always available to answer questions. If you would rather never touch it again, that is fine too, and it runs the same either way.

What about warranty and support?

Every build ships with a component-level warranty that covers the parts we selected, and a support agreement that covers the firmware and configuration. If a fan fails or a module needs swapping, we handle it. If a pfSense or OPNsense upgrade goes wrong, we roll it back. You are not left holding a box with a support number that does not answer.

Can I keep my existing modem or fiber ONT?

Almost always yes. The custom router sits behind whatever the provider installs at the wall, and treats it as the WAN uplink. In some setups we bridge the provider's box so it becomes a pure modem, which removes its routing from the path entirely. Both pfSense and OPNsense handle this cleanly, and we tell you what will happen before we start.

How is this different from a mesh system?

A mesh system is several wireless access points working together. A custom router is the thing the mesh connects to. Many high-demand households need both: a real router at the head of the network, and mesh access points for coverage. We build the router and, where it helps, we design the mesh around it.

What happens when a new Wi-Fi standard arrives?

The design is deliberately modular. The wireless radios, storage and WAN interfaces are separate from the CPU and firmware, so when Wi-Fi 8 or 25G becomes standard, we swap the module rather than the whole router. The chassis, the CPU and the pfSense or OPNsense configuration stay exactly as they are.

Ready for a router built around your household?

From the first survey to the signed spec sheet, Davidsons IT Agency designs, builds and benches a custom router tuned to your devices, your rooms and the way you actually use the network. pfSense or OPNsense, your choice.

Request a Custom Router Build
Hand-built hardware pfSense or OPNsense Signed benchmark report