Protectli VP2420: Router Yes, Server Maybe
The question
protectli vault vp2420 user wants a small reliable box to replace an isp router and run several always-on home
The VP2420 can replace routing and firewall duties and host light services, but it still needs an ISP modem or ONT and a separate Wi-Fi access point.
Yes: the Protectli Vault VP2420 can reliably handle the routing and firewall part of a typical ISP gateway while running a few lightweight home services. It is not a complete drop-in replacement, however—you still need the ISP’s modem or ONT, a separate Wi-Fi access point, and realistic expectations about virtualization and deep packet inspection.
The hardware itself is well suited to continuous operation. The larger reliability risk comes from putting the router, DNS, home automation and every other essential service on one host: one Proxmox update, storage failure or configuration mistake can then disconnect the entire house.
What the VP2420 actually replaces
An ISP gateway commonly combines four jobs:
- A cable, DSL or fiber modem or ONT.
- A router performing NAT, DHCP and firewalling.
- An Ethernet switch.
- A wireless access point.
The VP2420 replaces the second job. With OPNsense, pfSense or OpenWrt installed, it can become the router, firewall, DHCP server, DNS resolver and VPN endpoint. Its four independent 2.5GbE interfaces also give you physical ports for WAN, LAN, a management network and a separate IoT or guest network.
It does not terminate a fiber line or coaxial cable. The ISP device must remain as the modem or ONT, normally in bridge or IP-passthrough mode. Protectli’s setup documentation explains that bridge mode passes the public address to the Vault and prevents the double NAT that occurs when both boxes remain configured as routers. Some providers do not permit full bridge mode, so that provider-specific restriction must be checked before buying hardware. Protectli’s firewall setup guide documents the required arrangement.
Do not plan to use the VP2420 as the household Wi-Fi access point. Protectli’s M.2 Wi-Fi 5 modules are not supported by the FreeBSD-based OPNsense and pfSense platforms, and the company recommends a standalone access point for better range, speed and reliability. Protectli’s Wi-Fi compatibility table makes this limitation explicit.
The measured routing ceiling
The VP2420 contains a four-core, four-thread Intel Celeron J6412, AES-NI acceleration and four 2.5GbE interfaces. It accepts one DDR4-3200 SO-DIMM up to 32GB and provides both an M.2 2280 SATA slot and an internal 2.5-inch SATA connection. The M.2 slot does not accept NVMe drives. These details are specified in the official VP2420 datasheet.
Home Network Guy independently tested traffic routed between two VP2420 interfaces under OPNsense. Basic routing reached about 2.3Gbps, while Zenarmor still delivered roughly 2.15Gbps. Suricata was the sharp limit: enabling it on one interface reduced throughput to approximately 630Mbps, and inspecting traffic across two Suricata-enabled interfaces dropped the result below 400Mbps. The reviewer identifies these as best-case local iperf3 tests with minimal other services, so they should not be treated as guaranteed internet speeds. Home Network Guy’s VP2420 measurements are nevertheless much more useful than the 2.5GbE number printed on the specification sheet.
That produces a clear dividing line:
- For ordinary routing, VLANs, DNS filtering and firewall rules on an internet connection up to roughly 1Gbps, the VP2420 has ample capacity.
- For multi-gigabit routing without intensive inspection, the independent result shows that it can get close to the practical limit of one 2.5GbE link.
- For gigabit service with comprehensive Suricata inspection, the J6412 can become the bottleneck before the Ethernet ports do.
- Running additional virtual machines consumes the same four CPU cores needed for inspection, VPN encryption and packet forwarding.
Several home services change the reliability answer
Light services such as Pi-hole or AdGuard Home, a small Home Assistant installation, a VPN endpoint, an MQTT broker and a modest reverse proxy fit the VP2420’s general capability. A Proxmox installation can run OPNsense or pfSense in a VM alongside containers for those services. Protectli publishes a Proxmox configuration using the VP2420 and supports VT-d for assigning physical network interfaces to the firewall VM. Its pfSense-on-Proxmox guide uses separate WAN and LAN interfaces on this model.
Just want the recommendation?
Skip to the picksCapability is not the same as appliance-like reliability. If the firewall runs as a VM, restarting Proxmox also restarts the internet connection. A failed system SSD takes down routing and every hosted service simultaneously. A container exhausting CPU, memory or storage can affect the firewall unless resource limits are configured correctly.
For the least tinkering, install OPNsense or pfSense directly on the VP2420 and run home services elsewhere. If consolidating onto one box is non-negotiable, use these boundaries:
- Reserve one physical interface for Proxmox management and never expose that interface to the WAN. Protectli’s virtualized OPNsense example similarly separates
vmbr0management from the WAN bridge. The OPNsense virtualization guide shows the three-interface layout. - Give the firewall VM startup priority and verify that it boots without manual intervention after a complete power loss.
- Apply CPU and memory limits to non-network containers.
- Store configuration exports and VM backups on another device, not only on the VP2420’s internal SSD.
- Put the Vault, ISP modem or ONT, switch and wireless access point on the same UPS. Protecting only the router does not keep the network alive.
- Test a cold boot before depending on the installation. Confirm WAN recovery, DNS, DHCP, Wi-Fi and access to the management interface.
- Do not expose the Proxmox, OPNsense or pfSense administration interface to the public internet. Use a VPN for remote administration.
What its power and cooling figures prove
The fanless aluminium chassis removes a mechanical fan from the failure equation and keeps the box silent. It does not prove a particular failure rate: no independent lab has published multi-year VP2420 fleet reliability or mean-time-between-failure measurements.
Home Network Guy measured approximately 10W at idle and 20–21W during performance testing with a Z-Wave energy-monitoring plug. Protectli’s own Ubuntu stress test recorded 8.1W idle, 18.4W with CPU load plus iperf3, a CPU temperature of 72°C and no reported throttling. Protectli’s power measurements broadly agree with the independent power result, despite using a different operating system and workload.
Those figures support the VP2420 as an economical 24/7 appliance, but the replaceable SSD, RAM and external 12V power supply remain possible failure points. Keep airflow around the chassis; its metal enclosure is the heatsink and should not be buried under other equipment.
Check the NIC revision before buying old inventory
A detail buried in the datasheet matters when evaluating existing or older stock. VP2420 units manufactured before June 2024 contain Intel I225-V controllers, while later units contain I226-V controllers. Protectli says both use FreeBSD’s igc driver, so either revision is supported by OPNsense and pfSense, but a buyer specifically expecting I226-V should verify the manufacturing date rather than relying on a generic listing.
The current hardware overview also says the VP2420 has been replaced by the VP2420e, whose only functional change is removal of the onboard eMMC storage. Protectli’s VP2400 hardware overview says this does not affect performance. That makes the original VP2420 most sensible when you already own one or have located the configuration you specifically need, rather than as an automatic new-hardware choice.
There is no honest reason to label the VP2420 unreliable or issue a blanket skip verdict. Its limitations are checkable and architectural: four CPU threads, 32GB maximum memory, SATA-only M.2 storage, no suitable integrated Wi-Fi under OPNsense or pfSense, and a shared failure domain when the firewall and services are virtualized together.
When this box is the wrong consolidation target
Choose separate router and server hardware when internet access must survive server maintenance, or when the service list includes video transcoding, an NVR with several cameras, a storage-heavy NAS, game servers with bursty CPU demand or a large database. The VP2420 also stops being a comfortable choice when full IDS/IPS must retain gigabit-or-faster throughput; the independent Suricata results show why.
For basic routing plus a handful of restrained services, the VP2420 can do the job. For the most reliable home network, let it be the router first and treat any services running beside the firewall as optional workloads—not as permission to turn a four-core network appliance into an entire homelab.
The bottom line
The short answer:
Top pick
It depends
Protectli Vault Pro VP2420 4-Port Intel Celeron J6412 16GB RAM 480GB M.2 SATA SSD
Protectli Vault
The four 2.5GbE ports and 32GB RAM ceiling support a light firewall-and-services host, but Protectli documents SATA-only M.2 storage and says the VP2420 has been replaced.
Consider this configuration for OPNsense or pfSense plus a few carefully limited services, especially if you already have the hardware. Its drawback is limited growth: four CPU threads, a 32GB memory ceiling and an M.2 slot that accepts SATA rather than NVMe drives.Available at Amazon(paid link) — opens Amazon in a new tab. Price and availability shown there.
Recommended products
Ordered by how well each one fits the situations above. Each link below is a paid link.
Protectli Vault Pro VP2420 4-Port Intel Celeron J6412 16GB RAM 480GB M.2 SATA SSD
Protectli Vault
Consider — The four 2.5GbE ports and 32GB RAM ceiling support a light firewall-and-services host, but Protectli documents SATA-only M.2 storage and says the VP2420 has been replaced.
Consider this configuration for OPNsense or pfSense plus a few carefully limited services, especially if you already have the hardware. Its drawback is limited growth: four CPU threads, a 32GB memory ceiling and an M.2 slot that accepts SATA rather than NVMe drives.Available at Amazon(paid link) — opens Amazon in a new tab. Price and availability shown there.
Sources
Pages consulted while researching this article. None of these are affiliate links.
- Protectli VP2420 Datasheet — kb.protectli.com
- Protectli VP2420 2.5G Network Appliance Review — homenetworkguy.com
- Getting Started With the Vault as a Firewall — kb.protectli.com
- WiFi Modules for Protectli Vaults — kb.protectli.com
- How to Install pfSense CE as a VM on Proxmox VE — kb.protectli.com
- How to Install OPNsense as a VM on Proxmox VE — kb.protectli.com
- Vault Power Draws and UPS Uptime Estimates — kb.protectli.com
- VP2410 and VP2420 Hardware Overview — kb.protectli.com