Reduce your NAT GW spend by up to 50%! TNSR from Netgate is a high-performance, software-based NAT and routing platform that delivers line-rate performance, advanced networking features, and predictable costs, making it a cost-saving alternative to AWS NAT Gateway for high-throughput and cost-sensitive workloads.
Get high-performance routed site-to-site and remote access VPNs via IPsec or WireGuard® with no hidden fees - just unparalleled TCO.
Features:
VPN: Routed IPsec site-to-site VPNs and remote access with Mobile IPsec or WireGuard.
Management and Monitoring: Command line interface (CLI), RESTCONF API, GUI, SNMP, Prometheus Exporter, and IPFIX Exporter for simple management and monitoring.
Compatibility: IPsec and WireGuard VPN compatible software across various platforms, including pfSense Plus®, AWS®, Azure®, Cisco®, Fortinet®, Palo Alto Networks®, Sophos®, Juniper®, WatchGuard®, Barracuda®, CheckPoint®, and others.
Routing: BGP, OSPF, RIPv2, IPv4/IPv6, ECMP, and more.
Security: L2/L3/L4 ACLs, scalable to over 100,000 rules.
Open Source Technology: Vector Packet Processing (VPP), Data Plane Developer Kit (DPDK), Clixon, Free Range Routing (FRR), and others. Linux / Ubuntu base.
NOTE: Smaller 2-CPU instance sizes are meant for educational purposes only and should not be expected to perform as well as larger, more suitable instance sizes.
Highlights
Easy to Deploy VPN solution for edge, cloud, and multi-cloud.
Simple Management and Monitoring with a command line interface (CLI), RESTCONF API, GUI, SNMP, Prometheus Exporter, and IPFIX Exporter.
Stable Security and Performance, built with open-source technology and zero trust architecture in mind.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour for the EC2 instance type you choose to run this router and VPN software. All 31 dimensions bill the same way; they differ only by the underlying compute instance. Each instance family and size offers its own mix of CPU, memory, and network capacity. Smaller sizes like t3.large and m6i.large fit lighter workloads. Larger sizes and metal instances handle higher throughput. Pricing scales with the instance you select, since performance depends on the hardware. The software feature set stays the same across all instances, with no extra charge for capacity or throughput.
Top-of-mind questions for buyers
What does one hourly unit map to when I select an instance like m6i.xlarge?
One unit is the running EC2 instance you choose. You are billed per hour for each active instance running the software. The instance type sets its CPU, memory, and network capacity. Larger types and metal instances process more traffic. Each running instance meters its own hours separately.
Am I charged when an instance is stopped, and does the software fee vary with traffic?
Software charges apply per hour while an instance runs. A stopped instance stops accruing hourly software charges, though AWS may still bill underlying storage. The software fee does not change with bandwidth, feature use, or traffic type. You pay only for the instance-hours you run.
What determines the throughput I get, since price scales with the instance I pick?
Throughput follows the instance hardware. Faster CPU and more memory let one instance process more traffic. Packet size, encryption, and access control depth also affect speed. Since price scales with the instance, choose a size that matches your bandwidth and encryption needs.
www.netgate.com+2
Helpful?
Vendor refund policy
TNSR hourly subscriptions can be cancelled at any time. Customers will only be billed for time actually used while an AWS instance is active. TNSR annual subscription cancellations or downgrades are not supported. For assistance with subscription upgrades, visit our webpage.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
TAC PRO - 24x7x365 email support included with all instances types to .xlarge
TAC ENT - 24x7x365 email and phone support included with all instance types above .xlarge
To request TAC support, visit:
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Routed IPsec site-to-site VPNs, remote access with Mobile IPsec, and WireGuard VPN capabilities
Routing Protocols
BGP, OSPF, RIPv2, IPv4/IPv6, and ECMP routing support
Management and Monitoring Interfaces
Command line interface (CLI), RESTCONF API, GUI, SNMP, Prometheus Exporter, and IPFIX Exporter
Security Access Control
L2/L3/L4 ACLs scalable to over 100,000 rules with zero trust architecture
Underlying Technology Stack
Vector Packet Processing (VPP), Data Plane Developer Kit (DPDK), Clixon, and Free Range Routing (FRR) on Linux/Ubuntu base
Application Layer Visibility and Control
Complete application layer-7 visibility and control of traffic with next-generation firewall capabilities in AWS environments
AI/ML-Powered Threat Detection
AI/ML-powered inspection engine with researcher-grade signatures for detection of zero-day threats, exploits, malware, spyware, and command and control attacks
Dynamic Policy Management
Policy definitions that dynamically apply to cloud assets based on AWS tags, Application IDs, User IDs, geographies, or zones without manual intervention
Cloud Infrastructure Integration
Seamless integration with Gateway Load Balancer, AWS Auto Scaling, and Transit VPC with AWS Transit Gateway for protection across dynamic and large-scale deployments
Advanced Threat Prevention Service
Cloud-delivered Advanced Threat Prevention security service with market-leading threat coverage against known and zero-day threats while maintaining performance
Next Generation Firewall Architecture
High-performance firewall solution with core firewall, VPN, NAT, and advanced L4-L7 security services including application security, IPS, and anti-virus capabilities.
Anti-Virus and Malware Protection
Cloud-based anti-virus protection that detects and blocks spyware, adware, viruses, keyloggers, and other malware over POP3, HTTP, SMTP, and FTP protocols.
Intrusion Detection and Prevention
Intrusion detection and prevention (IPS) system integrated with application visibility and control through AppSecure for threat detection and workload protection.
VPN and Secure Connectivity
IPsec and full mesh VPN termination services enabling secure connectivity from on-premises data centers, campuses, and branches to AWS cloud across geographically dispersed VPCs.
AWS Cloud Service Integration
Native integration with AWS services including Elastic Load Balancer, Auto-Scaling Groups, CloudWatch, Security Hub, Key Management Service, Elastic Network Adapter support, and Gateway Load Balancer with L3 gateway and L4 load balancer capabilities.
The VPN features are the most robust and its seamless to the end users
What do you dislike about the product?
The User Interface is not so intuitive could be improved
What problems is the product solving and how is that benefiting you?
Its allowing it use a virtual device that saves on cost and management.
Jim Logan
Achieves exceptional performance and programmability with minimal hardware requirements
Reviewed on Apr 08, 2025
Review provided by PeerSpot
What is our primary use case?
We use Netgate TNSR as core routers and edge routers for peering. We have multiple edge routers, and we set up peering with our service providers and other peers on those edge routers. We also have core routers that do BGP route reflection and power our fiber rings. We found it extremely easy to use and highly performant.
How has it helped my organization?
TNSR allows us to pass hundreds of Gbps across our network, and between our peers, for a fraction of the cost of other vendors.
What is most valuable?
Netgate TNSR is a fully-featured router that handles all the technologies that we use. It has a very familiar and intuitive command-line interface. Additionally, it includes an API, which makes it easier to use in a programmatic fashion. It has been a very cost-effective alternative to larger router vendors, and we tend to get better performance out of it for the hardware that we use, achieving over four hundred gigs of throughput with very minimal hardware. Throughput is key to us.
What needs improvement?
I would like to see support for AMT (RFC7450) in future versions.
For how long have I used the solution?
We've been using it for the last year.
What do I think about the stability of the solution?
It's been rock solid - a set and forget kind of solution.
What do I think about the scalability of the solution?
TNSR will scale up directly with the hardware it is running on. It likes single CPUs with lots of cores, and RAM. But the reality is that it doesn't take THAT many cores to see terabit throughput.
How are customer service and support?
Netgate is known to have really good technical assistance, and the people we spoke to were just one hop away from the actual developers.
Which solution did I use previously and why did I switch?
We use Cisco routers for some of our sites, but we'll be moving them to Netgate TNSR as soon as possible.
How was the initial setup?
TNSR does require some basic tuning, which is just a few commands entered via the CLI. The documentation is excellent though and we got up and running very quickly. If you are used to a Cisco or Juniper CLI, TNSR's CLI will seem very familiar.
What about the implementation team?
We are mostly in-house.
What was our ROI?
Due to the low price of TNSR, the only investment worth noting is the hardware. Because these are running on our core network, calculating a firm ROI is difficult.
What's my experience with pricing, setup cost, and licensing?
On the market TNSR is the lowest cost, but don't let that throw you off. It is the best cooked product in its space. You do have to maintain your yearly licenses though, so it's a good idea to add the expiration date to your calendar.
Which other solutions did I evaluate?
We looked at VyOS and Juniper as well, but the CLI and performance of TNSR won the day.
What other advice do I have?
I would absolutely recommend Netgate TNSR. It is surprisingly high performance for very little total cost of ownership. I would rate Netgate at least a nine because their product is made very well, and I had no problems using it at all, even without reading any directions or documentation. It was just very intuitive. It's a really great product, and I would highly recommend it. I rate the overall solution a 9 out of 10.