Top picks
N100 firewall · 6× Intel I226 2.5GbE · DDR4

UDPTCP 6-Port Firewall Mini PC

The CNC-021 N100-6L puts six Intel I226 2.5GbE ports on one N100 board, two more than the usual firewall box. Add DDR4 memory, an NVMe slot, a SATA port and a serial header, and it covers dual-WAN routing with room left over.

  • ProcessorIntel N100, 4 cores, up to 3.4GHz, 6W TDP
  • Network6× 2.5GbE, Intel I226
  • Memory1× DDR4 SO-DIMM, 3200MHz
  • Storage1× M.2 2280 (PCIe 3.0 x1) + 1× SATA 3.0
  • VideoHDMI + DP + USB-C, three 4K@60Hz screens
  • Serial1× COM port
Buy it for
  • Two ISPs plus four separate networks on physical ports
  • OPNsense or OpenWrt on well-supported Intel NICs
  • Reusing a DDR4 laptop stick from a drawer
Skip it for
  • Using the box as a six-port switch
  • Anyone who wants 10GbE or SFP+ fibre
See today’s price

Six Intel I226 ports: two WANs and four networks, no switch

Four ports is the default for an N100 firewall. The CNC-021 N100-6L carries six, all Intel I226 at 2.5GbE behind filtered RJ45 jacks. Those two extra ports turn a single-uplink router into one that can hold two ISPs and still give every network its own physical port.

Six ports suit homes and small offices that segment by cable rather than by VLAN. Plenty of cheap unmanaged switches, cameras and smart-home hubs have no idea what a VLAN tag is. A separate port per segment keeps them apart without a managed switch in the middle.

PortExample role
1WAN, primary ISP
2WAN, backup ISP or LTE router
3Main LAN
4Guest network
5IoT and cameras
6DMZ for a self-hosted server

The I226 is native hardware on FreeBSD and Linux through the igc driver. OPNsense, OpenWrt, Linux and ESXi are the systems UDPTCP names, and pfSense runs on the same chips from its 2.7 release onward.

  • Install a current release; older installers predate stable igc support.
  • Label the ports on the case before the first boot, since the OS numbers them in its own order.
  • If one port drops link now and then, disabling Energy Efficient Ethernet on it is the usual first fix.

Dual WAN with automatic failover is the headline use. OPNsense and pfSense both handle gateway groups: the backup ISP takes over when the primary stops answering pings, and traffic moves back when it recovers. More layouts sit under N100 firewall mini PCs.

Hardware

What’s inside

SpecValue
ModelCNC-021 N100-6L
ProcessorIntel N100, 4 cores / 4 threads
Clock / cacheUp to 3.4GHz, 6MB cache
TDP6W
GraphicsIntel UHD Graphics
Memory slot1× DDR4 SO-DIMM, 3200MHz
NVMe1× M.2 2280, PCIe 3.0 x1
SATA1× SATA 3.0
Wireless slot1× M.2 2230, CNVi by default
Ethernet6× 2.5GbE, Intel I226, filtered RJ45 jacks
VideoHDMI + DP + USB-C, triple 4K@60Hz
USB2× USB 3.0, 2× USB 2.0
Serial1× COM
BIOSDelete key for setup; Auto Power On, Wake-on-LAN, GPIO, PXE boot
Supported systemsOPNsense, OpenWrt, Linux, ESXi

Bridging six ports does not make it a switch

Six ports tempt people to bridge the spare ones and skip buying a switch. It works, but it is the wrong job for this hardware. A switch moves frames in dedicated silicon at line rate on every port; a software bridge pushes each frame through the N100's four cores.

On a firewall OS, bridged traffic is also filtered traffic unless you tune it otherwise, so a file copy between two bridged ports competes with routing and VPN for CPU time. Four efficiency cores cope with light use, but two machines copying at 2.5GbE across a bridge will show it.

  1. Give each network its own port and route between them. That is what the box is built for.
  2. Hang a small switch off the LAN port for rooms with several wired devices.
  3. Bridge two ports only for low-traffic devices, such as a printer beside the router.
  4. For a faster link to a busy switch or server, bond two ports with LACP instead of bridging.
Link aggregation, not magic. Bonding two 2.5GbE ports gives several clients 5Gbit/s combined, but any single transfer still tops out at 2.5Gbit/s. Your switch must support LACP too.

The six-port layout pays off when each port carries its own network and the router decides what crosses between them. Treated that way, the extra ports are the most useful thing about the box. Treated as a switch substitute, they are the least.

That same logic applies to IDS. Suricata inspecting six busy interfaces asks far more of four small cores than one WAN link does. Run it on the WAN and the DMZ first, then widen coverage only if the CPU graph stays calm.

Market position

How it fits the lineup

N100 mini PC models by type, September 2026. Highlighted: UDPTCP 6-Port Firewall Mini PC.

DDR4-3200, one NVMe, one SATA and a CNVi slot

Most current N100 firewall boxes use DDR5. This one takes a single DDR4 SO-DIMM at 3200MHz, the laptop memory many people already have in a drawer from an upgrade. The N100 supports both types, and on a router the speed difference between them is not something you will notice.

UDPTCP does not state a memory or SSD configuration for this model, so plan on supplying both. One DDR4 slot runs the N100's single memory channel at full width, and the N100 is specified for up to 16GB. For a firewall, 8GB is plenty.

  • M.2 2280: NVMe on PCIe 3.0 x1, roughly 985MB/s, far more than a router needs.
  • SATA 3.0: a 2.5-inch SSD for logs, packet captures or a second OS.
  • M.2 2230: a wireless slot wired for CNVi by default.
  • COM: a serial header for console access when the network is down.
CNVi is Intel-only. A CNVi slot accepts Intel CNVi Wi-Fi modules such as the AX201 or AX211, not ordinary PCIe Wi-Fi cards. Buy accordingly, or skip Wi-Fi and wire a separate access point, which a firewall OS prefers anyway.

The serial port is a quiet win. A router that loses its network config is hard to reach over the network, and a console cable gets you back in without a monitor. HDMI, DisplayPort and USB-C cover the screen route, three 4K@60Hz outputs in all.

Auto Power On, Wake-on-LAN, PXE boot and GPIO headers sit in the BIOS, reached with the Delete key. Auto Power On is the one to enable on day one, so the box restarts by itself after a power cut. Chip limits are listed under N100 specs.

Other options

Three other routes

The CNC-021 against four-port and 10GbE boxes

Port count decides it. If four ports cover your plan, a four-port box is simpler and often fanless. If you need a second WAN plus several physical segments, six ports save a managed switch. If you need faster than 2.5Gbit/s on any single link, neither is the answer.

UDPTCP does not state a cooling method for the CNC-021. Confirm whether a fan is fitted before it goes in a bedroom or a living room. Idle power rises with each linked port; hedged ranges for firewall boxes sit under N100 power consumption.

  • Pick the CNC-021 for dual WAN and four separate networks on physical ports.
  • Pick the oaknode MGNASN for two 10GbE SFP+ cages and an LTE slot.
  • Pick the CWWK four-port for a configured build with memory and NVMe fitted.
  • Pick UDPTCP's industrial box for four ports plus RS232, GPIO and a 4G slot.

The parts list is short: one DDR4 SO-DIMM, one M.2 2280 NVMe drive, and optionally a 2.5-inch SATA SSD. Budget memory is fine here, since the box runs a single channel at 3200MHz whatever you fit. Start with 8GB, move to 16GB if Suricata or several containers join the router.

The six-port layout is the reason to buy. The DDR4 slot, the serial header and the dual storage are what make it pleasant to live with.

FAQ

Owner questions

How many network ports does the UDPTCP CNC-021 have?

Six 2.5GbE RJ45 ports, all on Intel I226 controllers.

Does it use DDR4 or DDR5?

One DDR4 SO-DIMM slot at 3200MHz.

Can I add Wi-Fi?

The M.2 2230 slot is wired for CNVi by default, so it takes Intel CNVi modules such as the AX201 or AX211, not standard PCIe cards.

Does it support OPNsense?

Yes. OPNsense, OpenWrt, Linux and ESXi are all supported, and the I226 chips use the native igc driver.