Acronis Bitdefender Fortinet Microsoft Cisco Duo HPE Adobe Adobe Green Rocket Acronis Bitdefender Fortinet Microsoft Cisco Duo HPE Adobe SolarWinds Green Rocket
Netgate product

TNSR high-performance software router

Deliver terabit-class routing, secure VPN, and cloud-native orchestration across hybrid networks.

40Gbps+
High-performance routing
VPP
Dynamic routing suite
REST
Secure VPN options
L3
Cloud + on-prem deployment

What is TNSR

TNSR is a high-speed software router and VPN concentrator leveraging VPP for exceptional throughput.

  • Advanced routing with BGP, OSPF, ECMP, and VRF
  • Secure VPN with IPsec and WireGuard
  • Cloud-native orchestration via NETCONF/RESTCONF and CLI

Performance with flexibility

Run on Intel or ARM64 in the cloud or on Netgate hardware.

AWS and Azure images for fast deployment

On-premises appliances for predictable throughput

Scale-out routing for multi-cloud architectures

Automation-friendly APIs

Key features

Routing and VPN capabilities built for demanding networks.

VPP acceleration

Vector Packet Processing for high throughput and low latency.

Advanced routing

BGP with BFD, OSPFv2/v3, ECMP, and IPv6.

High-performance VPN

IPsec and WireGuard for site-to-site and remote access.

Flexible deployment

Run on AWS, Azure, Netgate appliances, or hybrid environments.

Simple management

CLI plus NETCONF/RESTCONF for orchestration at scale.

Segmentation

VRF and policy controls for multi-tenant networks.

Architecture built for scale

TNSR focuses on dataplane performance and operational consistency.

  • Optimized dataplane with VPP and DPDK
  • Carrier-grade NAT and advanced routing policies
  • Telemetry and exportable monitoring
  • Secure defaults and role-based access

Cloud ready

Deploy in complex cloud architectures and multi-cloud designs.

Automation first

API-driven configuration for fleets of routers.

Predictable performance

Consistent throughput for routing and VPN workloads.

Use cases

Complex cloud architectures

Integrate routing across multi-cloud and hybrid environments.

High-capacity network expansion

Extend routing, NAT, and VPN capabilities at scale.

Service provider edge

Deliver secure routing and VPN services at the edge.

Why teams choose TNSR

High throughput

Terabit-class performance for demanding workloads.

Lower cost

Software routing at a fraction of traditional appliance costs.

Operational consistency

Standardized management across hundreds of instances.

Secure networking

VPN and segmentation built-in.

Performance highlights

100+ Gbps

High-performance routing

BGP + OSPF

Dynamic routing suite

IPsec + WG

Secure VPN options

AWS + Azure

Cloud + on-prem deployment

Ecosystem and integrations

Run TNSR wherever your routing strategy requires.

AWS support
Azure support
Netgate appliances
Intel & ARM64
NETCONF + RESTCONF
Operational CLI
Expert Analysis

What is TNSR and when should you choose it over pfSense?

TUTARI S.A. — Certified pfSense Engineers

Expert Analysis Latin America and the Caribbean

TNSR is Netgate's high-performance router based on fd.io VPP (Vector Packet Processing) technology, designed for 10-100+ Gbps throughput with microsecond latency. While pfSense excels at stateful firewalling up to ~10 Gbps, TNSR is built for network cores, BGP peering, high-speed site-to-site VPN, and environments requiring pure routing at wire-speed.

TUTARI deploys TNSR for ISPs, datacenters, and enterprises requiring bandwidth above 10 Gbps. Our certified engineers configure BGP with full-table (800K+ prefixes), OSPF, IS-IS, GRE/VXLAN encapsulation, line-rate IPsec, and segment routing. TNSR is managed via REST API or YANG-based CLI, ideal for automation tool integration with Ansible and Terraform.

TNSR licensing includes direct Netgate TAC support with enterprise SLA. TUTARI provides carrier-grade architecture design, migration from Cisco IOS/IOS-XE, Juniper JunOS or MikroTik, and continuous monitoring with proactive alerts. Every project includes documented performance testing (throughput, pps, latency) to validate infrastructure meets requirements.

FAQ

Frequently Asked Questions about TNSR

Answers to the most common questions about our services

What is the main difference between TNSR and pfSense?

pfSense is a stateful firewall designed for perimeter security (up to ~10 Gbps). TNSR is a high-performance router based on VPP (Vector Packet Processing) optimized for 10-100+ Gbps throughput with pure routing. pfSense inspects packets (firewall rules, IDS/IPS, NAT), TNSR routes at wire-speed. Use pfSense for security, TNSR for core routing and high-speed VPN. Many organizations deploy both: TNSR as edge/core router and pfSense as perimeter firewall.

What routing protocols does TNSR support?

TNSR supports full dynamic routing: BGP (full-table with 800K+ prefixes, communities, route-maps, prefix-lists), OSPF v2/v3, IS-IS, static routes with BFD (Bidirectional Forwarding Detection) for sub-second convergence. It also supports policy-based routing, ECMP, VRF (Virtual Routing and Forwarding) for multi-tenancy, and segment routing. Configuration is done via REST API (OpenAPI/Swagger) or YANG-based CLI.

Can TNSR replace Cisco or Juniper routers?

Yes, for pure routing and VPN use cases. TNSR replaces Cisco ISR/ASR and Juniper MX/SRX in scenarios including: BGP peering (IX or transit), edge router with multiple uplinks, high-speed IPsec VPN concentrator, core router with OSPF/IS-IS, and WAN encapsulation (GRE, VXLAN). Cost is 70-90% lower than equivalent Cisco/Juniper. It does not replace advanced L2 switching features or proprietary SD-WAN.

What real performance does TNSR deliver?

TNSR with VPP achieves: 40+ Gbps throughput with 1500-byte packets on standard x86 hardware (Intel Xeon with Intel XXV710/XL710 NICs), 20+ Mpps (million packets per second) with small packets (64 bytes), IPsec AES-256-GCM at 20+ Gbps with QAT (Quick Assist Technology). Forwarding latency is <10 microseconds. Performance scales linearly with CPU cores assigned to VPP workers.

How does TNSR integrate with automation tools?

TNSR is 100% managed via REST API (documented with OpenAPI/Swagger), enabling native integration with Ansible (REST modules), Terraform (HTTP provider), Python scripts, and orchestration platforms like NetBox. Configuration uses YANG models that guarantee syntax validation before applying changes. TUTARI delivers custom Ansible playbooks for configuration backup, interface provisioning, and automated VPN tunnel deployment.

Does TNSR include security features like a firewall?

TNSR includes ACLs (Access Control Lists) for basic traffic filtering and IPsec VPN with AES-256-GCM encryption at line-rate. However, it is not a stateful firewall — it does not perform connection state inspection, IDS/IPS, or complex NAT. For perimeter security, the recommended architecture is TNSR as edge router + pfSense as stateful firewall behind it. This combination delivers enterprise performance and security at a fraction of Cisco/Palo Alto costs.

Accelerate routing with TNSR

We help you size, deploy, and automate TNSR across cloud and edge.