Managed Virtual Routers with pfSense Routing Control
Route traffic between private networks, VLANs, and application tiers with NAT (Network Address Translation), BGP/OSPF (dynamic routing protocols), and multi-WAN failover, all managed by our engineering team.
Steer traffic between subnets, VLANs, and app tiers with centralized routing rules.
Manage outbound NAT and publish services safely with controlled port forwarding.
BGP and OSPF support for advanced topologies that outgrow static routes.
Gateway monitoring and failover policies keep connectivity up during upstream issues.
Part of our Network Security Solutions platform. Also available: Managed Firewalls and Managed VPNs.
What is a managed virtual router?
A virtual router controls traffic between networks: which subnets communicate, how outbound traffic is NAT’d, how inbound traffic is forwarded, and how routes are advertised or learned. Togglebox Managed Virtual Routers run as pfSense virtual appliances, letting you centralize routing rules in one place instead of scattering them across individual servers.
Routing and segmentation control
Define clear paths between private networks, application tiers, and management zones without exposing internal services.
NAT and gateway behavior
Manage outbound NAT, inbound port forwarding, and failover policy across one or more uplinks.
Dynamic routing readiness
Extend to BGP and OSPF networks when growth and resilience requirements outgrow static routes.
Core routing and NAT capabilities
NAT and reverse NAT (port forwards)
Use NAT for outbound connectivity and port forwards to publish specific services safely. Keep internal services on private networks while exposing only intended public entry points.
Static routing and policy-based routing
Static routes are the foundation of many cloud designs. Policy-based routing steers traffic over specific gateways based on source, destination, or service. It is especially useful in multi-uplink environments and staged migrations.
Segmentation between VLANs and networks
Separate public ingress, app tiers, databases, admin networks, and partner connectivity. A managed virtual router enforces boundaries while keeping routing clear.
Routing patterns for growing networks
Dynamic routing (BGP / OSPF)
When static routing becomes unwieldy, dynamic routing lets your network adapt as paths change. pfSense supports BGP and OSPF via the FRR package.
- BGP peering for controlled route exchange between environments or providers
- OSPF for internal route propagation in complex networks
- Route filtering to keep advertisements safe and intentional
Multi-WAN and failover
For environments with multiple uplinks, a managed virtual router supports multiple gateways and failover to maintain connectivity during upstream outages.
- Gateway monitoring to detect upstream failures
- Failover policy to shift traffic to the healthy path
- Traffic steering so critical services prefer the best route
Integration with private networks and ongoing support
Managed virtual routers often connect multiple private networks inside a Togglebox private cloud environment. Common patterns include isolating databases on a dedicated private network, creating an admin-only network reachable by VPN, and using a separate network for internal service communication.
Togglebox engineers help with initial network planning, NAT design, route troubleshooting, and later routing changes so the design stays understandable as your environment grows.
When to choose a virtual router vs. a firewall vs. a VPN
These solutions overlap. Pick based on your primary goal:
- Virtual Router: you need routing/NAT control between networks and a place to manage routing
- Firewall: you need security-focused ingress/egress rules, segmentation, and filtering
- VPN: you need encrypted connectivity between sites or for remote user access
For help choosing, the Network Security Solutions hub page breaks options down by use case.
Pricing and ordering
Pricing starts at $25/month + server resource costs. We can help you choose the right CPU/RAM allocation based on routes, throughput, and the features you plan to enable.
Also available: Managed Firewalls and Managed VPNs.
Trusted by businesses that rely on real support
“In every deployment our dev team scoped, Togglebox was the best value. The approach makes sense — pick your resources and allocate them across your machines however you want.”
Common Questions
How is ImunifyAV+ different from Imunify360?
ImunifyAV+ focuses on malware scanning and cleanup. Imunify360 adds layered controls such as WAF and broader intrusion protection.
How do I choose between firewall, VPN, and virtual router services?
Choose firewall for boundary control, VPN for encrypted remote access, and virtual routers for routing or segmentation design.
Can I get help reviewing my security architecture?
Reach out to a security engineer for a fit and sizing review.
No matching questions found.
Ready to deploy a managed virtual router?
Tell us your routing and network requirements. We will design the routing configuration and deploy it for you.
Managed by Togglebox engineers, backed by 20+ years of hosting experience.