Hi all, I would like your opinion about a setup I want to implement.
Our company offices has about 100 users. I want to setup an OPNsense system with all needed configurations such as IDS/IPS, web filtering and failover. Could you please suggest something like a 1U hardware or a mini PC like Dell Vostro ? Would an i5 or i7 be fine ? I would be grateful for any other additional information.
Thank you.
You will find great well supported appliances here:
https://shop.opnsense.com/
If you are unsure about the performance figures abd sizing, just ask them before buying.
Thank you for the information, I am aware that I can order ready appliances with excellent hardware but I would like to try and use hardware like what I described. Would it possible to have hardware description for that please ?
Thank you in advance.
You will need to find someone on this forum who
1. owns more or less this exact piece of hardware
2. has done extensive performance testing
Good luck with that.
I would pick hardware according to the performance requirements.
Thank you. Anyone else that could write his suggestion based on similar experience in enterprise use cases please ?
I don't get it. They offer 1 U units exactly like you required.
Apart from the 100 users, what bandwidth? And yoyu mention failover, so I assume you need two units?
I mean WAN failover = at least 3 NICs
Internet bandwidth? 1G? 10G? How much throughput with IDS/IPS enabled do you expect? Any VPN connections? If yes, how much bandwidth?
1G internet bandwidth, IDS/IPS throughput not metered, let's say something usual, VPN connections are handled by other system. Thank you.
So, the 100 users are a piece of cake for every serious system available. As is the 1 G uplink bandwidth if it is only basic filtering. With IDS/IPS active this system:
https://shop.opnsense.com/new-dec2600-series-opnsense-rack-security-appliance/
can do ~300 Mbps throughput.
Whereas this system:
https://shop.opnsense.com/dec2700-series-opnsense-rack-security-appliance/
can do ~1 Gbps throughput.
So I suggest the latter it is ...
I have been using hardware from Pondesk since long and they have just launched some new products.. seems very interesting for OPNsense. I have ordered this one last week MNHO-096 and so far its running very well but now I am planning to use Zenarmor along with OPNsense. You can look at this one
https://www.pondesk.com/product/Intel-N5105-4-LAN-i211-5G-CPE-Fanless-Network-Appliance-SDWAN-Security-Gateway-with-TPM_MNHO-096
All the best with your search
Dorthy