OPNsense Forum

English Forums => Hardware and Performance => Topic started by: snoopy78 on October 30, 2019, 03:16:16 pm

Title: newbie wants to build 1st opnsense firewall
Post by: snoopy78 on October 30, 2019, 03:16:16 pm
Hello,

I’m a newbie in terms of firewalling but want to consolidate my current network.

Currently i do have a vpn Firewall connecting tom my wan (100/40MBit) and LTE (10/10MBit) in spillover mode. Also acting as VPN Server for 2x IPSec site to site and 1–3 (max.) roaming clients.
I also have a 2nd router behind the firewall acting as openvpn client (to bypass georestrictions). Routing between my vlans is working.

My internal network is 10gbit backbone and also some clients/server have 10gbit connections.

My plan/idea is to migrate both existing routers into 1 opnsense box.

Also I would like to connect the vlans (internally) with 10g. Here is purely routing active, no nat/pat/...or ACL.
Additionally I want to have my existing site–to–site & roaming client vpns. But also the opensense should act as a openvpn client (maybe 2 or 3 different tunnels/targets). Here I want to use ACLs/Firewalling to define from which vlan/client i use which gateway. And only this gateway.
Also i have some incoming rules.

IDS/IPS will be maybe later.
Freeradius maybe later for cert based WiFi.
WebProxy when the kids grow a bit more.

From what I’ve read so far, I can realize all the things witH OPNsense.

So now comes the tricky part. I must save energy.

Therefore I was looking for this hardware.

https://www.asrock.com/mb/Intel/J5005-ITX/index.asp

Or

https://www.supermicro.com/en/products/motherboard/A2SDi-H-TF

Which one would you suggest? Also, are this systems able to handle my requirements?

I did check about i3 already but the idle/load consumption was way higher (at least what I’ve seen so far).
Also I already have an https://www.supermicro.com/en/products/motherboard/X10SDV-2C-TP4F  Working as my NAS.
The power consumption is also too high for 25/7 usage.

Thank you in advance.

BR
Snoopy78




Title: Re: newbie wants to build 1st opnsense firewall
Post by: daigoro on October 31, 2019, 03:13:20 pm
I'd vote for Supermicro, having 3 in production. Like 2x10Gb ports and IPMI.