OPNsense Forum

English Forums => Hardware and Performance => Topic started by: balubeto on September 22, 2018, 09:21:38 am

Title: purchase of an firewall hardware
Post by: balubeto on September 22, 2018, 09:21:38 am
Hi



I'm looking for an OPNsense firewall that can handle an Ethernet LAN consisting of 8 computers, a NAS, a printer and two smart-TVs connected to a 16-port switch. The Internet connection (VDSL2) is managed by the TIM router.


Now, I would like to buy a hardware firewall, managed by OPNsense 18.7 64 bit, that allows to completely manage this LAN and the Internet connection on PPPoE. Moreover, I would like to have the possibility to use also a backup Internet connection.


In addition to normal navigation, I do an intensive use of the P2P and torrent networks and I also see at the same time two different programs streaming on the two Smart-TVs.


So, which hardware firewall should I buy?


Thanks


Bye
Title: Re: purchase of an firewall hardware
Post by: marjohn56 on September 22, 2018, 11:18:34 am
Max VDSL speed is what and how much are you prepared to spend?


Also you want to make sure that whatever you buy is a little future proof.
Title: Re: purchase of an firewall hardware
Post by: balubeto on September 22, 2018, 11:46:49 am
Max VDSL speed is what and how much are you prepared to spend?


Also you want to make sure that whatever you buy is a little future proof.

The current theoretical speed of connection to the Internet is 100Mb but I expect an upgrade to 1Gb in a short time.

My maximum budget is 500-600 Euro.

Thanks

Bye
Title: Re: purchase of an firewall hardware
Post by: marjohn56 on September 22, 2018, 01:14:21 pm
Value for money go for a Qotom i7. Well tested by users here and will quite happily handle all that and more.
Title: Re: purchase of an firewall hardware
Post by: balubeto on September 22, 2018, 05:37:38 pm
Value for money go for a Qotom i7. Well tested by users here and will quite happily handle all that and more.

Where are the specifications of this product?

In the first post, I forgot to say that I also need to access the network from outside through an encrypted tunnel, creating, in this way, a VPN. In addition, I would like to use, as a backup connection, a router 4G that automatically intervenes if the main connection to the Internet does not work.

Since I live in Italy, I would like you to recommend a product that is also distributed in Italy.

Thanks

Bye
Title: Re: purchase of an firewall hardware
Post by: marjohn56 on September 22, 2018, 07:15:19 pm
Distributed in Italy, that will not be so easy, Qotom are supplied direct from Hong Kong. Seems like you'll need to search locally.
Title: Re: purchase of an firewall hardware
Post by: balubeto on September 22, 2018, 07:48:45 pm
Distributed in Italy, that will not be so easy, Qotom are supplied direct from Hong Kong. Seems like you'll need to search locally.

I'm sorry, what Qotom's model would you recommend?

Thanks

Bye
Title: Re: purchase of an firewall hardware
Post by: marjohn56 on September 23, 2018, 02:01:10 pm
I use i5's, more than sufficient for my use. First one is availble in i3, i5 & i7 config.


4 Port version - [size=78%]https://de.aliexpress.com/item/Qotom-Q300G4-S05-Qotom-Mini-PC-Core-i3-i5-i7-AES-NI-Linux-Pfsense-4-Gigabit/32857803116.html?spm=a2g0x.search0104.3.19.4916cf8ekHT3Rm&ws_ab_test=searchweb0_0,searchweb201602_3_10065_10068_10130_10547_10059_10884_10548_10887_10696_100031_10192_10190_10084_10083_10103_10618_10307_10820_10301_10821_10303,searchweb201603_60,ppcSwitch_3&algo_expid=401fff3e-abbc-4227-ac82-cac4ef9c8ce8-2&algo_pvid=401fff3e-abbc-4227-ac82-cac4ef9c8ce8&priceBeautifyAB=0 (https://de.aliexpress.com/item/Qotom-Q300G4-S05-Qotom-Mini-PC-Core-i3-i5-i7-AES-NI-Linux-Pfsense-4-Gigabit/32857803116.html?spm=a2g0x.search0104.3.19.4916cf8ekHT3Rm&ws_ab_test=searchweb0_0,searchweb201602_3_10065_10068_10130_10547_10059_10884_10548_10887_10696_100031_10192_10190_10084_10083_10103_10618_10307_10820_10301_10821_10303,searchweb201603_60,ppcSwitch_3&algo_expid=401fff3e-abbc-4227-ac82-cac4ef9c8ce8-2&algo_pvid=401fff3e-abbc-4227-ac82-cac4ef9c8ce8&priceBeautifyAB=0)[/size]


They now have a six port version too, it says Celeron, but you can choose an i3 or i5.


https://www.aliexpress.com/item/Qotom-Mini-PC-with-Celeron-Core-i3-i5-Pfsense-AES-NI-6-Gigabit-NIC-Router-Firewall/32863096123.html?spm=2114.search0604.3.16.59d12b45Tc7usP&ws_ab_test=searchweb0_0,searchweb201602_3_10065_10068_10130_10547_10059_10884_10548_10887_10696_100031_10192_10190_10084_10083_10103_10618_10307_10820_10301_10821_10303,searchweb201603_60,ppcSwitch_3&algo_expid=666a56f1-a1cf-44b0-b21f-1aa353cb1c4d-2&algo_pvid=666a56f1-a1cf-44b0-b21f-1aa353cb1c4d&priceBeautifyAB=0 (https://www.aliexpress.com/item/Qotom-Mini-PC-with-Celeron-Core-i3-i5-Pfsense-AES-NI-6-Gigabit-NIC-Router-Firewall/32863096123.html?spm=2114.search0604.3.16.59d12b45Tc7usP&ws_ab_test=searchweb0_0,searchweb201602_3_10065_10068_10130_10547_10059_10884_10548_10887_10696_100031_10192_10190_10084_10083_10103_10618_10307_10820_10301_10821_10303,searchweb201603_60,ppcSwitch_3&algo_expid=666a56f1-a1cf-44b0-b21f-1aa353cb1c4d-2&algo_pvid=666a56f1-a1cf-44b0-b21f-1aa353cb1c4d&priceBeautifyAB=0)



Title: Re: purchase of an firewall hardware
Post by: balubeto on September 23, 2018, 05:58:14 pm
I use i5's, more than sufficient for my use. First one is availble in i3, i5 & i7 config.


4 Port version - [size=78%]https://de.aliexpress.com/item/Qotom-Q300G4-S05-Qotom-Mini-PC-Core-i3-i5-i7-AES-NI-Linux-Pfsense-4-Gigabit/32857803116.html?spm=a2g0x.search0104.3.19.4916cf8ekHT3Rm&ws_ab_test=searchweb0_0,searchweb201602_3_10065_10068_10130_10547_10059_10884_10548_10887_10696_100031_10192_10190_10084_10083_10103_10618_10307_10820_10301_10821_10303,searchweb201603_60,ppcSwitch_3&algo_expid=401fff3e-abbc-4227-ac82-cac4ef9c8ce8-2&algo_pvid=401fff3e-abbc-4227-ac82-cac4ef9c8ce8&priceBeautifyAB=0 (https://de.aliexpress.com/item/Qotom-Q300G4-S05-Qotom-Mini-PC-Core-i3-i5-i7-AES-NI-Linux-Pfsense-4-Gigabit/32857803116.html?spm=a2g0x.search0104.3.19.4916cf8ekHT3Rm&ws_ab_test=searchweb0_0,searchweb201602_3_10065_10068_10130_10547_10059_10884_10548_10887_10696_100031_10192_10190_10084_10083_10103_10618_10307_10820_10301_10821_10303,searchweb201603_60,ppcSwitch_3&algo_expid=401fff3e-abbc-4227-ac82-cac4ef9c8ce8-2&algo_pvid=401fff3e-abbc-4227-ac82-cac4ef9c8ce8&priceBeautifyAB=0)[/size]


They now have a six port version too, it says Celeron, but you can choose an i3 or i5.


https://www.aliexpress.com/item/Qotom-Mini-PC-with-Celeron-Core-i3-i5-Pfsense-AES-NI-6-Gigabit-NIC-Router-Firewall/32863096123.html?spm=2114.search0604.3.16.59d12b45Tc7usP&ws_ab_test=searchweb0_0,searchweb201602_3_10065_10068_10130_10547_10059_10884_10548_10887_10696_100031_10192_10190_10084_10083_10103_10618_10307_10820_10301_10821_10303,searchweb201603_60,ppcSwitch_3&algo_expid=666a56f1-a1cf-44b0-b21f-1aa353cb1c4d-2&algo_pvid=666a56f1-a1cf-44b0-b21f-1aa353cb1c4d&priceBeautifyAB=0 (https://www.aliexpress.com/item/Qotom-Mini-PC-with-Celeron-Core-i3-i5-Pfsense-AES-NI-6-Gigabit-NIC-Router-Firewall/32863096123.html?spm=2114.search0604.3.16.59d12b45Tc7usP&ws_ab_test=searchweb0_0,searchweb201602_3_10065_10068_10130_10547_10059_10884_10548_10887_10696_100031_10192_10190_10084_10083_10103_10618_10307_10820_10301_10821_10303,searchweb201603_60,ppcSwitch_3&algo_expid=666a56f1-a1cf-44b0-b21f-1aa353cb1c4d-2&algo_pvid=666a56f1-a1cf-44b0-b21f-1aa353cb1c4d&priceBeautifyAB=0)





For you, how much RAM and what size (and specifications) of the SSD disk would be needed to ensure that this firewall works without problems considering also that this should work for many years without interruptions?

By chance, is there an Italian distributor that sells these Qotom Mini-PCs with the latest version of OPNsense 64bit pre-installed?

Thanks

Bye
Title: Re: purchase of an firewall hardware
Post by: marjohn56 on September 23, 2018, 08:42:21 pm
In answer to your final question, no, it will come with pfsense installed if you ask for it. You could always ask them to install Opnsense, whether they will or not is a matter for them.


There are no distributors AFAIK for Qotom, they are supplied directly by the manufacturer.


You could always buy a Deciso product, which will come with Opnsense installed and all the specifications can be found here:


https://www.deciso.com/short-introduction-opnsense/# (https://www.deciso.com/short-introduction-opnsense/#)
Title: Re: purchase of an firewall hardware
Post by: balubeto on September 24, 2018, 10:44:47 am
In answer to your final question, no, it will come with pfsense installed if you ask for it. You could always ask them to install Opnsense, whether they will or not is a matter for them.


There are no distributors AFAIK for Qotom, they are supplied directly by the manufacturer.


You could always buy a Deciso product, which will come with Opnsense installed and all the specifications can be found here:


https://www.deciso.com/short-introduction-opnsense/# (https://www.deciso.com/short-introduction-opnsense/#)

Among Deciso's Desktop products, is there a product suitable for my needs?

Thanks

Bye
Title: Re: purchase of an firewall hardware
Post by: marjohn56 on September 24, 2018, 11:08:39 am
I would expect the A10 Quad Core SSD Desktop Gen2 would more then meet your needs. It's not as powerful as the Qotom is more expensive but is made in Europe.
Title: Re: purchase of an firewall hardware
Post by: balubeto on September 25, 2018, 09:18:53 am
I would expect the A10 Quad Core SSD Desktop Gen2 would more then meet your needs. It's not as powerful as the Qotom is more expensive but is made in Europe.

Okay.

Another particular: Which is the purpose of a 128GB disk?

Thanks

Bye
Title: Re: purchase of an firewall hardware
Post by: marjohn56 on September 25, 2018, 09:31:48 am
Logs, rules and whatever else needs to stored on disk. A basic installation takes up very little space, the more complex it becomes with the addition of plugins and packages the more space is needed. For example my live unit runs in under 4Gb of disk, but my test unit uses 3 times that as I use it for development, neither of them have proxy or IDS/IPS though, if they did they would use more.