Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - TommyTran732

#1
So I just realized the CPU on the old DEC3850 is EPYC Embedded 3201. From the spec sheet, it looks identical to the the new DEC3852 and DEC3862, so guess the CPU is also the same there?  ???
#2
Hi,

I am looking to buy a rack mounted Deciso appliance, so I wonder if anyone can give me the CPU for the Deciso 2770, 3842, 3852, and 3862?

I have the DEC750 and it is running the Ryzen V1500B. Is this the same with the DEC2770 considering the throughput on the spec sheets is the same?

Thanks,
Tommy
#3
General Discussion / Re: Tor Configuration
September 19, 2023, 02:21:08 AM
This works for me.

One thing missing in the instruction is that you also need to NAT port 53 TCP/UDP on the interface used for Tor to 127.0.0.1:9053 to prevent DNS leaks.

Oh, and the 127.0.0.1 Socks ACL seems unnecessary.
#4
Hi,

I am seeing some conflicting information on the forum, so I hope to find some clarifications here :)

- I want to use NTS, so I installed the Chrony plugin. I enabled NTS client support and added NTS peers.
- Some posts suggest that the NTP servers should be removed from NTP settings (the Service -> Network Time) so that ntpd stops running and will not run at boot. I followed this advice as I don't want an unnecessary service running on my system. However, I wonder if this is strictly necessary or if Chrony would have overriden NTPd anyways?
- The default port for chrony is 323 somehow. Is it to avoid conflict with NTPd?
- As far as I understand, chrony will automatically set the time. There is no need for a cronjob to sync with the chrony daemon. Is this correct?
- Someone said that if I change the port to 123, I will need to set up a cronjob to synchronize the time. If what I said above is correct, why is this the case? Is this person just wrong?
#5
Good to hear.

I bought the DEC750 last week. I just recently realized that I may have 10Gbps fiber in the not-so-distant future, so I am debating on whether to just return the DEC750 and buy a DEC850 or not.
#6
Wow, interesting. I did not expect it to be that big of a difference.

I am a bit confused though: 400Mbps is well under the advertised 2Gbps. Are you using like a lot of rules or something?
#7
What is the maximum throughput that you got with it?
#8
Hi,

I wonder if anyone has done any threat protection throughput benchmark on these 2 devices with RSS? I see that without RSS it's 1Gbps on the DEC750 and 2Gbps on the DEC850, so I am wondering if RSS makes any difference.

Thanks,
Tommy
#10
Hi Schellevis,

I meant that I want the boot to be rejected in case an attacker has somehow loaded firmware which does not match Deciso's signature into the flash chip (be it a through physical attack or some sort of exploit).

I am pretty sure that this can be set up by the OEM regardless of the UEFI Secure Boot state. Take a modern laptop for example - I don't think that anyone can just flash random boot firmware without bricking the device because of Intel Bootguard / AMD Platform Secure Boot. One can disable UEFI Secure Boot and use FreeBSD and their firmware will still be protected. It would really be nice if the Deciso devices have these.

Also, I am a bit confused by the notation "[2]600 series". Do you mean the DEC675 and DEC695? In any case, I ended up ordering a DEC750 so it should have UEFI, right?
#11
Hi Schellevis,

Could you elaborate a bit more on this? What's stopping the EFI firmware from being verified regardless of the Secure Boot state of the operating system?

Thanks,
Tommy
#12
Hi,

I am looking to buy some Deciso appliances (mostly like the DEC695). I wonder if AMD SecureBoot is enabled on these devices? (Just to be clear, I am referring to the AMD Secure Boot that verifies the UEFI firmware, not UEFI Secure Boot).

I saw devices from other brands allowing users to just flash arbitrary boot firmware onto the devices and am not too happy about it, so I am hoping that Deciso devices will be different.

Thanks,
Tommy