1
General Discussion / Re: Sanity Checking My "Stick" Setup
« on: May 28, 2024, 10:19:54 pm »Nothing wrong with VLAN separation instead of physical interfaces. I run OPNsense on a single NIC machine.
You may want to consider running a hypervisor such as Proxmox so you can separate DNS from the firewall to reduce the attack surface. This will also let you snapshot before updates, although that improves availability more than security.
That is dependent on the amount of RAM in the HP, you'd want at least 8 GB for an OPNsense VM and something like a Pi-hole LXC.
Bart...
Many thanks for the helpful info Bart!
Its good to know that I at least got the VLAN setup mostly correct. I am still grasping the concepts of these kinds of network tech, so I am still learning the basics, but I think I am getting there.
As for the hypervisor setup, I read a lot of conflicting info on the practice, as many suggest running firewall on separate bare metal, while others say its just fine to run in hypervisor, but the risk is up to user responsibility, which is also fine by me.
I managed snag this hp machine for about 45 USD, and it came with a skylake i5, 8 gigs of ram, and the ever important intel NIC. I do have another machine running proxmox, which hosts my home automation software and other services, I have the internet based services relegated to the opnsense machine, running the firewall, unbound dns, and caddy reverse proxy.
While the setup hasnt given me many issues, I have come across hostname resolution issues from changing ip addresses. But that is relatively small and only and issue with seldom used computers.
I will investigate the options of using proxmox on the hp machine, as it stupidly underutilized for its purpose. I only have 500/500 internet speeds, and my LAN is wired for 1G only, so the machine is hardly breaking a sweat.