Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - rungekutta

#91
Bumping this thread. No ideas of similar experience? How do I raise a bug for this?
#92
Do you plan to / need IPS? Rackmount or stand-alone? Would fan noise be an issue or do you need it fanless?
#93
(to add - I note the workarounds to start hacking around with cron scripts and pfctl but I really want to avoid that if possible)
#94
19.1 Legacy Series / Scheduled states not working
June 19, 2019, 09:41:09 PM
Hi,

This seems to be a long standing issue in pfsense as well and since several years back:
https://forum.netgate.com/topic/69331/scheduled-blocks-won-t-work-without-manual-states-reset/2

Long and the short of it; in order to restrict kids' access to Internet at certain times of the day I've got the following rules:

Alias: kids' devices (KD)

Enable kids' devices to any, source KD, on schedule
Block kids' devices to any (source KD)
Default allow any other LAN to any (source !KD)

This almost works... except that states are not killed when the scheduled pass rule expires. So any new connection is blocked as expected, but already open ones are kept alive, which means the kids continue to play... until they have to switch page or whatever and suddenly find themselves locked out.

Firewall -> Advanced -> Schedule States is UNchecked (somewhat non-intuitively, but that's what everyone says)

As mentioned and as per the link above this seems to be an old issue and inherited into opnsense..?

Any ideas...?
#95
Nice one! And yes it would be interesting to hear your experience of this setup under load, this is a TDP 80W CPU right? But with superb performance to boot, the equiv Xeon D costs $$$$
#96
Should work: https://www.tp-link.com/us/support/faq/1842/

NB I have no personal experience from this product
#97
Quote from: harshw on April 20, 2019, 06:35:46 AM
Will try to get the X11SCL motherboard and use an i3 or i5-8400. I'll be running opnsense alone but I have gigabit internet and I wanted to run IPS/IDS on it as well as VPN. The other thing is I'll be using opnsense to bypass my ATT RG using netgraph. Have you had to use opnsense with gigabit throughput on IPS/IDS?
Nice. Yes I'm running gigabit internet with IPS/IDS on an i5-5250U cpu in a passively cooled Qotom box. I get close enough to full gigabit throughput that I'm happy. Haven't stressed openvpn speeds so not sure how it would perform then. An i5 8400 on the other hand should be almost twice as fast.
#98
Yes, Supermicro a bit more expensive but probably not by a huge margin when you account for power supply? Then you know the CPU fan will fit too. I would have gone that option... Still a relatively low cost compared to m/board with CPU and RAM.

What are you planning to run on it out of interest? Opnsense alone, or VMs / other stuff?
#99
Supermicro recommends this one: https://store.supermicro.com/1u-active-proprietary-cpu-cooler-snk-p0049a4.html

... but I guess that's if you use their chassis too. What chassis are you planning for it?
#100
Looking at it rationally, I guess for only a firewall and <=1Gbit, anything but the smallest Epyc 3101 is probably way overkill even including IDS. So if the need is there for a larger model, 10Gbit is probably in the mix too somewhere.

Bit different if the server is multi purpose, e.g. running ESXi and OPNsense only being one of several applications. Then the Epyc 3251 looks pretty bad-ass and great bang for the buck.
#101
They've started selling them in Sweden now. Bit cheaper than the equiv Xeon D-1500 and certainly D-2100 but no 10Gbit ethernet on the other hand. For 10Gbit the Xeons still look pretty good, also considering that architecture  would likely be the best supported from software/driver perspective.
#102
Sounds like you're in pretty good shape.
#103
Bleeding edge... not sure you can even buy them yet? Looks promising though.
#104
I'm not a professional network engineer either but here's me 5c and take them for what it's worth. Some considerations are necessary here which may help drive the decision; do the servers in the DMZ need to talk to each other or are they all completely stand-alone? What are they actually running in terms of OS and applications and how secure can they be? How many servers? Bear in mind that a firewall such as OPNsense is itself a server running FreeBSD - although with a lot of focus on keeping it secure. It may be possible to harden your application servers in themselves to a similar degree, depending.

A common practise for smaller setups would be to separate DMZ from LAN (as you have) and basically treat the DMZ almost as the public internet, i.e. assume that any server in there could be hacked (through what they expose to the internet) and therefore harden all the servers themselves, through absolute minimum number of ports and services open etc.

Additional layering (network segments and firewalls) can bring additional isolation and security as well as scale but I wouldn't go there just for the sake of it before taking a hard look at the servers themselves first and how they interact with one another on the DMZ if at all.
#105
Quote from: daquirm on March 14, 2019, 11:50:48 PM
Their appliances seem to use similar embedded AMD processors like APU2 by https://pcengines.ch/apu2.htm very dated I have no idea why would anyone use that expecially for the price of Deciso...I'd buy rather something more enterprise and contribute back to the project via donation unless you need their support, where I could understand why to pay extra...
Agreed, unfortunately. Maybe the lower end models offer a reasonable package, although very modest performance with embedded low-end AMDs as you say. But moving up the value chain with their embedded A10 quad core models, you're approaching SuperMicro Xeon server territory in terms of pricing, with higher performance in orders of magnitude and better expandability etc.