Building New OPNSense Box with Intel X520-DA2 -- Any Issues to Expect?

Started by Sinister Pisces, June 17, 2023, 07:36:34 AM

Previous topic - Next topic
Hello,
I've been using a fanless Topton box with an Intel Pentium Silver N6005 and 2x2.5 GbE ports for my OPNSense install, and am ready to upgrade to a bigger box to support 10GbE (and inter-VLAN switching to the extent I can't avoid it as I start building out VLANs on my currently flat network). This is for a small home network with no more than five 10 GbE capable machines--though some of them have two NICs.

I've picked up a Dell Optiplex 5040 with 16GB of RAM and also bought an Intel X520-DA2. Not the most powerful box ever, but it wipes the floor with the Topton box, and only cost me $120 shipped. It'll be here tomorrow and I'd like to try migrating my config on Sunday.
I'm going to make sure I update the firmware on the Intel X520-DA2 on a Windows machine before I try installing OPNSense. Is there anything else unusual I need to do, or should I expect the OPNSense installer to just recognize the card and go through without issue? I'm looking for 10GbE line speed.

Thanks!

It should be just picked up.  I'm relatively sure that the drivers are already built into OPNSense.  Line speed is going to be a complicated issue to answer and requires a lot more information than you've provided.

How are you connecting 5 machines with a 2 port card?  Are all of them going to be on the same VLAN?  Are you using any packet inspection or purely routing?

Quote from: CJRoss on June 20, 2023, 02:40:04 PM
It should be just picked up.  I'm relatively sure that the drivers are already built into OPNSense.  Line speed is going to be a complicated issue to answer and requires a lot more information than you've provided.

How are you connecting 5 machines with a 2 port card?  Are all of them going to be on the same VLAN?  Are you using any packet inspection or purely routing?
Thanks! It works just fine. :) I haven't tried LACP to combine the two SFP+ ports on the LAN-side, but I think I'm going to give it a go this weekend just to see if it works. I'm getting 9.5+ Gbps with iPerf on a flat network with no VLANs (I did have to change the MTU settings on the OPNSense LAN interface and my 10Gbps test client to use jumbo frames), so all is well. Now I can move on to actually setting up VLANs. Or trying to. Not done that before.
The OPNSense box's LAN connection runs from the 10Gbps card to a QNAP M1208-8C I'm using as a core switch. The rest of my network hangs off that. :)

I'm looking at setting up Crowdsec and Zenarmor at some point, as well, but I'm running a home/home office network in an apartment with 3 people, so I don't feel the urge to go nuts with IDS.