Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Hardware and Performance
»
Hardware possibilities
« previous
next »
Print
Pages: [
1
]
Author
Topic: Hardware possibilities (Read 3680 times)
steppi
Newbie
Posts: 14
Karma: 0
Hardware possibilities
«
on:
March 02, 2021, 12:07:51 pm »
Hey there,
I near to rebuild my home-it-setup and plan to use OPNsense for firewall, VPN and so on.
Best option I know and I was planing with is a PCEngines APU4D4 or APU2E4.
A bit sad, there is no "cheap" readyto use 19" mounting or case.
Is there a better option in 2021 then PCEngines or a better for the buck?
Logged
bartjsmit
Hero Member
Posts: 2005
Karma: 193
Re: Hardware possibilities
«
Reply #1 on:
March 02, 2021, 03:32:16 pm »
Have you looked at these?
https://shop.opnsense.com/dec3800-series-opnsense-rack-security-appliance/
Bart...
Logged
steppi
Newbie
Posts: 14
Karma: 0
Re: Hardware possibilities
«
Reply #2 on:
March 02, 2021, 07:20:23 pm »
Yeah for sure, but way too much for home-use.
Price should be better or near pcengines.
Logged
hushcoden
Hero Member
Posts: 544
Karma: 23
Re: Hardware possibilities
«
Reply #3 on:
March 02, 2021, 07:56:22 pm »
Have a look at Qotom and Protectli...
Logged
steppi
Newbie
Posts: 14
Karma: 0
Re: Hardware possibilities
«
Reply #4 on:
March 03, 2021, 10:02:10 am »
Thx for this.
Protectli looks really good.
Couldn't find it yesterday, are these Intels aware of spectre and meltdown?
Logged
Patrick M. Hausen
Hero Member
Posts: 6709
Karma: 565
Re: Hardware possibilities
«
Reply #5 on:
March 03, 2021, 11:15:03 am »
Quote from: steppi on March 03, 2021, 10:02:10 am
Couldn't find it yesterday, are these Intels aware of spectre and meltdown?
Spectre and Meltdown are side channel attacks in a multi-tenant environment. They are hardly relevant on a dedicated appliance without any remote user access. Unless you already have a remote code execution vulnerability in which case you have larger problems, IMHO.
Kind regards,
Patrick
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
steppi
Newbie
Posts: 14
Karma: 0
Re: Hardware possibilities
«
Reply #6 on:
March 03, 2021, 03:07:09 pm »
Thx @pmhausen for explaining.
I saw your signature.
Are you satisfied with APU4D4?
You know any possibility for Rackmount? Only found wallmounting-Kits.
Logged
Patrick M. Hausen
Hero Member
Posts: 6709
Karma: 565
Re: Hardware possibilities
«
Reply #7 on:
March 03, 2021, 04:53:10 pm »
APU4D4 are limited but suitable for the job in my case. I have a 50/10 Mbit/s DSL line ...
Don't expect gigabit speeds, couple of hundred M will be the most you are going to get, specifically with bridging.
And I have not even tried to run Sensei and/or Suricata. Again, they do perfectly well with a couple of less demanding services. I run AdGuardHome, WireGuard, Postfix, ... absolutely no problem.
And on the plus side, they are robust and need very little energy.
Rackmount:
https://www.varia-store.com/de/produkt/104337-19-quot-dualrack-system-konfigurator-fuer-pc-engines-apu4-boards-dual-slot.html
«
Last Edit: March 03, 2021, 05:38:28 pm by pmhausen
»
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
hushcoden
Hero Member
Posts: 544
Karma: 23
Re: Hardware possibilities
«
Reply #8 on:
March 03, 2021, 05:11:45 pm »
And if you need just 3 ports (and no need for SIM socket for 3G modem), I'd suggest you go with APU2E4, as it seems the i210 NICs perform better than the i211.
«
Last Edit: March 03, 2021, 05:19:01 pm by hushcoden
»
Logged
steppi
Newbie
Posts: 14
Karma: 0
Re: Hardware possibilities
«
Reply #9 on:
March 03, 2021, 08:09:53 pm »
Thx again,
atm i got 100/50 MBit DSL with perspectiv to 250mbit down.
On otherside i plan to divide my network in different zones and gigabit-link.
Beside FW, there will be Unbound, DNScrypt and VPN/ IPSEC don't know all points for now. Today there is only simple speedport and vm/ container piholes.
Thx for the rackmounting case. I thought more of cheap brackets. The case nearly costs like the Hardware itself.
@hushcoden
Thx for advice.
Normaly I wanted 4-Port, but there would be no problem using 3 Port with Vlan.
«
Last Edit: March 03, 2021, 08:13:39 pm by steppi
»
Logged
Patrick M. Hausen
Hero Member
Posts: 6709
Karma: 565
Re: Hardware possibilities
«
Reply #10 on:
March 03, 2021, 08:29:05 pm »
IMHO you can definitely run those services on an APU system. If you stick to the algorithms supported by AES-NI, then IPSec won't be a problem and the other services you mentioned are not compute intensive.
Use a switch. With VLANs or without, but don't bridge the interfaces of the APU to create a cheap switch. I regularly do that, because it works, but you won't get gigabit speeds. The bridging code will be vastly improved in FreeBSD 13. Some time in 2022 for OPNsense, I hear.
Similarly WireGuard performance will improve by a great margin, but probably this year already.
As for the cheap brackets: that price is a steal! Ever ordered simple metal brackets for anything by Cisco?
Kind regards,
Patrick
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
steppi
Newbie
Posts: 14
Karma: 0
Re: Hardware possibilities
«
Reply #11 on:
March 03, 2021, 09:50:01 pm »
Sounds good so far.
Switch will be there doing the work with bridging, vlans and so on. Don't know the concret model, cause I'm figuring out different options from new home or buisness models to used enterprise models... in fact in every case ist will be managed with layer 2 oder 3 functions.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Hardware and Performance
»
Hardware possibilities