Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Hardware and Performance
»
DEC3850 vs NetgateD1537 vs Netgate 6100 vs Supermicro C3958 / D1736NT / D1718T
« previous
next »
Print
Pages: [
1
]
Author
Topic: DEC3850 vs NetgateD1537 vs Netgate 6100 vs Supermicro C3958 / D1736NT / D1718T (Read 2300 times)
stif
Newbie
Posts: 15
Karma: 3
DEC3850 vs NetgateD1537 vs Netgate 6100 vs Supermicro C3958 / D1736NT / D1718T
«
on:
June 28, 2023, 12:59:12 am »
Hello Guys,
I need some advise regarding Firewall Hardware:
I am looking for a new firewall in a HA setup for approx. 200 Users.
It should be able to handle a 10Gbit backbone network and do some IDS/IPS as well as maybe 10+ simultan IPsec VPN Connections.
Here is a picture of the
planned topology
.
Since the firewall should also be able to utilize a future 10Gbit uplink, at least 3x 10Gbit SFP+ Interfaces should be possible (eg with extension cards).
I am not aware if upgrading the DEC3850 with more 10Gbit Interfaces is possible, but i guess it is not..
My first idea was to buy two Netgate D1537 as i am a long time pfSense User. But then i found out the CPU is already 8 years old and so i started to look around some alternatives.
This
C3958 Platform
for example has 4x 10Gbit Interfaces, but only a CPU Mark of 4281 which is maybe not beefy enough for IDS/IPS, what do you think?
The Xeon D-1700 CPUs, like on the Supermicro
SYS-510D-8C-FN6P
, are more power hungry than the D1500, and the SFP28 ports are not supported with pfsense 2.6 i read somewhere (this way i came across OPNsense)
And as far as i understand, the D17xx
NT
CPUs support Intels Quick Assist (QAT), which is mainly useful for faster VPN bandwidth, correct?
And since VPN is not our main goal, it is maybe also feasible to use a cheaper model without QAT, like the Supermicro
SYS-510D-4C-FN6P
with a D-1718T CPU?
I created a
list of features with the Hardware from the tile
for comparison, but i still dont know which hardware i should buy..
Another Question: is it possible to buy a Desico Support for the mentioned hardware?
Any insights to my questions would be highly appreciated,
Kind Regards,
Stif
Logged
stif
Newbie
Posts: 15
Karma: 3
Re: DEC3850 vs NetgateD1537 vs Netgate 6100 vs Supermicro C3958 / D1736NT / D1718T
«
Reply #1 on:
July 03, 2023, 06:11:34 pm »
I did had an error in my thoughts. the firewalls are in a High Availability Cluster, but not part of the Multi Chassis Link Aggregation. Thats why 2x SFP+ Ports for 10Gbit Backbone and 10Gbit Uplink should be enough - no need for a extension card in case of a 10Gbit uplink..
But the main question is still valid: Is the
SYS-510D-8C-FN6P
Board overkill for my use case and is it even supported by OPNsense? Or am i better off with a DEC3850 or any other hardware i mentioned?
Thanks
Logged
stif
Newbie
Posts: 15
Karma: 3
Re: DEC3850 vs NetgateD1537 vs Netgate 6100 vs Supermicro C3958 / D1736NT / D1718T
«
Reply #2 on:
July 04, 2023, 03:34:58 pm »
doh, there was no error in my thoughts, i do need 2xSFP+ ports for my network backend
the firewall is not part of the Multi Chassis Link Aggregation, true.
but from the perspective of the firewall it just sees one core switch and has a ordinary Link Aggregated connection to it (with LACP).
so every firewall still needs to be connected to both core switches, in order to be as fault tolerant as possible.
in that case i do need a extension card when i get a 10Gbit uplink
Logged
stif
Newbie
Posts: 15
Karma: 3
Re: DEC3850 vs NetgateD1537 vs Netgate 6100 vs Supermicro C3958 / D1736NT / D1718T
«
Reply #3 on:
July 05, 2023, 02:19:37 pm »
FYI: i was writing with an employee from deciso and wanted to share me findings (which many of you might already know anyway)
there is no way to put a extension cards into the DEC3850 (Netgate A20 Board without PCIe Header)
if you want to stick with OPNsense Hardware, for 3 SFP+ Ports you need a DEC4040
they have no experience with a Xeon D1700 board
in theory the Xeon D1700 Boards should be ok (there are drivers for FreeBSD, so also for OPNsense) and its also possible to buy business support for them from deciso (but maybe needs some paid extra effort, if there are any quirks)
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Hardware and Performance
»
DEC3850 vs NetgateD1537 vs Netgate 6100 vs Supermicro C3958 / D1736NT / D1718T