Technology Get the latest on technology, electronics and software…

pfSense firewall

Thread Tools
 
Old 03-06-2022, 09:50 AM
  #1  
Team Owner
Thread Starter
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,451
Received 2,203 Likes on 1,206 Posts
pfSense firewall

I'm thinking of giving pfSense firewall a shot on my home network. Is anyone here running it?

I have FIOS 1gig service and a few high bandwidth network consumers in my home that that can knock out my Linksys router if they get a little crazy with their connections/transfers.

The purpose built stuff for pfsense seems expense for what they are. I want something that will be able to maintain ~1gig speeds. I'm looking at some SFF options on eBay, such as a Dell OptiPlex 7020. I would add in another NIC card to it. Any opinions on this?

Last edited by doopstr; 03-06-2022 at 09:56 AM.
Old 03-17-2022, 06:54 PM
  #2  
dgy
Intermediate
 
dgy's Avatar
 
Join Date: Mar 2022
Posts: 28
Likes: 0
Received 6 Likes on 5 Posts
I have FIOS 1gig service and a few high bandwidth network consumers in my home that that can knock out my Linksys router if they get a little crazy with their connections/transfers.
Kinda like the butcher griping about "Prime Rib, again?"

The purpose built stuff for pfsense seems expense for what they are.
They are designed as appliances for specific purposes (contrast with PCs designed as commodity products). So, smaller quantities, higher marketing/support costs.

I want something that will be able to maintain ~1gig speeds. I'm looking at some SFF options on eBay, such as a Dell OptiPlex 7020. I would add in another NIC card to it. Any opinions on this?


A "motherboard" NIC is (generally) preferable to an add-in card, to ensure the bus i/f isn't a bottleneck. "Smart" NICs that can handle some of the packet processing overhead "in hardware" (misnomer) is also a win.

If you're running VPNs and/or encrypted tunnels, a processor that has built-in support for crypto can be a HUGE win (depending on the ciphers used).

I don't like buying hardware. There's always an old/unused PC somewhere that you can play with (friend, relative, neighbor, etc.). Pull the existing drive (in case you want to return the PC to its original owner "unaltered") and install a small drive or SSD (with enough RAM, the SSD doesn't offer much of a performance increase as it's a "load once" application -- unless you also want to run apps on the appliance ). Build the appliance. Deploy at some noncritical time (so you don't have folks complaining if you bork their connections/usage) and measure performance. Use those observations to tweek your implementation for the next iteration (different NIC, different PC, etc.) With FOSS, you can always tweak the codebase to "adjust" the load it places on the hardware.

I use Optiplex 160's (USFF) as (headless) appliances, here. They are small, low power, fanless. But, can't handle much of a workload (1.6GHz Atoms). OTOH, great for a name server, font server, print server, time server, etc. -- all-in-one! Even a temporary file server hosting an external USB drive in a pinch.

The following users liked this post:
doopstr (03-18-2022)
Old 03-17-2022, 07:52 PM
  #3  
Sanest Florida Man
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,405
Received 10,742 Likes on 6,514 Posts
A font server? WTF!

Doop why don't you get a Unifi Dream Machine Pro?
Old 03-17-2022, 08:58 PM
  #4  
dgy
Intermediate
 
dgy's Avatar
 
Join Date: Mar 2022
Posts: 28
Likes: 0
Received 6 Likes on 5 Posts
Originally Posted by #1 STUNNA
A font server? WTF!
For the same reason you install any service: so you don't have to replicate it on each client!

You don't need a print server -- if you have a printer plugged into every host!

You don't need a name server -- if you manually maintain hosts(5) on each host!

Or, a time server -- if you can manually maintain correct (for whatever you decide "correct" to be!) time on each host.

A font server lets you stash all of your fonts in a single place (instead of having to replicate ALL of them on each host) and provide consistent access to the entire set from any host (client). If you only have the standard set of fonts that came with your OS install, then there is no advantage to be gained. Or, if you only have a few additional fonts. If you have a large collection, then the benefits multiply!

Would you store your entire music collection on EACH computer -- just so you had everything available to you regardless of which computer you were using, at the time?
Old 03-18-2022, 01:08 PM
  #5  
Team Owner
Thread Starter
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,451
Received 2,203 Likes on 1,206 Posts
Originally Posted by #1 STUNNA
Doop why don't you get a Unifi Dream Machine Pro?
Do you know if the fans in that make a lot of noise? My experience with 1U networking equipment is that they are loud and I don't want that level of noise in my basement.
Old 03-18-2022, 02:48 PM
  #6  
Sanest Florida Man
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,405
Received 10,742 Likes on 6,514 Posts
According this reddit post it's very quiet, someone even posted a video showing a db meter

https://www.reddit.com/r/Ubiquiti/co..._on_fan_noise/
The following users liked this post:
doopstr (03-18-2022)
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Abe_Froman
Dating & Relationships
42
06-14-2011 11:24 AM
powens67
1G TSX Performance Parts & Modifications
39
12-07-2006 08:26 PM



Quick Reply: pfSense firewall



All times are GMT -5. The time now is 11:08 PM.