Jump to content

image.thumb.png.1fb7014a7bde84b679174a8ccc52a833.pngimage.thumb.png.3d546008cc073a0f16be743d65152276.png

 

These are the specs for the pfsens/opnsense build I want to make, I know it is very OP.  I just really want to future proof this for future pcie 4.0 support.

What kind of networking card should I get for now, I have gigabit internet, I am just wondering if I should get an i350-t4v2 or stick with the intel pro 1000 cards?

If so please provide links to genuine cards that are 4 port and at least gigabit, also pfsense/opnsense I do not think support Realtek.

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/
Share on other sites

Link to post
Share on other sites

One thing I forgot to mention, this will be acting mostly as a vpn server.

Also the gen 4 ssd, is for very fast boot times/ caching.  The real reason I picked the gen 4 is so that if I make a change to the config file, that I can reboot it with a backup quickly.

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619135
Share on other sites

Link to post
Share on other sites

16 minutes ago, Electronics Wizardy said:

No need for gen 4, esp for the ssd, get a cheap sata drives, or 2 for HA in raid 1

 

Get the newer i350 if your not going 10gbe.

 

Id probably get a i3 or pentium here, might as well save the money.

My specs (i5-7200U) from what I can gather are about the minimum for Gigabit OpenVPN.  So I'd probably not go below an 8th gen i3.

 

Definitely agree there is zero use for PCIe4 though, were only just getting to the point where FreeBSD can even handle 10Gbit never mind anything faster.

ASUS B650E-F GAMING WIFI + R7 7800X3D + 2x Corsair Vengeance 32GB DDR5-6000 CL30-36-36-76  + ASUS RTX 4090 TUF Gaming OC

Router:  Intel N100 (pfSense) Backup: GL.iNet GL-X3000/ Spitz AX Switches: Netgear MS510TXUP, MS510TXPP, GS110EMX
WiFi6: Zyxel NWA210AX (1.7Gbit peak at 160Mhz) WiFi5: Ubiquiti NanoHD OpenWRT (~500Mbit at 80Mhz)
ISPs: Zen Full Fibre 900 (~930Mbit down, 115Mbit up) + Three 5G (~1200Mbit down, 115Mbit up, variable)
Upgrading Laptop/Desktop CNVIo WiFi 5 cards to PCIe WiFi6e/7

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619146
Share on other sites

Link to post
Share on other sites

4 minutes ago, Memer2424 said:

One thing I forgot to mention, this will be acting mostly as a vpn server.

Also the gen 4 ssd, is for very fast boot times/ caching.  The real reason I picked the gen 4 is so that if I make a change to the config file, that I can reboot it with a backup quickly.

I've never seen a notable difference in bootup between any SSD, its almost entirely CPU and general OS initialisation bound, not storage.

 

Caching is less and less practical now almost all sites are https only, it requires dirty hacks to cache that which adds its own security issues (you can't tell if you've made a secure connection to the destination with these hacks enabled).

ASUS B650E-F GAMING WIFI + R7 7800X3D + 2x Corsair Vengeance 32GB DDR5-6000 CL30-36-36-76  + ASUS RTX 4090 TUF Gaming OC

Router:  Intel N100 (pfSense) Backup: GL.iNet GL-X3000/ Spitz AX Switches: Netgear MS510TXUP, MS510TXPP, GS110EMX
WiFi6: Zyxel NWA210AX (1.7Gbit peak at 160Mhz) WiFi5: Ubiquiti NanoHD OpenWRT (~500Mbit at 80Mhz)
ISPs: Zen Full Fibre 900 (~930Mbit down, 115Mbit up) + Three 5G (~1200Mbit down, 115Mbit up, variable)
Upgrading Laptop/Desktop CNVIo WiFi 5 cards to PCIe WiFi6e/7

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619161
Share on other sites

Link to post
Share on other sites

3 minutes ago, Memer2424 said:

One thing I forgot to mention, this will be acting mostly as a vpn server.

Also the gen 4 ssd, is for very fast boot times/ caching.  The real reason I picked the gen 4 is so that if I make a change to the config file, that I can reboot it with a backup quickly.

What are you caching? From my experince web caching really doesn't help much, esp since you have a gig connections.

 

gen 4 ssd won't boot any faster than a sata ssd, id get 2 cheaper sata ssds here.

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619162
Share on other sites

Link to post
Share on other sites

I was thinking of caching windows updates, since I have 11 computers, but if gig is enough then 2 sata maybe the way to go.  I just want to make sure that this router is good for like 15-20 years.  I understand that I would probably need to change the network card out in the future.  If I go for 10 gig what would you recommend, that is rj45 that is also 4 port?

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619186
Share on other sites

Link to post
Share on other sites

1 minute ago, Memer2424 said:

I was thinking of caching windows updates, since I have 11 computers, but if gig is enough then 2 sata maybe the way to go.  I just want to make sure that this router is good for like 15-20 years.  I understand that I would probably need to change the network card out in the future.

I don't think its practical to do that on pfsense/OPNsense, sadly.

ASUS B650E-F GAMING WIFI + R7 7800X3D + 2x Corsair Vengeance 32GB DDR5-6000 CL30-36-36-76  + ASUS RTX 4090 TUF Gaming OC

Router:  Intel N100 (pfSense) Backup: GL.iNet GL-X3000/ Spitz AX Switches: Netgear MS510TXUP, MS510TXPP, GS110EMX
WiFi6: Zyxel NWA210AX (1.7Gbit peak at 160Mhz) WiFi5: Ubiquiti NanoHD OpenWRT (~500Mbit at 80Mhz)
ISPs: Zen Full Fibre 900 (~930Mbit down, 115Mbit up) + Three 5G (~1200Mbit down, 115Mbit up, variable)
Upgrading Laptop/Desktop CNVIo WiFi 5 cards to PCIe WiFi6e/7

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619192
Share on other sites

Link to post
Share on other sites

4 minutes ago, Alex Atkin UK said:

I don't think its practical to do that on pfsense/OPNsense, sadly.

I think so, it is a squid proxy thing, also which would you recomend pfsese,opnsense, or windows server 2019 as a router.  I have a copy of genuine windows server 2019.

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619209
Share on other sites

Link to post
Share on other sites

9 minutes ago, Memer2424 said:

I was thinking of caching windows updates, since I have 11 computers, but if gig is enough then 2 sata maybe the way to go.  I just want to make sure that this router is good for like 15-20 years.  I understand that I would probably need to change the network card out in the future.  If I go for 10 gig what would you recommend, that is rj45 that is also 4 port?

Yea I wouldn't bother with windows update caching. Window should already pull updates from other systems on the network, and with a gig connection the cache will the the same speed as the internet.

 

4 minutes ago, Memer2424 said:

I think so, it is a squid proxy thing, also which would you recomend pfsese,opnsense, or windows server 2019 as a router.  I have a copy of genuine windows server 2019.

WIndows server is a bad router. Id much rather go with something like untangle here if you want another option.

 

 

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619235
Share on other sites

Link to post
Share on other sites

5 minutes ago, Electronics Wizardy said:

Yea I wouldn't bother with windows update caching. Window should already pull updates from other systems on the network, and with a gig connection the cache will the the same speed as the internet.

I've never once seen that actually work, even if I update one PC then immediately update the other, it ALWAYS pulls it from the Internet.  Its quite annoying actually as I've double checked its enabled on all PCs.

 

Like you said though, with Gigabit Internet I'd consider it kinda pointless unless you have a data cap.

ASUS B650E-F GAMING WIFI + R7 7800X3D + 2x Corsair Vengeance 32GB DDR5-6000 CL30-36-36-76  + ASUS RTX 4090 TUF Gaming OC

Router:  Intel N100 (pfSense) Backup: GL.iNet GL-X3000/ Spitz AX Switches: Netgear MS510TXUP, MS510TXPP, GS110EMX
WiFi6: Zyxel NWA210AX (1.7Gbit peak at 160Mhz) WiFi5: Ubiquiti NanoHD OpenWRT (~500Mbit at 80Mhz)
ISPs: Zen Full Fibre 900 (~930Mbit down, 115Mbit up) + Three 5G (~1200Mbit down, 115Mbit up, variable)
Upgrading Laptop/Desktop CNVIo WiFi 5 cards to PCIe WiFi6e/7

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619258
Share on other sites

Link to post
Share on other sites

The real reason I need to switch is because I  made a horrible decision on getting a LRT214  in 2015 that crashes the router when using the vpn and only getting about 15 mbits up and down through it.  That is the real reason, I am hoping that I will have a pfsense router that will last for at the very least 10 years.  I am tired of the consumer router crap, and even small business crap.  Also with the 2 ssd drives, why raid 1 have you guys ever have a ssd fail?

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619328
Share on other sites

Link to post
Share on other sites

14 minutes ago, Memer2424 said:

The real reason I need to switch is because I  made a horrible decision on getting a LRT214  in 2015 that crashes the router when using the vpn and only getting about 15 mbits up and down through it.  That is the real reason, I am hoping that I will have a pfsense router that will last for at the very least 10 years.  I am tired of the consumer router crap, and even small business crap.  Also with the 2 ssd drives, why raid 1 have you guys ever have a ssd fail?

Yea I have multiple dead ssds. Raid 1 would be a much better way to spend the budget than getting a gen 4 nvme drive. That speed would be wasted.

 

Id personally get something like a dell r220/r230 here. There pretty cheap used, easily fit in a rack, and have good nics built in.

 

How much vpn bandwidth do you need?

 

I still think the hardware is way overkil, I have gotten gig routing on first gen i3s before, so it really doesn't take that much power.

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619402
Share on other sites

Link to post
Share on other sites

all of the bandwidth with probably 5 concurrent( yes i mean 200 mbps up and down for each) clients, no rack, needs to be quiet, I am using full tunnels instead of split.  I went with a slim case to make sure that it fits in a triangle spaced closet that has to be no longer than 6.5 feet and no wider than about 1 foot. This is a small closet, that holds an nvr, a ups, phone stuff and alarm stuff.  Also my budget is extremely flexible.  I want high availability that will last a very long time.  I am a computer science student that is also very interested in security, so i will most likely use suricata on this machine as well.

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619429
Share on other sites

Link to post
Share on other sites

13 minutes ago, Memer2424 said:

all of the bandwidth with probably 5 concurrent( yes i mean 200 mbps up and down for each) clients, no rack, needs to be quiet, I am using full tunnels instead of split.  I went with a slim case to make sure that it fits in a triangle spaced closet that has to be no longer than 6.5 feet and no wider than about 1 foot. This is a small closet, that holds an nvr, a ups, phone stuff and alarm stuff.  Also my budget is extremely flexible.  I want high availability that will last a very long time.  I am a computer science student that is also very interested in security, so i will most likely use suricata on this machine as well.

Yea then the only changes id make is

 

Using the stock cooler, those low profile artic coolers are about as good, and this cpu won't be under heavy load here anyways.

 

Get 2 cheaper ssds, speed won't matter, but raid 1 is nice to have.

Link to comment
https://linustechtips.com/topic/1322542-pfsenseopnsense-build/#findComment-14619504
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×