Posted: 8/3/2025 9:43:49 PM EDT
[Last Edit: bionicmonkey][Edited]
|
I just moved from Amplifi mesh to Orbi, but not interested in the net armor subscription, and i want more options to control prioritizing my work traffic, allowing routing to the homeassistant server from wifi and wired, locking down IOT and generally increasing security and configurability. Looking at Pfsense, firewalla, and opnsense, it looks like the Netgate 4200 might be a really nice future proof setup, but rather than spend bucks up front, i have an old optiplex 6200 i3 with 16gb ram and a 250gb ssd i was going to put a dual 2.5gb nic into and try opnsense. i figure if I can get value from it, and it works, then i could either invest in making sure that box is reliable or transfer to a modern microbox or get the netgate 4200 and move into pfsense. My questions are 1 is this a realistic plan from an app perspective - assume I can manage the setup, vlans, putting orbi into AP mode etc.. 2 is there another path that is more highly recommended (e.g. if opnsense is crap ..) 3 any big hurdles to be aware of? 4 what other things could/should I think about at the same time? im WFH -network is simple - AT&T BG320, wired 2.5gb managed switch, my work machines, orbi mesh, bunch of wireless devices, and wireless IOT devices on a separate wifi SSID. right now unclear to me if the bg320 is in router mode (probably is) and the orbi is also in router mode for sure. |
|
You can put Pfsense CE on that SFF if you want to use Pfsense from the start. As for security there is not a lot of difference between Pfsense and OPNsense because they both use Suricata (for the most part). Even Unifi security is Suricata under the hood. If it were me and I had ATT fiber I would do the ONT bypass because ATT ONT/routers never really go into true bypass mode but you would then need something that can take an SFP+ module for the WAN connection. There are a ton of tutorials on YouTube on how to bypass the ATT box. If you ever do get a Netgate device buy the Max version. If you don't use a NVME drive for logging the ones they solder onto the board are kind of on the flaky side and can fail with enough writes which logging does a lot of. Being a small capacity there are a lot of people finding they break after a couple of years and the device won't boot at all if that happens. I personally think Netgate is kind of on the expensive side for the performance. When you have a gig or greater fiber connection the 4200 is the cheapest option to get full speed and it's twice as expensive as the Unifi UCG Fiber which can do 5 gigs with security on. |
I'm not the one REEING, motherfucker! -FCSD2162
|
Ok well blue truck showed up today with an ssd, 16gb and a dual 2.5gb nic. Got the install over with and managed to get the realtek driver done despite the lack of internet. Im thinking process wise to setup lan on re0 and put it in the back of the bgw320 but leave the bgw as is for now, run a new switch off the re1 port and that lets me get the setup done with my laptop and do testing. then i can cut over by putting the bgw in passthrough and connect the wifi system and put it in ap mode. |
|
I'll give my blanket UniFi recommendation for home networking and now with the ability to run the OS Server software & Network app on your own hardware, that's even more of an option. The one unified view, ease of updates, managed switches, etc....and now tons of various equipment types available for wi-fi and more. I also would suggest using Proxmox on your SFF (I have two of them, refurbs from Dell, great machines) and easily set up a mix of VM's and containers as needed. Add in a seperate Proxmox Backup Server and you're in a decent place. I'd love to add two more SFF's for a small cluster, but funds are tight right now. |
Way to go U.S. Military! Kick ass and take names! NRA Life member, Ohio CCW.org member, Ohio CCW licensee, Infidel ????
LEGP 2001 #321
LEGP 2001 #321
|
Originally Posted By castlebravo84: Are you running it bare metal or though a hypervisor? Bare metal. After i shutdown/restarted it magically forgot my realtek drivers so i had to set that up again. Now trying to get the dhcp working. Its getting an ip from the modem.. but cant seem to get it to give an ip to my laptop on the lan segment. |
|
Originally Posted By NukeThemTillTheyGlow: I'll give my blanket UniFi recommendation for home networking and now with the ability to run the OS Server software & Network app on your own hardware, that's even more of an option. The one unified view, ease of updates, managed switches, etc....and now tons of various equipment types available for wi-fi and more. I also would suggest using Proxmox on your SFF (I have two of them, refurbs from Dell, great machines) and easily set up a mix of VM's and containers as needed. Add in a seperate Proxmox Backup Server and you're in a decent place. I'd love to add two more SFF's for a small cluster, but funds are tight right now. Thats interesting.. will check into that thx. |
|
Originally Posted By bionicmonkey: Thats interesting.. will check into that thx. Originally Posted By bionicmonkey: Originally Posted By NukeThemTillTheyGlow: I'll give my blanket UniFi recommendation for home networking and now with the ability to run the OS Server software & Network app on your own hardware, that's even more of an option. The one unified view, ease of updates, managed switches, etc....and now tons of various equipment types available for wi-fi and more. I also would suggest using Proxmox on your SFF (I have two of them, refurbs from Dell, great machines) and easily set up a mix of VM's and containers as needed. Add in a seperate Proxmox Backup Server and you're in a decent place. I'd love to add two more SFF's for a small cluster, but funds are tight right now. Thats interesting.. will check into that thx. If you do virtualize, you will want to do some flavor of pcie passthrough on the nic or performance will be a fraction of what you would get with bare metal. I would just stick with bare metal if it is working (drivers ect) and you have no real need for a hypervisor. There are many ways to cripple NFV performance if you don't set it up right. |
|
Originally Posted By castlebravo84: If you do virtualize, you will want to do some flavor of pcie passthrough on the nic or performance will be a fraction of what you would get with bare metal. I would just stick with bare metal if it is working (drivers ect) and you have no real need for a hypervisor. There are many ways to cripple NFV performance if you don't set it up right. Originally Posted By castlebravo84: Originally Posted By bionicmonkey: Originally Posted By NukeThemTillTheyGlow: I'll give my blanket UniFi recommendation for home networking and now with the ability to run the OS Server software & Network app on your own hardware, that's even more of an option. The one unified view, ease of updates, managed switches, etc....and now tons of various equipment types available for wi-fi and more. I also would suggest using Proxmox on your SFF (I have two of them, refurbs from Dell, great machines) and easily set up a mix of VM's and containers as needed. Add in a seperate Proxmox Backup Server and you're in a decent place. I'd love to add two more SFF's for a small cluster, but funds are tight right now. Thats interesting.. will check into that thx. If you do virtualize, you will want to do some flavor of pcie passthrough on the nic or performance will be a fraction of what you would get with bare metal. I would just stick with bare metal if it is working (drivers ect) and you have no real need for a hypervisor. There are many ways to cripple NFV performance if you don't set it up right. |
Way to go U.S. Military! Kick ass and take names! NRA Life member, Ohio CCW.org member, Ohio CCW licensee, Infidel ????
LEGP 2001 #321
LEGP 2001 #321
|
well, everything is setup and working now.. that was a real struggle due to a: using a realtek card (that was a mistake) b: because the on-board nic is there, i had to do a few rounds to get all the setup onto the realtek 0 and 1, and also because apparently my laptop and dock has a weird relationship between the dock nic and the laptop onboard nic which made troubleshooting fun. but hey, if IT was easy everyone would do it. finally unbound DNS was crap and i turned it off and enabled the dnsmasq and it is working a lot better now. did a speedtest and a: im able to push full 600mbps to the internet (at&t limited) without delay or lag. which is good - and b; cpu hits 35-39% on the inbound and 35% on the outbound.. that seems to suggest i could get to 1.5GBPS across the firewall which is fine for my network. one thing that was interesting about that - i ran a speed test from a machine connected directly to the AT&T BGW 320 and then connected it to the firewall and re-ran. no noticeable change in speed or latency.. still pushing 620 up 626 down 4msec next up i need to get vlans setup and ad blocking.. |
Join the Community
Your next conversation starts here.
Create your free account to join discussions, share your experience, save topics, and connect with the AR15.COM community.
- Join discussions
- Follow topics and replies
- Connect with fellow enthusiasts
Already a member? Sign in
Stay informed by subscribing to our Newsletter