• Open VPN ASIC/FPGA?

    2
    0 Votes
    2 Posts
    1k Views
    stephenw10S

    Not really. Or at least nothing specific to OpenVPN.

    You can use something that OpenSSL can use directly, like AES-NI, or something that can tie into the crypto framework, like CESA. Both those will accelerate OpenSSL and hence OpenVPN but total throughput in OpenVPN is still limited by context switching (between kernel and user modes).

    Steve

  • USB WAN interface only getting 100Mbps

    7
    0 Votes
    7 Posts
    2k Views
    stephenw10S

    Or use VLANs with whatever interface is built into the laptop.

    Steve

  • G4400 or Core i5

    2
    0 Votes
    2 Posts
    823 Views
    stephenw10S

    There are a lot of variables here but….  I wouldn't expect any of those to have any issues at 150Mbps, including the SG-4860.

    The only way you would get close to the limit there is with VPN, probably only with OpenVPN. Though maybe if you ran Snort and Squid and IPSec you might run out of cycles.

    Steve

  • After some time of operation.

    3
    0 Votes
    3 Posts
    446 Views
    stephenw10S

    Yes, more info needed.

    Has this happened before? Does it happen every 15 days?

    What is your hardware?

    What version are you running?

    Are you running anything unusual, setup or packages?

    Steve

  • Hardware Advice

    4
    0 Votes
    4 Posts
    1k Views
    O

    Final motherboard choice is ASRock - H270M-ITX/ac Mini ITX LGA1151 Motherboard.

    Is there anything I should know when setting up pfsense.

  • Building an 8 port pfsense machine.

    10
    0 Votes
    10 Posts
    3k Views
    curtisgriceC

    @syndax:

    @stephenw10:

    Yes, you can bridge the interfaces to put them in the same subnet.

    It just than in most situations a switch is a better choice for that. If you have NICs to spare and CPU cycles to service them then you can do it.

    Steve

    I'm doing this in order to reduce clutter and merge several devices into one. Would an core i5 2500k suffice to achieve 1gbps speeds?

    Maybe. Bridging in BSD is not great. Also you're not putting the NICs in the same "subnet" you're putting them in the same broadcast domain (L3 vs L2). Even if you have the CPU to push 1Gb/s on all of your ports, you will still have much higher latency (lag). Get a cheap 12 port gig switch for $20 on ebay and it will be faster and easier to setup. It will also use less power and (if you looking at an i5) make less noise.

    Keep in mind bridging in pfSense means you should have an understanding of Layer 2 traffic and broadcast protocols like mDNS.

    In short, get the SG-3100 and support the project or look at the qotam boxes and a small switch.

  • PfSense firewall appliance build - encrypted

    3
    0 Votes
    3 Posts
    1k Views
    stephenw10S

    That's a really old thread. You might want to check out 2.4 with ZFS options. For example: https://forum.pfsense.org/index.php?topic=135937.0

    Steve

  • Are any external/USB graphics adapters supported?

    36
    0 Votes
    36 Posts
    3k Views
    W

    This thread needs to go in the ghetto weirdest thread hall of fame. 8)

  • Intel Atom® Processor C3758 or C3850

    3
    0 Votes
    3 Posts
    2k Views
    V

    what are your actual requirements? the C3xxx series comes in a lot of different sizes designed for a lot of different workloads. Whether they'd be better or worse than a different solution depends on the requirements…

  • How's my Hardware

    7
    0 Votes
    7 Posts
    985 Views
    ?

    Keep in mind that if you simply ingest that mirror port, you won't really have to worry about NAT speed or bridging or routing etc. Only 'eating' packets fast enough.

  • Finished my first project

    21
    0 Votes
    21 Posts
    4k Views
    G

  • Mini pc j1900

    7
    0 Votes
    7 Posts
    1k Views
    stephenw10S

    It's installed but not enabled by default.

    Go to System > Advanced > Miscellaneous.

    Enable powerd and set all three power types to 'high adaptive'.

    Check the dashboard to see the CPU current frequency. Depending on the CPU load that may make a significant difference.

    Steve

  • Xrio UBM1000 Won't Boot

    7
    0 Votes
    7 Posts
    598 Views
    stephenw10S

    Nice. We'll be here.

    That hardware looks like it could be pretty slow by modern standards. Fun project though.  ;)

    The by-pass relays could be extra fun!

    Steve

  • UP Squared SBC and PCI devices

    8
    0 Votes
    8 Posts
    1k Views
    B

    Thanks for the confirmation. I'm resigned to using an mSATA or plain SATA drive until Up^2 places nicely with FreeBSD.

    At least my eMMC wont get hammered with writes…  :-\

  • Chelsio 10GB Driver Does Not Recoginize DAC

    10
    0 Votes
    10 Posts
    1k Views
    stephenw10S

    Ah!  ;)

    Good to know anyway, thanks.

    Steve

  • Pfsense on a laptop i3 with external pci express for dual lan

    14
    0 Votes
    14 Posts
    2k Views
    stephenw10S

    Yeah I agree with that. Have you seen our store?  ;D

    If you really want to run on battery you might be better off with a DC supply. It's generally significantly more efficient even if you need converters.

    I salute your use of blue LEDS though.  ;)

    Steve

  • R210ii Fan Speed/Noise

    5
    0 Votes
    5 Posts
    4k Views
    stephenw10S

    I recommend setting powerd values to high-adaptive. It should fall back to the lowest frequency anyway but won't affect responsiveness like 'minimum' can.

    Steve

  • The difference when using pfsense router and PC when use pfSense

    13
    0 Votes
    13 Posts
    2k Views
    stephenw10S

    I think we need a diagram showing exactly how you have it setup. Otherwise any advise we give may be incorrect.

    Steve

  • Objections against his hardware for 2.4?

    5
    0 Votes
    5 Posts
    1k Views
    stephenw10S

    Yes that's true. I would expect >300Mbps OpenVPN throughput with that CPU though.

    YMMV  ;)

    Steve

  • Harware Pfsense is not responding

    14
    0 Votes
    14 Posts
    2k Views
    C

    we have a new hardware now, and it seems to be up for two days without issues.
    I'll report backup either it crashes again.
    thank you for all your support

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.