Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Hardware Suggestion for PFSense with Snort

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 4 Posters 645 Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E Offline
      EdgeRouter
      last edited by

      Hello,

      I'm running PFSense with DHCP, DNS, Snort (with VRT Rules only) and pfBlockerNg. My Internet connection is 500Mbit/s fiber, the LAN is divided in 5 VLANs with 1Gigabit. At the moment everything runs very nicely on a DELL mini pc. But the electric bill for that setup is too high.

      Can you suggest a suitable hardware that will fit my requirements without performance problems and saves energy too? My first thought was a NETGATE 5100, but with 700$ it's quite expensive. Can you suggest any other hardware (Netgate or custom) that fits my needs?

      Ps: I don't need a fiber converter within the router. Two network ports are enough (VLAN adressing is done by a vlan switch). No Wifi needed.

      JKnottJ 1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        How much power does the Dell mini actually use? What hardware is it? How much power do you want to be using?

        Steve

        1 Reply Last reply Reply Quote 0
        • bmeeksB Online
          bmeeks
          last edited by bmeeks

          I recommend something at least in about the same hardware class as the SG-5100. You might could cobble together a generic no-name box built from various parts and pieces for a little less than the cost of an SG-5100. But with all the supply chain issues and high chip prices today due to the pandemic, cobbling together a box might be more trouble than simply buying an SG-5100. Your call on that since it is your budget.

          For Snort (or Suricata) I strongly recommend at least 4 GB of RAM and a high speed Intel CPU. Snort is single-threaded, so you would want to favor higher clock speeds over core count to optimize performance when choosing the CPU. Single-threaded apps are only going to utilize a single CPU core. The tradeoff with clock speed is power consumption. Higher clock speed equals more power consumption.

          Last recommendation is to be sure the box has quality Intel NICs! No Realteks, and most definitely no USB NICs.

          1 Reply Last reply Reply Quote 1
          • JKnottJ Offline
            JKnott @EdgeRouter
            last edited by

            @edgerouter

            I have the computer described in my sig. Works well.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.