• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Recommendations for setup-and-forget "firewall only" nettop

Hardware
4
12
4.2k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    kayp2715
    last edited by Sep 29, 2013, 3:47 PM

    First off I am a new user, so please forgive me if there is something wrong with my question/post.

    I am looking for a "setup-and-forget" firewall nettop for home use only.  Planning to use common home related to packages.  Will probably use OpenVPN, IPSec in future.

    I am looking for a really small, fanless, and efficient fully assembld and ready to use nettop.  This system wold be ideal - http://utilite-computer.com/web/utilite-models - Utilite Pro.
    I have looked at
    http://store.netgate.com/Netgate-FW-525B-P1919C83.aspx - Netgate FW-525B - cons Atom D525, not power efficient, large and expensive
    http://www.amazon.com/Intel-D2500-Fanless-Mini-ITX-D2500CCE/dp/B008KB5YCK - cons Atom D2500, large
    http://www.amazon.com/Nexgen-Appliances-NG-MINI-Untangle-Appliance/dp/tech-data/B00F3QCGMG - expensive, though has better processor

    what I am looking for in terms of tech specs

    • power efficient and modern processor, preferably with 64 bit support
    • at least 2 GB ethernet NICs, preferably Intel
    • really small form factor
    • around $300 or less

    I am not looking for doing any video playback/transcoding/encoding/decoding, no games etc on this machine.

    Thank you.

    1 Reply Last reply Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Sep 30, 2013, 12:24 AM

      What bandwidth is your WAN?

      That first box you linked to has an ARM CPU, pfSense only supports x86 hardware currently.

      The D525 is not high power consumption though the N2800 is better.

      Steve

      1 Reply Last reply Reply Quote 0
      • K
        kayp2715
        last edited by Sep 30, 2013, 2:52 AM

        WAN bandwidth is ~25 Mbps.

        Yes, I know that the first box has ARM CPU but I wanted to refer to it for the sake of comparing dimensions and power utilization.  Although I know none of these Atom CPU based machines are going to match (low) power of ARM based ones.

        I could've bought the first box - Netgate FW-525B - even if its comparatively large in size but I feel like its pricey.  I wouldn't want to spend more than $300 for that.

        I understand that cost of the extra NICs, Wifi and other ports add up.  I wish they didn't have so many ports and priced the system lower.

        Does pfSense support x86 hardware only, not even x86-64/x64/AMD64?

        1 Reply Last reply Reply Quote 0
        • S
          Supermule Banned
          last edited by Sep 30, 2013, 2:57 AM

          Why not a cheap netgear router and just skip the troubles related to you purchase? Your bandwith is nothing and if you want to set and forget, then a SOHO router will be fine.

          PfSense needs maintenance and thats not what youre after.

          1 Reply Last reply Reply Quote 0
          • K
            kayp2715
            last edited by Sep 30, 2013, 3:06 AM

            Thanks for the suggestion Supermule, but -
            a) I want to learn and use pfSense, for personal hobby/passion reasons
            b) I want to use a real firewall that provides IPSec and OpenVPN - eventually
            c) While SOHO routers do provide basic security, they are not as secure, they don't generally get security updates, and decent ones are expensive
            d) I have Netgear WNDR3400 router that does the job but it keeps dropping connection after a week or so of uptime.  I paid around $150 for it.  I can go for a basic router and get switch and make WNDR3400 as access point only but if I have to go through so many hoops why not get a real firewall h/w then.  DD WRT has issues with the router so I didn't try it.

            1 Reply Last reply Reply Quote 0
            • S
              Supermule Banned
              last edited by Sep 30, 2013, 3:20 AM

              @kayp2715:

              Thanks for the suggestion Supermule, but -
              a) I want to learn and use pfSense, for personal hobby/passion reasons

              I understand. Its a nice piece of kit.

              @kayp2715:

              b) I want to use a real firewall that provides IPSec and OpenVPN - eventually

              IPSec is common in small routers and nothing to handle on a home network/LAN. Especially with your expected use of it.

              @kayp2715:

              c) While SOHO routers do provide basic security, they are not as secure, they don't generally get security updates, and decent ones are expensive

              If you enable automatic firmware download then it will. They are patched frequently and new firmware can be updated on the firmware page.

              @kayp2715:

              d) I have Netgear WNDR3400 router that does the job but it keeps dropping connection after a week or so of uptime.  I paid around $150 for it.  I can go for a basic router and get switch and make WNDR3400 as access point only but if I have to go through so many hoops why not get a real firewall h/w then.  DD WRT has issues with the router so I didn't try it.

              I had a Netgear CG3000 and it did the same. When using my home network connection it dropped all packages when loading the connection and I changed it to a Cisco router. Same problem. Its not your router, but a problem at your ISP.

              1 Reply Last reply Reply Quote 0
              • S
                stephenw10 Netgate Administrator
                last edited by Sep 30, 2013, 10:02 AM

                @kayp2715:

                I wish they didn't have so many ports

                Possibly the first person to say that  ;)

                @kayp2715:

                Does pfSense support x86 hardware only, not even x86-64/x64/AMD64?

                Sorry, yes there's a 64bit version. I should said X86 with 64bit extensions. Technically I think X86 includes both 32 and 64bit architectures but I think it also includes 16bit and you won't get pfSense to run on that!  ;)

                So you're looking for really very small and only two interfaces?

                For only 25Mbps have you considered an Alix? Or a box based on that such as:
                http://store.netgate.com/ALIX2D3-2D13-Kit-Blue-Unassembled-P173C82.aspx
                Those are very low power, like ~5W.

                Steve

                1 Reply Last reply Reply Quote 0
                • S
                  Supermule Banned
                  last edited by Sep 30, 2013, 11:50 AM

                  But does 2.1 run on those? I seem to recall mount errors on those?

                  1 Reply Last reply Reply Quote 0
                  • S
                    stephenw10 Netgate Administrator
                    last edited by Oct 1, 2013, 11:32 AM Sep 30, 2013, 2:03 PM

                    On the Alix board? Yes. The upgrade process is proving troublesome for some as far as I can see from the forum. I would expect it to be one of the most tested platforms since Netgate are distributing them and JimP runs one at home.
                    Personally I find the low ram and low processing power too restrictive but if total power consumption is a high priority it's hard to beat.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • K
                      kayp2715
                      last edited by Sep 30, 2013, 9:07 PM

                      Thanks Brian and Steve, for your replies and suggestions.

                      Steve, the ALIX 2D3-2D13 kit looks OK but, as you said, it does seem low on RAM and processing power.

                      I'll think about it and may go for that one.

                      Thanks again.

                      1 Reply Last reply Reply Quote 0
                      • S
                        stephenw10 Netgate Administrator
                        last edited by Oct 1, 2013, 11:35 AM

                        If you do make sure it will do everything you want first.
                        You could wait for the new Alix board which will likely be somewhere in between the old Alix and an Atom in terms of both performance and power consumption:
                        http://forum.pfsense.org/index.php/topic,59555.0.html
                        Of course it's untested right now but it will likely have a large pfSense user base in time.  ;)

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • K
                          kejianshi
                          last edited by Oct 1, 2013, 12:11 PM

                          Also, the less packages you install and the more simple you make it, the more you can "forget it" and trust its just working.

                          1 Reply Last reply Reply Quote 0
                          6 out of 12
                          • First post
                            6/12
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.