Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Purchase appliance or custom build?

    Scheduled Pinned Locked Moved Hardware
    15 Posts 5 Posters 5.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      Keljian
      last edited by

      Gigabit on lan side is easy. You can get dual/quad nics also which means you don't need many slots.

      Looking through your list, the key packages to watch are:
      suricata/snort
      and Havp

      Snort loves memory(imo have a minimum of 4gig of ram), HAVP eats a bit of processor power.

      Aggregated, he has a total of 30mbps on the WAN side, most modern hardware will hit this without even trying.

      Personally, as this is not a work installation, I'd build something based on a haswell celeron or pentium. You can probably get the parts for about the same as the soekris and end up with much more power on demand, and about the same power at idle.

      1 Reply Last reply Reply Quote 0
      • A
        Aluminum
        last edited by

        If you're spending someone else's money, appliance.

        Spending your own, build. Especially if you don't care about rack mounts, purchase orders or support contracts.
        There is just no contest on what picking your own parts can do, the price/performance isn't even in the same league. You can save a ton on certain parts if you check the grey/spare/used markets, and those parts work just fine despite any FUD.

        1 Reply Last reply Reply Quote 0
        • S
          S-KGray
          last edited by

          Thanks for the replies!

          I totally agree with the picking your own parts concept, just wanted to get confirmation so I can convince my co-worker that would be the way to go.

          Besides the above spare/used parts I have access to, I may be able to salvage an i3-530 or i5-650. Though the only mini-ITX 1156 board I see available is the Intel DH57JG, micro-ATX boards are abundant.

          I will look into newer parts as well (haswell, etc), just trying to help keep the cost down while being able to perform as requested.

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            @S-KGray:

            He is looking for something with at least four gigabit NICs. Two for dual WAN and two for redundant LAN connections to managed gigabit switches.

            This requires clarification. I looks like you may be planning only a single LAN interface arranged in a LAGG(teamed) to give redundancy? If that's the case then you will only ever have to deal with 30Mbps of throughput which lowers your hardware requirement considerably.
            If, however, you are going to use two Gigabit LAN interfaces then you may need 1000Mbps between them, massively more powerful hardware required.  ;)

            Steve

            1 Reply Last reply Reply Quote 0
            • S
              S-KGray
              last edited by

              @stephenw10:

              use two Gigabit LAN interfaces then you may need 1000Mbps between them, massively more powerful hardware required.

              I believe this is what he wants, he may want more than two LAN interfaces but two is the minimum requirement. I will ask for clarification.

              Thanks!

              1 Reply Last reply Reply Quote 0
              • S
                S-KGray
                last edited by

                Here is a drawing of what he intends to do. Each LAN interface will be setup with subinterfaces for different VLANs. He wants as close to gigabit as possible between VLANs.

                network.png
                network.png_thumb

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Definitely need the Xeon or something of similar power for that.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • ?
                    Guest
                    last edited by

                    @Aluminum:

                    If you're spending someone else's money, appliance.

                    Spending your own, build. Especially if you don't care about rack mounts, purchase orders or support contracts.
                    There is just no contest on what picking your own parts can do, the price/performance isn't even in the same league. You can save a ton on certain parts if you check the grey/spare/used markets, and those parts work just fine despite any FUD.

                    And then, if you encounter issues, be sure to blame the hardware, and not pfSense, OK?

                    1 Reply Last reply Reply Quote 0
                    • ?
                      Guest
                      last edited by

                      @stephenw10:

                      Definitely need the Xeon or something of similar power for that.

                      Wait a couple weeks.

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        More mysterious clues!  ;)

                        I'm waiting.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • A
                          Aluminum
                          last edited by

                          @gonzopancho:

                          @Aluminum:

                          If you're spending someone else's money, appliance.

                          Spending your own, build. Especially if you don't care about rack mounts, purchase orders or support contracts.
                          There is just no contest on what picking your own parts can do, the price/performance isn't even in the same league. You can save a ton on certain parts if you check the grey/spare/used markets, and those parts work just fine despite any FUD.

                          And then, if you encounter issues, be sure to blame the hardware, and not pfSense, OK?

                          Depends if its really the hardware's fault, isn't that what this forum is for? Sometimes it turns out to be the driver pfsense is using, in which case its freebsd's fault :)

                          I'm not trying to crap on you guys, its just the market reality for DIY builders right now. If you can get decent internet speeds (big if…) and start doing more things the appliances are either underpowered or significantly more expensive.

                          I point technically inclined people straight to pfsense because you can do a ton with it and not pay the crazy cisco tax for baseline networking functions, but by the same token I really can't steer them at most prebuilts. Your dell 1U is a lot better deal than the netgate atom stuff though.

                          1 Reply Last reply Reply Quote 0
                          • ?
                            Guest
                            last edited by

                            @Aluminum:

                            @gonzopancho:

                            @Aluminum:

                            If you're spending someone else's money, appliance.

                            Spending your own, build. Especially if you don't care about rack mounts, purchase orders or support contracts.
                            There is just no contest on what picking your own parts can do, the price/performance isn't even in the same league. You can save a ton on certain parts if you check the grey/spare/used markets, and those parts work just fine despite any FUD.

                            And then, if you encounter issues, be sure to blame the hardware, and not pfSense, OK?

                            Depends if its really the hardware's fault, isn't that what this forum is for? Sometimes it turns out to be the driver pfsense is using, in which case its freebsd's fault :)

                            I'm not trying to crap on you guys, its just the market reality for DIY builders right now. If you can get decent internet speeds (big if…) and start doing more things the appliances are either underpowered or significantly more expensive.

                            I point technically inclined people straight to pfsense because you can do a ton with it and not pay the crazy cisco tax for baseline networking functions, but by the same token I really can't steer them at most prebuilts. Your dell 1U is a lot better deal than the netgate atom stuff though.

                            All the Dell 1U does is fund the project.  They were given to us by a customer.  We refurb them, load pfSense, and ship them (in the custom box we had done.)

                            If by "netgate atom stuff" you mean the FW-7541, then … it's what we use internally (currently).

                            But better stuff is on the way, and buying it helps fund the project.

                            And there are three 1Gbps FTTH providers in Austin.  Grande has it now, AT&T this summer, Google by the end of the year.

                            1 Reply Last reply Reply Quote 0
                            • S
                              S-KGray
                              last edited by

                              @gonzopancho:

                              @stephenw10:

                              Definitely need the Xeon or something of similar power for that.

                              Wait a couple weeks.

                              @stephenw10:

                              More mysterious clues!  ;)

                              I'm waiting.

                              Steve

                              Definitely will be up to waiting to see also, my co-worker won't be purchasing, testing, and implementing his setup until late May.

                              As a side note, I ran iperf through a testbed pfsense setup I have at work (PDSBM-LN2+ w/Xeon 3060). The onboard intel 82573 NICs are setup as WAN and LAN, and I have an intel pro/100 PCI NIC as OPT1. I ran iperf between LAN and WAN to see if it could NAT/FW at gigabit speed. If I remember correctly, iperf results were around 850-900Mb/s, while pfsense webgui traffic graphs were showing around 950Mb/s and cpu at 100%.

                              1 Reply Last reply Reply Quote 0
                              • S
                                S-KGray
                                last edited by

                                Got a Kill-A-Watt and measured idle power draw of several different types of hardware for general comparison. Looks like I need to replace my current setup before I spend too much on additional electricity usage.

                                Initial setup
                                Case: eMachines micro-ATX mini tower
                                Motherboard: Supermicro PDSBM-LN2+
                                CPU: Intel Xeon 3060
                                PSU: Enermax EG465P-VE 460W
                                Disk: Western Digital 80GB HDD
                                NICs: Dual onboard Intel 82573L WAN/LAN, Intel Pro/100 PCI for WiFi AP

                                Current setup same as initial except
                                PSU: Antec VP450 450W

                                Test setup 1 same as initial except
                                Case: ABMX rackmount 1U
                                PSU: Ablecom 520W 1U
                                NICs: Intel Pro/1000 MT PCI-X in PCI slot

                                Test setup 2
                                Case: generic ATX tower
                                Motherboard: Supermicro C2SEA
                                CPU: Intel Q8300
                                PSU: Antec Neopower 650 Blue 650W
                                Disk: Seagate 7200.12 500GB HDD
                                NICs: Onboard Realtek RTL8111C for LAN1, Intel Pro/1000 PT x2 for WAN1/WAN2, Intel Pro/1000 CT for LAN2

                                Idle power draw

                                Initial setup: 70W
                                Current setup: 61W
                                Test setup 1: 69W
                                Test setup 2: 54W

                                and just for grins

                                Dell Optiplex 980/i3-530/pfsense: 36W
                                Dell Optiplex 980/i3-530/Win7: 34W
                                HP 8200 Elite/i5-2500/Win7: 24W
                                HP 8200 Elite SFF/i5-2400/Win7: 25W

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.