Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    First pfSense box - Xeon build

    Scheduled Pinned Locked Moved Hardware
    35 Posts 7 Posters 11.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      datum
      last edited by

      Hi.
      Check Asus P10s-i,  good board, 2 intel nics. Gigabyte as a similar but more expensive one.

      1 Reply Last reply Reply Quote 0
      • T
        toyebox
        last edited by

        @datum:

        Hi.
        Check Asus P10s-i,  good board, 2 intel nics. Gigabyte as a similar but more expensive one.

        Hey there, thank you but it seems that's not the correct socket for my proposed CPU.

        As a side note, I plan on using this system with  ubiquiti ES‑8‑150W managed switch. I have never had any issues with them .  anyone have any suggestions other than that?

        1 Reply Last reply Reply Quote 0
        • D
          datum
          last edited by

          Have not read good.

          Thought you were talking about this one

          http://ark.intel.com/products/88172/Intel-Xeon-Processor-E3-1220-v5-8M-Cache-3_00-GHz

          1 Reply Last reply Reply Quote 0
          • T
            toyebox
            last edited by

            @datum:

            Have not read good.

            Thought you were talking about this one

            http://ark.intel.com/products/88172/Intel-Xeon-Processor-E3-1220-v5-8M-Cache-3_00-GHz

            That's okay! Thanks for the suggestion though!

            I keep coming up with questions.. Should I opt to use an SSD? Is pfsense installed on the SSD or on flash memory like a flash drive? Is the SSD basically for cache and logs?

            1 Reply Last reply Reply Quote 0
            • C
              chrcoluk
              last edited by

              the ssd is presented as a drive to pfSense so even if the unit has its own built in flash, if you choose to install on the ssd, then it will host the entire OS not just cache and logs.

              pfSense CE 2.8.0

              1 Reply Last reply Reply Quote 0
              • T
                toyebox
                last edited by

                @chrcoluk:

                the ssd is presented as a drive to pfSense so even if the unit has its own built in flash, if you choose to install on the ssd, then it will host the entire OS not just cache and logs.

                Thanks for that. I will just grab a 120gb msata SSD then.

                1 Reply Last reply Reply Quote 0
                • D
                  datum
                  last edited by

                  From what i am planning on building a ssd will be for the so, the 2.5 for cache.
                  I dont know if its possible.Or preferably just standard hdd.

                  1 Reply Last reply Reply Quote 0
                  • ?
                    Guest
                    last edited by

                    Hey everyone. Firstly, i must apologize for posting yet another thread about the same repetitive questions you have all seen for years! I have been reading for two days and it seems there is so much information on this board with so many opinions, it's really hard to figure out what to do. This will be my first pfSense box, but i am not a newb when it comes to BSD, or hardware. I have always believed in "future proofing" my builds for at least 5 years. With that said… I have a 200/200 line coming in on a standard cable modem but plan on upgrading to a 1/1gbit line in the future. I have decided i should just go for it and grab the equipment necessary to handle the full 1gbit up/down. I have very little information about the packages available on pfSense so far, but i would rather plan to use them, than not, and need them.

                    Nice then you will know that each installed packet will be narrow down the entire throughput of your pfSense.
                    So it might be better, if you are not holding now any kind of spare parts in your hands, that you think a second time
                    about that all. The Xeon is only 2 Core and is really only around 2.0GHz, that might be fine for 1 GBit/s at the WAN
                    interface, but together with all installed packets it might be not enough, as I see it right.

                    TLDR; Looking to build 1gbit up/down with multiple packages enabled and a couple openVPN's.

                    You might be able to walk down the road with two CPU cores like Intel Core i3 is offering, but if it comes to
                    many packets I would set on 4 cores! Something likes a Intel Xeon E3-12xxv3 (4C/8T) @3,2GHz might be
                    the best bet at these days and nothing else will beat it. Power saving much more then the consumer CPUs
                    and really strong horse power delivering. Pointed to the OpenVPNs you should think an a quad core CPU with
                    HT if this is a main concern of your build.

                    -looking at an Xeon E3 1220L (I have looked around, and it seems the single thread score on the V2 is lower than the original V1 it seems?) http://www.cpubenchmark.net/compare.php?cmp%5B%5D=2183&cmp%5B%5D=1197

                    -I am having a very hard time finding a capable Mobo in mini ITX form.. Any suggestions would be greatly appreciated. This is the only one i could find. http://ark.intel.com/products/59046/Intel-Desktop-Board-DQ77KB

                    Do you own this two spare parts (CPU & MoBo) or do you try it to buy?

                    -The onboard NIC's are:
                    LAN Chipset:  Intel 82579LM
                    Second LAN Chipset:  Intel 82574L

                    I would give them a try first and then you might be able to get newer one(s) if really needed

                    Would you recommend getting a i350 pciE? I would much rather just use the dual intel NIC's if i can, but only if they will be efficient enough to handle the load. I have a feeling adding the Ethernet card will also cause problems with the small form factor.

                    Intel PRO/1000 PT Quad Port adapter
                    Intel I350-T2 (dual port) or i350-T4 (quad port)
                    pfSense shop low profile and Quad Port NIC based on Intel i350

                    Pleas not that all three cards will be PCIe 2.0 x4 and so the mainboard should be sorted also with that
                    slot to let you install a card such this!

                    -I would also like a few recommendations for some small form factor cases

                    Mini-ITX cases without any PCIe slot:
                    M350, Supermicro SC101i

                    Mini-ITX cases with an PCIe slot:
                    M300, Silverstone ML07 (SST-ML07B), Casetronic C137

                    If anyone has other suggestions, i love the knowledge, so have at it!

                    I was not able to get out of your writings, that you want to buy that equipment or you have bought that equipment ready yet?

                    My personal choice would be;

                    • ASUS Q87T + Intel Xeon E3-12xxv3
                    • Jetway NF952-Q170 plus any CPU >3.0GHz

                    Each of them is offering you a total other way to go, but lets you also walk on the mini-ITX road, likes you want.
                    One is coming with enough Intel based NICs nad the other is able to hold a real PCIe x4 card if needed!
                    One is able to insert Intel i3, i5 and i7 and the other a really wide vary of CPUs till a Xeon E3-12xxv3 after an BIOS update.

                    But all of them would be fine to route 1 GBit/s and let you install all packets you need and want.

                    1 Reply Last reply Reply Quote 0
                    • T
                      toyebox
                      last edited by

                      Thank you so much for the detailed response. I do currently have a 1220L already(v1). I also have a 3770K that is much faster and uses a lot more power.  I don't know where I got the idea that single thread rating meant more than a total rating when it came to pfSense. Either way, the v3 and v1 are all neck and neck on passmark rating so I am unsure how it won't keep up? I will check out your recommendations for mobo/CPU combos for sure!! Any suggestions for an SSD or does it not matter, just a reputable brand?

                      1 Reply Last reply Reply Quote 0
                      • ?
                        Guest
                        last edited by

                        Thank you so much for the detailed response. I do currently have a 1220L already(v1).

                        Ah, ok this was mot clear to me! Intel DP77KB I can´t see that the Xeon is supported and also there is no ECC RAM support too!

                        Any suggestions for an SSD or does it not matter, just a reputable brand?

                        One of the board is able to hold a mSATA and another miniPCIe slot for a WiFi card!
                        The other one is able to hold "only" a miniPCie WiFi card. Usually it would be good to
                        go with a SSD that has TRIM support. Intel, Crucial, Samsung, OCZ, Transcend,…

                        1 Reply Last reply Reply Quote 0
                        • C
                          chrcoluk
                          last edited by

                          intel and samsung are the most reputable brands.

                          However running pfsense is not going to stress the device, so just get something thats affordable.  However if the price isnt too big between diff models e.g. in my case I could have got a 30 gig ssd instead of 60 but was less than 5% cheaper, so I got the 60.

                          Pretty much any modern ssd now days should support trim and wear levelling technology.

                          pfSense CE 2.8.0

                          1 Reply Last reply Reply Quote 0
                          • T
                            toyebox
                            last edited by

                            @BlueKobold:

                            Thank you so much for the detailed response. I do currently have a 1220L already(v1).

                            Ah, ok this was mot clear to me! Intel DP77KB I can´t see that the Xeon is supported and also there is no ECC RAM support too!

                            Any suggestions for an SSD or does it not matter, just a reputable brand?

                            One of the board is able to hold a mSATA and another miniPCIe slot for a WiFi card!
                            The other one is able to hold "only" a miniPCie WiFi card. Usually it would be good to
                            go with a SSD that has TRIM support. Intel, Crucial, Samsung, OCZ, Transcend,…

                            I did verify its supported . via the Intel web page. For 130 dollars I can put the 1220L to work and see how it runs. Can't hurt I guess. I have never been apposed to building multiple systems so I will for sure try another with the v3 of the 1220L

                            1 Reply Last reply Reply Quote 0
                            • D
                              datum
                              last edited by

                              From what i have been reading, it seems that if you plan on running snort, few cores with higher Ghz is preferable to more cores chips.
                              Also good, if i understood it right, for traffic consisting mainly of small packets, inspected by snort.

                              1 Reply Last reply Reply Quote 0
                              • T
                                toyebox
                                last edited by

                                I'm liking the idea of that jetway 8 port mobo for 6th gen processors
                                Should I go for an i3 6100T or…

                                1 Reply Last reply Reply Quote 0
                                • ?
                                  Guest
                                  last edited by

                                  From what i have been reading, it seems that if you plan on running snort, few cores with higher Ghz is preferable to more cores chips.
                                  Also good, if i understood it right, for traffic consisting mainly of small packets, inspected by snort.

                                  Suricata is multi-threading, Snort will it be in some time as I know it, or it is perhaps also until now happened that it is multi-threading
                                  so many things in pfSense will be at a change at this time. OpenVPN is also multi-threaded since 2.3 and so it might be a game changer
                                  to own a CPU with more CPU cores, but actual you will be then not getting much profit out, and so it might be the best to be also future
                                  proof, to get a strong and powerful CPU with a higher CPU frequency (GHz) paired together with some more CPU cores too!

                                  So you will be getting out now and in the future the best results! And with an looking eyes on power saving options it might be the best
                                  to get an Intel Xeon E3 with 4 Cores and 8 Threads (HT). Actual one of the best options as I see it right, other might see it different and
                                  for sure a cheaper Intel Core i3 could be also an interesting platform.  And if AES-NI is also on board it might be a long time running box.

                                  I'm liking the idea of that jetway 8 port mobo for 6th gen processors
                                  Should I go for an i3 6100T or…

                                  Would be a stronger system together with AES-NI and more GHz as I see it right and so the 1 GBit/s will be even reachable for you.

                                  I did verify its supported . via the Intel web page. For 130 dollars I can put the 1220L to work and see how it runs. Can't hurt I guess. I have never been apposed to building multiple systems so I will for sure try another with the v3 of the 1220L

                                  Ok if the 1220L will work on that board I would suggest to give them a try, for sure this makes sense for me.

                                  • Intel DP77KB
                                    Now only the right matching case will be the question
                                  • mSATA 32 GB or 60 GB or 120 GB (transcend)
                                    16GB for plain install, 32GB for Snort, 60GB for Snort & Squid and 120GB for more users, services, HotSpot, Squid, Snort,…..
                                  • 2 x 4 GB RAM (fastest as the board will be supporting please) (DDR3-1600 in your case)
                                    Often the CPU is not saturated but the memory system is! And with 8 GB you will be able to high up the mbuf size to 1000000
                                  • Intel PRO/1000 PT refurbished or a refurbished Intel i350-T4 would my personal choice here
                                    Often able to get for ~$50 or ~$120 so the pfSense Shop NIC in low profile format could also be interesting
                                  1 Reply Last reply Reply Quote 0
                                  • T
                                    toyebox
                                    last edited by

                                    @BlueKobold:

                                    From what i have been reading, it seems that if you plan on running snort, few cores with higher Ghz is preferable to more cores chips.
                                    Also good, if i understood it right, for traffic consisting mainly of small packets, inspected by snort.

                                    Suricata is multi-threading, Snort will it be in some time as I know it, or it is perhaps also until now happened that it is multi-threading
                                    so many things in pfSense will be at a change at this time. OpenVPN is also multi-threaded since 2.3 and so it might be a game changer
                                    to own a CPU with more CPU cores, but actual you will be then not getting much profit out, and so it might be the best to be also future
                                    proof, to get a strong and powerful CPU with a higher CPU frequency (GHz) paired together with some more CPU cores too!

                                    So you will be getting out now and in the future the best results! And with an looking eyes on power saving options it might be the best
                                    to get an Intel Xeon E3 with 4 Cores and 8 Threads (HT). Actual one of the best options as I see it right, other might see it different and
                                    for sure a cheaper Intel Core i3 could be also an interesting platform.  And if AES-NI is also on board it might be a long time running box.

                                    I'm liking the idea of that jetway 8 port mobo for 6th gen processors
                                    Should I go for an i3 6100T or…

                                    Would be a stronger system together with AES-NI and more GHz as I see it right and so the 1 GBit/s will be even reachable for you.

                                    I did verify its supported . via the Intel web page. For 130 dollars I can put the 1220L to work and see how it runs. Can't hurt I guess. I have never been apposed to building multiple systems so I will for sure try another with the v3 of the 1220L

                                    Ok if the 1220L will work on that board I would suggest to give them a try, for sure this makes sense for me.

                                    • Intel DP77KB
                                      Now only the right matching case will be the question
                                    • mSATA 32 GB or 60 GB or 120 GB (transcend)
                                      16GB for plain install, 32GB for Snort, 60GB for Snort & Squid and 120GB for more users, services, HotSpot, Squid, Snort,…..
                                    • 2 x 4 GB RAM (fastest as the board will be supporting please) (DDR3-1600 in your case)
                                      Often the CPU is not saturated but the memory system is! And with 8 GB you will be able to high up the mbuf size to 1000000
                                    • Intel PRO/1000 PT refurbished or a refurbished Intel i350-T4 would my personal choice here
                                      Often able to get for ~$50 or ~$120 so the pfSense Shop NIC in low profile format could also be interesting

                                    Thank you for your post! In order to boost a the processing power of this new box,I am able to get my hands on an E3 1265Lv2 for a very very good price. I would assume it's quite power enough, right?

                                    1 Reply Last reply Reply Quote 0
                                    • V
                                      VAMike
                                      last edited by

                                      @toyebox:

                                      Thank you for your post! In order to boost a the processing power of this new box,I am able to get my hands on an E3 1265Lv2 for a very very good price. I would assume it's quite power enough, right?

                                      I'd rather have something like a 3.5GHz kaby lake i3 or pentium for the listed requirements. The improvements in the crypto processing in the latest intel processors and the better single thread performance will count for more than the extra cache and cores. If you've got your heart set on an E3, skip the L variants and get something clocked higher (and I'd personally get something newer than an ivy bridge).

                                      1 Reply Last reply Reply Quote 0
                                      • T
                                        toyebox
                                        last edited by

                                        So I just purchased a bunch of the accessories to go with this. A ubiquiti AP pro, ubiquiti 8 port managed edgeswitch, and all the parts to move forward with using the older e3 1220L. I will be picking up a 3770T soon which should undoubtedly be more than fast enough and has aes-ni . although some of you say grab a newer top of the line Intel and everything to match it, this 4 year old technology is well within its limits of pushing 1gbe IMO. I don't forsee pfSense outgrowing this equipments capabilities within the next 5 years.

                                        Total setup:
                                        I7 3770T
                                        16 gigs of corsair memory
                                        120 GB 850 msata
                                        Intel thin mini itx DQ77KB
                                        Silverstone pt13D case (looks fantastic!)
                                        Silverstone NT07-115X cooler

                                        Also picked up an arris sb6190

                                        1 Reply Last reply Reply Quote 0
                                        • ?
                                          Guest
                                          last edited by

                                          E3 1265Lv2

                                          Get it! It scales from 2,5GHz to 3,5GHz and has 4C/8T (HT) and AES-NI on top too.

                                          Silverstone pt13D case (looks fantastic!)

                                          If this is the Silverstone case where you want to put outthe extra NIC with 2 or 4 Ports?

                                          1 Reply Last reply Reply Quote 0
                                          • W
                                            whosmatt
                                            last edited by

                                            @toyebox:

                                            Also picked up an arris sb6190

                                            Might want to see this:

                                            https://www.dslreports.com/forum/r31079834-ALL-SB6190-is-a-terrible-modem-Intel-Puma-6-MaxLinear-mistake

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.