<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[pfSense hardware help for new box (DiY)]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">i want to ask for help with hardware review for new pfSense box  (home use). Max price 450€ (only local reseler - no eBay, Amazon, ... )</p>
<p dir="auto">Interfaces:<br />
2 x Wan: Wan1 50/1Mbps (LTE router), Wan2 (ADSL+ router) 8Mbps/512kbps, setup as wan failover for parents, childrens will use only Wan2<br />
1x LAN<br />
1x Wifi (i will use AP)<br />
1x DMZ (optional)</p>
<p dir="auto">planned services:<br />
snort (on all interfaces), pfblocker, ntopng, DHCP, DNSSEC, Dynamic DNS, OpenVPN server for ADSL+, nut, traffic totals</p>
<p dir="auto">My HW from local reseller:<br />
CPU: Intel i3-8100<br />
RAM: 16G DDR4 2666 CL16 (HyperX Fury Black)<br />
SSD: Intel 545S 128GB<br />
Mobo: Asus TUF B360-PRO GAMING<br />
LAN card: EDIMAX EN-9260TX-E V2 (RTL8168E) 4x</p>
<p dir="auto">Thx,</p>
<p dir="auto">Marian.</p>
]]></description><link>https://forum.netgate.com/topic/141752/pfsense-hardware-help-for-new-box-diy</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 17:07:11 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/141752.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 20 Mar 2019 10:45:38 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to pfSense hardware help for new box (DiY) on Mon, 25 Mar 2019 14:55:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marian78">@<bdi>marian78</bdi></a> said in <a href="/post/832792">pfSense hardware help for new box (DiY)</a>:</p>
<blockquote>
<p dir="auto">Is there any WIFI n/ac module, that it can work with pfSense on that board, ideal for 2,4GHz and another for 5GHz?</p>
</blockquote>
<p dir="auto">I'd advise not to go that route. You won't get any (AFAIK) -ac to run, -n would be the most and even for that, the hardware to choose from is very sparse and picky. You could try some Atheros based cards but considering your time and the money for that, you'd be better of buying some good and configurable AP (I took a unify AP-AC-Pro and had no regrets).</p>
]]></description><link>https://forum.netgate.com/post/832809</link><guid isPermaLink="true">https://forum.netgate.com/post/832809</guid><dc:creator><![CDATA[JeGr]]></dc:creator><pubDate>Mon, 25 Mar 2019 14:55:53 GMT</pubDate></item><item><title><![CDATA[Reply to pfSense hardware help for new box (DiY) on Mon, 25 Mar 2019 14:33:02 GMT]]></title><description><![CDATA[<p dir="auto">Thx all for advices, now i must consider, what i will choose.  <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60c.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--relieved" style="height:23px;width:auto;vertical-align:middle" title=":relieved:" alt="😌" /></p>
<p dir="auto">When done, i will post.</p>
<p dir="auto">Thx, again. <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44d.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--+1" style="height:23px;width:auto;vertical-align:middle" title=":+1:" alt="👍" /></p>
<p dir="auto">so:<br />
pcengines APU4c4<br />
mSATA 30G</p>
<p dir="auto">Is there any WIFI n/ac module, that it can work with pfSense on that board, ideal for 2,4GHz and another for 5GHz? <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f385.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--santa" style="height:23px;width:auto;vertical-align:middle" title=":santa:" alt="🎅" /></p>
]]></description><link>https://forum.netgate.com/post/832792</link><guid isPermaLink="true">https://forum.netgate.com/post/832792</guid><dc:creator><![CDATA[marian78]]></dc:creator><pubDate>Mon, 25 Mar 2019 14:33:02 GMT</pubDate></item><item><title><![CDATA[Reply to pfSense hardware help for new box (DiY) on Fri, 22 Mar 2019 09:00:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/vegastech">@<bdi>vegastech</bdi></a></p>
<blockquote>
<p dir="auto">An entire setup with case and power supply should be under $300, probably more in EU.</p>
</blockquote>
<p dir="auto">Nope on the contrary. Complete APU bundles are available for around ~165€ for an APU2D2 (3 NICs) or ~175€ for a APU4C2 (4 NICs). For less than 50Mbps I'd stay low on the hardware.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marian78">@<bdi>marian78</bdi></a></p>
<p dir="auto">Yeah I would agree with <a class="plugin-mentions-user plugin-mentions-a" href="/user/vegastech">@<bdi>vegastech</bdi></a> , just don't use Realtek based cards. Simply not worth the trouble. Just drop in a simple Intel card and be good.</p>
<blockquote>
<p dir="auto">snort (on all interfaces), pfblocker, ntopng, DHCP, DNSSEC, Dynamic DNS, OpenVPN server for ADSL+, nut, traffic totals</p>
</blockquote>
<p dir="auto">See no sense in running snort a) on all interfaces (why the hell?) or on WAN at all. Are you planning to offer services on your DSL line or via LTE? I suppose not, so can't see the deeper sense of running an IDS or even in IPS mode if most or all traffic on WAN is blocked anyways. pfBlockerNG's lists and settings are well used for additional LAN-&gt;WAN blocking.  Any other things aren't that performance greedy so could run on an APU without hitch.</p>
<blockquote>
<p dir="auto">hardware list</p>
</blockquote>
<p dir="auto">Besides that I'd go for a solution better suited for network purpose. The hardware is bonkers IMHO. i3-8100 isn't needed for anything as the connection is no more then 50Mbps at max, even crypted. 16GB are too much and not needed anywhere. I've seen big corporate setups of pfsense that don't even need 8. I'd go with 8GB to have reserves but that's it.<br />
SSD is nice even if 128 won't be needed but SSDs are happy little bunnies if they have enough space for wear leveling so nothing wrong with it. But as <a class="plugin-mentions-user plugin-mentions-a" href="/user/vegastech">@<bdi>vegastech</bdi></a> already pointed out, a gaming MoBo and lowbob Realtec networking card show a severe lack of understanding what <em>really</em> is important for pfsense. A good/moderate CPU, RAM and superb network interfaces. The hardware list seems more like: "hey let's build a gaming rig and throw pfSense on it, if it annoys me, I'll just turn it into a gaming PC again" <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f609.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--wink" style="height:23px;width:auto;vertical-align:middle" title=":wink:" alt="😉" /></p>
<p dir="auto">As you're now running on a microserver, why bother with a gaming rig and don't just build/use something like a real networking platform? E.g. use a denverton based SOC (c3558 or alike) and put it in a small case, throw 8GB RAM into it and your SSD and be done? That thing can route a bunch and will most likely serve you years if you don't plan to require more than ~400-500Mbps of encrypted performance <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f604.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--smile" style="height:23px;width:auto;vertical-align:middle" title=":smile:" alt="😄" /></p>
<p dir="auto">Perhaps there are smaller Denverton SOC boards around but I'd go the Atom C2xxx or C3xxx route  if an APU is too small for you. Will serve you well with network performance AND low power (~10W) instead of stealing ~60-80W with that gaming rig setup.</p>
<p dir="auto">Cheers,<br />
Jens</p>
]]></description><link>https://forum.netgate.com/post/832268</link><guid isPermaLink="true">https://forum.netgate.com/post/832268</guid><dc:creator><![CDATA[JeGr]]></dc:creator><pubDate>Fri, 22 Mar 2019 09:00:42 GMT</pubDate></item><item><title><![CDATA[Reply to pfSense hardware help for new box (DiY) on Thu, 21 Mar 2019 17:40:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marian78">@<bdi>marian78</bdi></a></p>
<p dir="auto">Hello, we build a lot of routers based on PC Engines APU2C4. An entire setup with case and power supply should be under $300, probably more in EU.</p>
<p dir="auto">I imagine most people will complain about a Realtek LAN card. We used to use a lot of HP NC365T quad port LAN cards. Those are built with Intel LAN chipsets.  They cost about $30 on eBay. There is a NC364T but that is based on Broadcom LAN chipsets which other people dislike.</p>
<p dir="auto">If you can find a 30GB or 60GB SSD for a little less it makes more sense. The 128GB is fine, just a bit overkill.</p>
<p dir="auto">Same kind of overkill for memory and mobo. The APU2C4 run with 4GB and have never given our offices any limiting issues. A gaming mobo is fancy but I would chose a CSM model (long term business support) from Asus/MSI/Asrock.</p>
<p dir="auto">If you're happy with the local supplier, request a change to the LAN card, but, everything else will work fine. It just super duper hardware for home use.</p>
]]></description><link>https://forum.netgate.com/post/832150</link><guid isPermaLink="true">https://forum.netgate.com/post/832150</guid><dc:creator><![CDATA[vegastech]]></dc:creator><pubDate>Thu, 21 Mar 2019 17:40:33 GMT</pubDate></item></channel></rss>