Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    New hardware

    Off-Topic & Non-Support Discussion
    7
    61
    565
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JKnott
      JKnott last edited by

      As I mentioned earlier, the computer I was running pfsense on died recently. I have decided on one of these as a replacement. I'll be getting the Q350G4 4200U NO WiFi bundle with 4 GB of RAM. I trust this would be adequate for pfsense. I have a 500 Mb down/20 up Internet connection.

      Comments?

      tnx jk

      noplan JKnott 2 Replies Last reply Reply Quote 0
      • noplan
        noplan @JKnott last edited by

        @jknott

        I recommend >4gb ram better for Playin around with DNSBL

        Only Intel to use Intel NICs and for the horsepower hmmm some AES NI supported CPU

        BrNP

        JKnott 1 Reply Last reply Reply Quote 0
        • JKnott
          JKnott @noplan last edited by JKnott

          @noplan

          I'm not sure what your reply is saying. That 4 GB is well above the minimum specs for pfsense and what does DNSBL mean? It also has Intel NICs and AES-NI. The system it replaced has an Athlon 3200+ CPU and 4 GB, which ran very well and had no problem keeping up with 500 Mb download.

          NogBadTheBad noplan 2 Replies Last reply Reply Quote 0
          • NogBadTheBad
            NogBadTheBad Galactic Empire @JKnott last edited by NogBadTheBad

            @jknott said in New hardware:

            @noplan

            I'm not sure what your reply is saying. That 4 GB is well above the minimum specs for pfsense and what does DNSBL mean? It also has Intel NICs and AES-NI

            Hes talking about pfBlocker.

            TBH RAM is cheap

            noplan JKnott 2 Replies Last reply Reply Quote 0
            • noplan
              noplan @JKnott last edited by

              @jknott

              hi,
              if u plan tu use pfBlocker and play a little with DNSBL (DNS-based Blackhole List)
              then the more RAM u have the better.

              have u thought about gettin a NETGATE SG1100 box depending on your use case ...
              and by the way much cooler than the aliX import ;)

              AES and Intel Nics are keepin u headache free ;)

              JKnott 1 Reply Last reply Reply Quote 0
              • noplan
                noplan @NogBadTheBad last edited by

                @nogbadthebad said in New hardware:

                TBH

                ?? damn i'm from europe i dont speak emojii ;)

                NogBadTheBad 1 Reply Last reply Reply Quote 0
                • NogBadTheBad
                  NogBadTheBad Galactic Empire @noplan last edited by

                  @noplan said in New hardware:

                  @nogbadthebad said in New hardware:

                  TBH

                  ?? damn i'm from europe i dont speak emojii ;)

                  I'm in Europe too 🇬🇧

                  TBH = To Be Honest

                  noplan 1 Reply Last reply Reply Quote 0
                  • JKnott
                    JKnott @NogBadTheBad last edited by

                    @nogbadthebad said in New hardware:

                    Hes talking about pfBlocker

                    I don't use pfblocker.

                    1 Reply Last reply Reply Quote 0
                    • JKnott
                      JKnott @noplan last edited by

                      @noplan said in New hardware:

                      have u thought about gettin a NETGATE SG1100 box

                      When that was discussed earlier, the opinion was that it was a bit anemic and to go for a better model.

                      noplan 1 Reply Last reply Reply Quote 0
                      • noplan
                        noplan @JKnott last edited by

                        @jknott

                        have a look SG-2100 here a little over 300 EUR not including VAT

                        @ SG1100 same here !

                        but compare it wirh the SG2100 maybe it fits

                        JKnott 1 Reply Last reply Reply Quote 0
                        • noplan
                          noplan @NogBadTheBad last edited by

                          @nogbadthebad said in New hardware:

                          I'm in Europe too

                          No you are not ! You kicked yourself out !

                          :😁 😀

                          1 Reply Last reply Reply Quote 0
                          • JKnott
                            JKnott @noplan last edited by

                            @noplan said in New hardware:

                            but compare it wirh the SG2100 maybe it fits

                            It's about twice the price of the Qotom I selected.

                            noplan JKnott 2 Replies Last reply Reply Quote 0
                            • noplan
                              noplan @JKnott last edited by

                              @jknott 053d9e79-bdd6-4f17-a7dc-b26b2fad97a6-grafik.png

                              but the shippin from them to me flippy expensive

                              bingo600 1 Reply Last reply Reply Quote 0
                              • bingo600
                                bingo600 @noplan last edited by bingo600

                                @noplan

                                Isn't shipping around $40 w. DHL ?

                                noplan 1 Reply Last reply Reply Quote 0
                                • noplan
                                  noplan @bingo600 last edited by

                                  @bingo600

                                  i think i'll get a new toy ;) but i think customs declaration & import tax will kill the benefit

                                  7eeca1df-bbb5-40d2-9cf7-00658b24961c-grafik.png

                                  but @ netgate i found this
                                  79597b5f-8add-4c03-8d9b-33ccb5d0a04a-grafik.png

                                  1 Reply Last reply Reply Quote 0
                                  • JKnott
                                    JKnott @JKnott last edited by

                                    @jknott said in New hardware:

                                    @noplan said in New hardware:

                                    but compare it wirh the SG2100 maybe it fits

                                    It's about twice the price of the Qotom I selected.

                                    Hmmm... Somehow I got the idea it was twice the price, but on checking further it appears to be roughly the same. Which would have better performance? The Qotom is an i5 CPU and has Intel NICs, but the Netgate has an ARM CPU and Marvel NICs. Both have 4 GB.

                                    noplan 1 Reply Last reply Reply Quote 0
                                    • noplan
                                      noplan @JKnott last edited by

                                      @jknott

                                      depends on your use case, and on how long u wanna use the "box"
                                      if u are a home/lab user and planning to use the box till it dies go with the netgate box considering the future possibility to go all in with the pfS+ version they are talkin about

                                      and hey its a netgate box vs a china box ;)

                                      dont get me wrong i really dont have a clue what hardware i m gonna buy in the next 6 months

                                      jwj 1 Reply Last reply Reply Quote 0
                                      • jwj
                                        jwj @noplan last edited by

                                        @noplan said in New hardware:

                                        and hey its a netgate box vs a china box

                                        Exactly where do you think the Netgate device is manufactured?

                                        JKnott 1 Reply Last reply Reply Quote 0
                                        • JKnott
                                          JKnott @jwj last edited by

                                          @jwj

                                          As was the Unifi AP I recently bought. Does the Netgate have those AES-NI instructions?

                                          bingo600 jwj 2 Replies Last reply Reply Quote 0
                                          • bingo600
                                            bingo600 @JKnott last edited by

                                            @jknott said in New hardware:

                                            @jwj

                                            Does the Netgate have those AES-NI instructions?

                                            AES-NI is an Intel extension

                                            JKnott 1 Reply Last reply Reply Quote 0
                                            • jwj
                                              jwj @JKnott last edited by jwj

                                              @jknott No. It doesn't. The i5 will crush the ARM device for single thread performance and OpenVPN throughput. Question is, do you need that performance? Netgate box will be more energy efficient.

                                              For what it's worth, I've always seen the 5100 as entry level. Then I cried inside at the price... The LAN<->LAN filtering rates is what I pay attention to. I would want line speed.

                                              2020_Netgate_Hardware_Comparison_Chart.png

                                              JKnott 1 Reply Last reply Reply Quote 0
                                              • JKnott
                                                JKnott @bingo600 last edited by

                                                @bingo600 said in New hardware:

                                                AES-NI is an Intel extension

                                                It's on other CPUs too.

                                                bingo600 1 Reply Last reply Reply Quote 0
                                                • bingo600
                                                  bingo600 @JKnott last edited by bingo600

                                                  @jknott said in New hardware:

                                                  @bingo600 said in New hardware:

                                                  AES-NI is an Intel extension

                                                  It's on other CPUs too.

                                                  Please mention just one ARM CPU that has it (AES-NI)

                                                  JKnott 1 Reply Last reply Reply Quote 0
                                                  • JKnott
                                                    JKnott @jwj last edited by

                                                    @jwj said in New hardware:

                                                    No. It doesn't. The i5 will crush the ARM device for single thread performance and OpenVPN throughput. Question is, do you need that performance? Netgate box will be more energy efficient.

                                                    The Netgate takes a 12V 2A power supply, which means it runs less than 24W. The Qotom takes 15W, so there's not much difference. As for the AES-NI instructions, it wasn't that long ago that plans were dropped to require them. I don't have much of a need for those, as I only occasionally use the VPN, but I wouldn't want to lose the ability to update the software for the lack of them.

                                                    jwj bingo600 2 Replies Last reply Reply Quote 0
                                                    • JKnott
                                                      JKnott @bingo600 last edited by

                                                      @bingo600 said in New hardware:

                                                      Please mention just one ARM CPU that has it (AES-NI)

                                                      According to that article I linked to, several do.

                                                      bingo600 1 Reply Last reply Reply Quote 0
                                                      • jwj
                                                        jwj @JKnott last edited by jwj

                                                        @jknott For sure not an obvious choice. You're going to have to have a think about it.

                                                        Also some of the discusion around pfSense+ leads me to believe the REST API is on the roadmap. Will that bring back the AES requirement or will they work around that with the other instructioin sets available on the ARM devices. I have no idea...

                                                        What do you see as the lifespan of this device?

                                                        noplan JKnott 2 Replies Last reply Reply Quote 0
                                                        • noplan
                                                          noplan @jwj last edited by

                                                          @jwj
                                                          couldn't agree more here with @jwj

                                                          1 Reply Last reply Reply Quote 0
                                                          • bingo600
                                                            bingo600 @JKnott last edited by

                                                            @jknott said in New hardware:

                                                            @bingo600 said in New hardware:

                                                            Please mention just one ARM CPU that has it (AES-NI)

                                                            According to that article I linked to, several do.

                                                            Where does it say that an ARM CPU has AES-NI ??

                                                            I see this , where it specifically mentions that AES-NI is Intel/AMD only

                                                            82f3b105-a660-4e73-b724-4646a13248ad-image.png

                                                            Other architectures have Crypto instructions too , but not AES-NI

                                                            /Bingo

                                                            JKnott 1 Reply Last reply Reply Quote 0
                                                            • JKnott
                                                              JKnott @jwj last edited by

                                                              @jwj said in New hardware:

                                                              What do you see as the lifespan of this device?

                                                              Well, based on my other experience, until something significantly better comes along or it dies (as happened with my previous firewall). I'm not one to run out and buy the latest & greatest, unless it yields significant improvement. For example, if a pfsense update had required AES-NI, then I would have bought something that supports it, as the HP computer I was running didn't.

                                                              Another example, my current desktop computer case originally had a 32 bit CPU. I've since replaced the mom board a couple of times. The case is so old it's cream coloured, not black (matches my IBM model M keyboard, but not much else). I also recently finally got an AP that support 5 GHz.

                                                              BTW, that keyboard is built like a tank and old enough to not have a Windows key. 😉

                                                              jwj 1 Reply Last reply Reply Quote 1
                                                              • bingo600
                                                                bingo600 @JKnott last edited by

                                                                @jknott said in New hardware:

                                                                The Netgate takes a 12V 2A power supply, which means it runs less than 24W. The Qotom takes 15W, so there's not much difference.

                                                                The CPU TDP is 15W

                                                                0db78d15-f5da-47e4-b97d-6aa8b82b99b7-image.png

                                                                The NIC's (Phy's) + other electronics also consumes

                                                                My Qotom came w. a 12V/5A PSU

                                                                /Bingo

                                                                JKnott 1 Reply Last reply Reply Quote 0
                                                                • JKnott
                                                                  JKnott @bingo600 last edited by

                                                                  @bingo600 said in New hardware:

                                                                  Other architectures have Crypto instructions too , but not AES-NI

                                                                  So, what does pfsense do with those Crypto instructions? Ignore them? I could be wrong, but I would assume software written for an ARM CPU would take advantage of the ARM instructions.

                                                                  It's been a while since I've written software, but I seem to recall compilers can link in appropriate libraries for the different target hardware.

                                                                  jwj bingo600 2 Replies Last reply Reply Quote 0
                                                                  • jwj
                                                                    jwj @JKnott last edited by

                                                                    @jknott said in New hardware:

                                                                    @bingo600 said in New hardware:

                                                                    Other architectures have Crypto instructions too , but not AES-NI

                                                                    So, what does pfsense do with those Crypto instructions? Ignore them? I could be wrong, but I would assume software written for an ARM CPU would take advantage of the ARM instructions.

                                                                    It's been a while since I've written software, but I seem to recall compilers can link in appropriate libraries for the different target hardware.

                                                                    There are some threads concerning that. To the best of knowledge it does ignore them at the moment.

                                                                    I have sent you a private message...

                                                                    1 Reply Last reply Reply Quote 0
                                                                    • bingo600
                                                                      bingo600 @JKnott last edited by

                                                                      @jknott said in New hardware:

                                                                      @bingo600 said in New hardware:

                                                                      Other architectures have Crypto instructions too , but not AES-NI

                                                                      So, what does pfsense do with those Crypto instructions? Ignore them?

                                                                      If Netgate want their ARM boxes to perform decent w. crypto they probably have enabled the usage of any Crypto instructions available.

                                                                      I could be wrong, but I would assume software written for an ARM CPU would take advantage of the ARM instructions.

                                                                      On embedded programming you often have to make sure to use the correct libraries. It's usually done with a couple of compiler switches , that pulls in the correct linker library. Sometimes you even have to set a few bits in the MCU , in order to enable any "Crypto part in the MCU" , often "extensions" are disabled on POR , to minimize power usage.

                                                                      It's been a while since I've written software, but I seem to recall compilers can link in appropriate libraries for the different target hardware.

                                                                      Yepp , if being told to do so.

                                                                      But you were referring to AES-NI
                                                                      And i replied correctly it was an Intel extension.

                                                                      /Bingo

                                                                      JKnott 1 Reply Last reply Reply Quote 0
                                                                      • jwj
                                                                        jwj @JKnott last edited by

                                                                        @jknott said in New hardware:

                                                                        @jwj said in New hardware:

                                                                        What do you see as the lifespan of this device?

                                                                        Well, based on my other experience, until something significantly better comes along or it dies (as happened with my previous firewall). I'm not one to run out and buy the latest & greatest, unless it yields significant improvement. For example, if a pfsense update had required AES-NI, then I would have bought something that supports it, as the HP computer I was running didn't.

                                                                        Another example, my current desktop computer case originally had a 32 bit CPU. I've since replaced the mom board a couple of times. The case is so old it's cream coloured, not black (matches my IBM model M keyboard, but not much else). I also recently finally got an AP that support 5 GHz.

                                                                        BTW, that keyboard is built like a tank and old enough to not have a Windows key. 😉

                                                                        I'm very much the same. For example, my 2015 VW Golf is just about broken in. I'll drive it until it has no value and then replace it.

                                                                        Buy nice things and use them, don't worry about the new things until your done with the ones you have ;)

                                                                        JKnott 1 Reply Last reply Reply Quote 0
                                                                        • JKnott
                                                                          JKnott @bingo600 last edited by

                                                                          @bingo600 said in New hardware:

                                                                          My Qotom came w. a 12V/5A PSU

                                                                          How much does it actually consume? What does the label by the power connector say? The info I saw listed 12V 2A. It's good practice to over spec things like power supplies, provided you don't go overboard. Either way, both devices are in the same ballpark and will require far less power than the HP desktop computer that's being replaced.

                                                                          bingo600 1 Reply Last reply Reply Quote 0
                                                                          • bingo600
                                                                            bingo600 @JKnott last edited by bingo600

                                                                            @jknott said in New hardware:

                                                                            @bingo600 said in New hardware:

                                                                            My Qotom came w. a 12V/5A PSU

                                                                            How much does it actually consume?

                                                                            I haven't measured it yet , i might

                                                                            Either way, both devices are in the same ballpark

                                                                            I would expect the 2100 to use less than the Qotom.
                                                                            Guesstimate ... Around half.

                                                                            and will require far less power than the HP desktop computer that's being replaced.

                                                                            I totally agree

                                                                            1 Reply Last reply Reply Quote 0
                                                                            • JKnott
                                                                              JKnott @bingo600 last edited by

                                                                              @bingo600 said in New hardware:

                                                                              But you were referring to AES-NI

                                                                              My original intent was to write AES-NI or equivalent, but I didn't bother.

                                                                              1 Reply Last reply Reply Quote 0
                                                                              • JKnott
                                                                                JKnott @jwj last edited by

                                                                                @jwj said in New hardware:

                                                                                I'm very much the same. For example, my 2015 VW Golf is just about broken in. I'll drive it until it has no value and then replace it.
                                                                                Buy nice things and use them, don't worry about the new things until your done with the ones you have ;)

                                                                                I'm driving a 2005 Ford Taurus and it's still going strong. I generally drive my cars until the wheels fall off. 😉

                                                                                1 Reply Last reply Reply Quote 1
                                                                                • jwj
                                                                                  jwj last edited by

                                                                                  No matter what it will soon be new hardware day. That's a happy occasion. Cheers!

                                                                                  JKnott 1 Reply Last reply Reply Quote 0
                                                                                  • JKnott
                                                                                    JKnott @jwj last edited by

                                                                                    @jwj

                                                                                    One other thing I just noticed about the Netgate box. It doesn't appear to have a video port. That's not critical, as I do have a USB serial port, but I have a 4 port HDMI/USB KVM, which I used to connect to my old firewall. I could just switch from my computer to my firewall as needed.

                                                                                    jwj 1 Reply Last reply Reply Quote 0
                                                                                    • First post
                                                                                      Last post

                                                                                    Products

                                                                                    • Platform Overview
                                                                                    • TNSR
                                                                                    • pfSense Plus
                                                                                    • Appliances

                                                                                    Services

                                                                                    • Training
                                                                                    • Professional Services

                                                                                    Support

                                                                                    • Subscription Plans
                                                                                    • Contact Support
                                                                                    • Product Lifecycle
                                                                                    • Documentation

                                                                                    News

                                                                                    • Media Coverage
                                                                                    • Press
                                                                                    • Events

                                                                                    Resources

                                                                                    • Blog
                                                                                    • FAQ
                                                                                    • Find a Partner
                                                                                    • Resource Library
                                                                                    • Security Information

                                                                                    Company

                                                                                    • About Us
                                                                                    • Careers
                                                                                    • Partners
                                                                                    • Contact Us
                                                                                    • Legal
                                                                                    Our Mission

                                                                                    We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

                                                                                    Subscribe to our Newsletter

                                                                                    Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

                                                                                    © 2021 Rubicon Communications, LLC | Privacy Policy