Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    This this overkill for PFSense?

    Scheduled Pinned Locked Moved Hardware
    7 Posts 5 Posters 956 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      alpine7513
      last edited by

      So I want some opinions if this is overkill. I brought home a computer that we were going to destroy at work as it was just too old. It’s an i3-4150 With 16 gigs of RAM and a 120gb intel 330 series SSD. I have Comcast one gig down 40 mb up and the built in Realtek and the PCI-e Realtek cards were only getting 330mb to the FW. Found an article about slow performance with realtek cards. I won an Intel X550 10gb dual card at a vendor show that I have not used. I installed it and now I get full gig speed down. My question is…..is this massive overkill? I have snort, DHCP, DNS, and OPENVPN running on it. Just thinking that maybe I can use a lower performance system and get the same amazing performance that this one gets. Power is not an issue as this running off a solar system with battery power.

      FYI : I am using AES for crypto

      Intel(R) Core(TM) i3-4150 CPU @ 3.50GHz

      4 CPUs: 1 package(s) x 2 core(s) x 2 hardware threads

      AES-NI CPU Crypto: Yes (active)

      QAT Crypto: No

      Hardware crypto AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS

      Thank you in advance for any and all help!

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @alpine7513
        last edited by

        @alpine7513 Maybe but if it works... :) Do you have System/Advanced/Miscellaneous -> PowerD enabled? I'm guessing not from your copy/paste since there should be a line for the CPU frequency. We have one older PC on 2.6 that is just fine left at "hiadaptive." (note the dashboard will use CPU time for all its updates, so the real usage is likely less than shown)

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • Cool_CoronaC
          Cool_Corona
          last edited by

          No its not.

          ? 1 Reply Last reply Reply Quote 1
          • ?
            A Former User @Cool_Corona
            last edited by A Former User

            @cool_corona

            Intel(R) Core(TM) i3-4150 CPU @ 3.50GHz

            For ~500 MBit/s you should have a 2,0GHz CPU and yours
            is pretty much over (3,5GHz) so this is well for 1 GBit/s.

            question is…..is this massive overkill?

            Never, it all depends on how many packets you were installing and what you are doing with it! Also how many
            snort rules and/or pfBlocker-NG lists you will be loading might be a huge difference to a "normal" usage.

            I have snort, DHCP, DNS, and OPENVPN

            If later perhaps some packets comes on top and also some rules more for snort you may be lucky about the 16GB.

            1 Reply Last reply Reply Quote 1
            • Cool_CoronaC
              Cool_Corona
              last edited by Cool_Corona

              This runs Suricata and pfB with a shitload of rules both on WAN, LAN and DMZ.

              9b32f8d1-03f6-44b2-b24c-0129ca5b9027-billede.png

              So 16GB is more than enough.

              ? 1 Reply Last reply Reply Quote 0
              • ?
                A Former User @Cool_Corona
                last edited by

                @cool_corona

                This runs Suricata and pfB with a shitload of rules both
                on WAN, LAN and DMZ.

                Cool! I would wisch the data were from mine! I have installed

                • pfBlocker-NG
                • SquidGuard
                • ClamAV
                • Squid
                • Snort

                I get with a tuned AMD CPU something between 30 - 50 %
                CPU load and from 4 GB 50 % - 90 % sometimes more sometimes less are in usage and 10 % - 50 % from 4 GB
                swap are normally in usage. So you know a 3,5GHz CPU
                and 16 GB is not really overkill it from my point of view
                running a fully UTM better then good to own!

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  I would say 16G is probably not necessary there but the CPU is probably in the ball-park for 1G throughput with a bunch of packages.
                  That CPU socket gives you a lot of options too. Not the most power efficient device though.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.