Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    New CPU/Plattform REcommendation

    Scheduled Pinned Locked Moved Hardware
    15 Posts 5 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG
      Gertjan @sysadminfromhell
      last edited by Gertjan

      @sysadminfromhell

      I never saw a TNSR install, so all I know is this https://www.netgate.com/tnsr-software/performance#get-to-know - the (max) performance shown over there is mind boggling.
      I wonder what hardware Netgate was using to see those specs. They could tell you ^^

      100 Gbits++ is enough for a small county ^^

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      1 Reply Last reply Reply Quote 0
      • P
        Patch @sysadminfromhell
        last edited by

        @sysadminfromhell said in New CPU/Plattform REcommendation:

        I will be gettin 1G WAN in this year (end of year) and for VPN I use WireGuard and IPsec.
        IDS/IPS was planned and is installed but not active currently.

        @sysadminfromhell said in New CPU/Plattform REcommendation:

        I currenlty dont know how to benchmark the system

        I suggest starting with Netgate benchmarks. They provided known performance and price in a balanced system
        https://www.netgate.com/appliances?priceMin=179&priceMax=3148&user_profile=&software=pfSense+Plus&form_factor=#compare-products

        You may find buying there optimal, if not you can compare the specs of your proposed system to theirs. You are unlikely to get as good system component balance but it should at least get you in the ball park.

        S 1 Reply Last reply Reply Quote 0
        • S
          sysadminfromhell @Patch
          last edited by

          @Patch this answer doesn’t really help. How does Netgate benchmark ?

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            You don't need to upgrade. What you have is already waaaay more powerful that it needs to be.

            The only reason I could imagine for upgrading would be to something less powerful to reduce running costs.

            S 1 Reply Last reply Reply Quote 1
            • S
              sysadminfromhell @stephenw10
              last edited by sysadminfromhell

              @stephenw10 said in New CPU/Plattform REcommendation:

              You don't need to upgrade. What you have is already waaaay more powerful that it needs to be.

              The only reason I could imagine for upgrading would be to something less powerful to reduce running costs.

              i would love to have the ability to use QAT as well as somehow "know" how much I could press through the firewall - so how to benchmark properly. I am kind of new to the whole Benchmark'ing thing. Would be good to know where the limit is of the hardware.
              EDIT: I also don't really know how much better QAT is against the normal crypto acceleration build-in the CPU but would be good to have the option to it. Thats why I asked for a recommendation.

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by stephenw10

                QAT is not that much of an advantage. Unless you're hitting a limit in crypto throughput it's not going to help you much. And and can only imagine that being an issue if you're passing all your traffic over a VPN?

                Additionally if you're running Plus IPSec-MB is as fast or faster for many cipher types.

                For a basic test try passing iperf3 traffic through the box between two interfaces and check the output of top -HaSP at the CLI while it passes.

                Then try sending that over a VPN and retest.

                S 1 Reply Last reply Reply Quote 0
                • S
                  sysadminfromhell @stephenw10
                  last edited by sysadminfromhell

                  @stephenw10 said in New CPU/Plattform REcommendation:

                  For a basic test try passing iperf3 traffic through the box between two interfaces and check the output of top -HaSP at the CLI while it passes.

                  direct connected with twp or just virtually (ETH0->EHT1 routing)?

                  EDIT: I guess around 38 GBits?

                  75c970b3-4617-4d07-8fae-83ed5a615f6a-image.png

                  stephenw10S 1 Reply Last reply Reply Quote 0
                  • w0wW
                    w0w @sysadminfromhell
                    last edited by w0w

                    @sysadminfromhell said in New CPU/Plattform REcommendation:

                    Supermicro X11ssh-TF

                    https://www.supermicro.com/en/products/motherboard/x11sdv-8c-tp8f

                    1 Reply Last reply Reply Quote 1
                    • stephenw10S
                      stephenw10 Netgate Administrator @sysadminfromhell
                      last edited by

                      @sysadminfromhell said in New CPU/Plattform REcommendation:

                      I guess around 38 GBits?

                      That can't be right unless I'm missing something. Those are all 10G NICs?

                      I guess that could be right if you have 40G NICs and if so that's a huge number!

                      But more likely you tested between the devices on pfSense itself? You want to test between two other host devices on two subnets routed through pfSense.

                      S 1 Reply Last reply Reply Quote 0
                      • S
                        sysadminfromhell @stephenw10
                        last edited by

                        @stephenw10 yea I only got 10G NICs. I tested on the host itself for today to get the setup right. Tomorrow I am going to test with my 2 Servers which are capable of doing 10G via SFP+

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.