<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Build (or buy) VPN 100Mbps appliance?]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I found recently pfsense and I would like to substitute my actual router (Asus Rt-N16) with a pfsense router/firewall: I have following needs:</p>
<ol>
<li>4 gigabit ports (or more), 1 WAN and 3 LAN</li>
<li>100Mbps VPN (with Openvpn or L2TP/IPSEC)</li>
<li>50 users</li>
<li>1Gbit/s total throughput</li>
<li>2 USB ports</li>
<li>wireless b/g/n</li>
<li>Under $500/$600</li>
</ol>
<p dir="auto">Most restrictive it's VPN throughput (my actual router give me near 10Mbps with openvpn); my questions is:</p>
<p dir="auto">It's betters to buy an OEM appliance or build it from myself?</p>
<p dir="auto">In first scenario I found very few router (under $600), for example Hacom Mars Openbricks-M, in second scenario I have found only few articles about VPN thoughput (theoretical) but none real experience about CPU, RAM, NIC card, crypto card need and so on.</p>
<p dir="auto">DO you have some advice about first and second scenario (obviously for cheapest solution)?</p>
<p dir="auto">Thanks in advance</p>
<p dir="auto">Alex</p>
]]></description><link>https://forum.netgate.com/topic/32492/build-or-buy-vpn-100mbps-appliance</link><generator>RSS for Node</generator><lastBuildDate>Sat, 06 Jun 2026 10:27:18 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/32492.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 07 Apr 2011 12:10:03 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Build (or buy) VPN 100Mbps appliance? on Fri, 08 Apr 2011 14:53:37 GMT]]></title><description><![CDATA[<p dir="auto">No, it isn't supported.  Support is included in FreeBSD 8.2, so it might make it into pfSense 2.1.</p>
]]></description><link>https://forum.netgate.com/post/274260</link><guid isPermaLink="true">https://forum.netgate.com/post/274260</guid><dc:creator><![CDATA[jasonlitka]]></dc:creator><pubDate>Fri, 08 Apr 2011 14:53:37 GMT</pubDate></item><item><title><![CDATA[Reply to Build (or buy) VPN 100Mbps appliance? on Fri, 08 Apr 2011 14:19:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jasonlitka">@<bdi>jasonlitka</bdi></a>:</p>
<blockquote>
<p dir="auto">Unless you have a reason to filter your LAN traffic, if you want to do 1Gbit/s LAN-LAN then buy a switch, don't use multiple NICs in your firewall.  As to the 100Mbit/s VPN requirement, the Atom alone won't do it, though a high-end C2D can (something like a E8400 would be adequate).  I'm not sure about the D525 Atom+hifn, though my suspicion would be that it will fall short, probably in the 80Mbit/s area.</p>
<p dir="auto">EDIT: AES-NI support in FreeBSD 8.2 is going to make all these threads go away.  A chip like the Xeon W3680 in my desktop is capable of doing about 80Gbit/s of AES256 with AES-NI.  A newer "low-end" $200 chip like the i5-2300 can still do around half that.</p>
</blockquote>
<p dir="auto">Thanks,</p>
<p dir="auto">AES-NI seems a good solution, perhaps better than crypt card.</p>
<p dir="auto">Good CPU seems i5-2390T, low power (35W and perharps fanless) and good performance for $210 (but this CPU isn't avalaible at this moment).</p>
<p dir="auto">Sorry for my ignorance but AES-NI is supported with pfsense?</p>
<p dir="auto">Thanks</p>
]]></description><link>https://forum.netgate.com/post/274256</link><guid isPermaLink="true">https://forum.netgate.com/post/274256</guid><dc:creator><![CDATA[ciccio]]></dc:creator><pubDate>Fri, 08 Apr 2011 14:19:44 GMT</pubDate></item><item><title><![CDATA[Reply to Build (or buy) VPN 100Mbps appliance? on Thu, 07 Apr 2011 20:20:43 GMT]]></title><description><![CDATA[<p dir="auto">Unless you have a reason to filter your LAN traffic, if you want to do 1Gbit/s LAN-LAN then buy a switch, don't use multiple NICs in your firewall.  As to the 100Mbit/s VPN requirement, the Atom alone won't do it, though a high-end C2D can (something like a E8400 would be adequate).  I'm not sure about the D525 Atom+hifn, though my suspicion would be that it will fall short, probably in the 80Mbit/s area.</p>
<p dir="auto">EDIT: AES-NI support in FreeBSD 8.2 is going to make all these threads go away.  A chip like the Xeon W3680 in my desktop is capable of doing about 80Gbit/s of AES256 with AES-NI.  A newer "low-end" $200 chip like the i5-2300 can still do around half that.</p>
]]></description><link>https://forum.netgate.com/post/274146</link><guid isPermaLink="true">https://forum.netgate.com/post/274146</guid><dc:creator><![CDATA[jasonlitka]]></dc:creator><pubDate>Thu, 07 Apr 2011 20:20:43 GMT</pubDate></item><item><title><![CDATA[Reply to Build (or buy) VPN 100Mbps appliance? on Thu, 07 Apr 2011 19:13:19 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for your suggestions.</p>
<p dir="auto">My actual router (Asus RT-N16) it's fast but not so fast to get 1Gbps total throughput (including LAN to LAN) nor 100Mbps vpn.</p>
<p dir="auto">If I understand it's possible to reach 100Mbps vpn only adding crypto card (for example soekris vpn1401/vpn1411) but with Atom 525 it's adequate? (Hacom Mars openbricks-m with Atom D525 1,8GHZ with soekris vpn card it's $620).</p>
<p dir="auto">TIA</p>
]]></description><link>https://forum.netgate.com/post/274138</link><guid isPermaLink="true">https://forum.netgate.com/post/274138</guid><dc:creator><![CDATA[ciccio]]></dc:creator><pubDate>Thu, 07 Apr 2011 19:13:19 GMT</pubDate></item><item><title><![CDATA[Reply to Build (or buy) VPN 100Mbps appliance? on Thu, 07 Apr 2011 15:04:16 GMT]]></title><description><![CDATA[<p dir="auto">On your budget, it's probably more feasible if you build it yourself with one caveat - No Wifi-N on pfSense.  <br />
On the latter, you can re-use the RT-N16 as an overpowered access point (disable DHCP, hook up LAN port to pfSense LAN).</p>
<p dir="auto">1Gb/s of throughput is quite a lot with NAT turned on.  The Mars openbrick won't cut it.  Period.  And that's assuming 1Gb/s total throughput (i.e. inclusive of LAN to LAN routing both directions).  When you throw 100Mb/s of VPN in, just forget it.  The D525 simply won't make it.</p>
<p dir="auto">Considering that the Hacom Jupiter with C2D @ 2GHz only pushes about 70+Mb/s of VPN without the accelerator card…</p>
<p dir="auto">You're probably looking at 2.4GHz and faster Core 2 Duo as a minimum or add a VPN accelerator if you want to push that kind of throughput together with VPN at 100Mb/s (worst case scenario).</p>
]]></description><link>https://forum.netgate.com/post/274106</link><guid isPermaLink="true">https://forum.netgate.com/post/274106</guid><dc:creator><![CDATA[dreamslacker]]></dc:creator><pubDate>Thu, 07 Apr 2011 15:04:16 GMT</pubDate></item><item><title><![CDATA[Reply to Build (or buy) VPN 100Mbps appliance? on Thu, 07 Apr 2011 14:57:59 GMT]]></title><description><![CDATA[<p dir="auto">You won't get 1Gbit/s firewall throughput or 100Mbit/s of VPN out of that Atom D525.  I'm not sure that this is possible for $500.</p>
<p dir="auto">Do you really need that level of performance?  I find it hard to believe that your current Asus router could come anywhere near those numbers.</p>
]]></description><link>https://forum.netgate.com/post/274105</link><guid isPermaLink="true">https://forum.netgate.com/post/274105</guid><dc:creator><![CDATA[jasonlitka]]></dc:creator><pubDate>Thu, 07 Apr 2011 14:57:59 GMT</pubDate></item></channel></rss>