binhex Posted December 12, 2017 Share Posted December 12, 2017 Let me kick this off with a very cheap and cheerful xmas presents for myself this year:- 1 x Aluminum USB 3.0 Hard Disk Drive Enclosure for 2.5 Inch/ 3.5 Inch SATA HDD and SSD - replaces existing caddy connected to my nuc 7the gen for recording dvb-t tv, yeah i know its boring :-) https://www.amazon.co.uk/gp/product/B00RCJ54BC/ref=oh_aui_detailpage_o00_s00?ie=UTF8&psc=1 1 x Jabra Move Wireless Bluetooth On-Ear Headphones - going to be used for late night movie watching, slightly more exciting but still practical. https://www.amazon.co.uk/gp/product/B00NHSFWG4/ref=oh_aui_detailpage_o01_s00?ie=UTF8&psc=1 you guys getting anything good? Quote Link to comment
wgstarks Posted December 12, 2017 Share Posted December 12, 2017 pfSense router- https://aliexpress.com/s/item/32825684280.html?trace=storeDetail2msiteDetail Quote Link to comment
binhex Posted December 12, 2017 Author Share Posted December 12, 2017 7 minutes ago, wgstarks said: pfSense router- https://aliexpress.com/s/item/32825684280.html?trace=storeDetail2msiteDetail thats nice!, not a bad price either, so you will be doing a traditional install of pfsense on this i guess right, no docker? Quote Link to comment
wgstarks Posted December 12, 2017 Share Posted December 12, 2017 44 minutes ago, binhex said: so you will be doing a traditional install of pfsense on this i guess right, no docker? Right. And if I work things right, I should have a good excuse to buy some new AP’s later in the new year.? Quote Link to comment
raidserver Posted December 12, 2017 Share Posted December 12, 2017 (edited) Ubiquiti airCube AP Qotom Q330G4 Mini PC pfSense firewall Edited December 12, 2017 by raidserver Quote Link to comment
PSYCHOPATHiO Posted December 12, 2017 Share Posted December 12, 2017 Noctua NH-D15 SE-AM4 USB-C to HDMI Adapter Samsung 960 EVO 1TB Samsung 32GB USB 3.0 Flash Drive and other minimal accessories Quote Link to comment
ljm42 Posted December 12, 2017 Share Posted December 12, 2017 I bought my present early I got a QOTOM-Q355G4 (3607 passmark Core I5, 8G Ram, 120G SSD). If I were doing it again I'd save a little and get a smaller SSD. I tried buying from AliExpress, but they wanted a scan of my drivers license to prove who I was?!? I wasn't willing to give them that, so I bought it from Qotom's Amazon store instead. Cost an additional $15 or so, but definitely worth it. I had planned on using pfSense, but was turned off after finding out you have to pay $99/year to access the manual. And their forums weren't too friendly either. I went with OPNsense and have been very happy so far. Currently I am using my old ASUS router as an AP, but I've lost some functionality since it doesn't support VLAN tagging on the guest network. My next purchase will be two smoke-detector style APs, deciding between Ubiquiti and Zyxel. Quote Link to comment
unevent Posted December 12, 2017 Share Posted December 12, 2017 2 minutes ago, ljm42 said: I bought my present early I got a QOTOM-Q355G4 (3607 passmark Core I5, 8G Ram, 120G SSD). If I were doing it again I'd save a little and get a smaller SSD. I tried buying from AliExpress, but they wanted a scan of my drivers license to prove who I was?!? I wasn't willing to give them that, so I bought it from Qotom's Amazon store instead. Cost an additional $15 or so, but definitely worth it. I had planned on using pfSense, but was turned off after finding out you have to pay $99/year to access the manual. And their forums weren't too friendly either. I went with OPNsense and have been very happy so far. Currently I am using my old ASUS router as an AP, but I've lost some functionality since it doesn't support VLAN tagging on the guest network. My next purchase will be two smoke-detector style APs, deciding between Ubiquiti and Zyxel. $99 to access the manual? You mean the subscription for paid support? There are multiple books available (even at your local library) for pfsense and their forum is usually all you ever need. It is free software, they have to pay the bills somehow. Quote Link to comment
Greygoose Posted December 12, 2017 Share Posted December 12, 2017 Samsung gear S3 smart watch Another 8tb Contemplating a new keyboard. Probably another Unraid license now I somehow taken the route to setting up a second system ? Quote Link to comment
ljm42 Posted December 12, 2017 Share Posted December 12, 2017 14 minutes ago, unevent said: $99 to access the manual? You mean the subscription for paid support? I mean the "pfSense Gold Subscription" which is required to access the "pfSense Book" but specifically does not get you any kind of support. https://www.netgate.com/our-services/gold-membership.html Quote Link to comment
wgstarks Posted December 12, 2017 Share Posted December 12, 2017 2 minutes ago, ljm42 said: I mean the "pfSense Gold Subscription" which is required to access the "pfSense Book" but specifically does not get you any kind of support. https://www.netgate.com/our-services/gold-membership.html Right. The paid support packages are much more expensive. I haven’t had any issues with the user forum though. They have seemed very helpful and I’m pretty much a total noob when it comes to firewalls. Experiences are bound to vary though I guess. Quote Link to comment
unevent Posted December 12, 2017 Share Posted December 12, 2017 (edited) 7 minutes ago, ljm42 said: I mean the "pfSense Gold Subscription" which is required to access the "pfSense Book" but specifically does not get you any kind of support. https://www.netgate.com/our-services/gold-membership.html Ahh, Gold membership...well worth the money, IMO, if need that kind of support. Edit: Some of their forum members can be intimidating, but there is a lot of expertise available there and most likely any question outside of something completely unique has already been answered. Edited December 12, 2017 by unevent Quote Link to comment
unevent Posted December 12, 2017 Share Posted December 12, 2017 Picked up early present the other day, Ryzen 7 1700 and ASRock X370 Taichi to replace ancient Phenom II X4 940. Quote Link to comment
binhex Posted December 13, 2017 Author Share Posted December 13, 2017 18 hours ago, raidserver said: Ubiquiti airCube AP Qotom Q330G4 Mini PC pfSense firewall hmm i sense a lot of love for pfsense (no pun intended hehe), im a bit afraid to find out exactly what it can do for me over a decent router, cos i know if it looks good i will HAVE to set one up, the inner geek in me is too strong, i....can't.....resist Quote Link to comment
wgstarks Posted December 13, 2017 Share Posted December 13, 2017 2 hours ago, binhex said: hmm i sense a lot of love for pfsense (no pun intended hehe), im a bit afraid to find out exactly what it can do for me over a decent router, cos i know if it looks good i will HAVE to set one up, the inner geek in me is too strong, i....can't.....resist If you decide to go for this make sure the cpu supports AES-NI. Quote Link to comment
Greygoose Posted December 13, 2017 Share Posted December 13, 2017 3 hours ago, binhex said: hmm i sense a lot of love for pfsense (no pun intended hehe), im a bit afraid to find out exactly what it can do for me over a decent router, cos i know if it looks good i will HAVE to set one up, the inner geek in me is too strong, i....can't.....resist pfsense is amazing, i paired this with a unifi AP and netgear switch. The forums are not the best in terms of help, mainly as most questions have been answered and many of the knowledgeable are probably frustrated. However for someone like myself who does this for fun the questions are not always easy to understand and many members there lack the time to explain. A world apart to limetech forums, where everyone helps each other. Quote Link to comment
PSYCHOPATHiO Posted December 13, 2017 Share Posted December 13, 2017 (edited) On 12/12/2017 at 9:41 PM, ljm42 said: were doing it again I'd save a little and get a smaller SSD. if your planning to use squid, its recommended to use a minimal of 60GB for caching. I'm using a 64GB ssd Edited December 13, 2017 by PSYCHOPATHiO Quote Link to comment
raidserver Posted December 13, 2017 Share Posted December 13, 2017 10 hours ago, binhex said: hmm i sense a lot of love for pfsense (no pun intended hehe), im a bit afraid to find out exactly what it can do for me over a decent router, cos i know if it looks good i will HAVE to set one up, the inner geek in me is too strong, i....can't.....resist Received the mini pc this evening. It's got it's quirks already. Couldnt get into the bios no matter what I tried, i planned on re-seating the CPU with mx4 so after that I unplugged/reconnected the mobo battery, this "fixed" the bios key not working lol Doesn't seem to like my usb keyboard connected prior to boot only after booted. I used efi shell to flash the firmware found on pfsense forum which has some intel me removed. Now pfsense usb installer has hung on install. Exactly what I signed up for ? Quote Link to comment
JonathanM Posted December 14, 2017 Share Posted December 14, 2017 14 hours ago, binhex said: hmm i sense a lot of love for pfsense (no pun intended hehe), im a bit afraid to find out exactly what it can do for me over a decent router, cos i know if it looks good i will HAVE to set one up, the inner geek in me is too strong, i....can't.....resist Depends what routers you call "decent". If your decent router has an MSRP over ~$500, then pfsense probably won't do a whole lot more for you. If you are calling any mid - high range consumer router decent, then pfsense has much more to offer, not least of which is potential CPU power for traffic shaping, analysis, VPN throughput, multiple redundant WAN sources, proxy servers, caching, pretty much anything the multi thousand dollar corporate routers do. Then again, if you only have access to 5Mbps download and 512Kbps up on a DSL line, pfsense probably holds little appeal. If you have symmetrical Gbps WAN, then not running pfsense or some other capable router software on a high power platform is criminal. Quote Link to comment
TUMS Posted December 14, 2017 Share Posted December 14, 2017 hehe, yeah that's basicly why i've never messed with it. The fastest internet speed I can get around here is 9mbps. I'm running a Asus rt-n16 router with shibby tomato. No need for much else.. Quote Link to comment
binhex Posted December 14, 2017 Author Share Posted December 14, 2017 11 hours ago, raidserver said: Now pfsense usb installer has hung on install. Exactly what I signed up for ? im not sure if you're being sarcastic, if you aren't then your idea of fun and mine are a bit different Quote Link to comment
binhex Posted December 14, 2017 Author Share Posted December 14, 2017 7 hours ago, jonathanm said: Depends what routers you call "decent". If your decent router has an MSRP over ~$500, then pfsense probably won't do a whole lot more for you. If you are calling any mid - high range consumer router decent, then pfsense has much more to offer, not least of which is potential CPU power for traffic shaping, analysis, VPN throughput, multiple redundant WAN sources, proxy servers, caching, pretty much anything the multi thousand dollar corporate routers do. Then again, if you only have access to 5Mbps download and 512Kbps up on a DSL line, pfsense probably holds little appeal. If you have symmetrical Gbps WAN, then not running pfsense or some other capable router software on a high power platform is criminal. Decent for me a business class router, not talking top dollar stuff but i got a half decent router that has rock solid performance for my current line (ADSL 20Mb/s dl 1Mb/s ul), i guess this could change though if i switch to fibre, which i have been thinking about recently, so who knows maybe the router wont be able to cope as well when i up the speeds to 60 Mb/s dl, i shall see eh. I think the only additional functionality i would like to get out of pfsense is probably proxy cache, pi hole type functionality (does it do this?), and maybe QoS. Quote Link to comment
unevent Posted December 14, 2017 Share Posted December 14, 2017 (edited) 5 hours ago, binhex said: Decent for me a business class router, not talking top dollar stuff but i got a half decent router that has rock solid performance for my current line (ADSL 20Mb/s dl 1Mb/s ul), i guess this could change though if i switch to fibre, which i have been thinking about recently, so who knows maybe the router wont be able to cope as well when i up the speeds to 60 Mb/s dl, i shall see eh. I think the only additional functionality i would like to get out of pfsense is probably proxy cache, pi hole type functionality (does it do this?), and maybe QoS. Caching proxies are really not as beneficial these days given the large Internet pipes, even your 20/1. They slow the Internet experience because you are constantly working from the cache by writing to/checking if exist/reading from disk, even with SSD. The Squid package in pfsense is what you would use for the transparent proxy which will proxy non-encrypted traffic. Not much these days is non-encrypted so benefit varies. You can do encrypted traffic cache proxy by configuring certificates you install on all client devices, but headache if you have many devices. There is another way to do encrypted caching without certificates, but can give some browsers/devices fits. It used to be good for caching Windows update stuff, but MS changes delivery and becomes unreliable and you are always having to tweak the filters to capture the updates to cache. The QoS is no where near as simple to configure as one would have experienced with Toastman Tomato. There are books, videos, etc. on it though. Pi hole (ad blocking) can be done with pfblockerNG and works extremely well, add Snort for IDS/IPS. Edited December 14, 2017 by unevent Quote Link to comment
DZMM Posted December 14, 2017 Share Posted December 14, 2017 12 hours ago, binhex said: Decent for me a business class router, not talking top dollar stuff but i got a half decent router that has rock solid performance for my current line (ADSL 20Mb/s dl 1Mb/s ul), i guess this could change though if i switch to fibre, which i have been thinking about recently, so who knows maybe the router wont be able to cope as well when i up the speeds to 60 Mb/s dl, i shall see eh. I think the only additional functionality i would like to get out of pfsense is probably proxy cache, pi hole type functionality (does it do this?), and maybe QoS. I've got a adsl connection and the traffic shaping is a life saver - means the right services get bandwidth when they need it, and p2p, Usenet etc when they don't. Having full control over traffic is a big plus as well e.g my son got a Google mini for his birthday at the weekend and being able to work around not enabling upnp to get working was very satisfying. Quote Link to comment
DZMM Posted December 14, 2017 Share Posted December 14, 2017 6 hours ago, unevent said: Caching proxies are really not as beneficial these days given the large Internet pipes, even your 20/1. They slow the Internet experience because you are constantly working from the cache by writing to/checking if exist/reading from disk, even with SSD. The Squid package in pfsense is what you would use for the transparent proxy which will proxy non-encrypted traffic. Not much these days is non-encrypted so benefit varies. You can do encrypted traffic cache proxy by configuring certificates you install on all client devices, but headache if you have many devices. There is another way to do encrypted caching without certificates, but can give some browsers/devices fits. It used to be good for caching Windows update stuff, but MS changes delivery and becomes unreliable and you are always having to tweak the filters to capture the updates to cache. The QoS is no where near as simple to configure as one would have experienced with Toastman Tomato. There are books, videos, etc. on it though. Pi hole (ad blocking) can be done with pfblockerNG and works extremely well, add Snort for IDS/IPS. Take care when using squid with a VPN as it can leak dns Quote Link to comment
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.