Physical or Virtual? A Silent 4x 2.5GbE Proxmox VE pfSense and OPNsense Box

Поділитися
Вставка
  • Опубліковано 30 чер 2024
  • We review another 4x 2.5GbE firewall solution to see if this Topton unit is any better than the Hnsun unit we reviewed previously. We also ask that important question: physical or virtual firewall. This time we show how to setup the system with either pfSense or OPNsense running firewall and VPN services (as well as HAproxy.) We also discuss how by using virtualizing and Intel i225 pass-through on this Intel J4125 firewall, one can run more services like Guacamole to access Project TinyMiniMicro nodes. We are going to put this in our new STH Mini PC series.
    STH Main Site Article: www.servethehome.com/topton-i...
    STH Main Site Article 2: www.servethehome.com/how-to-p...
    STH Merch on Spring: the-sth-merch-shop.myteesprin...
    STH Top 5 Weekly Newsletter: eepurl.com/dryM09
    STH Forums: forums.servethehome.com
    ----------------------------------------------------------------------
    Where to Find STH
    ----------------------------------------------------------------------
    STH Forums: forums.servethehome.com
    Follow on Twitter: / servethehome
    ----------------------------------------------------------------------
    Where to Find The Unit We Purchased
    ----------------------------------------------------------------------
    We are documenting where we purchased these units in the forums to keep one record. You can find that here for this unit: forums.servethehome.com/index...
    ----------------------------------------------------------------------
    Timestamps
    ----------------------------------------------------------------------
    00:00 Introduction
    01:21 External Hardware Overview
    04:21 Configuration and Pricing
    05:09 Internal Hardware Overview
    08:33 Power Consumption
    09:11 Virtualized or Physical pfSense and OPNsense on Proxmox VE
    18:56 Looking Toward the Next-Generation
    19:48 Key Lessons Learned
    20:57 Wrap-up
    ----------------------------------------------------------------------
    Other STH Content Mentioned in this Video
    ----------------------------------------------------------------------
    - Similar Hunsn J4125 and i225 Unit: • 4x 2.5GbE Intel J4125 ...
    - TinyPilot Raspberry Pi KVM: • TinyPilot Voyager Simp...
    - Dell OptiPlex 7080 Micro: • Dell OptiPlex 7080 Mic...
    - Dell OptiPlex 7070 Micro: • Dell OptiPlex 7070 Mic...
    - Dell OptiPlex 7060 Micro: • Is a 65W TDP CPU in 1L...
    - HP EliteDesk 800 G6 Mini: • HP EliteDesk 800 G6 Mi...
    - HP EliteDesk 405 G4 Mini: • Nice One! HP ProDesk 4...
    - HP EliteDesk 705 G5 Mini: • HP EliteDesk 705 G4 Mi...
    - HP Not Enabling AMD PSB: www.servethehome.com/hp-amd-r...
    - Lenovo PSB Locking Ryzen CPUs: • Yikes! Lenovo is vendo...
    - Lenovo M90q Tiny: • 10C/20T in 1L Lenovo T...
    - Lenovo M80q Tiny: • Lenovo ThinkCentre M80...
    - Lenovo IdeaCentre 5i Tiny: • No way! Lenovo IdeaCen...
    - Lenovo ThinkCentre M75q-2 Tiny (Gen 2): • Lenovo ThinkCentre M75...
    - Apple Mac Mini M1 10GbE Edition: • Apple Mac Mini M1 Gets...
  • Наука та технологія

КОМЕНТАРІ • 291

  • @Robbaz
    @Robbaz 2 роки тому +18

    Wonderful to see a video on this, got a J4125 4x i225 to pick up next week and N6005 4x i225 is a few weeks away "reviews seems to be dropping in on the mobile site", both from Topton. Feel somewhat secure in the purchase now.

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому +2

      I still have not gotten any of the newer N5105/ N6005 units at this point.

    • @ecotts
      @ecotts 2 роки тому

      Do they do the 6x port version on the N6005?

    • @Robbaz
      @Robbaz 2 роки тому +2

      @@ServeTheHomeVideo I've been waiting forever as well. But reviews probably means people are getting them.

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому

      I hear they are easier to get in China than to get shipped right now. Hopefully soon

    • @combine2180
      @combine2180 2 роки тому

      @@ServeTheHomeVideo mine just departed country of origin today according to tracking so about a 16 day lead time to get it shipped and another 30 to arrive with standard shipping on aliexpress for the 5105 model is what it looks like rn for USA.

  • @slip0n0fall
    @slip0n0fall 5 місяців тому +3

    Just want to say that even a year later this video really help me wrap my head around physical port mappings for virtualized FW/virtualization hosts. Something even nearly all the "tutorial" videos simply gloss over. I really appreciate this!

  • @cyruschan5507
    @cyruschan5507 2 роки тому +2

    Nice piece of content! I had virtual servers for networking and always want to consolidate & upgrade them. This shed light on how the set up will go.

  • @beauregardslim1914
    @beauregardslim1914 2 роки тому +36

    WAN port selection really needs to take failure modes into account. If there is some kind of "factory" reset, or if file system corruption deletes your port config file, you don't want your WAN cable going to the port that will ask for a DHCP address and allow logins.

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому +13

      Totally true. The virtualized model helps with this as it uses the default ordering

  • @BobHannent
    @BobHannent 2 роки тому +5

    I bought that one after the first video, installed pfSense on it, but I feel it's under utilised. I've been thinking of installing Proxmox on it, so this video is very pertinent

  • @yourfriendwill
    @yourfriendwill 2 роки тому +1

    just found your channel, you have the exact approach to computer hardware I've been looking for. so, thanks!

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому

      Thank you and welcome

    • @yourfriendwill
      @yourfriendwill 2 роки тому

      @@ServeTheHomeVideo I've subscribed and I'll probably work my way through your backlog this coming week, appreciate your good work and keep it up!

  • @Viking8888
    @Viking8888 2 роки тому +38

    You lay in bed vexing over virtualizing your router or not too???? And here I thought it was just me! 😉

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому +1

      :-)

    • @Viking8888
      @Viking8888 2 роки тому

      @@ServeTheHomeVideo Patrick, thanks for the video. I've been searching for a good small low power computer to run pfsense on for quite a while. These boxes are really nice just a bit pricey when you're on a tight budget. Time to save my pennies! 😉

    • @KeenanV
      @KeenanV Рік тому +2

      Im doing it right now!

  • @vonkruel
    @vonkruel 2 роки тому +4

    I run OPNsense virtualized under Proxmox, and personally I like it. I went the "one big server that serves all the things" route. Of course, if I need to do maintenance on the machine, all of it goes down during that. It's a reliable machine, though, and while I'm doing maintenance I don't need to be online. I appreciate being able to manage OPNsense as just another VM.
    These are interesting little boxes! Within these limitations, many people's needs for a server appliance could be met.

    • @strandvaskeren
      @strandvaskeren 2 роки тому +1

      Once you get a second server that problem goes away, just run your OPNsense vm on the server you're not currently doing maintenance on.

  • @arcadiosincero
    @arcadiosincero 2 роки тому +5

    I set up the firewall protecting my Proxmox VM cluster as a VM running on that cluster. I was having second thoughts about that decision because it seemed like I'd run into an issue where I wouldn't be able to manage the cluster remotely if something happened to it because the firewall was one of the VMs on that cluster. However, that decision was reaffirmed a few weeks back when something happened to the host the firewall was living on. I couldn't get into my cluster remotely, and I was like "oh no ... this eventual nightmare has finally come true". But then, about 5 minutes later the firewall came back up because Proxmox migrated it to another host for me. I was pretty impressed and I was happy with my decision to have made it a VM after that.

    • @bjornarsimonsen7592
      @bjornarsimonsen7592 Рік тому

      I didn't know automatic migration was a thing in Proxmox. That's really cool!

  • @KSJAFN
    @KSJAFN 2 роки тому +6

    Bought a machine that looks physically similar to this a couple of years back with a Celeron J1900. It's a great little firewall for home which was very cheap uses hardly any power - but like you, I find the RAM and SSD a bit of a worry (they're branded "Kston"). My decision to put the LAN on interface 0 and the WAN on interface 3 will from now on keep me awake at night.

  • @DmnkRocks
    @DmnkRocks 2 роки тому +4

    it always depends.... as long as your virtualization is performant enough, there is no problem with running virtual. but you need to consider, your infrastructure should be solid enough to avoid problems (like multiple hypervisors, vMotion enabled or better yet - a virtual HA with both vFirewalls on different Hypervisors)

  • @tokyotexture
    @tokyotexture Рік тому +6

    I bought one of the 1Gbps variants off of Alibaba, and the SSD died about a year in, so definitely a valid concern to call out.

  • @gowinfanless
    @gowinfanless Рік тому +4

    Very impressive video review,actually this model is our first generation which is stable but big.We have developped this router to the third generation,pocket size with 3*2.5Bge+ dual 10.0Gbe port

  • @justinnamilee
    @justinnamilee 2 роки тому +1

    I won't go back from virtual... snapshots, simple remote console access, adjusting the hardware on the fly, so many benefits for me!

  • @andrewvarey2027
    @andrewvarey2027 2 роки тому +1

    Very informative like it . Keep doing great videos

  • @ryanblue4204
    @ryanblue4204 2 роки тому +8

    FYI- the reason pfsense/opnsense appear to consume all the ram you get it is because BSD doesn't have the qemu-guest-agent driver that reports memory usage back to the hypervisor like most Linux instances do. Proxmox just sees that the OS has reserved all that memory even though it may just be being used for caches or unused inside the instance. Trust what the pfsense ui tells you, not proxmox. It'll run fine on 2-4gb for most use cases

    • @rudyNok
      @rudyNok 6 місяців тому

      I run pfSense in Proxmox with 512 MB for a few years now, no problem :)

  • @pythonprofreak7522
    @pythonprofreak7522 2 роки тому +3

    Good review!

  • @chromerims
    @chromerims 3 місяці тому

    To be or not to be [virtual], that is the question. While an older video now, regardless I find myself here.
    Excellent video👍, awesome channel, thank you. 17:10 -- STH _unblocked_ on my pihole.
    Testing on N100 C[heap]PU, by which I mean fooling/playing around.
    Kindest regards, neighbours and friends.

  • @TerraMagnus
    @TerraMagnus 2 роки тому +16

    Just bond all the NICs and use VLAN tags for LAN, WAN, etc. When you're virtualizing your firewall anyway, this just works.

    • @TerraMagnus
      @TerraMagnus 2 роки тому +1

      @@sirsean1227 so informative.

    • @rodrigocsouza8619
      @rodrigocsouza8619 Рік тому

      Do you know any issues when running multiple VLANs in that scenario? I'm testing pfSense at my home lab, running into a VM over Proxmox and even though I have, initially, set firewall rules allowing full communication between the VLANs, I'm not even able to ping between the networks.

  • @alfblack2
    @alfblack2 2 роки тому +1

    sweet. another question in my mind answered. Thx.

  • @MatthewHill
    @MatthewHill 2 роки тому +11

    Been virtualizing my firewall (OPNsense) on my "main" homelab server for about a year now. I'm pretty happy with it, and the box overall has enough horsepower that I can pretty much dedicate as many resources as I want to the firewall should performance be an issue. My worry is that if anything happens to that server--it is basically a pile of used enterprise parts I got off ebay--all my internet connectivity goes away.

    • @HydrarDraconis
      @HydrarDraconis 2 роки тому +3

      I'm planning moving my homelab to virtualized pfsense too, my plan to counter that is to run the VM with proxmox HA + replication, and internet vlaned to 2 hosts, allowing relatively transparent failover if any of my gear fails when I'm not home

    • @MatthewHill
      @MatthewHill 2 роки тому +1

      @@HydrarDraconis Hmm that's an interesting idea. I may try that.

    • @HydrarDraconis
      @HydrarDraconis 2 роки тому +2

      @@MatthewHill Just remember to have at least 3 nodes, or add a qdevice for reliable quorum in the HA cluster and it seems to fail over fine in my limited testing

    • @MatthewHill
      @MatthewHill 2 роки тому

      @@HydrarDraconis it's a homelab. It hasn't got two nodes, let alone three. :-)

    • @jay9404
      @jay9404 7 місяців тому

      I'm about to purchase the n100 version of this box. Now that a year has passed since your comment, how's the virtualized firewall been working out? If you could do it again, would you go baremetal?

  • @denvera1g1
    @denvera1g1 2 роки тому +7

    The cooling on this case would probably be able to cool the Intel Core U or AMD U series processors if limited to 15-20w average

  • @interceptor001
    @interceptor001 2 роки тому +1

    I had a problem using proxmox + pfSense and suricata with it. I don't know why but using ESXi solved that issue. Also CPU utalz. is 10% lower when assigning 4 instead of 2 cores.

  • @eazysnatch
    @eazysnatch Рік тому +3

    Awesome videos, buddy i love all of them. Just to say, snapshots are not backups every snapshot will decrease performance, so we use them before changes/upgrades...etc after we know everything works and you can keep them for day / week then we delete them.

    • @rudyNok
      @rudyNok 6 місяців тому

      What do you mean by "every snapshot will decrease performance"? I don't get it.

  • @PeterZin
    @PeterZin 2 роки тому +1

    My N6005 unit was also taking like a month to be shipped. So I contacted them and they said they couldn't get n6005 atm because of Shanghai lock down. They said they have n5105 in stock. So I changed my order and it shipped same day.

  • @DK-hs3oz
    @DK-hs3oz Рік тому +1

    Tiny computers can be addicting, be careful. soon you may have 5 to 6 of the things; justifying your habit by the price/value of small size and power consumption. That said, I have a few. My latest has 6 ETH ports, the N5105 CPU (outperforms the j4125 by a good ways)., and DOES have 2 so-dimm slots. They exist! Shipping seems to be better now... but anything that crosses an ocean is a miracle of tech and you should be happy to get it at all.
    Nice review and some good information, many thanks.

  • @gjkrisa
    @gjkrisa Рік тому

    Man and I was stressing over going unraid or proxmox/ Truenas for a new board I bought then being like is 2.5 gig going to work since there both 2.5 gig glad this video tells me yes no prob but now I may not have enough 2.5 although this new board was more for doing data log for my fanless pfsense play with vms and serve video backups. And possibly Learn new stuff to get a job I could grow more in.

  • @axn40
    @axn40 2 роки тому +1

    I am actually watching this vidéo in my bed!😅 Great guide! Thanks

  • @DragonReborn100
    @DragonReborn100 2 роки тому +2

    I did buy the barebones version of this on Aliexpress in Black and got Black! It did turn up quite quicky! I did have a 8Gb stick of Memory hanging around and i did purchase a named brand of SSD for install of pfSense for bare metal install. It does seem to be performing well for me, a home user. Does seem to be nice and cool as well. I never even thought of VM the pfsense. I may look into this in the future. Thanks P 🙂

    • @RazorSkinned86
      @RazorSkinned86 2 роки тому +3

      Ditto. I love these boxes. All the lock downs over in china has really fk'd up shipping times.

    • @vision8579
      @vision8579 2 роки тому

      I bought the same, barebones. I installed brand name ram and SSD. However, my unit seems to be a dud. Can't even boot into the BIOS reliably, sometimes yes and sometimes no (mostly no). After about 6 hours of messing with it, I gave up.

    • @gregglowery3452
      @gregglowery3452 2 роки тому

      I am curious about the memory slot. On the aliexpress website, all the specs (and even the picture of the motherboard) indicate 2 slots running in dual channel. So is it true that these devices have just one slot?

    • @DragonReborn100
      @DragonReborn100 2 роки тому

      @@gregglowery3452 Yes one slot only

  • @Bauanga
    @Bauanga Рік тому +3

    I would love a detailed guide for the network configuration in proxmox for a opnsence vm.

  • @skaltura
    @skaltura 2 роки тому +1

    bought one, let's see how well it actually works :)

  • @denvera1g1
    @denvera1g1 2 роки тому +5

    With a virtualzied firewall, PFSense can use USB based cellular modems, but it requires a virtual switch instead of direct hardware access.

    • @rudyNok
      @rudyNok 6 місяців тому

      I'm using an old android phone with USB tethering and direct hardware access. It works.

  • @maullah001
    @maullah001 Рік тому +2

    Where can I learn about the use of management port (and how to actually use it in real life situation)? Also, can the lan port for Proxmox be a virtula connection to pfsense rather than using a physical port?

  • @twistedridermike
    @twistedridermike 2 роки тому +1

    I am working on a virtualized firewall too. I want to virtualize so I can also run my docker swarm manager, reverse proxy and home assistant on that same machine. This will allow me to take all other machines up or down as I wish and know the workloads will remain up. Ran into a few issues: 1) IOMMU on E3-1200 V3 is a disaster, probably will virtualize ports from the i350T4s I installed. 2) I have an early 320GB SLC Fusion IO drive to park my web cache on, but recompiling the drivers for Proxmox 7.1 is proving difficult. 3) I realized four of the SATA ports on my Supermicro X9SCM-F are 3gb after I bought it... and the SSDs for the bulk storage. Fail. I would love to see more details about configuring a virtualized firewall with other VMs on a virtual switch in Proxmox.

  • @shephusted2714
    @shephusted2714 2 роки тому

    good content here - opnsense fork ftw! running a couple of these in HA config makes sense for smb - good mkt opp for small builders! i think that going fwd the prices for these small boxes will plummet - zen4 derivatives and nascent arm devices will exert mkt pressure on intel solutions - these small pc will also present good options for smb sector for scaleable cluster nodes - fast network and nvme will help adoption #netfs #galera

  • @combine2180
    @combine2180 2 роки тому +4

    Got my n5105 version on April 1st after your j4125 video and arrival estimates were 17th of May or later. It seemed like the sweet spot to me as it was going for ~215 usd after tax with no ram or ssd. Glad to see you did a review on the 4125 version. I wonder if the 6005 version will be powerful enough to run both a firewall and use the igpu to transcode for services like plex?

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому +1

      You are lucky!

    • @chuck1011212
      @chuck1011212 2 роки тому +3

      I am hosting Plex on a n5105 based system and with PlexPass enabling hardware transcoding, I have successfully hardware transcoded two 4k streams of this test file: jellyfish-400-mbps-4k-uhd-hevc-10bit.mkv and it did it just fine. (google the file name for the web site with many versions of test files available) Totally amazing from such a cheap and power efficient CPU. I wasn't doing that while the Plex server was virtualized though, my Plex transcode testing was done via Ubuntu server installed directly on the hardware.

    • @tjb_altf4
      @tjb_altf4 2 роки тому +1

      I've got an n6005 unit coming, ordered in March, but still not sent yet :(

    • @combine2180
      @combine2180 2 роки тому

      Just got mine today and am installing ram and storage now and I can confirm it has two ram slots on the n5015 version.

  • @nickoutram6939
    @nickoutram6939 2 роки тому +3

    You can't possibly expect a software stack to have the throughput of hardware, functionally though it sounds like a good plan.

  • @wayland7150
    @wayland7150 2 роки тому +1

    I'm in this dilemma too. I have a Proxmox already so I could do it. I am getting a new Internet service with just a modem and no router so I need a router. I want to save some money, at least for a month or two. So it looks like I will at least start with a virtual router and maybe get a physical one later.

  • @p4wk0r
    @p4wk0r 2 роки тому +8

    For flexibility I use all ports in lagg and use vlans for WAN, LAN, DMZ etc
    Waiting for 10G/SFP+ version ;)

    • @TerraMagnus
      @TerraMagnus 2 роки тому

      I know a lot of folks knee jerk against this but it works nicely.

    • @BobHannent
      @BobHannent 2 роки тому +1

      I have a spare 10G Mellanox card and I've been tempted to use a mini-PCIe to PCIe adapter on mine. It sounds like a horrible Frankenstein's Monster, but could be fun.

    • @AndrewFrink
      @AndrewFrink 2 роки тому

      just make sure you really trust your switch to keep the traffic separate, and that you can actually disable the mgmt interface on the WAN ports.

  • @jolness1
    @jolness1 2 роки тому +2

    lol the intro is amazing.
    “I’m in bed thinking: ‘Am I doing this right?’“ hehe

  • @SHREYAS1112
    @SHREYAS1112 6 місяців тому

    Is there a guide on how to set this all up from the beginning?
    I have just managed to install proxmox, and enable VT-d on a 4 port Intel i-226 N100 PC.
    Patrick mentioned how he prefers the 4 ports to be setup in a virtual environment, but how to actually set these up?
    I am new to all this. Any input would be splendid.
    Thank you.

  • @dangingerich2559
    @dangingerich2559 2 роки тому +2

    Maybe I'm just too inexperienced with Proxmox, or maybe I'm just too dim, but I don't see why one would want to use PCI passthrough for a pfsense or opnsense VM. I've done just fine with both ESXi and Hyper-V without passthrough, plus it allows for migration and HA. Is it for latency? Is there some hardware feature that just works way better with a physical NIC rather than a virtual NIC?

  • @DominicFlynn
    @DominicFlynn 2 роки тому

    There's also a version with, 2xUSB, 2xUSB3, 1xUSB-C (with 4kx60hz), HDMI2.0, DP1.4, TF-Card reader.

  • @wudchk
    @wudchk 2 роки тому +7

    I want to mention that there is also a SIM card slot, I'm going to test to see if I can add my 5G/LTE modem.

    • @dreamer9393
      @dreamer9393 2 роки тому

      Let us know, if it works

    • @wudchk
      @wudchk 2 роки тому

      @@dreamer9393 Will do, I have been busy with work. I'll crack it open tonight.

    • @PeterZin
      @PeterZin Рік тому

      @@wudchk I’m curious. does it work?

    • @wudchk
      @wudchk Рік тому

      @@PeterZin it does! I forgot to update this comment, thanks for the reminder

    • @PeterZin
      @PeterZin Рік тому

      @@wudchk Can I ask which specific modem you used? Any extra steps? I'm totally new to Proxmox and I can't get it to see my intel ax210 wifi card. I wanna create additional wireless wan in pfsense.

  • @LampJustin
    @LampJustin 2 роки тому +7

    Just some stupid idea: I would really love to see a blog post of running a small kolla-ansible deployed OpenStack deployment on TinyMiniMicro. That would be sooo cool and really shouldn't be hard at all, one controller node (no ha to keep it simple), one network node with 2 ports (one port needs to be given to a ovs bridge if you don't want to tinker with Linux bridges and veth pairs) and a couple hypervisors. Oh my I know I'm dreaming but that would be siick

    • @handspiker1994
      @handspiker1994 2 роки тому

      I love to see that!
      When Project TinyMiniMicro started, I thought they were going to do more with it. Instead it's become "here we are looking at a slightly different node. It has the same features as XYZ and XYA".

    • @LampJustin
      @LampJustin 2 роки тому

      @@handspiker1994 yeah sadly I got to agree on that... I also wished they would explore some options you could do, like HCI with oVirt, Proxmox, XCP-ng, Kubernetes or even Cloudstack. The possibilities are endless

  • @enickel
    @enickel 2 роки тому +3

    18+ days also waiting for the shipping of my n6005 box! XD

    • @kenniltv
      @kenniltv 2 роки тому

      Ordered one a few days ago. Guess it will take a loooong time to arrive to Europe. Sad xD

  • @moonobservergilles5730
    @moonobservergilles5730 2 роки тому

    you can add one of those fans we put on a wood stove works with heat ? maybe would improve the cooling ?

  • @Jarek.
    @Jarek. 28 днів тому +1

    I'd love to see at least a basic security assessment - at least it's a *HEAP* unit from *CHINA* supposed to be used as your *FIREWALL* . Other than that - I'm sold to this idea of a virtualised FW.

  • @bastian433
    @bastian433 2 роки тому +2

    Nice review. I have a "Parttaker" i5 8350u unit that works really nice. It looks the same but black and with 6 ethernet ports. It has just 1 gbit ethernet ports though. I connected a USB 2,5 gbit adapter as well. It reaches about full speed with a samba share. Also works really well with virtualisation in proxmox. With a 1 tb msata ssd and an option for say a large 2,5 inch ssd it is quite a nice box. The 8350u does get pretty warm when you put it to work. While not really needed I eventually strapped a Noctua fan on top to keep it a bit cooler (so it does not clock down as much)

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому

      There is a 6-port J4125 version now, but things are taking so long to ship these days that I did not prioritize it. Maybe when the N5105/ N6005 units start to ship. Those have a big generational performance bump.

    • @Lukas-jh2uk
      @Lukas-jh2uk 2 роки тому

      @@ServeTheHomeVideo I was really lucky then. I order a 4 ports 2.5gbit N5105 unit (28th of March) after your first review video and have already received mine.
      Got the unit in less than 16 days from China to Germany with free shipping.
      I was really surprised how quick it went that I now have to wait on my locally order RAM and SSD.

  • @LampJustin
    @LampJustin 2 роки тому +5

    Hey Patrick, nice one as always ;) BTW have you checked out VyOS, I think it's great and I am pretty close to switching to it fully, but you know how it is to switch firewalls. It ain't done in a couple of minutes...

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому +7

      I looked at it some time ago. Perhaps it is time to have Rohit take a look at it this year.

    • @LampJustin
      @LampJustin 2 роки тому +1

      @@ServeTheHomeVideo oh yes that would be nice! It's gotten really good, been using it for wireguard and BGP for some time now!

    • @cyruschan5507
      @cyruschan5507 2 роки тому +1

      Curious on your experience with VyOS. How do you feel about the rolling release on the free tier on VyOS? Or are you paying and using LTS versions?

    • @LampJustin
      @LampJustin 2 роки тому +1

      @@cyruschan5507 yeah that's the only annoying thing.... I'm not paying for the stable release, but if and when I'm moving to trying building stable images with docker from source

  • @brodriguez11000
    @brodriguez11000 2 роки тому

    How well do these boxes do with IDS? Usually a lot slow down with everything running.

  • @fanshaw
    @fanshaw 2 місяці тому

    Or you could run vlans and have a host with a single nic. ;) In my opinion, its better to have two physical units for failover. If something goes wrong, and you aren't there to fix it, you can always get your SO to pull the power cord on the broken unit. I like to keep the absolutely critical systems isolated from nice-to-have services. I don't want to bring down my internet, DNS or DHCP because I was playing with my docker server and hit the wrong button.
    In this firewall's case, you might use virtualisation to isolate your firewall config from the hardware so you can swap hardware without updating the firewall config, rather than for adding more services. Or as mentioned, to have a quick failback without having to find a usb stick and a keyboard / screen to plug into the unit, which is located up in a cupboard...

  • @dominic0315
    @dominic0315 2 роки тому

    Hi! Is that right your box has a WLAN module and antennas? I have nearly the same setup as you do, Proxmox VE as hypervisor and a firewall/router VM running Linux, but for sure a different CPU, an Intel i5 (10th Gen). I hit an issue which the WLAN, without lossing signal with client (as seen from client side), but wouldn't able to have purposeful packet traffics (as evident by no ping response to either the VM's IP or external IPs). I have now renice-ed the hostapd to -20 (highest priority as the kernel) and also the VM process at PVE layer reniced to -20 and worked fine so far. I wonder whether you may able to have an experiment as well to verify process scheduling is the real issue? And do you have a better thought as to how to nicely tune it and be able to profile/debug the "dead period"? Thank you in advance!

  • @ZimTachyon
    @ZimTachyon 2 роки тому

    I'm going to get an alarm clock that wakes me up with "Hey Guys, This is Patrick from STH". I guarantee I'll double my productivity. :)

  • @YukikazeQ
    @YukikazeQ 2 роки тому +1

    been virtualizing pfsense and for the past couple years opnsense on proxmox for the past 7 years pcie passthroughing an intel i350-T4v2 into the vm and it has been great much nicer than having a dedicated machine for the sole purpose

  • @adam-user
    @adam-user Рік тому +2

    Hi! Great video, BTW, very high quality content! Do you have any thoughts on power-failure safety of a bare-metal pfSense vs a virtualized one? UPS-es can only hold up as much and once the power goes off, you want your router to boot up again all the time and every time. With a physical router that's a none-issue. What about pfSense on a bare metal or OPNSense on Proxmox?

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  Рік тому +1

      There is a box to check "Start at boot" or something similar in all hypervisors that you need to check if virtualizing a firewall.

    • @adam-user
      @adam-user Рік тому

      @@ServeTheHomeVideo Yep, once Proxmox boots it's easy. My concern is that while routers tend do have no issues with powering them off/on/off/on, Proxmox's ext4 filesystem might get corrupt if not shut down correctly. I think that probably a read-only fs mount would help, but I'm not sure if that even possible.

    • @RambozoClown
      @RambozoClown Рік тому

      @@adam-user Thats why your UPS sends out a shutdown signal before it keels over.

    • @adam-user
      @adam-user Рік тому

      @@RambozoClown Yep, I just don't like to rely on UPS signals to go through. But I understand your point. With a regular router, you can usually pull the plug as often as you want and the OS won't get corrupted. For example a read-only boot fs (the one that newer raspberry pi os supports) is a great solution, IMHO.

  • @reneb5222
    @reneb5222 2 роки тому +1

    Hi Patrick. I have the same one running very well. Got mine faster 😂. Have a awesome 🐣

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому +1

      I am just unlucky with these :-)

    • @reneb5222
      @reneb5222 2 роки тому

      Btw they are now selling it with the j5000 series.

  • @JasonsLabVideos
    @JasonsLabVideos Рік тому +1

    Patrick, have you come across any mini pc's that have SFP+ or dual 10gbe nics ? I'm looking to buy one for a VERY powerful firewall. Dream would be Xeon-D but the Higher end Atom's or i3's are good too.

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  Рік тому +1

      Maybe getting something this week that was supposed to be sent in August with SFP+

    • @JasonsLabVideos
      @JasonsLabVideos Рік тому

      @@ServeTheHomeVideo ohhhhhhh now my interests are perked!

  • @theophilusbassaw580
    @theophilusbassaw580 2 роки тому +2

    I would use pfsense/opnsense more if there is better cloud-init support. Being able to spin them up through terraform would be handy

    • @dfgdfg_
      @dfgdfg_ 2 роки тому

      I get most of the way with Ansible

  • @PedroLopez-yo7nr
    @PedroLopez-yo7nr Рік тому

    Hi I have been enjoying your videos. You mention a video that installing Proxmox and pfsense on the tiny 5105 router. I can’t seem to find it.
    Thank you. I order one through AliExpress.

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  Рік тому

      Hi Pedro,
      We usually do guides more for the main site like:
      - www.servethehome.com/topton-intel-j4125-4x-i225-fanless-virtualized-firewall-appliance-review-pfsense-opnsense-proxmox-ve/3/
      and
      - www.servethehome.com/how-to-pass-through-pcie-nics-with-proxmox-ve-on-intel-and-amd/

  • @TheChemisch
    @TheChemisch 2 роки тому

    I'd imagine it would be pretty easy to get unifi os running on proxmox? I haven't messed around much with proxmox to much since I can do everything I want visualized through arch and vfio passthrough. Does proxmox need dedicated cores? or is pretty flexible. With the j4125 currently I hit about 70% cpu with routing gigabit through wiregaurd. If it is pretty flexible like the KVMs I use on my arch install I think I should be good but reassurance would be nice. Probably will do it regardless because it sounds like fun.

  • @hcjkruse
    @hcjkruse 2 роки тому +1

    Paying attention. About to replace an Edgerouter. A switch of the product line literally melted.

  • @OVERKILL_PINBALL
    @OVERKILL_PINBALL 2 роки тому +3

    I would use bare metal for the firewall and virtualize Pi_hole. I make an image of ther drive for DR. The image is small and quick to restore if needed.

    • @bcboncs
      @bcboncs 6 місяців тому

      I think I'm one of the few agreeing with you on bare metal firewall but how would you go about it? Like what Base OS would you use and does it have the ability to do a proxmox layer under the physical firewall and docker capabilities? I am leaning between openwrt and opnsense but want the downstream proxmox and docker functionality. Thanks kindly

  • @stormfox81
    @stormfox81 2 роки тому +2

    Tip: buy a 2TB ssd and use it for a virtual xpenology NAS. It will run like a beast

  • @auronarcher
    @auronarcher 2 роки тому

    I saw on the pics it has it showed a sim card slot, can you confirm if that is actually there? I would love to get one of these as a pfsense box with a 4g sim for failover all in one neat bundle.

  • @most-average-athelete
    @most-average-athelete 11 місяців тому

    18:47
    what is the "VM3 wifi controller"?
    does not pfSense do this already? I just bought a similar unit (shipping on the way) and was planning to add an M2 wifi board (it has two m2 slots both M-key)

  • @AlexandreAlonso
    @AlexandreAlonso 2 роки тому +1

    what is the maximum routing throughput of the device if all port use to route network packages?

  • @iBrandooon
    @iBrandooon Рік тому +1

    I virtualized pfsense on my 5950x on esxi, it auto starts on boot so no downtime! Setting up the VLANs was kinda pain but everything is set

  • @iulianch
    @iulianch Рік тому

    ​ @ServeTheHome Can you please share how you set up the storage of the server for all the vm? thank you very much

  • @AndrewFrink
    @AndrewFrink 2 роки тому

    Can we directions (or an RPZ file) for unblocking ads on the STH mainsite?

  • @gnuzmaz8961
    @gnuzmaz8961 11 місяців тому

    After few years of usage similar router on Celeron J1900, im switching to Dell mini-PC with old i7. No enough power for running few virtual machines working properly.

  • @opticalip1
    @opticalip1 2 роки тому +3

    Been using this for this exact purpose for a few years now. Got a i3-4030U w/ 8GB ram, threw in a good ssd and run pfsense + a few containers.
    Never had an issue and get great performance. Also got the unit on amazon for around $250-300

    • @RobertoCarlos-tn1iq
      @RobertoCarlos-tn1iq 2 роки тому +1

      really? care to share a link to your purchase so we can get the same unit with the 2.5gb ports?

    • @johnknightiii1351
      @johnknightiii1351 2 роки тому

      @@RobertoCarlos-tn1iq pretty sure the model that has the 4030u only has gigabit ports. I think he was just saying this is what he did with that box, not thst he has a box with 2.5gb ports

  • @newchannel-gl4ez
    @newchannel-gl4ez 3 місяці тому

    Can you show us how to do these things? Im wanting to learn and setup my own home setup but it sounded like this could also be done for business? Im dreaming of running my websites from my own home server which is why im wanting to learn all of this

  • @shephusted2714
    @shephusted2714 2 роки тому +1

    a better way to gain throughput is to divide up ports via bonding or bridging - 2 heads is better than 1 but really serious folk will be looking for fw devices with 10g (at least) - 100g potato routers are around the corner and only a couple hundred bucks more per port for 4x perf, the mikrotik 100g 800 buck switch looked sweet and prices on commodity small 100g routers should drop as well going forward #paper launches #paper tiger #sonic #software defined networks #lcd

  • @jrader
    @jrader 2 роки тому

    At 18:49 I think you mean for the graphic to say that you're using ETH2 as your pfSense LAN and ETH3 as WAN. You've reversed them in the graphic.

  • @I4get42
    @I4get42 2 роки тому +1

    Looking for an opinion: Would it be worth using a USB gig NIC for management to have the high-speed NICs for LAN and WAN, or is relying on USB asking for trouble?

    • @wayland7150
      @wayland7150 2 роки тому +2

      USB for management is fine, what's to manage anyway once it's running. However I have a 2.5GBe USB NIC which is fast for about 100GB of traffic then it crashes. I don't know if this is typical but I'd can't trust it.

    • @harrisonbaxter9038
      @harrisonbaxter9038 2 роки тому

      I was thinking the exact same thing. I think I'll give it a try.

  • @Pabula
    @Pabula 2 роки тому +1

    Do you know if the N6005 version of your case from the same Aliexpress vendor also comes with a single memory slot? I ordered one but its been a month still hasn't shipped, so just wondering about the memory.

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому

      I ordered a second last night. Hoping one ships so I can tell you for sure

    • @Pabula
      @Pabula 2 роки тому

      @@ServeTheHomeVideo You seem like me, cant wait to get it. I feel the N6005 is going to go rounds on the Netgates 6100 Atom 3358. If you want, can you do a yt short when either of your N6005 ships, i might cancel and move to where you placed your second order.

    • @Pabula
      @Pabula 2 роки тому

      @@ServeTheHomeVideo Mine just shipped today =), hope yours ships soon.

  • @danagoyette7932
    @danagoyette7932 2 роки тому

    How do they do with SQM (Cake) on OpenWRT? I'm currently using an HP T730 with an i350 NIC, but it uses something like 40 watts, so this might be better.
    Internet connection is 500 megabits; I doubt we'll get gigabit unless the price goes way down.

  • @denvera1g1
    @denvera1g1 2 роки тому +1

    4:25 IT usually takes ~3 months for my batteries to get here from AliExpress

  • @OsX86H3AvY
    @OsX86H3AvY 2 роки тому

    so i dont have one of these, never seen inside it or anything...but could there be another sodimm slot on the other side of the mobo, sorta like how some laptops would have one slot on the bottom and one under the keyboard....is that possible? did you take the board out by chance and look on the opposite side of it? either way anything else interesting there?

    • @blkspade23
      @blkspade23 2 роки тому

      It looks fairly flush other than the inside of the chassis being the heatsink for the CPU.

  • @ArthursHD
    @ArthursHD 11 місяців тому +1

    Those things are cheaper than ever :) N5105 bear bones box under 150€ I would get a reputable SSD localy.

  • @CoryAlbrecht
    @CoryAlbrecht 2 роки тому +1

    What do you think of the similar Celeron N5095 devices with the i225v3 ports? 15W TDP instead of 10W.

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому

      The Topton M6 we just did a video on with the N5105 used much more power

  • @lesfilanto
    @lesfilanto Рік тому

    I am virtually running sophos xg on proxmox on a dell R310. What type of limits would I see in using it. I am thinking of adding newer nic's. Right now on my 300 mb cable I generally get 360 mb or better. I have ids running and fiber is potentially coming soon to my address

  • @HuyLe-qc8jc
    @HuyLe-qc8jc Рік тому +1

    I am testing out a similar system based on the N5105 processor. Heat is a concern. At idle, the chassis is about 50C (122F) and the CPU core temp is 60C (140F). I am not sure how long these system will last running at these temperature continuously. If you are interested in buy these, I'd look for ones that have extensive fins to keep the system cool or go for ones with a fan.

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  Рік тому +1

      These CPUs have a Tjunction temp of 105C because they are more embedded not consumer parts

    • @abel4776
      @abel4776 Рік тому +1

      A commenter on another video stated that he took it apart and repasted the copper sink, dropped 20C. Also, activate some BIOS settings for power management and limiting wattage.

  • @stuartlunsford7556
    @stuartlunsford7556 2 роки тому +1

    What node are these network chips on? I know IO doesn't scale as well with smaller nodes, but I still think passive cooling would be more common if these are sub 12nm.

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому +3

      The J4125 is 14nm. The next-gen is 10nm. The i225's are 28nm.

    • @stuartlunsford7556
      @stuartlunsford7556 2 роки тому

      @@ServeTheHomeVideo Thanks for the easy knowledge! The future is looking cool lol.

  • @damzelfly
    @damzelfly 2 роки тому +1

    I saw they are selling the new model with Celeron N5105 and Pentium N6005 now. How would you think the performance difference compared to this unit with J4125? In terms of proxmox virtualization.

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому

      Likely better, but I have heard they are using more power. We have been waiting about a month for ours to ship and now have orders with multiple sellers

    • @damzelfly
      @damzelfly 2 роки тому

      Thanks for replying and have a nice holiday weekend!!
      I'm looking forward to the next review.

    • @ytmadpoo
      @ytmadpoo 2 роки тому

      @@ServeTheHomeVideo It will be interesting to see a review of the N6005 once you get yours. I ordered mine yesterday with an ETA for delivery stateside of May 8, so we'll see. Worth the wait - I'm updating from an old, huge Juniper SSG firewall and decided I've suffered enough with a second hand unit that's many years out of date (running the "interesting" ScreenOS). I'm excited to jump into the pfSense or OPNSense world.

    • @florianalbeck
      @florianalbeck 2 роки тому

      Can you provide a link please?

  • @lost4468yt
    @lost4468yt 2 роки тому +2

    If you virtualise it in a home network and use it as your router, how do you deal with accessing it if the pfSense or whatever VM crashes or fails to boot/work/etc?

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому

      First you can rollback snapshots/ backups. Second, you can get the VM console

    • @lost4468yt
      @lost4468yt 2 роки тому

      @@ServeTheHomeVideo But how do you get to it if your network is down? You would have to either do something like connect a laptop directly to the machine and setup the laptop as a gateway. Or you would have to connect a screen to the machine and fix the VM through the CLI.

    • @blkspade23
      @blkspade23 2 роки тому +2

      @@lost4468yt Your "network" won't actually be down. You'll lose services like DHCP, DNS and internet (connections from outside), but the host port would always be accessible and would (should) have a static IP address. As long as some physical connection exists with a switch to the hypervisor itself, you'd only have to set a static IP on whatever device you're managing from.

  • @patrickmacasinag1749
    @patrickmacasinag1749 Рік тому

    Hi, Im new with the proxmox. Do you have and step by step procedure to install proxmox then install the pfsense?
    Can I also access the promox gui thru the lan port of pfsense?
    Thank you.

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  Рік тому +1

      We do not have a step-by-step. The Proxmox VE and pfSense installers are basically just download and click through the install wizards. The pfSense on Proxmox VE setup is documented here which is the potentially trickier part: docs.netgate.com/pfsense/en/latest/recipes/virtualize-proxmox-ve.html
      On the LAN port of pfSense, you can, but usually we just have a dedicated Proxmox VE port on these for management since there are four ports. Two dedicated to pfsense (WAN/ LAN) one Proxmox VE dedicated management port, one Proxmox VE LAN port for VMs.
      I know that is not what you are asking for, maybe we will have someone on the team do a guide later this month.

  • @aihysp
    @aihysp 2 роки тому

    i just got mine the mail two SODIM Slots ,1090NP-12 VER 1.4
    not sure if got fooled or got a new iteration my board is blue
    and i dont see the intel chips you are talking about
    can you help me understand :)

  • @thisnthat3530
    @thisnthat3530 2 роки тому +1

    Does this work with a 32GB DIMM installed?

  • @thirdenvoqation7735
    @thirdenvoqation7735 2 роки тому +3

    I ended up buying one of these units from Protectli, I'd rather trust them than a no-name Chinese import. One other advantage, at least for me, is that it can come with Coreboot. Pay a bit more for the privilege though.

    • @florianalbeck
      @florianalbeck 2 роки тому +1

      But the Protectli don’t have 2,5 Gbit Nic

    • @thirdenvoqation7735
      @thirdenvoqation7735 2 роки тому +1

      @@florianalbeck I just realised I mis-typed and should have said I'd wait ( I'll end instead of I ended) but give it a few months and they'll most likely have it. I'd rather wait till there's a company I can trust for core infrastructure. The price difference is negligible as well.

    • @RobinCernyMitSuffix
      @RobinCernyMitSuffix 2 роки тому +2

      Funny enough: I got one of the exact same units that Protectli sells, directly from China. Protectli is basically just a reseller, and they add quite a bit of markup on top.

    • @thirdenvoqation7735
      @thirdenvoqation7735 2 роки тому

      @@RobinCernyMitSuffix I never said they wasn't, the main difference is that you can get CoreBoot as part of the build and deal wtih a European team if anything goes wrong. In other words customer service is better. That and when you order they arrive quicker, horses for courses.

  • @Jorvs
    @Jorvs 2 роки тому

    @6:00 there is a slim card can this be used for data or internet connection?

  • @ryannow
    @ryannow 2 роки тому +2

    Speaking of no name storage from China: I would be really hesitant to put ANY software that originated in that part of the world, (or better yet, that I didn't install myself) into production as the firewall in charge of securing and gatekeeping my entire network... I'd also be equally as cautious about checking over any NV storage hardware imported from Asia - simply because I have _personally_ ordered simple, basic, run-of-the-mill USB sticks on Ali, and when they arrived a couple of them were pre-loaded with what appeared to be legit rootkits - AKA free memberships for the whole family - welcome to the BotNet Club! 😅

  • @nickharvey5149
    @nickharvey5149 2 роки тому

    I might be being stupid, but where is the purchase link?

  • @NickG_
    @NickG_ 2 роки тому

    Can you do 802.3ad link aggregation with these?

  • @jannikmeissner
    @jannikmeissner 2 роки тому +1

    I'm curious, is there a rackmount version of something like this?

  • @sanjibstha8966
    @sanjibstha8966 2 роки тому +1

    I got the 4*2.5G ports, Celeron N5105 and tried installing ESXi 7.0.3 but there was an error - No Network Adapters were detected... Is there any solution for this issue?

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому

      Usually VMware has poor support for hardware. I have not tried that combo, but in the old days you would sideload drivers

  • @TheLazyJAK
    @TheLazyJAK 2 роки тому +1

    Is Adguard better than pi hole?

  • @be-kind00
    @be-kind00 2 роки тому

    I’m on an iPad and can’t see the notes for this video. I see them fine on my android phone and windows pc but what’s with the iPad UA-cam app? Same thing happens when using UA-cam app on Roku.

  • @eltreum1
    @eltreum1 2 роки тому +1

    I am looking to replace my MicroTik cloud router pro because I can't get a ping time anywhere lower than 80ms when the 100M raw connection gets 20-30s ping to same places. I need it for competitive gaming and streaming, no inbound services, just a simple NAT overload out for 4-5 devices.

    • @ServeTheHomeVideo
      @ServeTheHomeVideo  2 роки тому +2

      I made CS:Go Global Elite on my main and smurf account using a pfSense firewall

    • @bcboncs
      @bcboncs 6 місяців тому

      @@ServeTheHomeVideo nice! I played cs beta and now play cs2 lol that's where the cs suffix comes from in my 2 decade old name.
      What Base os would I need for openwrt or pfsense to be bare metal and can I layer proxmox and docker underneath it?