pfSense 2.7.0 Homelab 2.5Gb Router + 10Gb Networking!

Поділитися
Вставка
  • Опубліковано 31 січ 2025

КОМЕНТАРІ • 99

  • @gustavocadena5089
    @gustavocadena5089 Рік тому +10

    I can’t wait for more home network videos 😊

  • @Felix-ve9hs
    @Felix-ve9hs Рік тому +6

    1:51 If you're using pfSense, you really don't want to use SMT because it increases the likelihood that two routing threads will have to share a single CPU core, which will degrade performance.
    Using high clockspeed 4-, 8-, or 16-core CPUs without SMT will give you the best results of a pf based firewall. :)

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +2

      Great info! I didn't know that. Going to correct that tomorrow. 🙏

  • @buf0rd
    @buf0rd Рік тому +1

    It always feels good having extra parts.

  • @SupremeMortal
    @SupremeMortal Рік тому +2

    I use Linux-based OpenWRT as my router inside a Proxmox LXC container to obtain bare-metal throughput. Installation and upgrade aren't as intuitive as pfSense, but I see it as a worthwhile compromise to achieve maximum performance without needing another dedicated machine.

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +1

      I'm planning on installing a pretty high performance n2700 switch this weekend and have seen openWRT as an option. I've used it in the past but running routers in VMs should make for easy testing. Good idea!

  • @alexfischer9493
    @alexfischer9493 11 місяців тому

    got pfsense running my home!

  • @Anaerin
    @Anaerin 11 місяців тому

    I've got a HP DC5800 Desktop computer, with Core2Duo CPU and RTL8211 GBe card running pfSense 2.7.0 - It does the work that I need, including hosting, using my FTTH connection, but it's a bare metal device that only does routing.

  • @MM-vl8ic
    @MM-vl8ic Рік тому +1

    I use several Enterprise Add In Cards, which need airflow not typically available with a "gamer" case... I'm a fan of the older cases with side vent and the ability to have a fan(s) blowing on the PCIe slots.... significantly reduces the temperature of Add In Cards, Mellanox ConnectX-3 40/56Gb nics, Intel 10Gb nics, Raid/HBA controllers, PCIe NVMe cards/controllers (Supermicro) ETC...... also reduces noise.... the plastic "windows" can be modded also.....

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +1

      Great idea! I have metal bits and like making holes in things. Extra fans laying around also that could keep the connectx-2 cooler

  • @fritsonpetitfrere9038
    @fritsonpetitfrere9038 7 місяців тому +1

    Using a Netgate sg2100 as my router right now.

  • @KamiMountainMan
    @KamiMountainMan Рік тому +2

    I am not sure if we can achieve the same speeds or if the 10Gb is an option on these, but to save space ,electricity, maybe something like Protectli Vault is a good option. Also, I was wondering if we could use those Dell mini PCs and upgrade the NICs . I saw other UA-cam videos using those for the Proxmox server or home lab. Also, lots of Chinese mini PCs are right now you can buy at Amazon. In idle mode, many of those use less than 10Wh.

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +2

      Yeah even a more modern Intel would likely idle lower but once you put a 10G or 40G card in the ability to idle seems hindered drastically. I'll probably have to stick to some PCIe accessable format as I'm adding in a switch that will be the main backbone and expect to run a 100G card off this.

  • @HxgDan
    @HxgDan Рік тому +2

    Eager to see how the performance changes once it's virtualized. I have opnsense virtualized, and I can definitely tell there seems to be a bit of a performance hit when I'm really trying to max my throughput.
    Also - any plans for improving fault tolerance? That's the biggest downside I've experienced with virtualized opnsense. I once had a failure with a PCIe NIC, and that completely took me offline since all of the interfaces in opnsense were tied to that pcie passthru card. I've since moved to all virtualized interfaces, which has more performance bottlenecks, but I can migrate to another proxmox host rather quickly and pick back up from there, with almost zero downtime. This doesn't seem like a very talked about setup/situation, so I'm curious what others think about it.

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому

      Thanks will be measuring the impacts on latency and BW the best I can when the 2.5GB switch shows up. I'll then have 2 hosts with bridge interfaces able to use CARP failover is the plan. I hope to not have a serious performance hit can you specify more what you experienced?

    • @HxgDan
      @HxgDan Рік тому

      @@DigitalSpaceportI think you're going to avoid the issues I ran into if you're going the CARP failover route - I don't have a 2nd machine that I can throw another 2.5GbE NIC into so I have to rely on proxmox "HA" failing over using the same KVM, with all of the interfaces being virtualized in proxmox attached to the main linux bridge, and each VLAN having their own virtualized interface with the VLAN tag set in the KVM settings. With this setup it mostly works, but I lose the ability to use hardware offloading on the NICs, and there are some quirks I've yet to fix with how proxmox handles VLANs/ bridges/bonds. I went from being able to obtain ~2.2Gb/s over my LAN to only ~900Mb/s, so I think something is either negotiating wrong now, or there is some setting I've missed for link speed somewhere.

  • @traderpete007
    @traderpete007 11 місяців тому +1

    Does your cable provider allow for public IP or BGP? Getting decent IP address allocations at home is a major pain.

  • @CharlesM236
    @CharlesM236 4 місяці тому +1

    21:45 why are you testing your network inside a browser?

  • @HomeSysAdmin
    @HomeSysAdmin Рік тому +3

    That case is way too big for a pfsense build haha. I don't know if you plan to do any IDS/IPS, but if you do - you'll really want that CPU performance! Especailly at 1gbps+. That may also be a factor playing into whether you virtualize or not.

    • @HomeSysAdmin
      @HomeSysAdmin Рік тому +2

      Also that wattage you have there vs mine is making me want to build another lol. I tried to go as efficient as possible but still ended up at 35W. Of course, 10W of that is being eaten by the BMC/IPMI and I didn't want to give that up. Maybe another build will be in the works eventually - because... why not!

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +1

      The case is ridiculous 😆 but I'm hoping to get a ripping software VM in it along with a nginx reverse proxy lxc. I do plan on running the new suricata 7 package but it's not available in the repo yet. In checking the GitHub it looks like a lot of integration work for 7 is underway however currently.

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +2

      Yeah AMD doesn't idle down well vs Intel so that's a bit of a bummer. Pair of 100Gbit nics on the way and I'm working on my layout to have the sn2700 as the core switch, but just discovered the mikrotiks I have do not have high performing buffers and I'm hitting too many tx/rx pauses now. Funny that never happened with the older router but it was just pushing 1g connections.

    • @HomeSysAdmin
      @HomeSysAdmin Рік тому

      @@DigitalSpaceport Wow, I didn't even realize there was a v7 coming out. The list of new features looks fantastic - esepcially the improved vlan support to layer 3. It would be awesome to exclude or include certain vlans instead of the entire physical adapter. I always hated mine sitting there wasting CPU cycles/power scanning the traffic streaming from my security vlan to my blueiris VM (just the h264 streams). I eventually added a 2nd interface on the blueiris server to the security vlan to stop that from happening.

    • @HomeSysAdmin
      @HomeSysAdmin Рік тому +1

      @@DigitalSpaceport Regarding the power, make sure PowerD is enabled under System > Advanced > Miscellaneous. It didn't make much of a difference for me, but it might for you? I'm thinking my bios power management is working better but I'm not sure. I don't think 50W is bad at all for super high-performance routing/pfsense.

  • @michaelfragrances
    @michaelfragrances Рік тому +1

    Such serious equipment and a ping of 88 ms🤔

  • @ronwatkins5775
    @ronwatkins5775 Рік тому +1

    Using UDMPRO and USW-Pro-Aggregation for the 10G/25G ports.

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому

      Unifi has the best user experience I think hands down.

  • @jakeleo1857
    @jakeleo1857 Рік тому

    Good job sir 👏

  • @clij5202
    @clij5202 8 місяців тому

    I did pfSense in the past on ESXi but would not do it again. A dedicated (low energy) box of pfSense/OPNSense is the way I planned to go until I go some Ubiquiti stuff. But since the intra-VLAN routing (at 10Gbps) is not what I wanted I might go back to a dedicated router box.

    • @DigitalSpaceport
      @DigitalSpaceport  6 місяців тому

      I do like dedicated boxes also, but the HA setup I have for opnsense now is pretty damn good.

  • @iliakarpov
    @iliakarpov 7 місяців тому

    Seems like the CPU heatsink is mounted as an intake, while all of the case fans are mounted as exhausts. Wouldn't they be working against one another that way?

    • @DigitalSpaceport
      @DigitalSpaceport  6 місяців тому

      Its the weird fan mounted filter screens that old school case came with. I just went and checked you had me worried lol.

  • @TimRex.
    @TimRex. 2 місяці тому

    Quick explainer on the preference to install using BIOS mode rather than UEFI?

  • @visghost
    @visghost Рік тому

    I use 1U server, DFI SD 106 motherboard, celeron G4400 processor, 8GB RAM, Intel x520-D2 network card, Pfsense+ OS

  • @timothywilliams2887
    @timothywilliams2887 5 місяців тому +1

    I use OpenBSD PF

  • @CPR9969
    @CPR9969 Рік тому +1

    I have 1.5gb download and 960mb upload and I get the full service with my udm pro using pppoe

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому

      Does the udm pro use the 10gb sfp+ uplink to your ISP?

  • @unoptanio
    @unoptanio Рік тому

    Salve, ho visto che una volta installata la versione 2.7.0 CE (installato su PC assemblato) è possibile andare sul sito di netgate poi su pfSense+ Software Subscription.
    Vedo che è possibile l'aggiornamento gratuito alla versione PLUS per uso HOME (non commercial use) e per uso LAB
    Cosa conviene fare? che differenze ci sono? In rete leggo che in futuro i due prodotti PLUS e CE divergeranno sempre più...

  • @unoptanio
    @unoptanio Рік тому

    Salve,
    [installazione pfsense 2.7.0 su macchina fisica dedicata Intel I7-13700 con n.2 NVME da 1Tb]
    Nella scheda madre MSI che sto utilizzando, da Bios ho la possibilità di creare un volume Raid1 con i 2 dispositivi NVME.
    Questa soluzione è sconsigliata? ci sono dei motivi particolari?
    Conviene far gestire il raid1 direttamente a pfsense seguendo le impostazioni per la creazione del volume raid durante l'installazione? senza creare il volume raid dal Bios?

  • @unoptanio
    @unoptanio Рік тому

    Installando pfsense 2.7.0 da DVD su PC assemblato Intel, l'impostazione nel BIOS "Bios mode" è consigliabile impostarla in "CSM=compatibility support mode" oppure "UEFI" ?

  • @raywilcher1385
    @raywilcher1385 Рік тому

    What are you using to rip media to Plex?

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +2

      ARM is the best! Automatic Ripping Machine

    • @nikhilrups
      @nikhilrups 3 місяці тому

      @@DigitalSpaceport Hi, did you face any problems running ARM on Proxmox such as Blu-ray drive pass through etc. Since you said you use Makemkv and handbrake, how did you manage that on a Proxmox vm while your drives are connected to the sata ports on the MB?

  • @heyitsjel
    @heyitsjel Рік тому

    Honestly, just use a Mikrotik.
    Affordable; fast; insanely customizable/configurable; and power efficient.
    There's a bit of steep learning curve, but there's plenty of content out there to help you get started, and most of the community sites will likely have the answers you need.

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +3

      I have 2 mikrotiks switches and both exhibit concerning levels of buffer underrun resulting in high TX/RX pauses on 10gb connections.

    • @heyitsjel
      @heyitsjel Рік тому +1

      @@DigitalSpaceport can't say I've heard of that issue myself; what switch/s models are these? are they running SwitchOS or RouterOS?
      Could make for an interesting video :)

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +1

      @@heyitsjel They are a CSS326-24G-2S+ and a CRS305-1G-4S+IN running latest FW in switchOS. Yeah I have been testing now and learning with FLENT and man its good. Not easy to deploy a testbed setup but its very useful.

  • @unoptanio
    @unoptanio Рік тому +1

    Ciao! Pure io sto costruendo in questi giorni un nuovo firewall hardware Pfsense 2.7.0
    Per la scheda Realtek 2.5G RTL8125 c'è un nuovo driver aggiornato
    FreeBSD:14:amd64 Package ver: 198.00_3

    • @unoptanio
      @unoptanio Рік тому +1

      Non capisco perchè dalla shell di pfsense ritorna due versioni di driver differenti:
      pkg info -x realtek
      Return: realtek-re-kmod-198.00_3
      pkg search realtek
      Return: realtek-re-kmod-198.00_1

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому

      pkg info -x realtek
      ritorna per me
      realtek-re-kmod-198.00_1
      🤔

    • @unoptanio
      @unoptanio Рік тому

      @@DigitalSpaceport prova ad installare il nuovo driver dal sito

    • @unoptanio
      @unoptanio Рік тому

      @@DigitalSpaceport prova ad installare l'ultimo dal sito f r e s h port

  • @electronicparadiseonline2103
    @electronicparadiseonline2103 Рік тому +1

    Good comparison video. Me Likee.

  • @linearburn8838
    @linearburn8838 10 місяців тому

    It makes sence when you include tercota ips and crap like that

  • @grantoutou
    @grantoutou Рік тому

    The same in a rack u1?

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому

      I dont follow the question here. Maybe rephrase that?

    • @grantoutou
      @grantoutou Рік тому

      @@DigitalSpaceport yeah sorry, you use a simple PC case, can you put exactly the same but in a rack 1 or 2 u server case

  • @ACSMUSICnTV
    @ACSMUSICnTV 9 місяців тому

    Yo is all this at your house?

  • @Phil-D83
    @Phil-D83 11 місяців тому +1

    Opnsense here

    • @DigitalSpaceport
      @DigitalSpaceport  11 місяців тому

      I'm leaning this way. Have been reading some things online that make me wonder about pfsense direction

    • @Phil-D83
      @Phil-D83 11 місяців тому +1

      @DigitalSpaceport I kept having issues with crashes,etc with pfsense about 2+ years ago. Tried opnsense and never went back. They need to update their OpenSSL to v3. Pfsense is going to go the way of ddwrt with the changes they made...

    • @DigitalSpaceport
      @DigitalSpaceport  11 місяців тому

      I'll give it a try this week, thanks! SSLv3 is important for me and I have had pfblocker issues like crazy. WAF drastically lowered when website mysteriously break.

  • @fhuzy
    @fhuzy Рік тому +1

    Damn have your own server room in your house...heating and cooling alone...there is this thing called Cloud. :) Just sayin...

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +2

      This is much less expensive vs cloud for what I run. It's not really that bad, the DC portion of the house is about 150/mo including cooling for about half the year and around 100 when it's not cooled. Heating isn't needed in Austin TX 😂

  • @psycl0ptic
    @psycl0ptic Рік тому +4

    You lost me at Realtek!

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +4

      I told myself it would be okay, but it's not been. I've had some strange disconnects recently and bizarre lag. Finding a X1 slot Intel 2.5g is proving to be a bit challenging also.

  • @basildu4382
    @basildu4382 Рік тому

    The CPU cooler was installed at wrong direction, air flow should be to the case fan.

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +1

      The airflow from the CPU cooler is directing to the back. That is correct airflow.

  • @JasonsLabVideos
    @JasonsLabVideos Рік тому

    I don't understand why you put so much cpu & resources into a box, when pfsense runs on a potato.

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +8

      I did mention in the vid it's so I can get a baseline on bare metal. I'll be installing proxmox on this same machine and running pfsense as a VM with a few other VMs. Then I can see what performance impacts measure up as. For sure you don't need anything close to this for any typical pfsense setup.

  • @yuan.pingchen3056
    @yuan.pingchen3056 8 місяців тому

    I want build a 2.5gb pfsense router, but the key-component: 4 port Intel i226-V adapter are all made in China, and it's very expensive, this is like a replica of the 2020 global pandemic and mask incident.

    • @DigitalSpaceport
      @DigitalSpaceport  8 місяців тому

      Older realtek driver support in BSD sucked. OPNsense is pretty darn good frankly. Just an option maybe. It's also way cheaper.

    • @yuan.pingchen3056
      @yuan.pingchen3056 8 місяців тому

      @@DigitalSpaceport They are vigorously promoting the X540 10Gb network card that was replaced by the government surveillance department. The signs are everywhere, from the Chinese circumventing the wall to make videos to promote homemade 10Gb NAS, to buying foreigners to buy second-hand parts from Aliexpress. After all, they control the world. Human hands shouldn't be so easily noticed and seen, but they did it too exaggeratedly, I don't wanna be a mind controlled monkey.

  • @HURENSOHNYOUTUBE
    @HURENSOHNYOUTUBE Рік тому

    bro i tested 2999 times no difference witrh threadripper or celeron

  • @SakuraChan00
    @SakuraChan00 9 місяців тому

    could of went with a Intel X550-T2 card so you dont need 2 network cards (=^-^=)

  • @AtanasPaunoff
    @AtanasPaunoff Рік тому +1

    I do like your videos and your setup, but this particular video is not what I expected ! Calling this insanely fast router is so misleading ;)

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому

      Did you watch to the end? My WAN is indeed much faster. Sure I could get a 2.5gb/10gb switch and do the same likely (one is ordered already for failover) but then I wouldn't have a good reason to build something.

    • @AtanasPaunoff
      @AtanasPaunoff Рік тому

      @@DigitalSpaceport WHat I expected from insanely fast pfSense router was to see over 20 Gbit/s throughput because I still doubt it is possible without DPDK VPP etc... Honestly I am just into a process of upgrading some equipment here to 100Gbit and still couldn't figure out what I should use as router which can do a couple of hundred gigabit and wont broke the bank LOL

  • @downwiththesneaker9933
    @downwiththesneaker9933 Рік тому

    So i have been thinking of setting up a filecloud server at home for my wifes business. Would this pfsense be something beneficial for me to use for this type of setup. Looking to have 4-5 employees connecting remotely to the server for files.

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому

      Yes you can setup openVPN for the remote workers to access in pfsense pretty easy if you wanted a secure tunnel. Nextcloud can be ran behind your router with ports forwarded and is a good file share.

    • @downwiththesneaker9933
      @downwiththesneaker9933 Рік тому

      @@DigitalSpaceport Awesome. Moving soon to an area with 2gig up and down fiber speeds so I need to start researching how to do that. Unless your services are for hire?

    • @DigitalSpaceport
      @DigitalSpaceport  Рік тому +1

      @@downwiththesneaker9933 You need an onsite person to do networking for 1 critical reason especially. When you bonk the network with a setting, you cant unbonk it remote. I do some remote services, but networking is best done IRL.

  • @anand-nb4bb
    @anand-nb4bb Рік тому

    Hi Bro,
    I want the internet to be working on my base system as well & also should be able to connect to my work network as a lot of websites are blocked inside the work network. Split Tunneling is enabled on the OpenVPN server but it seems my system is missing some configuration which is causing it to not work
    Can you please tell me what settings I need to do on my laptop VPN to make this work. Kindly help.
    There is a ovpn configuration file in which following details are given as below
    pull-filter ignore "redirect gateway"
    route-nopull
    route 255.255.255.255
    But still after connecting vpn the internet on my ubuntu machine disconnects

  • @unoptanio
    @unoptanio Рік тому

    Pfsense 2.7.0
    Per la scheda Realtek 2.5G RTL8125 c'è un nuovo driver aggiornato che dovrebbe risolvere un pò di problemi di caduta rete
    FreeBSD:14:amd64 Package ver: 198.00_3
    Supported devices:
    * 2.5G Gigabit Ethernet
    - RTL8125 / RTL8125B(S)(G)
    * 10/100/1000M Gigabit Ethernet
    - RTL8111B / RTL8111C / RTL8111D / RTL8111E / RTL8111F / RTL8111G(S)
    RTL8111H(S) / RTL8118(A)(S) / RTL8119i / RTL8111L / RTL8111K
    - RTL8168B / RTL8168E / RTL8168H
    - RTL8111DP / RTL8111EP / RTL8111FP
    - RTL8411 / RTL8411B
    * 10/100M Fast Ethernet
    - RTL8101E / RTL8102E / RTL8103E / RTL8105E / RTL8106E / RTL8107E
    - RTL8401 / RTL8402
    Non capisco perchè dalla shell di pfsense ritorna due versioni di driver differenti:
    pkg info -x realtek
    Return: realtek-re-kmod-198.00_3
    pkg search realtek
    Return: realtek-re-kmod-198.00_1