Currently I have full network VPN over a Asus router with Asus-WRT firmware.
This has a few problems. First, DNS is not routed through the VPN and there is no way to change that so the ISP still has all my Data, and due to upcoming laws they are even allowed and required to monitor it "for network safety" up to the session layer of the OSI model.
Second, the single core arm chip without in-hardware-encryption is not powerful enough to encrypt my 100Mbit connection. In fact I only have 20 Mbits. Not ideal.
Due to lack of money I have been living with this for 5 months now and now. After watching the recent pFsense videos I found the motivation to change that, get full control over my network and learn some new stuff about networking and BSD.
So maybe you want to come along for the ride. If you guys and female guys (no idea about gender composition because this is my first post on here, never really tried forums, but I feel like this is the one. Been watching since long ago in the Tek Syndicate days... climbing dat Mountain if you know what I mean... this errand is getting long) are interested I could document it and post it on here somewhere for educational purposes.
Many words, no sense, lets get to the point.
I'm looking for a small pFsense machine.
Budget: about 3 fiddy... 350 Euros. For the box and the access point (The small one from ubiquity: https://www.ubnt.com/unifi/unifi-ap-ac-lite/ heard they where the shit these days, but I'm open to others)
Features:
- 64 Bit (due to 32 bit support for pFsense going away)
- AES-NI In hardware encryption instruction (In pFsense version 2.4 OpenVPN will have support for it and it will be required in some long away future pFsense versions)
- Small and not to ugly (its going to live in a room with me)
- reasonably power efficient up to 35 Watts or something (money reasons)
- reasonably powerful (able to support 100Mbit OpenVPN encryption, and maybe a file server and of course the simple task of routing the currently 5 devices on my network)
- Hardware support for pFsense but I don't mind compiling a driver from Github.
So I've done my research and came up with the following ideas:
Build the smallest PC I can. https://pcpartpicker.com/list/VLPf4C
I don't know if these parts are a good choice but they are small. Unfortunately with the access point kind of over budget and generally overpowered. But I could do small home server or a media pc for the TV with this which is nice.
Also didn't look into hardware compatibility.
This NUC: http://www.intel.de/content/www/de/de/nuc/nuc-kit-nuc6cays.html
It includes RAM and Storage and a Windows 10 license (ewwww....)
This NUC Kit: http://www.intel.de/content/www/de/de/nuc/nuc-kit-nuc6cayh.html
Same as above but you have to buy ram and storage (the cheapest SSD you can find) separately so its about the same price depending what you go with.
These two NUCs are the cheapest of the current generation NUC, support for the WiFi card will be there in pFsense 2.4 since its based on BSD 11.
And I think they should be easily up to snuff with the requirements and leave room for future expansions.
Buy some cheap and/or old laptop and tuck it away in a corner where you cant hear the fan screaming for its life.
I've looked a bit further for some other small boxes but not enough to find anything I liked on first look, so if you have some recommendations I will look into it.
And if the budget is to tight for what I want I can wait for some more minerals. The 350 are what I found to be fitting.
What are your suggestions and thoughts?
Anything I forgot or I could do better? What about the hardware? And are you interested in a "My wild love story with pFsense" Topic in the future where I write about setting it up and having fun with it?
Feedback and new Ideas would be greatly appreciated. Thanks for reading and have a nice weekend.