looking into a mini/micro pc for running opnsense.
I would normally build something (and I have several machines laying around) BUT, it has to fit into a structured media panel, in a wall. So I need something small.
I’ve also never actually specc’d something out for this, as I’ve always had something dedicated, and way overkill (VM on my old R710, HP ML310e w/ 16GB RAM, and so on.)
there’s enough mini pcs out there to make my head spin, so I want to know what everyone thinks.
Use:
-Gigabit Internet (Fios)
-VLAN termination and routing
-IPS
-VPN (client-server, possible site-to-site in the future)
-QoS
-Will be dual-stacking ipv4 and v6, though i doubt that will affect performance at all at the hardware leve. worth mentioning.
I’d really prefer intel networking if we can, and I only need two ports.
I’m based in the US, and would prefer to purchase new and close to current gen hardware.
Any suggestions?
I didn’t realize those had come down so much in price, I’ll take another look at them.
Also, I’m sure an i5 wouldn’t struggle with IPS, would an i3? that’s really where I’m a little lost here. I’ve always had really overspec’d hardware for my firewalls, and now I’m trying to be as energy sipping as possible, without sacrificing throughput @ 1Gig with a few features enabled.
I was looking at… I believe the GK41 before I posted, that’s what spurred me to join and make sure I’m not underspeccing my self.
Any idea on throughput with IPS, and VPN enabled on those chips? I’m going to make the move to wireguard slowly, I’m pretty familiar with openvpn (As well as it’s downsides, and heaviness…), so I’m making that move slowly.
Given that pricing is pretty close I guess going for i5 makes sense in that regard. I would also be a bit concerned about aftermarket support regarding bios updates etc for the chinese ones.
Yeah not concerned about gig over openvpn, I rate limit that anyhow, no need. I host some game servers so that’s really all that’s used for at the moment. Wireguard will be implemented soon, and that will have road-warrior style setup for my phones and such. Yay pihole in all the places!
IPS? honestly because I feel like it. I know it’s a pain to manage but, I know it’s overkill, but yeah.
I’ll keep that in mind if I end up going used. The potential of vPRO would also be nice, if I get the right model.
That would also totally fit in the space this is going in.
I’d also like a few of those or similar to mess with kubernetes soooo