Firewall for home

Discussion in 'Networking' started by Hap, Jun 15, 2011.

  1. Hap

    Hap New Member

    Joined:
    May 14, 2011
    Messages:
    7
    Likes Received:
    1
    Using a Cisco RVS4000, tho I did add a enermax fan on top to keep some of the parts cooler inside, and again wondering if others might be using this small business security router
     
    #1
    Mike Bailey likes this.
  2. drake3

    drake3 New Member

    Joined:
    Feb 11, 2011
    Messages:
    14
    Likes Received:
    2
    I am using the WRVS4400N at home for an access point. The router is feature packed, although I could never get the second SSID/VLAN segmentation to work. It does generate a lot of heat. However, I use Astaro (now Sophos) products for my firewall at work and home.
     
    #2
  3. apnar

    apnar Member

    Joined:
    Mar 5, 2011
    Messages:
    105
    Likes Received:
    17
    I used to use a Linksys e3000 with a modified dd-wrt on it, but I've recently moved over to using pfSense in a virtual machine on my all-in-one NAS/ESXi box. I've been very happy with it so far. I pass through a physical ethernet card to it with VT-d which I use to connect to my ISP. It also has a virtual interface on my internal network. It does a great job handling all my firewalling, routing, VPNs, etc.

    Even on a commodity standalone box I'd suggest taking a look at pfSense.
     
    #3
  4. Patrick

    Patrick Administrator
    Staff Member

    Joined:
    Dec 21, 2010
    Messages:
    11,559
    Likes Received:
    4,490
    Just wondering, how is the latency on your pfsense box, and what hardware are you running on it? I am thinking of converting an Atom machine or two over.
     
    #4
  5. apnar

    apnar Member

    Joined:
    Mar 5, 2011
    Messages:
    105
    Likes Received:
    17
    I haven't noticed much in the way of latency, but all my traffic passing through it is hitting slower networks (cable modem and a couple wireless links). I'm running it as a VM on ESXi 4.1 with 1 processor and 1 gig of RAM assigned to it and the VM is barely using any of it unless I'm pushing the VPN. The underlying physical proc is a Xeon E5620.

    I've been running the latest 2.0 x64 release candidates with the ipv6 repo overlay. So far it's been working great and my VPN performance is much improved over what the e3000 could handle (now my bandwidth is the limiting factor). I suspect an Atom would do ok assuming you aren't putting a lot of encryption/decryption load on it.
     
    #5
  6. damarious25

    damarious25 New Member

    Joined:
    Jan 29, 2012
    Messages:
    1
    Likes Received:
    0
    I'm running pFsense on an old PIII with 756 ddr I found for free in a local add. The NICs are only 10/100 but I have 6 months until fiber optic internet is available in my neighbourhood so for home network use it's fine.
     
    #6
  7. dswartz

    dswartz Active Member

    Joined:
    Jul 14, 2011
    Messages:
    377
    Likes Received:
    28
    Even a 100mb enet will be fine unless you are springing for 100mb fiber?
     
    #7
  8. zicoz

    zicoz Member

    Joined:
    Jan 7, 2011
    Messages:
    140
    Likes Received:
    0
    Anyone tried Astaro Securoty Gateway Home and know how it does compared to PFSense?
     
    #8
  9. dswartz

    dswartz Active Member

    Joined:
    Jul 14, 2011
    Messages:
    377
    Likes Received:
    28
    I am using it instead of pfsense now. They are both good, but ASG has a number of features that pfsense doesn't (such as an spam/virus filter that sits in front of my mail server - has a web quarantine, etc...)
     
    #9
  10. _Adrian_

    _Adrian_ Member

    Joined:
    Jun 25, 2012
    Messages:
    41
    Likes Received:
    1
    Ummm...
    pf does have a mail scanner package.
    But for me the most important is the HAVP antivirus Package
    Antivirus: HAVP (HTTP Antivirus Proxy) is a proxy with a ClamAV anti-virus scanner. The main aims are continuous, non-blocking downloads and smooth scanning of dynamic and password protected HTTP traffic. Havp antivirus proxy has a parent and transparent proxy mode. It can be used with squid or standalone. And File Scanner for local files.

    Here's a quick run down on the mail package...
    mailscanner-dev Services beta
    4.83.5 pkg v.0.2.1
    platform: 2.0
    MailScanner is an e-mail security and anti-spam package for e-mail gateway systems. This is a level3 mail scanning tool with high CPU load.
    MORE INFO HERE

    BTW, im running this on a "retired" DL360 G4 with Mellanox card and NC340T
     
    #10
    Last edited: Jun 25, 2012
  11. dswartz

    dswartz Active Member

    Joined:
    Jul 14, 2011
    Messages:
    377
    Likes Received:
    28
    ASG has all of that too, and it's (IMO of course) better integrated. I've seen a lot of problems with the way addon packages work with pfsense. If it works for you, that's the important thing.
     
    #11
  12. _Adrian_

    _Adrian_ Member

    Joined:
    Jun 25, 2012
    Messages:
    41
    Likes Received:
    1
    Over the past few years it stopped a lot of attempts which otherwise would have ended otherwise...
     
    #12
    Last edited: Jun 25, 2012
  13. dswartz

    dswartz Active Member

    Joined:
    Jul 14, 2011
    Messages:
    377
    Likes Received:
    28
    Well, good (seriously), but I was never saying otherwise. I just think external package integration in pfsense is fragile, due to how it works. I think the devs have done wonders with it, it's just inherent.
     
    #13
  14. _Adrian_

    _Adrian_ Member

    Joined:
    Jun 25, 2012
    Messages:
    41
    Likes Received:
    1
    I'm on the new 2.1 Beta and have no issues to speak of.
    Everything works perfect even though I'm on the daily builds.

    OpenVPN, IPv6 Tunnel, and my Default IPv4 gateway from my provider works flawlessly !
    And not even mentioning the other packages that have been added in and running in the background.
    But then again... I'm running quite powerful machine for what it is...

    Latency you ask ?
    +2->4ms over your default gateways latency
     
    #14
  15. ehorn

    ehorn Active Member

    Joined:
    Jun 21, 2012
    Messages:
    342
    Likes Received:
    52
    Interesting...

    Would be nice to see some comparative reviews of these two:

    Sophos UTM (aka. ASG)
    vs
    pfSense w/Snort, etc...

    Features, performance, hardware requirements, etc...
     
    #15
  16. ehorn

    ehorn Active Member

    Joined:
    Jun 21, 2012
    Messages:
    342
    Likes Received:
    52
    Hi Patrick, Did you ever get around to playing with this?

    The guys over at pfSense say max throughput ~ 550Mb/s on the newer atoms (without add-in packages). I don't recall latency measurements though... They seem to be suggesting the low-power pentiums with pico PSU's for Gb speeds and some left over for packages (if intended)...

    I am considering a UTM/pcap setup... Currently looking at a DQ77KB platform... I saw Aluminum (member here) had a similar setup. With a pcap build as well. If he stumbles along this thread, I would love to here his experience with this setup.

    I am wondering how an ESXI setup might work for this purpose: VM1 for firewall/router and VM2 (sitting inside for pcap)...

    Any thoughts/ideas?
     
    #16
  17. Patrick

    Patrick Administrator
    Staff Member

    Joined:
    Dec 21, 2010
    Messages:
    11,559
    Likes Received:
    4,490
    I did. Here is a bit on the Supermicro X7SPE-HF-D525 and pfsense. Bottom line, I rebooted the machine once in the last 11 months. I only put WAN traffic through the pfsense box though and I do not have a 550mbps home connection :)
     
    #17
  18. ehorn

    ehorn Active Member

    Joined:
    Jun 21, 2012
    Messages:
    342
    Likes Received:
    52
    Thanks for the link. I forgot I actually read that some time ago... At my age, "CRS" is becoming a problem...

    Yeah, not sure too many folks would stress that BW from a home. hehe... :)

    However, add in some packages and/or a few VPN connections (with IPSec/Encryption) might bring that throughput number down considerably. I have not seen many metrics (CPU/BW) for the atoms under those conditions.

    Have you done any VPN with it or are you running any IDS/pcap/etc... packages on top?
     
    #18
  19. cactus

    cactus Moderator

    Joined:
    Jan 25, 2011
    Messages:
    826
    Likes Received:
    76
  20. Patrick

    Patrick Administrator
    Staff Member

    Joined:
    Dec 21, 2010
    Messages:
    11,559
    Likes Received:
    4,490
    #20
Similar Threads: Firewall home
Forum Title Date
Networking Home Build of Firewall / Monitor Help Dec 27, 2017
Networking Home firewall poll Feb 3, 2017
Networking Help me pick a replacement home firewall/router Jan 30, 2016
Networking RouterOS: basic firewall policy and rules model Nov 18, 2019
Networking Hardware for Gbit VPN/firewall Oct 22, 2019

Share This Page