New machine for virtualized pfsense/opnsense, DNS, DHCP and OpenSM

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

NablaSquaredG

Layer 1 Magician
Aug 17, 2020
1,344
820
113
Hey,

I am looking for two new little machine to do virtualized pfsense/opnsense (I don't like BSD), BIND9 DNS, kea DHCP, OpenSM, VPN Endpoint (Should be able to do at least one wireguard at full 1GBit) and maybe print server

My requirements for the hardware are a bit different, because I need an PCIe slot for a Mellanox card

Requirements:
- Small (i.e. not Desktop ATX size), energy efficient (ideally sub 10W in IDLE) and not too expensive (let's say max 500€ per machine)
- Should probably have at least 4 Cores, Coffeelake, Zen 2 or newer
- 2 PCIe slots (min. 4 lanes 3.0 + 1 lanes 2.0) OR updateable Quad NIC + 1x PCIe slot (at least 1x 2.0) - Updateable because I need SR-IOV and Virtual Functions for virtualization and the older firmware versions often have bugs
- 2x M.2 NVMe or 2x M.2 SATA


Generally, it seems to be quite difficult to find hardware that matches those requirements.

Potential candidates I have identified:

- Intel NUC 9 Extreme - Currently selling for very good prices in Germany!
Although only the model with 9750H (NUC975QNX) or 9300H (NUC9i5QNX) would work, as the i9 version seems to IDLE at 40W?
@Patrick has tested the Pro version with a 25GBe NIC and got sub-25W - Patrick, have you tested without the NIC? Can you perhaps tell us an exact number?

- Dell Optiplex 5060 / 5070 / 7060 / 7070 SFF
The Dell models seem to be very efficient, although I couldn't really find any definite numbers for the SFF models too...
They're at the upper end of what's possible regarding size of the machine, but they have the PCIe slots

The i7 models are quite rare, so it doesn't really make a difference whether it's coffee lake (5060 / 7060) or Coffee Lake Refresh (5070 / 7070). With an i7, the non-refresh generation would be better, as they have hyperthreading whereas for the refresh models, only i9 has hyperthreading


Any other ideas?
 

RolloZ170

Well-Known Member
Apr 24, 2016
5,366
1,613
113
cases like Lenovo Ideacentre SFF / Dell Optiplex SFF (but rotated Mainboard, PCIe other side)
CiT MTX008B
Akyga AK-202-01BK
 

Stephan

Well-Known Member
Apr 21, 2017
942
711
93
Germany
Coffee Lake Refresh has hardware Meltdown fix, so 1/10 context switching time, so preferable. For 1 Gbps VPN you need at least a 35W better 65W Skylake so no chance going to anything lower, fanless or embedded. Mellanox will require airflow, but Dell 7070 SFF has a fan blowing at PSU and cards, might work.
 

NablaSquaredG

Layer 1 Magician
Aug 17, 2020
1,344
820
113
Coffee Lake Refresh has hardware Meltdown fix,
Only Meltdown V3 and L1TF, the other vulnerabilities like Spectre V2, V4 and Meltdown V3a are unfixed

but Dell 7070 SFF has a fan blowing at PSU and cards, might work.
Are you sure? I couldn't see one on any of the pics of the inside I could find. But I believe you can install one on all the 5060, 5070, 7060, 7070 models
 

Stephan

Well-Known Member
Apr 21, 2017
942
711
93
Germany
I'm not a Dell savant, but top right looks like a Sunon 80x80 or 92x92 fan to me:

s-l1600-3-9-1024x768.jpg

The manual has a different view, with a different CPU fan, but you can see the front where a fan can be fitted, right before the power supply:
Capture.JPG
 
  • Like
Reactions: RolloZ170

NablaSquaredG

Layer 1 Magician
Aug 17, 2020
1,344
820
113
Yes, you could place a fan there. But you cannot connect it.


FAN_SYS header is not soldered. Closeup is from my 5050, Screenshot from 7070 teardown video

One way would be use a fan splitter for the CPU fan and connect the additional 80mm fan. There is 1x SATA Power which could be splitted and used to power the fan (but no fan control then)

Or NUC9 or DIY.
 

Stephan

Well-Known Member
Apr 21, 2017
942
711
93
Germany
The only issue is that the model with radial fan doesn't seem to have a front fan 4-pin PWM connector. So you'd need a Y cable to run both the radial and front fan from the FAN CPU header. Luckily, a Mellanox doesn't need alot of airflow, but only some to bleed off 10 Watts.
 

Marsh

Moderator
May 12, 2013
2,646
1,496
113
I have a Proxmox cluster of 4 x Dell Optiplex 5060 , like it a lot.

Added a 80mm fan like Stephan suggestion , Intel P3600 nvme , 10gbe , temperature is fine .

I like having a fan inside the small case, that is why I picked Dell series small computer.
 
  • Like
Reactions: Stephan

Marsh

Moderator
May 12, 2013
2,646
1,496
113
Dell OptiPlex USFF 5060 i5-8500, 32gb ram , 1 SSD , 2 fan
Proxmox 7.1 idle 10-11w

Dell OptiPlex USFF 5060 i5-8500, 32gb ram , 1 SSD , 2 fan
1 Nvme Samsung 960gb SSD , 2.5gbe Ethernet
Proxmox 7.1 idle 14-15w

Since I took the power measurement , I upgrade to Intel P3600 1.6tb nvme.
I don't have new power measurement , probably 3-5w more.
 

Fritz

Well-Known Member
Apr 6, 2015
3,386
1,387
113
70
Your 5060 are SFF, not uSFF/TMM, right? I wouldn't think a P3600 would fit in uSFF
Yea, model numbers are confusing. I have a 5060 (must be uSFF) and this thread definitely doesn't apply to it.
 

Sean Ho

seanho.com
Nov 19, 2019
774
357
63
Vancouver, BC
seanho.com
Right, TMM: Lenovo Tiny, HP ProDesk/EliteDesk Mini, Dell OptiPlex Micro. I prefer to call them uSFF; some folks like 1L.

In any case, in the context of this thread the OP is probably looking for SFF (2x low-profile PCIe slots, usually x16 and x1, full-size DIMMs, internal PSU, 1x 3.5", potentially 2.5" and m.2).
 

Fritz

Well-Known Member
Apr 6, 2015
3,386
1,387
113
70
Mine has no PCIe slots and uses a naked SATA SSD. It will take 16GB of ram and run Linux like a champ.