Qotom Denverton fanless system with 4 SFP+

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

foureight84

Well-Known Member
Jun 26, 2018
493
417
63
Make sure to configure software flow offloading in your firewall rules. It significantly reduces CPU load, which in turn translates directly to higher throughput. :) There are some NIC offloads that are useful too, but I don't know if you can use those when virtualized.

My unit showed all interfaces without a BIOS update. Interesting that yours didn't.
I edited that post to remove that section because it after further investigation, the x553 controller doesn't support 1GBase-T SPF modules. 1.25/2.5/5/10G Base-T seems to work but I haven't tested speed negotiation yet. I got sidetrack trying to figure out how to had a small fan to blow air over the SFP+ ports to try and reduce the heat in case I need to use more than 1 10GBase-T module.
 

blunden

Well-Known Member
Nov 29, 2019
1,218
435
83
I edited that post to remove that section because it after further investigation, the x553 controller doesn't support 1GBase-T SPF modules. 1.25/2.5/5/10G Base-T seems to work but I haven't tested speed negotiation yet. I got sidetrack trying to figure out how to had a small fan to blow air over the SFP+ ports to try and reduce the heat in case I need to use more than 1 10GBase-T module.
I see. I sometimes get a reply in an automated email that doesn't show up here on the forum for hours (possibly pending manual review or something) so I sometimes respond to those anyway. :)

For 1GBASE-T, use the built-in RJ45 ports. There are more than enough of them anyway, seeing as they are routed interfaces connected directly to the CPU, not to an internal switch.

For 10GBASE-T, I suggest going for the transceivers rated for 80 or 100 meters (available reasonably cheap from AliExpress) as they are the ones known to work within the power limit of each port, and also the ones that have somewhat reasonable temperatures. I would still try to minimize the use of them as much as possible. Also make sure they are programmed to spoof being a 10GBASE-SR transceiver as they are otherwise likely to be rejected as unsupported.
 

foureight84

Well-Known Member
Jun 26, 2018
493
417
63
I see. I sometimes get a reply in an automated email that doesn't show up here on the forum for hours (possibly pending manual review or something) so I sometimes respond to those anyway. :)

For 1GBASE-T, use the built-in RJ45 ports. There are more than enough of them anyway, seeing as they are routed interfaces connected directly to the CPU, not to an internal switch.

For 10GBASE-T, I suggest going for the transceivers rated for 80 or 100 meters (available reasonably cheap from AliExpress) as they are the ones known to work within the power limit of each port, and also the ones that have somewhat reasonable temperatures. I would still try to minimize the use of them as much as possible. Also make sure they are programmed to spoof being a 10GBASE-SR transceiver as they are otherwise likely to be rejected as unsupported.
Yea definitely. I was experimenting with maximizing ports. This router will be setup for my 10GBit fiber in a few months. In the meantime, I am still on 500Mbit so I figured instead of making two WANs, just use one of the SFP+ ports and use an SFP 1000Base-T for now with the current ISP and swap out for a 10GBase-T when the new fiber gets connected.

I will definitely grab some 10GBase-T rated for 80 to 100 meters. The ones I'm currently using on one of my switches are only for 30M and they're HOT like can't touch them hot. I didn't realize that those rated for longer length can run cooler. That's awesome, thank you!
 

blunden

Well-Known Member
Nov 29, 2019
1,218
435
83
Yea definitely. I was experimenting with maximizing ports. This router will be setup for my 10GBit fiber in a few months. In the meantime, I am still on 500Mbit so I figured instead of making two WANs, just use one of the SFP+ ports and use an SFP 1000Base-T for now with the current ISP and swap out for a 10GBase-T when the new fiber gets connected.

I will definitely grab some 10GBase-T rated for 80 to 100 meters. The ones I'm currently using on one of my switches are only for 30M and they're HOT like can't touch them hot. I didn't realize that those rated for longer length can run cooler. That's awesome, thank you!
Oh, I see. In that situation I can certainly see why you would try that. :)

My understanding is that the reason the old ones are limited to 30 meters is mostly due to the power draw and heat generation. You can read more about them in the thread below:


I personally own three different ones using that same chip. :D
 

foureight84

Well-Known Member
Jun 26, 2018
493
417
63
Oh, I see. In that situation I can certainly see why you would try that. :)

My understanding is that the reason the old ones are limited to 30 meters is mostly due to the power draw and heat generation. You can read more about them in the thread below:


I personally own three different ones using that same chip. :D
Are you currently running VyOS 1.5 rolling release? I just realized that they don't allow anyone to build off the LTS branch now (made it private). The only two options to get LTS builds are pay $40/month or contribute to the project. That's a bit off pudding for an open source project. Mikrotik has a 60-day trial for CHR and it's not that expensive for a 10Gbit license ($99, a few distributors have it for less).
 

blunden

Well-Known Member
Nov 29, 2019
1,218
435
83
Are you currently running VyOS 1.5 rolling release? I just realized that they don't allow anyone to build off the LTS branch now (made it private). The only two options to get LTS builds are pay $40/month or contribute to the project. That's a bit off pudding for an open source project. Mikrotik has a 60-day trial for CHR and it's not that expensive for a 10Gbit license ($99, a few distributors have it for less).
Rolling releases, yes. I've never had a problem with those. :) There is definitely no need to pay for a license for home use.

I'm currently using a custom ARM64 build of VyOS on a BPI-R4 actually. :)
 
  • Like
Reactions: foureight84

foureight84

Well-Known Member
Jun 26, 2018
493
417
63
The x553 chip has got to be one of the most basic 10GBe out there. It can only do 10GBit. Isn't able to negotiable slower speeds. If you try to use an SFP+ transceiver that can do 1/2.5/5/10 it will always connect at 10. So the problem occurs when you connect an RJ45 that's running at a slower speed (1Gbit). If you're lucky, you'll be able to get around 400-500Mbit. Worst case scenario, 1-2Mbit depending on the transceiver. But this isn't the NIC's fault. Just trying to force something it's not meant to support.

On the side of 10GBit chips, Marvell Alaska M 3610 based 10GBase-T transceiver will probably be the coolest running transceiver (1.1W max power draw). Seems that the only company that is known to use that chip is BotBlox but can't find any of the transceivers on sale. The next best thing seems to be Wiitek 100 Meters, 10Gbps SFP+ to RJ45 Modules, 1G/2.5G/5G/10GBase-T which one reviewer reported measuring only 39c (wow!). They're not cheap though $46/unit. Still better than getting burn by XZSNET (Marvel AQR113C - 2.5W) transceivers I am currently using.
 

foureight84

Well-Known Member
Jun 26, 2018
493
417
63
Mikrotik CHR might not a viable solution with proxmox. I might try the last free version of ESXi but for now PCIE Passthrough doesn't work properly with the X553 chip. PCIE speed is atrocious. I made sure PCIE power management is turned off as well. I couldn't get SR-IOV to work but I might need to revisit again and make sure I didn't make any mistakes.

1770084655282.png
 
Last edited:

foureight84

Well-Known Member
Jun 26, 2018
493
417
63
Looks like ESXi SR-IOV works better than Proxmox and I am getting full PCIE speed for the SFP+ ports.

1770114691131.png

But another problem I found is that Intel QuickAssist on the Denverton is not supported by Intel ESXi Drivers. https://community.intel.com/t5/Inte...-Atom-C3000-series-on-VMware-ESXi/m-p/1498572

Doesn't seem like there's any solution / workaround so QAT can never be utilized by the VM. Trying to enable it in ESXi results in the constant "Enabled / Needs reboot" messaging. Warm and cold boots don't have any effects. Disabling ACS check in ESXi also doesn't change this. Unless I am wrong. Please feel free to chime in if I am missing something.

1770114815969.png
 

t2_tony

New Member
Mar 29, 2020
9
0
1
Los Angeles Metro
anybody run into situation where no vga? been a long while since i connected on serial console, but its not prompting either (stored settings, pretty sure 9600 worked once upon a time) i scrounged the MB4C911MB doc, didn't see typical reset header pin
take any suggestions at this point. tia
 

blunden

Well-Known Member
Nov 29, 2019
1,218
435
83
anybody run into situation where no vga? been a long while since i connected on serial console, but its not prompting either (stored settings, pretty sure 9600 worked once upon a time) i scrounged the MB4C911MB doc, didn't see typical reset header pin
take any suggestions at this point. tia
Did it work before or is this a new unit?
 

foureight84

Well-Known Member
Jun 26, 2018
493
417
63
What do you plan to use QAT for? :)
You know I don't think I need it at all. I thought it would be beneficial for VPN performance but AES-NI is what is needed for this instead of quickassist. I don't think I'm going to be doing any sort of DPI either.

I'm going to try and get sr-iov working for the x553 under proxmox again. ESXi has pretty slow bootup time compared to proxmox.
 

foureight84

Well-Known Member
Jun 26, 2018
493
417
63
anybody run into situation where no vga? been a long while since i connected on serial console, but its not prompting either (stored settings, pretty sure 9600 worked once upon a time) i scrounged the MB4C911MB doc, didn't see typical reset header pin
take any suggestions at this point. tia
Did you happen to turn off CSM? VGA won't work under UEFI and you're stuck with legacy.
 

blunden

Well-Known Member
Nov 29, 2019
1,218
435
83
You know I don't think I need it at all. I thought it would be beneficial for VPN performance but AES-NI is what is needed for this instead of quickassist. I don't think I'm going to be doing any sort of DPI either.
It's useful for IPsec and OpenVPN DCO as far as I know (faster than AES-NI), but the version of QAT in the Intel Atom C3000 series doesn't support the ciphers used by Wireguard.
 

t2_tony

New Member
Mar 29, 2020
9
0
1
Los Angeles Metro
Did you happen to turn off CSM? VGA won't work under UEFI and you're stuck with legacy.
pulled the nvme until i can restore some console
whats available in "legacy"? haven't seen a board not boot into bios before other than a usual bricking nightmare; i hadn't gotten that far in a mod, not certain if i deliberately disabled CSM...how would it have 'dropped' into UEFI?

for now,RTC battery yanked and chassis unpowered, but no idea if this'll reset anything
 

foureight84

Well-Known Member
Jun 26, 2018
493
417
63
pulled the nvme until i can restore some console
whats available in "legacy"? haven't seen a board not boot into bios before other than a usual bricking nightmare; i hadn't gotten that far in a mod, not certain if i deliberately disabled CSM...how would it have 'dropped' into UEFI?

for now,RTC battery yanked and chassis unpowered, but no idea if this'll reset anything
Just checking because I made that mistake after updating the bios. You would have had to look for it to change it, it's under the Advanced options I believe and wouldn't be easy to change by mistake.

The one thing I noticed about these unit, not sure if it would help, sometimes warm reboots will just hang and won't post. Then forcing shut off and cold booting will cause it to hang for a good 5 minutes before posting. But I don't think you have this problem.
 
Last edited:

foureight84

Well-Known Member
Jun 26, 2018
493
417
63
It's useful for IPsec and OpenVPN DCO as far as I know (faster than AES-NI), but the version of QAT in the Intel Atom C3000 series doesn't support the ciphers used by Wireguard.
The C3000 QAT seems very limited after looking more into it. Intel doesn't even support it in their newer drivers.
 

blunden

Well-Known Member
Nov 29, 2019
1,218
435
83
The C3000 QAT seems very limited after looking more into it. Intel doesn't even support it in their newer drivers.
It's a platform originally from 2017. It supports the most important ciphers/algorithms from that time and is really powerful if it matches your use case, but naturally lacks some modern features. :)

I would expect the drivers to be stable at this point so I don't see that as much of an issue. Not sure why you're having problems in Proxmox. Perhaps it doesn't include the QAT driver?