Forum Topic

Unified PFSense Users

  • @polka
    you can buy this:

    - HP thin client T610 (it only had 1 gigabit ethernet connection, but a VLAN capable switch can easily fix that)
    - TPlink SG105e

    Is the above setup still good for home network with url filtering, access control, bandwidth control, ips/ids? Thank you.

    -- edited by Cuida on Nov 25 2019, 11:10 AM
  • ^
    yep its still capable machine, that thing can route 1gbit connection without breaking a sweat.

    IPS/IDS is also good, good thing about this hardware is it support upto 16gb of ram so just slap in more ram to it, but the cpu is a bit too much for it so it can only route around 300mbit traffic with suricata enabled.

    url filtering is hopeless now a days due to how SSL website works now, you cant really blame pfsense here, any firewall out there cant handle this thing out there not unless you want to break the internet that badly. Take note if your force MITM the traffic, google services will not work it will always complain about security certificates, if you use the latest google chrome as well, MITM is no longer viable as by default chrome now ignores self sign certificates.

    access control and bandwidth control is probably the basic thing that pfsense can do so yeah sure.
  • sa setup na naka VM ang pfsense
    Pwede ba na isa lang ang LAN card ng host PC, at si pfsense na naka VM ang magiging gateway.

    para sa diskless server na iisa lang ang Lan, possible ba? paano ang settings mga sir?

  • ^possible, just get TPlink SG105e or any switch that support 802.1q vlans.

    after that you can just setup your pfsense as 1 network card (both physically and virtualization setting). just make sure that you set the network card setting on the vm to allow all promiscuous mode.
  • @polka
    thanks sa info sir...
  • Post deleted #12286298
  • Looking to build my own pfsense box.

    Anyone have a good budget build that can handle, over a gigabit connection about 1.4gbit?
  • ^the main computer component should be easy to get, a 1151 motherboard with G4400 should be more than enough. (it can do NAT around 3gbit just fine) for ram 4 -8gb ask your self if you want to run more services on it (eg suricata, pfblocker).

    now for the hardcore part, the NIC, since your aiming 1.4gbit, you have no choice but to go SFP+ or 10GigE card as we say always go with Intel branded nic, you can get this cards on ebay for like around 100-150usd a dual port x540-T2 should be more than enough.

    total damage, around 25k (including case and reputable branded 80+ psu)
  • Hi,

    Legit po ba yung nagbebenta ng J1900 sa Lazada/Shopee? Puro galing overseas kasi.
    Ano recommende CPU/RAM quantity kung ang goal ay mag load-balance ng total 50-70Mbps multi-ISP links?

  • I need help.

    meron akong huwei 5g model h112-370. Need ko i DMZ si PFSENSE para ma enable ko ung RDP (although not safe pero ung server ay tapunan ko lang ng file for remote). Na dedetect naman ni Huwei ung PFSENSE kaso nung I reremote ko na (using NO-IP, by the way ung NO-ip naka enable sya sa PFSENSE) hindi na ma contact ung server.

    I have the same setup before kaso nag palit ako ng ISP.
  • ^dont bother, afaik (feel free to correct me) all wireless connection here in Phlippines are under CGNAT. so setting a DMZ doesnt make sense.

    if you want to remote on your system as if you were doing a port forward. use Zerotier. pfsense also have a "unofficial" zerotier package, still not recommended to install, but you can install it on your computer. What zerotier do is just doing a UDP punch hole, so in this way each computer have a direct connection to each other despite being under a NAT.
  • ^
    CGNAT the right term im looking sakin problema... Anyway mukhang ayaw ng magpadaya ng mga ISP ngaun.
  • Mga sir, kaya po ba ang pfsense ng ganitong specs ng mini pc? Thanks
    PROCESSOR : Intel Celeron 1037U Dual Core 1.8Ghz Processor
    -M.BOARD : Intel NM70 QT-Q100 Industrial Mini Board
    -FRONT PANEL : 1x Power Switch Button / 1x hdd led /4x USB 2.0 / 1X -Microphone Port / 1x Serial Port
    -BACK PANEL : 1x DC Input / 1X HDMI Port / 1x VGA Port / 2x Gigabyte Lan Port / 1x Speaker Port
    -4GB DDR3 Laptop Memory
    -32GB MSata
  • @badburns

    ok pa yan, compared to j1900, that 1037u celeron is faster on single core performance and dual core performance, not bad narin, it should be able to handle gigabit NAT so kaya yan kahit 1gbps pa internet speed mo.
  • @polka

    Thank you po sa info sir.