Saturday, August 24, 2024

Re: Hardware rec, 10 gigabit home firewall

I have many APU's and loved them. But I switch to the ProtectLI and I am
very happy.

And yes, it is fanless, run CoreBoot, NVMe, for the latest one,they have
2, 4 and 6 ports and even have a newer one with 10Gb port. Never tried
that one, so I can't say much about it, but they are fully well
supported, NOT like what Alix sale!

And if you know the APU CoreBoot was supported by Dasharo/3mdeb, the
same people do it for ProtectLI.

After I hit the bios issue with so many servers from SuperMicro that got
stuck because of the bug in the BIOS that got the servers stuck after
the date pass 2020, I ONLY buy hardware that support CoreBoot now and
never look back.

You have a series of possible model to choose from. Real cheap if that's
what you want of way more powerful if that's what you need. Even some
with SFP if you need that.

I used the VP2420 for a few years now and I am very happy with it.

So yes thee is possibility that are well supported and that are not
blowing up after a few months and that run CoreBoot and the company for
them is in the US too.

Have a look if you want.

https://protectli.com/

CoreBoot stuff:

https://doc.coreboot.org/mainboard/index.html#protectli

for mine:

https://doc.coreboot.org/mainboard/protectli/vp2420.html

And I get emails directly from Dasharo when a new coreboot is release as
I subscribe to them.

Last email I got from them for my VP2420 was 5/16/2024, so it's stay
current.

https://newsletter.3mdeb.com/archive/Ghg7wEnK-/n2EpSxtqL/UX881QVvE

And you can see all the changes on github too.

So yes, it is well supported!

Have fun.

Hope this help you.

Daniel


On 8/24/24 4:23 AM, jslee wrote:
> Hi,
>
> On Sat, 24 Aug 2024, at 09:15, Anders Andersson wrote:
>> I bought an 85 year old house in the woods, and apparently I can get
>> 10 Gbit/s there. My good old APU4 firewall is barely keeping up with
>> 100 Mbit/s so I need to look for an alternative.
>
> It won't do 10Gbps but you should be able to do significantly better
> than 100Mbps
>
> My APU4C4 seems to have no trouble routing/filtering things at up to
> 450Mbps, plus hosting unbound+nsd. Not doing any IPSec/Wireguard. I
> don't know what its true limits are as I suspect I'm limited by my wifi APs.
>
> What else are you running on it?
>
>> My goal is an OpenBSD firewall/router that can do the packet filtering
>> and some VLAN and routing without having to worry about adding too
>> much. I've never dealt with anything faster than gigabit, is there a
>> "best" 10 gigabit chipset for OpenBSD that supports all the hardware
>> offloading features and whatever multi-process functionality is
>> already implemented?
>>
>> Something small and stand-alone would be nice, with 3-4 ports.
>
> It's unfortunate but it seems there's not really an obvious compelling
> APU2/3/4 replacement out there that ticks all the same boxes (well
> documented/supported, serial console, fanless, small, good ethernet
> chipset, can use NVMe storage) *and also avoids ticking the unwanted boxes*.
>
> John

No comments:

Post a Comment