this post was submitted on 11 Jun 2023
10 points (100.0% liked)

homelab

171 readers
1 users here now

founded 4 years ago
MODERATORS
 

I finally decided to buy a mini PC to make it as a pfsense router and I was wondering witch option is more suitable for my needs

First I was thinking of doing with proxmox so I could install pi-hole and wireguard in it but looking more into pfsense I see that there is PfblockerNG and also a Wireguard package that could be installed inside.

What does everybody in here use? I'm curious to know if thinkering in proxmox to run pfsense is more efficient than just installing bare-metal.

Thank you

Conclusion: will go with sole pfsense since I never used it in the first place, once accustomed will switch to proxmox, thank you everyone I hope there will be more posts like this in this platform

top 13 comments
sorted by: hot top controversial new old
[–] ProctorZeuss@lemmy.ml 8 points 1 year ago (1 children)

I'm currently running OPNsense virtualised in Proxmox. It's a little confusing if you haven't run a custom firewall before but the setup was relatively simple and works flawlessly now that I understand it a bit better. The only downside being if you want to restart your server your network will go down as well.

[–] beep@infosec.pub 5 points 1 year ago

Same here, opnsense on proxmox. I'm very happy with it. Snapshots mean I don't have to worry about a "bad" update and I appreciate the easy console access through prox gui without needing an ipkvm or similar in scenarios where I've screwed something up and can't hit the gui or ssh. Plus, if you backup your *sense config after any changes you make, in the event you need to setup a new physical box it's a quick iso install and restore config. For me the pros outweigh the cons, even if a bit of performance is lost.

[–] ptz@dubvee.org 6 points 1 year ago* (last edited 1 year ago)

I had a bad experience with a pfSense VM once when I was still learning.

TL;DR: I was trying to use 100% SDN in my lab and painted myself into a corner.

I was using that pfSense VM as my core router for my lab and got into a bit of a bootstrap problem after a long power outage because everything in my lab relied on DV switches through vSphere (which I couldn't manage and couldn't 'see' the hosts). After a tedious recovery, I pulled pfSense back to a physical box.

Lessons learned: always keep your core network router separate from anything that depends on it. lol. I do still use virtual pfSense for dev environments, though.

[–] cablepick@lemmy.cablepick.net 4 points 1 year ago

I run opnsense, which has a long a storied history with pfsense and in my opinion is better, on a VM in proxmox.

I have a cluster of three servers and I can live migrate the VMs around to do maintenance. It gets backed up to proxmox backup server so restoring from a bad upgrade, which I’ve never had happen, or severe experimentation, which happens frequently, is simple.

It’s also one less device to power on, and pay for. My cluster is running regardless and every watt less helps keep my wife happy.

I’ve never had any issues that I could attribute to it being run in a VM. It does my 1gbe fiber and a dozen vlans with no issues.

What hardware did you buy? I'm looking at building a new box for proxmox. Currently I'm using an old laptop with an extra ethernet port dongle to run proxmox and virtualize opnsense, unifi controller and a couple other lvms. From others posts i read, i the choice between bare metal or virtualized seems personal. I went with proxmox just to learn a thing or two about vm environments and its applications.

[–] icewave@proit.org 2 points 1 year ago (1 children)

I currently use VyOS with it hosted on proxmox. I pass-through a 4-port network card and I get my full internet speed. It should be similar, but I will say it is nice being able to host other things on the proxmox host such as pihole. I keep only the router functions and core functions there, with another machine for other services

[–] coffelov@lemmy.ml 1 points 1 year ago

Interesting, I never heard of that name, will look more into it

[–] petriborg@lemmy.ml 1 points 1 year ago (1 children)

Thank you @coffelov for your timely post - I was going to post a very similar question myself today. What sort of hardware are you considering to use for your pfsense server?

There are a lot of possible solutions that could be suitable, wondering what sort of hardware you were thinking about.

[–] coffelov@lemmy.ml 1 points 1 year ago (1 children)

I bought the Intel Celeron n5105 from some vendor called wooyi store on AliExpress, from what a saw on yt that CPU is a little overkill for a router and it uses too much idle power, but I think it was a good purchase for me bc I don't plan to switch this router soom.

[–] petriborg@lemmy.ml 0 points 1 year ago (5 children)

Yeah the n5105 looks like a nice little processor. I also liked that those boards come with the i226-V 2.5GbE controller.

For myself, I really wanted wifi 6e and something able to mesh (for the happy wife factor) so I recently purchased the TP Link Deco. It should arrive in a week or so.

Personally, I would have preferred to setup OpenWRT for a nice mesh but for some reason there are no Wifi 6 ones yet let alone 6e.

[–] coffelov@lemmy.ml 1 points 1 year ago

Mmm that device is a little too expensive where I live, I think I will buy an older version of that if I decide to go that route, thank you for replying!

load more comments (4 replies)