Earlier quoted context omitted.
I don't know. What is your reasoning? I don't really understand why you'd want to force people to upgrade HW when they don't need to.
There is a difference between a design decision reasonable people can disagree, even forcefully, about, and a design decision that is actually a deceptive attempt to get people to buy new hardware.
PfSense 2.5 and AES-NI
31–40 of 90 posts
Re: PfSense 2.5 and AES-NI
#32Earlier quoted context omitted.
Close. Sadly the Celeron I bought that came out in 2011 doesn't support this. https://www.newegg.com/Product/Product.aspx?Item=N82E1681911... Do newer, but still cheap CPU's work with AES-NI?
What is your definition of cheap? Don't rule out ARM based solutions.
I'm certainly not ruling anything out. I simply want to be able to get a working PFSense instance up and running.
Re: PfSense 2.5 and AES-NI
#33If you're going to use OpenVPN and other common software, why not just move to linux side of things? It seems that for home use you wouldn't need any enterprise grade software which I feel is the big advantage of pfSense. Sure pf is great but iptables isn't terrible either.
I find that the BSDs are becoming increasingly reluctant to any change that goes against their principles which I sometimes find a tad misplaced.
Re: PfSense 2.5 and AES-NI
#34Earlier quoted context omitted.
Close. Sadly the Celeron I bought that came out in 2011 doesn't support this. https://www.newegg.com/Product/Product.aspx?Item=N82E1681911... Do newer, but still cheap CPU's work with AES-NI?
What is your definition of cheap? Don't rule out ARM based solutions.
However, the poor I/O capabilities of most/all toy SoCs rule use as a high-bandwidth router out; you can't do Gigabit routing with just one built-in MAC and the other connected to a USB 2.0 port or somesuch.
Re: PfSense 2.5 and AES-NI
#35Earlier quoted context omitted.
Are you referring to timing attacks or something even more subtle?
Most/all software implementations of AES had various side channels in the past. Considering AES-GCM, as far as I'm aware no software implementation is considered "safe". Some libraries do not support AES-GCM without hardware instructions that make it safe (e.g. libsodium choose that way). This is mainly due to AES relying heavily on substitution boxes, i.e. small arrays that are indexed with secrets, which is easy to…
Re: PfSense 2.5 and AES-NI
#36Earlier quoted context omitted.
What if we just added and SD-WAN implementation to pfSense?
I see pfSense playing two possible roles the SD-WAN. The first is customer-centric, and will allow pfSense edge devices to connect to a third-party SD-WAN service or one provided by Netgate itself. The other is vendor-centric, and will allow SD-WAN vendors to use pfSense for their Point-of-Presence software when building the geographically distributed network for SD-WAN traffic optimization. Both are smart strategies…
Thanks! Running our own SD-WAN service seems a lot like opening a cute little coffee shop: A fine way to spend a lot of money with no result.
There is a third option, which is also customer-centric: Allow the customer to run their own SD-WAN.
Re: PfSense 2.5 and AES-NI
#37This is quite obviously an attempt to cut out the flood of cheap embedded PCs which are ideal for pfSense and steer more sales to their own hardware. Systems such as "The vault" sold by protectli.com are completely adequate for the home network (I am capable of pushing > 100Mbit/s over OpenVPN at ~35% CPU). These run older celeron processors and are dirt cheap. Hints: 1) The post implies this restriction will only be…
Well, if you care about security AES-NI allegedly prevents a side channel attack.
Re: PfSense 2.5 and AES-NI
#38Earlier quoted context omitted.
Are you referring to timing attacks or something even more subtle?
Most/all software implementations of AES had various side channels in the past. Considering AES-GCM, as far as I'm aware no software implementation is considered "safe". Some libraries do not support AES-GCM without hardware instructions that make it safe (e.g. libsodium choose that way). This is mainly due to AES relying heavily on substitution boxes, i.e. small arrays that are indexed with secrets, which is easy to…
Re: PfSense 2.5 and AES-NI
#39This may be a good time to try a new relative open source product. OPNSense is a fork of PFSense with some philosophical and practical differences. Here are some notes on what and why https://docs.opnsense.org/fork/thefork.html
Re: PfSense 2.5 and AES-NI
#40Earlier quoted context omitted.
What is your definition of cheap? Don't rule out ARM based solutions.
Well, to get 2.5 running I am going to have to build another box. I'll need a CPU and motherboard. Possibly RAM. I'd like to find that for under $300. Under $150 would be more ideal. I'm certainly not ruling anything out. I simply want to be able to get a working PFSense instance up and running.