Live data from Hacker News

PfSense 2.5 and AES-NI

netgate.com

51–60 of 90 posts

Re: PfSense 2.5 and AES-NI

#51
post #23

This may be a good time to try a new relative open source product. OPNSense is a fork of PFSense with some philosophical and practical differences. Here are some notes on what and why https://docs.opnsense.org/fork/thefork.html

I'd recommend people take a look at VyOS[1] as well. It's a great router distribution, which comes with a lot of batteries included to do many, many things.

I guess I might still use pfSense when I need a _firewall_. I'd immediately grab VyOS whenever I need a router. Both can do routing and firewalling, though.

[1]: https://wiki.vyos.net/wiki/Main_Page

Re: PfSense 2.5 and AES-NI

#52
post #33

Isn't a linux headless box a great alternative to pfsense for non-commercial use? The problem here seems to be that home users now have to shell out more. If you're going to use OpenVPN and other common software, why not just move to linux side of things? It seems that for home use you wouldn't need any enterprise grade software which I feel is the big advantage of pfSense. Sure pf is great but iptables isn't terribl…

> I find that the BSDs are becoming increasingly reluctant to > any change that goes against their principles which I > sometimes find a tad misplaced. This seems a bit uncharitable. pfsense is an open source firewall product, made/released by a company that sells support and services. I wouldn't call it "one of the BSDs" any more than I would call say.. Sophos Firewall or Smoothwall as linux distributions. Running a…

I'm not calling it one of the BSDs, but you still have to consider who's running the show. The FreeBSD part behind pfSense is as important as the Debian beind VyOS (although I'm not suggesting VyOS here).

If things are completely same from a management/security perspective, then I'd be wrong but it does make a difference when it comes to management, updates, and compatibility etc.

Your definition of technically capable is a bit vague. What can a technically capable user do? It can vary from barely being able to use the cli and minimal understanding of basic networking, to being able to compile/tune the kernel by themselves and write drivers in case they are missing.

Re: PfSense 2.5 and AES-NI

#53
I look after a pfsense box for a school on a 9 year old E2200 that is obsolete by this.

On one hand I cannot complain because the server is 9 years old and lasted well, but on the other hand, why not an option for those just needing a packet filter to bypass this?

Am I missing something?

Re: PfSense 2.5 and AES-NI

#54
post #5

Sounds like a move to sell more hardware. My pfsense barely does any crypto. This will push me over to openbsd.

If this was a move to sell more hardware, why wouldn't we make the decision for 2.4 (which is imminent) rather than 2.5, which is based on FreeBSD 12, when 12.0R isn't even scheduled?

Explain then. Why would community release only need new hardware?

Re: PfSense 2.5 and AES-NI

#55
post #23

This may be a good time to try a new relative open source product. OPNSense is a fork of PFSense with some philosophical and practical differences. Here are some notes on what and why https://docs.opnsense.org/fork/thefork.html

Oh yes, OPNsense. Those sure are some philosophical and practical differences. Differences as in: - code theft - copyright abuse - attempt to steal pfSense trademark in Europe - toxic project members who publicly attack anyone who dares to point out issues (including assault on all major pfSense developers). - hiding serious vulnerabilities - downplaying serious vulnerabilities Oh yes, that's a very different project…

I think it would be healthy for you to 1) read about what copyright actually is and 2) read about what various licenses permit. There seems to be a disconnect between what is actually occurring and your understanding (and subsequent nerd-rage).

Re: PfSense 2.5 and AES-NI

#56
post #42

Earlier quoted context omitted.

Wait, your argument is that isn't a way to sell more hardware is that you will do it later, not now?

If we only allowed people to load pfSense on hw that we sell,or have sold, you would have a point. Since we don't even attempt same, my point stands.

That point no makes sense as this decision cuts out a lot of the cheaper hardware people ran pfSense on previously so when they look at their options now your own lower priced stuff becomes more attractive and oh yes it has AES-NI and is fully compatible.

This really feels like a long con to get people to upgrade their hardware to a pfSense unit.

Re: PfSense 2.5 and AES-NI

#57
post #47
post #43

Earlier quoted context omitted.

The expressobin board has 3 NICs, runs a dual-core Marvell 3700, which is ARMv8, and has a crypto-offload on the SoC. It sells for $49 on Amazon. https://www.amazon.com/dp/B06Y3V2FBK AES-GCM runs quite well on ARMv8: https://www.rsaconference.com/writable/presentations/file_up...

That's an interesting board, but it still only has one Ethernet interface, plus an on-board switch.

It has two, actually. I'm looking at the 3700 and some of the NXP CPUs for a 2018 "microfirewall".

We have a 3 port ARM board (one port has a switch on it) being announced on Thursday.

Re: PfSense 2.5 and AES-NI

#58
post #23

This may be a good time to try a new relative open source product. OPNSense is a fork of PFSense with some philosophical and practical differences. Here are some notes on what and why https://docs.opnsense.org/fork/thefork.html

Oh yes, OPNsense. Those sure are some philosophical and practical differences. Differences as in: - code theft - copyright abuse - attempt to steal pfSense trademark in Europe - toxic project members who publicly attack anyone who dares to point out issues (including assault on all major pfSense developers). - hiding serious vulnerabilities - downplaying serious vulnerabilities Oh yes, that's a very different project…

I have read your comments, visited your linked website. I think you may have some points.. To be clear I am testing OPNSense now for the first time. I thought their license is Apache. I will consider your points during my testing. I will also continue reading your posts on reddit and compare it to testing and repository data. Thank you for your comment, though somewhat harsh.

Re: PfSense 2.5 and AES-NI

#59
post #47
post #43

Earlier quoted context omitted.

The expressobin board has 3 NICs, runs a dual-core Marvell 3700, which is ARMv8, and has a crypto-offload on the SoC. It sells for $49 on Amazon. https://www.amazon.com/dp/B06Y3V2FBK AES-GCM runs quite well on ARMv8: https://www.rsaconference.com/writable/presentations/file_up...

That's an interesting board, but it still only has one Ethernet interface, plus an on-board switch.

The device has 3 ethernet interfaces - one directly connected to the SoC, and the other two via an onboard switch.
Post reply on HN