Live data from Hacker News

OPNsense: Open-source security platform

opnsense.org

11–20 of 151 posts

Re: OPNsense: Open-source security platform

#13
post #4

OPNsense is the core router platform I default to for all my network infrastructure (work devops env, homelab, vpn to family members etc). Its feature packed and ROCK solid. I almost always run it in a virtual machine so i can live migrate it between hosts and have no downtime. The cluster / high availability works great and ensures no loss of connectivity during upgrades. OPNsense is a true hidden gem in the open so…

I did a bare metal migration and it was pretty painless. Had to reinstall some packages, but it was as simple as just hitting the + on the package manager.

Yes! The single file xml config export is super easy to move an install between systems (physical and virtual). There is even a plugin to manage the changes with git!

Re: OPNsense: Open-source security platform

#14
post #4

OPNsense is the core router platform I default to for all my network infrastructure (work devops env, homelab, vpn to family members etc). Its feature packed and ROCK solid. I almost always run it in a virtual machine so i can live migrate it between hosts and have no downtime. The cluster / high availability works great and ensures no loss of connectivity during upgrades. OPNsense is a true hidden gem in the open so…

Has there been a positive inflection in its quality recently? I tried it a while back but pretty quickly it got Unbound's config XML in a state which wouldn't allow the daemon to run. I had to get in and fix it up by hand to get it going again. Wasn't impressed with the quality it was showing me, switched to pfSense and haven't had any similar issues, so I haven't felt the need to look at OPNsense again.

Re: OPNsense: Open-source security platform

#15
post #11

What kind of hardware do you use to install OPNsense? Please don't suggest to buy some old Dell optiplex from ebay. Hardware that can beat any commercial vendor, is better.

There’s this class of devices: https://www.servethehome.com/cheap-intel-pentium-n6005-4x-2-... I have one of them, they’re great. I haven’t checked hardware support on FreeBSD as I run Linux so please do your own research.

Re: OPNsense: Open-source security platform

#16
post #2

As an alternative, I've been watching VyOS with great interest and it seems like they are finally going to release their controller and LocalUI interface this year, which is exciting. It seems to have a similar architecture as a Ubiquiti controller. https://blog.vyos.io/

I always wanted to try it, but $8k / year for the cheapest stable release license isn’t in my universe for affordability.

> It seems to have a similar architecture as a Ubiquiti controller.

That’s a hell of an insult to be tossing around for an unreleased product. Lmao.

Re: OPNsense: Open-source security platform

#17
post #11

What kind of hardware do you use to install OPNsense? Please don't suggest to buy some old Dell optiplex from ebay. Hardware that can beat any commercial vendor, is better.

You say "don't suggest to buy some old Dell Optiplex from eBay" but I did exactly this.

I spent $43.97 (which included shipping) for the Optiplex, added a 2 port NIC for $16.37, and it's been running my house great since then.

Re: OPNsense: Open-source security platform

#18
post #3

Pfense is practically no longer open source. OPNsense has come a long way and even has some features pfsense does not

PfSense has some pretty bad problems relating to interfaces disappearing temporarily and services dying from it. I would go as far as saying 2.6.0 is unreliable.

With PCEngines shutting down it’s almost impossible to find reliable, cost effective hardware. I hope pfSense gets back on track because their hardware seems ok.

Re: OPNsense: Open-source security platform

#19
post #11

What kind of hardware do you use to install OPNsense? Please don't suggest to buy some old Dell optiplex from ebay. Hardware that can beat any commercial vendor, is better.

I run mine on HP’s version of an optiplex with a 2nd hand pcie 1Gb quad nic, but if you wanted nicer “real” hardware with a proven track record, an HP microserver gen10 or gen10+ can be had on eBay for very little. A gen10+ should even come with iLo, which is nice.

Re: OPNsense: Open-source security platform

#20
post #11

What kind of hardware do you use to install OPNsense? Please don't suggest to buy some old Dell optiplex from ebay. Hardware that can beat any commercial vendor, is better.

I just got a Protectli Vault FW4B to run it on. I wanted something small and fanless. Didn't even realize Celeron's were still made. Been running it 2 years now with no problems. Even that hardware (8GB RAM / 32GB msata) is overkill for home network.

Protectli was nice to buy from, but I do think there's a lot of similar options.

https://protectli.com/product/fw4b/

Post reply on HN