Live data from Hacker News

OPNsense: Open-source security platform

opnsense.org

21–30 of 151 posts

Re: OPNsense: Open-source security platform

#22
post #11

What kind of hardware do you use to install OPNsense? Please don't suggest to buy some old Dell optiplex from ebay. Hardware that can beat any commercial vendor, is better.

You say "don't suggest to buy some old Dell Optiplex from eBay" but I did exactly this. I spent $43.97 (which included shipping) for the Optiplex, added a 2 port NIC for $16.37, and it's been running my house great since then.

The main issue I see with that option is space and power, the micro-form factor (NUC-sized) clone systems that people are discussing in here are quite nice for that. Functionally an old Dell tower should be fine.

Re: OPNsense: Open-source security platform

#23
post #2

As an alternative, I've been watching VyOS with great interest and it seems like they are finally going to release their controller and LocalUI interface this year, which is exciting. It seems to have a similar architecture as a Ubiquiti controller. https://blog.vyos.io/

I always wanted to try it, but $8k / year for the cheapest stable release license isn’t in my universe for affordability. > It seems to have a similar architecture as a Ubiquiti controller. That’s a hell of an insult to be tossing around for an unreleased product. Lmao.

Why’s that? I actually like the api system for Ubiquiti gear.

Re: OPNsense: Open-source security platform

#24

Earlier quoted context omitted.

You say "don't suggest to buy some old Dell Optiplex from eBay" but I did exactly this. I spent $43.97 (which included shipping) for the Optiplex, added a 2 port NIC for $16.37, and it's been running my house great since then.

The main issue I see with that option is space and power, the micro-form factor (NUC-sized) clone systems that people are discussing in here are quite nice for that. Functionally an old Dell tower should be fine.

Sure, but those tend to be much more expensive, so depending on the actual cost of electricity in your area, it may take a long time for you to break even.

However, if you want to have a really small appliance-like pc, then yeah, the NUC-sized ones are much better.

Re: OPNsense: Open-source security platform

#25
post #4

OPNsense is the core router platform I default to for all my network infrastructure (work devops env, homelab, vpn to family members etc). Its feature packed and ROCK solid. I almost always run it in a virtual machine so i can live migrate it between hosts and have no downtime. The cluster / high availability works great and ensures no loss of connectivity during upgrades. OPNsense is a true hidden gem in the open so…

I used to find it rock solid, but around two years ago reliability tanked. I found myself regularly having issues with interfaces (a genuine Intel server-grade multi-port NIC) flip-flopping. About a year ago, I started having random issues with traffic no longer routing, out of the blue. Lately both issues seem to have gone away.

Right now the software update function dies half the time I try to run a check, with a long sqlite query string / error being dumped to the console. This has been going on for at least the last couple of months worth of releases.

About a year or two after install, reboots and power-offs stopped working. The system just hangs instead after printing out a message about USB, and I cannot figure out for the life of me what's wrong. It's a standard Dell SFF PC, nothing exotic, and had been working fine until a major release broke it. FreeBSD's documentation about ACPI is impenetrable, so I can't figure out what's going on.

Startups and reboots used to be lightning quick, with maybe a minute or less between the bootloader kicking off loading the kernel and interfaces/routing/firewall up and it giving its happy chime. These days the system spins its wheels for ages doing...something, not sure what.

I find the project pretty outdated and behind the times. The UI purposefully obtuse with terrible organization and field names and a lot of missing help text to keep their support/consulting biz strong.

They're really far behind on features. There's no application blocking, monitoring/diag is rudimentary, it has extremely limited backup functions (Google Drive and that's it, I believe), and even the DNS blocklist functionality is extremely rudimentary, with only a fixed list of really trashy, unreliably lists available to pick from (one of the groups they pull lists from has demonstrated extensive issues with QA, routinely including things like certificate validation servers in their blacklists.) They've also gone out of their way to make the Adguard Home plugin annoying and confusing to get working if you want to configure it as a proxy to unbound, which is needed if you want DHCP hostname records to work (speaking of which, DHCP leases are needlessly obtuse to mange.)

Their release process is wildly unsuitable for production network equipment. A 'major' release is immediately EOL'd as soon as the next major release comes out. Running 20.1 and need to stay on it because 20.2 breaks something or you want to wait for the dust to settle? Too bad. There's no security releases for older major revisions. And it wouldn't be so bad if each major release was followed by a number of "oops we fucked up...." point-point releases because their QA isn't very good.

The devs are sticks in the mud, too - mostly "franco." They bitched and moaned up a storm for YEARS about wireguard being "insecure" despite no evidence to back their claims, citing that as the reason for refusing numerous requests for integration, and even refusing code contributions from the community for it. They eventually caved. The wireguard plugin is still pretty meh and difficult to navigate unless you know wireguard well.

ARM support? Zero interest in even assisting community efforts, which have gotten impressively far with it, especially now that ARM support in FreeBSD got appreciably better in the last release or two. I suspect it's because they see it as a threat to their (grossly overpriced) hardware offerings.

The list goes on.

They forked pfSense (a good thing, the pfSense devs were being massive dicks) but seem to now be largely on "cruise control" and leveraging community goodwill.

Re: OPNsense: Open-source security platform

#26
post #2

As an alternative, I've been watching VyOS with great interest and it seems like they are finally going to release their controller and LocalUI interface this year, which is exciting. It seems to have a similar architecture as a Ubiquiti controller. https://blog.vyos.io/

ubiquiti indeed ran vyos underneath then improved it over the years

Re: OPNsense: Open-source security platform

#27
post #13

Earlier quoted context omitted.

I did a bare metal migration and it was pretty painless. Had to reinstall some packages, but it was as simple as just hitting the + on the package manager.

Yes! The single file xml config export is super easy to move an install between systems (physical and virtual). There is even a plugin to manage the changes with git!

Every time I've given up on an OPNsense instance and re-installed it, importing a config backup, half the config didn't import. Maybe things are better these days.

Re: OPNsense: Open-source security platform

#28

Recently transitioned from Ubiquit stuff to a OPNSense setup. It was such a good decision. The firewall rules make much more sense. Better functions than the dream machine series. You can also get a lot more for the same price. Ubiquti hardware is very under spec for the money you pay for. Highly recommend this guide to setup your own. It’s very dense and more verbose than you need so skip the irrelevant sections. [1…

I’ve been thinking about swapping out my UDMP for opnsense, but keeping the ubiquiti APs, they’re the best I’ve ever known and I think they play reasonably well with non-ubiquiti stuff. Thanks for the link to the guide!

Re: OPNsense: Open-source security platform

#29
post #19
post #11

What kind of hardware do you use to install OPNsense? Please don't suggest to buy some old Dell optiplex from ebay. Hardware that can beat any commercial vendor, is better.

I run mine on HP’s version of an optiplex with a 2nd hand pcie 1Gb quad nic, but if you wanted nicer “real” hardware with a proven track record, an HP microserver gen10 or gen10+ can be had on eBay for very little. A gen10+ should even come with iLo, which is nice.

Yeah, parent commenter is being a crank. If you want "real" hardware, but (insert 1U hardware from Lenovo, HP, Dell, or Supermicro here.)

I've had it running on a dell SFF desktop for years.

Re: OPNsense: Open-source security platform

#30

Earlier quoted context omitted.

The main issue I see with that option is space and power, the micro-form factor (NUC-sized) clone systems that people are discussing in here are quite nice for that. Functionally an old Dell tower should be fine.

Sure, but those tend to be much more expensive, so depending on the actual cost of electricity in your area, it may take a long time for you to break even. However, if you want to have a really small appliance-like pc, then yeah, the NUC-sized ones are much better.

The low-power AMD based systems everyone recommended a couple years ago were indeed great, until the ebay resellers realized what was going on and started slapping "opnsense pfsense AES-NI" etc on their listings and doubled their prices. The systems went from selling at $40-50 to over $100.

Also, the AMD processor in those systems is getting extremely long in the tooth.

Post reply on HN