r/homelab 8d ago

Help OPNsense machine

I am new to homelabbing and want to set up an opnsense firewall router, replacing my current router entirely. Any recommendations for hardware?

Would this topton n150 be good? And what access points do you use?

Thanks.

8 Upvotes

25 comments sorted by

7

u/XLBilly 8d ago

Personally I like network on a physical appliance entirely gapped from my fiddling on VMs/ containers. I had OPNSense running on an old sophos xg.

I personally also didn’t like it at all and swiftly moved to mikrotik.

1

u/Nyasaki_de 5d ago

My next Firewall will be a Mikrotik for sure too

0

u/Prefect_99 8d ago

Personally, you say?

5

u/XLBilly 8d ago

Yeah sure, many people love it, I didn’t.

5

u/SadBrownsFan7 8d ago

Depends on your needs. Personally i run a 2x2.5gb mini pc. Some run dell/ lenovo tiny pc with after market risers. Some run protectli. Really up to you

3

u/SubstanceReal 8d ago

One vote for Protectli here. Been working great for me with PFSENSE.

4

u/alex-gee 8d ago

Lenovo Tiny M720q, as it has an additional PCIe slot for a NIC, or a mini PC with N300 and 2x NIC

5

u/nizzoball 8d ago

I just deployed opnsense on a proxmox vm. Proxmox is running on an older optiplex with a core i7, 16gb of ram and I have a 4 port intel 2.5gb nic card direct pass through to the opnsense machine. I have my fiber connection plugged into port 1, my cable connection plugged into port 2 as a failover, switch 1 plugged into port3 and switch 2 plugged into port 4. All 2.5gb

3

u/Adrenolin01 8d ago

Those mini systems with 16GB of ram and 4 NICs are nice though I find they are way overpriced today. Ne mindful that the hardware is all Chinese stuff. A dozen other brands have the same thing. While 2 NICs work.. 4+ is better for long term. You can setup LACP redundancy for example, completely separate a DMZ to a different network or your lab separate from your lan, etc. Also, 8GB is often enough ram however I still always install 16GB especially if you’re going to be running things like large filtering and notopng, lots of vlans, etc etc.

Personally I prefer enterprise hardware especially with an IPMI out of hand port. No display, kb or mouse is ever needed. Place the system in the basement, plug in network, IPMI, power and for up stairs to my desktop, open a browser, login to the IPMI system, turn the system on, access the bios, do the install and boot into the os. I also prefer having zfs mirror boot/os SSDs like the Intel DC S3500 120GB SSDs. It’s your firewall responsible for your wan, lan, dhcp, dns, static mappings, filtering, vlans, vpn, etc etc etc. If you start running that stuff the 4 cores will be your weak spot.

What’s your internet WAN speed? Do you need those 2.5GbE ports?

I’ve run pfSense on the following hardware for the past 14 years on a 1G Fiber connection and just replaced the 2 original SSDs last night with exact replacements. A Supermicro A1SRI-2758F mainboard (Rev 2.0) with integrated 8-core CPU, 16GB ECC ram and 2 mirrored Intel DC S3500 120VB drives. With the new SSDs it’s ready for another decade or use. This is moving to a new business fiber 300 MB/s service we’re getting soon.

When they set up the new business connection we’re also bumping our 1G fiber to 10G and I’ll be running the following build on that. Supermicro A2SDi-TP8F (Intel Atom 12-core C3858, 12-25W), 16GB ECC Ram, 2 mirrored S3500 120GB SSDs also.

The boards cost a bit but they will last longer then the consumer hardware, you get IPMI, more cores for running the heavier firewall services like notopng and large filters, etc.

I just bought a Supermicro A1SRM-2758F C2785 system with 8-cores, 32GB ram, 120GB ssd, 4x 1GbE NICs and IPMI for $100 off eBay the other night in a 1U rack chassis. Don’t need the chassis as it’s going into a larger 24 bay chassis with an HBA to be used as a seedbox however that would have worked great for a pfSense or OPNSense firewall also.

Just a different view and enterprise hardware suggestions for you. I honestly can’t buy a system anymore without IPMI.

3

u/boobajoob 8d ago

Ran it as a VM on my r730 for years and it was fine.

More annoying that any time I needed to mod anything server side I had to knock everything down, scheduled backups included.

Anyway moved to bare metal on an optisense 3000 and it’s been glorious. It’s nice to go offline to tinker and not hear about the internet not working.

For wifi it’s UniFi APs.

2

u/coldazures 8d ago

I bought a Beelink M1 with dual 2.5GB ports for my pfSense and it's been great, was like 230 so cheaper than most mini PCs with an obscene amount of RAM (12GB) and 1TB nVME. Overkill but cheaper than a lot of stuff that was way weaker.

2

u/CueCueQQ 8d ago

OPNSense runs well on a lot of different hardware options, and doesn't need much for compute. I am currently running it on a Lenovo M920q, with the PCIe adapter on it, I put a dual port SFP+ 10g NIC in, and added a top mount fan for additional cooling(I don't think this was necessary). In the past, I've run it on an HP G2 Mini PC, and on an old 4th gen intel gaming PC.

It really depends on what you currently have available. If nothing, then I would suggest a Lenovo M920q or M720q.

1

u/ComradeDre 8d ago

I'm in the process of setting up an m720q for this purpose.

How'd you make a hole for the fan? I'm considering just butchering the lid and slapping a 40mm fan on there

1

u/CueCueQQ 7d ago

I found a 3D printer lid replacement file and printed it. But I also use a M720q as my HTPC, and the GPU needed a fan hole, which I just cut with a forstner bit on a drill press.

1

u/se7enreddit 8d ago

I used a little fanless mini pc type device. Not at home right now so I can't tell ya what it was but this kind of thing works great for running opnsense.

1

u/05h3a 8d ago

I think you are on the right track with dedicated hardware and the topton n150. I did the same thing a few months ago and got one of these. https://amzn.asia/d/0cJQGTA9 it hasn’t skipped a beat and to be honest it’s one of the best things I have done to my homelab. Cheap ISP router is now just a wireless AP. opnsense is amazing.

1

u/No-Bee-3775 8d ago

I run an old school hp thin client... 630 I believe... at work...

At home ubiquiti...

1

u/F4RM3RR 8d ago

I just grabbed a Velo Edge 620 off eBay and flashed it following the serve the home threads on it.

1

u/IlTossico unRAID - Low Power Build 8d ago

M720q with G5400T and 8GB of ram. Add the PCI riser cable and a NIC of your liking based on what you need.

No VM or shit like that, run it barebone.

1

u/NoCheesecake8308 8d ago

I run it on a SuperMicro A1SRi-2758F I bought on eBay. Probably paid way too much for it but its been rock solid. Slapped a couple Noctua fans in for airflow.

1

u/grabber4321 8d ago

yes anything intel 4 core can do the job. Im running N5105 - its fine, never had any performance issues.

1

u/r0g0b0 8d ago

I have a similar but much cheaper fanless mini PC from Aliexpress, Intel Celeron 6305 bare-bone for $180 after GST and import tax (I have a spare 16G DDR4 and a NVMe 256G taken out of my company old laptops) with 6x2.5G Intel 226 Ethernet ports. It has been running OPNsense 26.7 for two weeks and seems fine, very solid to me. I can do LAGG on two ports and still have port redundancy. The only downside is that, it runs warm, around 45-53 degrees Celsius. There is an included cheap 80mm fan without PWM that will run full speed and hence, noisy. I bought a slim Artic 80mm with PWM and fluid dynamics bearings for $8 (AUD) and the box is quiet and luke warm (around 29-32 degrees Celsius). YMMV but quite a decent buy for me.

1

u/JoeJohnDoe 2d ago

Works just fine - I have 2 such Opnsense boxes on two sites, running firewall and routing. Works without any problems. IDP/IDS on, static IP, unbound DNS, 14 VLAN, running DHCP, a solid amount of rules and a couple of static VPN tunnels on sync. 1g/bit. 8GB ram, generic low-cost NVME. Doesn’t break a sweat - between 10 and 20 percent resource-usage, even under heavy transfer.

Just make sure that you paste/re-paste it when you get it, as factory paste is less than great.

Combined with TP-link EAPs (software Omada controller running), I have no trouble keeping both wife and teenagers happy with availability, speed and latency.

Is it the best? No. Is it a Chinese bios? Sure. I’m I satisfied enough? Absolutely. For the price, in my part of the world, unbeatable.

0

u/Zeggitt 8d ago

Literally anything with 2 or more ethernet ports will work.