Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

None of the above.

Run pfSense on an old x86 box and you'll end up with something an order of magnitude better. As far as an access point goes I'd suggest going with ubiquiti gear if it's in your budget.



There are huge disadvantages in using old x86 boxes, like size, noise, power consumption, lack of ethernet ports and so on.

If you wanted to sensibly advise using pfsense you could point at the zrouter project http://zrouter.org/projects/zrouter/wiki/Supported_devices


I do not think those disadvantages apply in most cases. Back when DSL was new I used an old 486 for many years, this is not new territory for me.

Size is irrelevant unless you're putting it in your entertainment center (why?) or live on a sailboat. Just stick it in the basement, stack on top of the fileserver, whatever. If you're doing the dorm room thing or living aboard a sailboat you have to realize that involves some highly unusual lifestyle compromises. For most people its not an issue.

Noise: I did splurge on some large slow fans (like $10) to replace old small fast (LOUD) fans. Again this is a lifestyle thing, where if your castle has no location further than 5 feet from your sleeping head, you're going to have serious lifestyle issues that most people simply will not have. I don't find my desktop at home or work to be particularly loud. I did at one time run a more modern desktop as a firewall and specifically ripped out the fancy graphic card and used the on board video, to reduce noise a little. After installation I never used the video or keyboard again, all SSH access, so its not like it needed fancy graphics. My main firewall/wifi/dhcp/asterisk/stuff/etc box is about 50 walking feet from my sleeping head, past the (sometimes) loud fridge, the dishwasher, the clothes dryer, the hot water heater... For most people its not going to be an issue.

Power consumption. Not an issue. I was drawing about 50 watts which will cost about $50 or about 3 weeks of cablemodem service per year. Using the EE tradition of it costs about $1 to provide 1 watt for one year. I admit I was an idiot and upgraded to a soekris box many years ago which is basically a 5 watt PC. So I save about $45 per year of damage to my finances and the environment. Great, that'll only take like ten years to pay off the capital expense / manufacturing environmental degradation. That was a dumb move on my part and I'd suggest you're always better off both financially and environmentally by reusing an old desktop.

Lack of ethernet ports (LOL, serious? Plug in another board?)


>Size is irrelevant unless you're putting it in your entertainment center (why?) or live on a sailboat.

No, it's not. If you're using *DSL (including FTTC) then how much space you have available depends on where your phone line enters your house, for instance.

My lines comes in, from a pole in the alley behind my house, to my kitchen and the master socket is by my kitchen door in the hall. I certainly don't have room for a large box there, but a typical router fits nicely.


A laptop is a good option for x86 network stuff. Relatively low power with a battery back-up. I would never use a desktop PC, too expensive.


Do many laptops have multiple ethernet ports?


multiple usb ports


USB ethernet is very sucky.


I set this up recently and really like it a lot. I had an ASUS AC66U as my home gateway/firewall/router/wap which was beginning to struggle with the crazy home lab setup I was concocting.

pfSense is radical. It's like OpenWRT in that it's a self-contained router/firewall/etc... operating system, with great gui and cli management tools. It's based on FreeBSD and has a very active community of developers and users. There's even a pretty cool subreddit for it: http://reddit.com/r/pfsense

One of the unexpected side-effects of the pfSense box was seeing my internet speeds increase significantly. The only variable that I changed was from the ASUS router to an older system running pfSense. In both scenarios I was hardwired using cat6. Prior to pfSense I would get ~20mbps down and now I am hitting ~30 with no problems.

I've got it setup with a dual gigabit nic. The motherboard ethernet port goes to my cable modem for WAN, and each port on the gig nic corresponds with my LAN and LAB subnets. LAN goes to my house, wifi devices, etc... and the LAB subnet is for my servers.

It's nice having an ipsec VPN running that I can connect to when on the road. For example, I'm in California right now for the holidays and can still hit my Freenas box for file storage/backups that is 3,000 miles away in Northern Virginia.

I built a rack for the setup, you can see the black pfSense box down below: http://instagram.com/p/g4JuvrBf7N/

It's an older Compaq/AMD Sempron system that I refurbished a bit. After installing the HP dual-gig nic, I also threw in a cheap SSD and upgraded the processor to a dual-core AMD Athlon. It was like $6 on Amazon.

Here's a video that I made explaining some of it, for those who are curious: https://www.youtube.com/watch?v=O8Lk07vi98o

---

Alternatively, there's some cool hardware out there that is more custom/indie such as Mikrotik (http://www.mikrotik.com) or Netgate (http://store.netgate.com)


"Run pfSense on an old x86 box"

I will one up that with: run pfsense on an old s86 laptop with two pcmcia card slots. Because xircom realport.

Because it is a laptop you'll never need KVM because KVM is built-in - no more fiddling with the com port or lugging over a monitor, etc. (also, built-in UPS is a nice bonus).

But my favorite part is that by using two xircom realport LAN cards[1], you end up with a device with three full size rj45 ports on it (assuming the laptop itself has one).

It's cute and sexy to have some tiny little embedded board, but the laptop wins for usability by a wide margin.

[1] http://reviews.cnet.com/adapters-nics/xircom-realport-2-card...


Good answer.

Although you do not even need pfSense. You just need a BSD with pf. You can run your own customized BSD image with a Soekris or Alix board.

Can you run BSD with Ubiquiti's boards? What if I do not want a Linux-based system? There is no GNU pf.


Or just run OpenBSD so you get the current pf version with new stuff in 5.3.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: