> A full-stack PHP framework delivered as a C-extension!
I mean, I've can't even begin to imagine how insecure that awful combination of insecure by default languages is.
But, looking at: https://docs.opnsense.org/development/architecture.html It seems that it's mostly just the frontend that's php, or am I missing something?
> I mean, I've can't even begin to imagine how insecure that awful combination of insecure by default languages is.
What is inherently insecure about PHP? Or Phalcon? Do they have vulnerabilities that other C programs don't have?
C programs are often exposed to classes of vulnerability owing to weaker safety guarantees see[2]
[2] https://msrc-blog.microsoft.com/2019/07/22/why-rust-for-safe...
OPNSense also splits front-end into the MVC and control layer, as well as the back-end between the control layer and the configuration daemon which is written in python.
All of the actual packet processing and daemons are C or C++, essentially the standard packages you'd find in FreeBSD.
Whether PHP or C is more secure depends on who wrote it.
While I haven't really done any hardcode PHP work after PHP5 came out, there are plenty of ways to do it wrong, and a few ways to do it right. One thing is separation of concerns and encapsulation to the point where a fault in PHP can only mess up the PHP part and not the external system PHP calls into to ask for configuration changes.
Currently, a lot of the old pfSense code has been removed and replaced with code in the MVC framework, but it's a lot of work, and the team behind open-source OPNSense isn't huge. It will take time to cover it all.
My main reasons were that it did everything I wanted pfSense to do, something about the UI felt a bit smoother to me, and it didn't have the smarmy/wonky feeling that pfSense does (aggressive company behavior, closed-ish stuff, and then post-switch the Wireguard stuff happened).
I'm running this on a Protectli FW4B and have been quite happy. It's still doing exactly what I wanted, updates have been good, a bug I reported got fixed quickly, and it's... just working.
Also, by going to open hardware (and not the Netgate stuff I was originally thinking of) I can switch to another platform (eg: Untangle, OpenBSD) if desired.
But, for the forseeable future, OPNsense seems to be working just fine. <shrug>
I also had a very frustrating ARP bug where ARP broadcasts wouldn't work across mesh'd APs (https://www.reddit.com/r/UNIFI/comments/ghs4bg/arp_for_clien...).
Then there was just some various other quirkyness/weirdness, and I happened to get out just before the big security breach was disclosed.
I ended up going to a Ruckus R610 AP that I got via eBay running the Unleashed OS, and it's outstanding. Coverage is so good I no longer need my old AP + extra mesh'd one.
For switching I'm just using an old TP-Link that I had laying around.
UniFi seemed really neat at first, but then it just felt... overwraught. I don't need single-pane-of-glass monitoring of a ton of stuff for my home network. I don't want to run a management software server just for my home network. I do want something robust, but I don't want to worry about it, and I want to be able to piecemeal upgrade it. A small PC running OPNsense + a solid AP + just whatever for switching does exactly that.
(I'm not a homelab-type person... If I want that I use VMs, or my employer's hardware. I want my home network to be a solid, reliable utility that requires little maintenance. I don't want to be tweaking my home network after my day job.)
Note that Phalcon is a PHP extension (not a C extension) that provides new functionality available in the PHP runtime. This is roughly equivalent to a Ruby gem with a C extension, like Nokogiri.
Phalcon was at one point moderately well-regarded, though it's fallen out of favor for a wide variety of reasons, mostly the PHP development style moving on. I say this because as near as I can tell, Phalcon has had an entire single CVE in its entire decade plus of active development.
Casual anti-PHP bigotry isn't just uninformed, its harmful.
Just means anyone who wants to try OpenBSD should spec something a little more powerful than that appliance.
Only issue I've had is that if it's a J1900 Celeron CPU, ensure you have the machine set to boot via UEFI before installing. (IIRC there's an open issue for FreeBSD installations failing to legacy boot on J1900 boards.)
In all cases I’d double check the individual chipset by doing a quick search on the forums whether you decide to go pf or opn.
PfSense offers a range of hardware they support, which disproves your assertion by itself without even mentioning companies like Apple and System76.
> one of the appliances that opnsense sells. Just expect to pay a premium to be lazy.
I'm totally willing to pay a premium to be lazy. Where did I imply otherwise? If OPNsense offers hardware these days then why didn't anyone just say so?
That disproves nothing. If you want to build your own system you need to research hardware if you want to have a pain free deployment.
> I'm totally willing to pay a premium to be lazy. Where did I imply otherwise? If OPNsense offers hardware these days then why didn't anyone just say so?
This forum is generally filled with people who want to build their own. As for why nobody mentioned they sell hardware: probably because they sold hardware from the beginning and it’s advertised all over their site?
Again, I said nothing about building my own.
> This forum is generally filled with people who want to build their own.
This forum is generally filled with people with a lot of qualities. For instance, there are a lot of people here who buy Apple products, which are very much not in the spirit of building one's own. Your assumption doesn't make a lot of sense to me.
> As for why nobody mentioned they sell hardware: probably because they sold hardware from the beginning and it’s advertised all over their site?
That's fair, I haven't looked at their site in ages because the last time I used OPNsense was after the very initial split and to my recollection there was no hardware then.
----
0: https://www.servethehome.com/buyers-guides/top-hardware-comp...
1: https://www.freebsd.org/cgi/man.cgi?query=cxgbe&sektion=4
Does the OPNsense project recommend or endorse any specific models of low-power all-in-one computer hardware for running OPNsense? And if no, is there any specific thing the community would recommend?
I don't want to spend hours on research or build something on Newegg. I want to by a complete piece of hardware that I install OPNsense on and know that I won't have to worry about hardware compatibility.
PS: Apparently OPNsense offers their own appliances these days just like PfSense does.
How does security patching compare?
Migration is really a complete reinstall and rebuild of your rules. I took a backup of my physical pfsense box and restored it to a VM then reinstalled opnsense on the physical hardware. With the pf box running in a vm I could just reference it while creating new rules.
I think someone made a script to load a pfsense backup onto an opnsense instance but I really think you’re better off with a clean slate.
Kind of a pain, sure, but I felt better knowing it was a fresh build and everything was where it should be.