OpenBSD Router Guide (2020)
openbsdrouterguide.net
openbsdrouterguide.net
Those of us building our own routers (I've done so since about 2006 when I got 1Gbps fibre installed for the first time) usually have a quite large cross-section with people on bleeding edge internet connections, and with (pro-)consumer 10Gbps internet and networking becoming more and more common a router capable of such is also more relevant. I see very little information about what's the minimal/cost effective hardware requirements capable of routing with NAT at wirespeed for these applications. Most of the content I read is either geared towards slower speeds (e.g. 1Gbps) or using overly beefy machines which are both power hungry and most likely overkill for the purpose.
Something that would be interesting to see as well is high speed NAT routing performance comparison between Linux, NetBSD, OpenBSD and FreeBSD using Intel or other well supported 10Gbps nics.
DPDK network HBAs have been out for several years now and 25/50/100 is replacing 10 in the datacenter. Maybe there's some deals available on ebay? Quick glance, an Intel X520 is available for ~90 USD.
Various NAT-related perf tests: https://docs.fd.io/csit/master/report/vpp_performance_tests/...
Disclaimer: I am involved with the project
1. Get a Xeon D box (like a Supermicro X10SDV-TLN4F, TDP 45W).
2. Install any Linux distribution on it and just use iptables/nftables. It's good enough.
3. You now have a normal Linux box with normal userspace networking, feel free to also run some more services on it without having to deal with DPDK getting in your way.
DPDK is nice and all if you absolutely need to scream through tiny packets at multi-dozen-gigabit speeds, but you almost certainly don't need it at home for Netflix and seeding Ubuntu ISOs.
This can't be true for video gamers? I'd assume most video game protocols are tiny UDP packets.
But maybe video game protocols don't need "wirespeed", since they're actually quite efficient in terms of bytes transferred. But you want to minimize latency.
Or ubiquity ER-8-XG.
I already have an OpenBSD firewall running on a PC Engines APU 2. Despite this, I still learned a few things from this guide (namely that urpf-failed already handles antispoof and that scrub shouldn't just be littered without any consideration).
I was actually impressed at how well things perform despite the BKL of OpenBSD. I have only a 350Mbps down 35Mbps up connection and OpenBSD is nowhere near being a bottleneck.
Here's a writeup I did last year but it doesn't touch on OpenBSD: https://0x85.org/ubiquiti.html
I'm mostly over BSD in general. I don't know why, given that Debian exists and performs much better, I'd reach for BSD unless it had support for some esoteric hardware that Linux doesn't support.
1) DNS reflection was an issue for some internal services I host. 2) Connecting to my Virgin Media (uk) router and handling PPPoE was confusing and I struggled with the documentation. 3) Just in general, having an internet connection is really importaint to troubleshooting problems. Having my internet down while trying to fix things was just too inconvenient for me.
In the end, I went back to PfSense. I have a bash script that backs up the config daily to s3. Was good enough to recover from a different issue recently. It's a real shame, I'd love to do this all my self but I may never pick this project back up.
I'm running pfsense now because I'm nothing if not lazy, but if opnsense makes things nicer in some way, I'd like to hear it!
I have a Superhub 3.0. In modem-only mode there's no PPPoE, it just rather transparently acts like you have an ethernet cable running to your ISP. Just putting dhcp in my hostname.em0 works exactly as intended and my router gets assigned the public IP address.
shark# cat /etc/hostname.pppoe0
inet 0.0.0.0 255.255.255.255 NONE \
pppoedev em0 authproto chap \
authname '<username>' authkey '<my_password>' up
dest 0.0.0.1
!/sbin/route delete default
!/sbin/route add default -ifp pppoe0 0.0.0.1
shark# cat /etc/hostname.em0
up
shark#This book by Tony Mancill used to be an excellent guide for Linux routers but now after 20 years it is already obselete [1].
[1]https://www.amazon.com/Linux-Routers-Primer-Network-Administ...
$ uname -a
OpenBSD XXXXX 6.9 GENERIC.MP#3 amd64
$top
load averages: 0.83, 0.62, 0.44
94 processes: 93 idle, 1 on processor
CPU00 states: 0.5% user, 0.0% nice, 0.2% sys, 0.3% spin, 0.6% intr, 98.4% idle
CPU02 states: 6.5% user, 0.0% nice, 1.9% sys, 0.4% spin, 0.0% intr, 91.1% idle
CPU04 states: 4.9% user, 0.0% nice, 1.6% sys, 0.3% spin, 0.0% intr, 93.1% idle
CPU06 states: 4.0% user, 0.0% nice, 1.1% sys, 0.3% spin, 0.0% intr, 94.6% idle
CPU08 states: 1.4% user, 0.0% nice, 0.6% sys, 0.2% spin, 0.0% intr, 97.8% idle
CPU10 states: 1.4% user, 0.0% nice, 0.5% sys, 0.2% spin, 0.0% intr, 98.0% idle
CPU12 states: 0.6% user, 0.0% nice, 0.3% sys, 0.1% spin, 0.0% intr, 99.0% idle
CPU14 states: 0.7% user, 0.0% nice, 0.3% sys, 0.1% spin, 0.0% intr, 98.8% idle
Memory: Real: 3292M/5988M act/tot Free: 9109M Cache: 1692M Swap: 0K/15GTo the grandparent: PF is still single threaded. If you had performance issues with that before you may still have them, but CPU improvements over time may have negated that impact. It's worth trying it out again.
SD-WAN, DLP, Application-aware filtering, etc
I think the main blocker for OpenBSD in the commercial market is the inability to load binary blob drivers without maintaining a custom kernel.
This is known since April https://forum.opnsense.org/index.php?topic=22761.0 and confirmed there https://forum.opnsense.org/index.php?topic=24112.0
One would think, since OpenBSD is BSD licensed, it would be more likely to have vendorized forks available on the marketplace. Companies being obliged to share their code is allegedly a disadvantage of GPL-licenced Linux. But with OpenBSD, there are no prominent commercial forks. The one "active" OpenBSD fork today is HyperbolaBSD, and it hasn't made a single release yet after 2 years. Previous attempts at OpenBSD forks have failed (Bitrig, ÆrieBSD). Somehow, OpenBSD appears to be less fork-able than other BSDs.
Why does the OpenBSD project subvert our expectations of a BSD-licenced OS?
I'm asking as someone who had a positive experience setting up an OpenBSD router and VPN, but not much beyond that.
There are companies that build commercial (virtual) firewall appliances based on OpenBSD. But they do not publish an open source, BSD-licensed, operating system.
https://en.m.wikipedia.org/wiki/List_of_products_based_on_Fr...