Fanless Intel J4125 4x I225 Virtualized Firewall Appliance Review
servethehome.com
servethehome.com
I've used Protectli and PC Engines boxes before, which have been great. I'm definitely leaving some value/performance on the table compared to the hardware described in this article. I also know that Protectli hardware in particular is supposed to be identical to some of the Aliexpress boxes, at a higher price. But at least I have some assurance that the company behind the hardware has a reputation at stake and will hopefully stand behind their products.
Recently I picked up their fairly high-end DEC750 which is based on their Netboard A10 Gen 3 board, which uses an AMD Ryzen Embdedded V1500B, VLP LPDDR4 unregistered ECC memory, has an M.2 socket with a PCIe x4 NVMe SSD, three Intel i210 ports and two SFP+ ports.
Idles at 8W, about 16-17W at full tilt either pushing 10Gbps through it, or nearly 2Gbps of IPSec traffic. With much lower latency (54us) than the 150us they provide in the specs. Once Wireguard is in kernel space, I'd expect around 2Gbps using Wireguard as well (more around 900Mbps right now with it in userspace). Barely gets warm to the touch.
The DEC700 series are meant to be on a desktop or shelf, but they make a rackmount version as well. There's also older devices using AMD EPYC Embedded. Nothing they make is cheap, but it's very high quality, very high performance kit coming from an organization I trust. With my DEC750, I figure I'm good until 203x.
ASRock has a Ryzen Embedded NUC, but with Realtek NICs, questionable BIOS and not much of a focus on Linux/BSD.
HP t740 thin client with Ryzen Embedded is closer to Mac Mini size, with PCIe slot for low-profile NIC.
You can read more about that specific Netboard here: https://www.deciso.com/netboard-a10-gen3/
Do they mean an extra M.2 slot?
> 2x integrated 10Gbps SFP+
A rare usage of Ryzen's 10Gbps IP block, https://en.wikichip.org/wiki/amd/ryzen_embedded/v1500b#Netwo...
Their previous generation hardware looks like an upscale version of PC Engines APU2, similar CPU, more RAM, better case. Does it support coreboot? https://shop.opnsense.com/product/dec695-opnsense-desktop-se...
NixOS is a hard requirement in my lab, so no plans to use OPNSense or any other BSD at this time. The Deciso hardware page says that “Linux” is supported so I might give it a try.
Uh oh.
Also, if you need that much memory in a firewall, its queues are too big and you're adding substantial latency.
FWIW, I'm not using it as bare OS firewall. Instead, it's running Debian with pfSense in a VM with 2 passthrough NICs (though I'm considering replacing Debian with Proxmox).
It sounds like this one might fall into either the "doesn't work right" case or the "only works right with certain modules" case. It could also just be strain on the memory controller and need to be either slower RAM or ultra fast RAM that will cap out at a much lower than rated speed in the box instead of middle rung RAM which doesn't handle being run in strained scenarios at full speed well.
I don't usually go out of my way to stick more in than is supported unless I can find reliable reports from others that get it working or just happen to have the sticks sitting next to me but I have been very successful going over the spec sheet limits and still passing a day of memtesting (and then years of use). Particularly for laptops and embedded class CPUs, not so much in desktop or server CPUs.
Maybe it's stateful and you've got a whole lot of connections? Or in this case, they're planning to run VMs and things on the box, so might need more ram for that.
It replaced an enterprise-grade Mikrotik router, which while no doubt being more performant (it has hardware offload for routing/firewall), was a pain to configure and certain scenarios are almost impossible to implement (WAN failover where one of the WAN interfaces is a PPPoE link) on it where as in OpenWrt they work out of the box.
The lack of hardware offloading for firewall/routing doesn't seem to be an issue in practice for gigabit links.
Generally CPU is more about PPS than bandwidth, any of this 4000 or 6000 series intel chips seem plenty for a few Gbit of home network loads that are generally gaming (FPS or minecraft), streaming (youtube, amazon, netflix), browser traffic, or plex.
Sure if you ran a game server with 10Gbit + and 100s or 1000s of clients it might die, but that's not a normal home traffic load.
I'm kinda skeptical, unless I'm missing something. How much time does it take for a VM host to reboot and resume firewall guest vs reboot firewall on metal?
In that context the quote is about rebooting the firewall VM after an OPNsense update not about rebooting the host.
> Installing updates
> Updates can be installed from the web interface, by going to System ‣ Firmware ‣ Updates. On this page, you can click Check for updates to search for updates. If they are available, a button will appear to install them.
Usually the time to pause the guest (ie halt it and dump memory to the disk) and resume exceeds standard shutdown/startup times.
Though in this case I think they treat a router OS update as a firmware.
I didn't saw a Linux based OS on a hardware for a long time, but at least in VMs current distros start up pretty fast, while *BSD based VMs take a little more time to init, though everything start in less than a minute.
Edit: I see you were referring to the host boot times plus the VM boot times, which I am not and neither is the article.