Post Aw0uIk0Biu9m8dSAeO by shmok@snac.bsd.cafe
(DIR) More posts by shmok@snac.bsd.cafe
(DIR) Post #Aw0poSiF2bN20nMirQ by shmok@snac.bsd.cafe
2025-07-11T04:24:36Z
0 likes, 0 repeats
Is there a need for having an 8-core N355 in home router environment for #openbsd firewall, or would a 4 core N150/N250 work well? At any time there could 5 systems using the net
(DIR) Post #Aw0uIj2HJeEb8pQKGm by Tubsta@soc.feditime.com
2025-07-11T04:47:07.676232Z
0 likes, 0 repeats
@shmok Probably overkill. PF will only run on one core, so faster cores the better. If you are running various other daemons on it then more cores will help. Depending on your uplink, how many states and concurrent streams each device behind it is using (think torrent), then 8 cores is going to be overkill.My 'gateway' is 2vCPU and 2GB of RAM running 7.7-RELEASE. IPv4/IPv6 NSD,Unbound,multi-vlan,IKEv2,OpenBGPD,wireguard no issues at all.
(DIR) Post #Aw0uIk0Biu9m8dSAeO by shmok@snac.bsd.cafe
2025-07-11T05:12:46Z
0 likes, 0 repeats
@Tubsta@soc.feditime.com Thanks man, that helps from mentioning using multi vlan and wireguard, which I don't use, that gives an idea of how extreme 8 cores is for at home. I have gigabit internet service but several computers always streaming video, torrent running, website multimedia, and LAN file transfers between computers.
(DIR) Post #Aw0wE1uvt4WiA5sPHU by subnetspider@mastodon.bsd.cafe
2025-07-11T05:26:20Z
0 likes, 0 repeats
@shmok Even a Intel N150 should be more than enough for routing/firewalling 1 gigabit of WAN to LAN traffic. I used to run a pf-based firewall on an AMD GX-222GC (2x 2.2 GHz x86 SoC from 2014) and got up to 770 Mbit/s even with that. 😎
(DIR) Post #Aw0wE3OOP1gajkfRq4 by shmok@snac.bsd.cafe
2025-07-11T05:36:28Z
0 likes, 0 repeats
@subnetspider@bsd.cafe I didn't realize it was that light on resources, thanks man. I know that all the router is doing is directing bits, but for you get that much speed on 2 cores, that is very easy. I've been looking at 6 port 2.5Gb routers and deciding between N150 or N350
(DIR) Post #Aw101nVs12ErpUZnhg by subnetspider@mastodon.bsd.cafe
2025-07-11T06:08:13Z
0 likes, 0 repeats
@shmok PF on modern CPUs barely has any trouble filtering packets at gigabit speeds, more cores do help with routing though - which also depends on your network card, it's drivers, and it's queues. I would recommend Intel i226 NICs when getting a mini-PC, don't touch the i225 NICs though (they suck at stability). Some good-ish 2.5G Realtek NICs also exist, but I never tried them.
(DIR) Post #Aw101ojjSyvBcm4Nwu by shmok@snac.bsd.cafe
2025-07-11T06:19:06Z
0 likes, 0 repeats
@subnetspider@bsd.cafe I think all of the hardware I have looked at is Intel 1226 but I made a note of that, thank you for the info, it helps. I only buy 2.5Gb NIC so that everything can run at full speed without overhead