4 ms·
This whole fiasco has made me question why I bother with pfsense for my home network. When I only require a simple NAT/port forwarding for torrents, OpenBSD see
by jron 6y ago
This whole fiasco has made me question why I bother with pfsense for my home network. When I only require a simple NAT/port forwarding for torrents, OpenBSD seems like an obvious choice. Other than hardware support, is there another reason why OpenBSD hasn't taken off as a viable home router alternative to pfsense and opnsense? SecurityRouter is the only OpenBSD specific routing appliance that I'm aware of and it is no longer being developed. It also had a closed source backend and unknown licensing for the client.
- nimbius 6y agothere may be reasons you wish to reconsider OpenBSD https://isopenbsdsecu.re/ https://isopenbsdsecu.re/
- jron 6y agoHere is the presentation which provides more context than the slides alone: https://www.youtube.com/watch?v=3E9ga-CylWQ https://www.youtube.com/watch?v=3E9ga-CylWQ I've watched it before and it is compelling; however, at the end of the day, an OS that tries to take security seriously is probably better than one that doesn't. The OpenBSD code is small and I suspect that the defects/KLOC is far less than other projects capable of routing. I'd love to hear more critiques for using it as a home router though.
- rurban 6y agoYes. If you need 10x less performance, you'd choose OpenBSD. Otherwise you'd go for DragonFly
- jron 6y agoI have no doubt that DragonFly could handle higher throughput but for a home router at 1GbE or less, OpenBSD seems ideal assuming it doesn't add additional latency. Benchmarks are hard to find; if you know of any, please let me know.
- kaliszad 6y agoYeah, the whole Spectre/ Meltdown was handled very badly by Intel. Illumos, OpenBSD and others basically found out from the media/ mailing lists of other projects where people were told under NDA. Not a great position to be in, they did, what they could in the shortest time possible.
- mishac 6y agoIIRC OpenBSD's version of pf is single-threaded, which might be an issue depending on your network speed and hardware. A single core of an Atom or Celeron might struggle on a gigabit or 10gig network, if that's the use case.
- jron 6y agoI might have the history wrong on this one but it sounds like FreeBSD forked OpenBSD's PF code at one point to add SMP support. OpenBSD's continued PF updates have not been merged into FreeBSD due to the incompatibilities introduced by their SMP changes. I believe single thread performance has also increased quite a bit since the fork happened. I don't require 10gig support currently but I have no doubt that SMP support will eventually be required if OpenBSD wants to remain usable as a router in the future.
- jjav 6y agoMy externally facing firewall at home is an OpenBSD box with an Atom C2550 @ 2.40GHz, it's plenty enough to handle all internet traffic (internal network traffic doesn't go through it). I don't have 10gig internet link at home though (who does?)
- uncledave 6y agoI treat my home network as insecure and use an off the shelf ISP provided router (FritzBox). I have saved hours of my life doing this. I was running various unixy things over the years and suddenly something went snap and I decided not to bother. It’s fine for corporate and medium sized networks but not worth it for home stuff any more. Just costs time, money and eats a lot of power.