3 ms·
What I find easy(ier?) is to run (x)sense on a dedicated firewall and either a mesh with cheap openwrt routers or get something like Deco mesh and run it in AP
by trustingtrust 3y ago
What I find easy(ier?) is to run (x)sense on a dedicated firewall and either a mesh with cheap openwrt routers or get something like Deco mesh and run it in AP mode if you don’t have cat6 at home. I think this combination can be under 300$ for a 3-pack of mesh Deco x20 + an intel card on a refurb dell optiplex.
- dgroshev 3y agoIME (x)sense is quite problematic when you start doing anything other than the bare minimum. I spent multiple days trying to figure out why it silently stopped accepting IPv6 delegation, or why does it spike latency for no visible reason under load. The underlying reality is that FreeBSD's network stack is much more conservative and has less resources than Linux's, which shows up in articles like this one [1]. On the same Celeron J4125/i226 box VyOS was absolutely perfect, not a single issue, significantly low (and always low) latency with higher throughput. On the hardware side, I think the /r/homelab hivemind doesn't get challenged enough. Dell optiplexes cost very similarly to Aliexpress Protectli alternatives (such as [2]), while being larger, having a fan, and being overall more hassle. TP Link/Ubiquiti WiFi APs seem to be overall inferior to Aruba Instant On, which is exactly the same hardware HP sells in their Aruba line, but for the same SOHO price. [1] https://teklager.se/en/knowledge-base/opnsense-performance-optimization/ https://teklager.se/en/knowledge-base/opnsense-performance-o... [2] https://www.aliexpress.com/item/1005004272231167.html https://www.aliexpress.com/item/1005004272231167.html
- trustingtrust 3y agoThe biggest reason I like xSense is because of unbound and using root dns. OpenWRT supports that, but otherwise I have to setup a local linux instance to serve DNS via unbound. With pfsense and opnsense I find that the dns is a lot more stable than unbound as using a resolver seems to work more reliably than a forwarder like dnsmasq.