0

Discussion topic: fortinet routers/switches/vpns

Reply
Reply
FinnieFinFin
Topic Author
This message was authored by FinnieFinFin This message was authored by: FinnieFinFin

Re: fortinet routers/switches/vpns

XCY Router Intel i225V 6 NIC 2.5G Gigabit Ethernet Enterprise Firewall Appliance pfSense OPNsense Gateway Linux Ubuntu Mini PC

This any good?

FinnieFinFin_2-1703968215534.jpeg

 

 

....
This message was authored by mae-3 This message was authored by: mae-3

Re: fortinet routers/switches/vpns

@FinnieFinFin 

 

This is the one I used and upgraded the memory to 16GB.

 

VENOEN Firewall Micro Appliance 2.5gbe Firewall mini PC Celeron J4125, 4x2.5GbE I225-V LAN Firewall Router PC, 8GB RAM 256GB SSD Fanless PC, AES-NI, HD-MI, VGA, 2xUSB 3.0, SIM Slot, VPN Server.

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
This message was authored by mae-3 This message was authored by: mae-3

Re: fortinet routers/switches/vpns

@FinnieFinFin 

 

The mini PC you have picked is also good for an OPNsense firewall. 😀

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
FinnieFinFin
Topic Author
This message was authored by FinnieFinFin This message was authored by: FinnieFinFin

Re: fortinet routers/switches/vpns

You've made me so happy because sky option 61 has been the bane of my life and for years I've been trying to find a solution and now I have, thank you so much!. I will definitely continue to speak to you if that's 👍 

....
This message was authored by mae-3 This message was authored by: mae-3

Re: fortinet routers/switches/vpns

@FinnieFinFin 

 

If any help you need with OPNsense or Zenarmor don't hesitate to enquire... 😀

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
FinnieFinFin
Topic Author
This message was authored by FinnieFinFin This message was authored by: FinnieFinFin

Re: fortinet routers/switches/vpns

Will do!! 
you've been so helpful 🙏

I'll draw up an illustration tomorrow of the homelab I've dreamed off ☺️

....
This message was authored by mae-3 This message was authored by: mae-3

Re: fortinet routers/switches/vpns

@FinnieFinFin 

 

For a media cluster don't forget to look at Ubuntu. DRBD and OCFS2 file system which requires a disk for Ubuntu and 2nd SSD disk for shared media on the cluster mini PCs.

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
FinnieFinFin
Topic Author
This message was authored by FinnieFinFin This message was authored by: FinnieFinFin

Re: fortinet routers/switches/vpns

Been looking at 64 gig, 8 core, 16 thread, ddr5, firewall mini pc routers/servers/gaming/etc

they come at around £700+

Looks nice, but I looked at the gen and they are old ones? 11 gen some are 10!

 

Cant find a 12 or 13th gen with these specs anywhere

 

How have you setup your router to bypass or authenticate skys 61 option?

Is there an option you can choose in the firmware? Will I see different advanced options once I'm all setup with the router and is it easy to setup?

 

....
This message was authored by mae-3 This message was authored by: mae-3

Re: fortinet routers/switches/vpns

@FinnieFinFin 

 

By all accords, the interface on OPNsense is a nicely designed web interface, pretty simple to set up NGFW in comparison to others but you do need to go down to the SSH to perform complex tasks on infrequent occasions. As an example, I went down to the shell level to adjust the resolver and forwarders for DNS.

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
FinnieFinFin
Topic Author
This message was authored by FinnieFinFin This message was authored by: FinnieFinFin

Re: fortinet routers/switches/vpns

I found a better server homelab virtualisation (T9 Plus Mini PC Intel Alder Lake N100 16GB DDR5 1TB NVMe SSD)

FinnieFinFin_0-1703976939412.png

Most likely order 3 of these and these will be my go to for homelab use 

The router you have will be the firewall or should I get something high spec?

....
FinnieFinFin
Topic Author
This message was authored by FinnieFinFin This message was authored by: FinnieFinFin

Re: fortinet routers/switches/vpns

OMG...not a DNS! NIGHTMARE!! 
I lost my cool so many times cos of this 😄

....
This message was authored by mae-3 This message was authored by: mae-3

Re: fortinet routers/switches/vpns

@FinnieFinFin 

 

My resolver and DNS forwarders do this for our network, randomly selecting DNS forwarders...

 

Screenshot 2023-12-30 at 23.07.25.png

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
FinnieFinFin
Topic Author
This message was authored by FinnieFinFin This message was authored by: FinnieFinFin

Re: fortinet routers/switches/vpns

😄 seeing this gives me hope

Ya, definitely will ask for your help when I receive all the goods and set it all up with open sense 

Goodnight for now, thank you for all your help 🙏

....
FinnieFinFin
Topic Author
This message was authored by FinnieFinFin This message was authored by: FinnieFinFin

Re: fortinet routers/switches/vpns

meh.JPG

....
FinnieFinFin
Topic Author
This message was authored by FinnieFinFin This message was authored by: FinnieFinFin

Re: fortinet routers/switches/vpns

Evening mae!

 

I posted a quick diagram of what im trying to accomplish

 

The rack is a must, 10 or 12 inch rack but some of the hardware I still may purchase come at 19 inches...so i may have to go for an ugly big rack...

 

Essencially i'd like to have a rack on display, yep, i'd like to look at it each time i pass the room 😉

May even purchase a cheap old thinkpad to have under the rack on a slider so i can manage it right there instead of having to go all the way to the main computer.

I'll have ubuntu on the thinkpad or maybe some dual hybrid with windows or just boot into windows or linux with a flash drive.

 

But the 3 mini pc's i showed you before will be the server's for virtualization and using Qubes http://www.qubes-os.org/intro/ and tails I believe comes with qubes, not sure, but can always add this later, https://tails.net/index.en.html

 

 

....
Reply

Was this discussion not helpful?

No problem. Browse or search to find help, or start a new discussion on Community.

Start a new discussion

On average, new discussions are replied to by our users within 4 hours

New Discussion