24
submitted 2 years ago by poVoq@slrpnk.net to c/selfhosted@lemmy.world

I am not overly happy with my current firewall setup and looking into alternatives.

I previously was somewhat OK with OPNsense running on a small APU4, but I would like to upgrade from that and OPNsense feels like it is holding me back with it's convoluted web-ui and (for me at least) FreeBSD strangeness.

I tried setting up IPfire, but I can't get it to work reliably on hardware that runs OPNsense fine.

I thought about doing something custom but I don't really trust myself sufficiently to get the firewall stuff right on first try. Also for things like DHCP and port forwarding a nice easy web GUI is convenient.

So one idea came up to run a normal Linux distro on the firewall hardware and set up OPNsense in a VM on it. That way I guess I could keep a barebones OPNsense around for convenience, but be more flexible on how to use the hardware otherwise.

Am I assuming correctly that if I bind the VM to hardware network interfaces for WAN and LAN respectively it should behave and be similarly secure to a bare metal firewall?

you are viewing a single comment's thread
view the rest of the comments
[-] poVoq@slrpnk.net 1 points 2 years ago

Sounds great. What about hardware acceleration features of the NIC? I read somewhere that its better to disable the support for that in OPNsense when running it in a VM?

[-] Illecors@lemmy.cafe 2 points 2 years ago

Dunno, worked well for me. Give it a shot and see if anything needs to be disabled.

[-] wildbus8979@sh.itjust.works 1 points 2 years ago* (last edited 2 years ago)

Another option is to pass through the PCIe devices to the VM.

[-] poVoq@slrpnk.net 2 points 2 years ago* (last edited 2 years ago)

I just saw that option. What would be the advantages and disadvantages of this?

I guess when I pass the actual NIC device the hardware acceleration should work?

Edit: Looks like my host system does not support this, at least that is the error I get when trying ;)

[-] wildbus8979@sh.itjust.works 1 points 2 years ago* (last edited 2 years ago)

For one you offload the entire processing and driver handling to the VM, so if the OS wants to do something funky, it can.

this post was submitted on 28 Mar 2024
24 points (100.0% liked)

Selfhosted

61512 readers
605 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS