|
|
The one thing to think about when pfSense (or any firewall for that matter) is running as a virtual machine, is when you get windows updates or need to reboot the computer hosting the VMs for any reason, you lose all internet connectivity. Consider some updates for windows can take some time, you are sat there with no Internet. You may then need to update and reboot the virtual machine with pfSense on, losing all connectivity again.
My advice would be to get a separate pfSense box, set it up and forget about it. They do a low powered but high performance model now, using only a few watt that you could install next to the ONT. https://store.netgate.com/pfSense/SG-1100.aspx
I'd echo that. I originally had my pfSense on my main home server, it worked well, but...
It became a hassle in the end. I wanted to upgrade the underlying Ubuntu install that the VM was running on, it was going to take a while to do so I had to keep putting it off because the router VM was running on that machine.
In the end I moved pfSense of onto its own low power PC. The Jetway PC I'm using isn't available anymore, but it is similar to this one:
https://www.mini-itx.com/~JBC375-F533M
I do still run less mission critical VMs, just not my router
|
|
|
|
I have just built my pfSense box in preparation for my FTTPoD connection. I went with a refurb HP 600 G2 SFF PC and installed an Intel i3-6100, 8GB DDR4, 120GB SSD and a dual port Intel PCIe x4 network card. I've not used pfSense before so this might be overkill for a 330/30 connection but I can always swap parts if necessary. Idle power consumption is showing as 15W which I think is pretty low for a PC - no doubt due to the 80+ Platinum PSU in these boxes.
Next step is to connect it to my existing Plusnet FTTC connection and have a play.
|
|
|
|
Hi
Yes probably overkill but better that than being too slow, although these days a mini-itx fan-less box is typically plenty fast enough.
The power consumption isn't too bad for a PC, I get 10 watts on my own built kit, unfortunately it could be around 5 watts idle if it wasn't for the BMC management chip in it (its a Supermicro board). Essentially it has a second processor for remote management running some form of Linux and it's own network port, the idea being you can always remote control/view the screen regardless of the state of the actual operating system, so there is never any need for an attached monitor or keyboard even if it crashed and wouldn't boot as you can be 'at the computer' via a web browser. I've not needed it really, but you can't turn it off to save a bit of power which is a shame.
For the SSD, you can set pfSense to write various temp files to memory (which you have plenty of so no issue doing that) to save wear and tear on the drive.
Regards
Phil
|
|
Register (or login) on our website and you will not see this ad.
|
|
|
|
Project 2
Desktop Quote - Openreach estimated the build charge at £6,900.00 + VAT
Labour £6,778.00
Stores £4,089.00
Contract Labour £0.00
Civils £14,150.00
Civils Stores £0.00
Tree cutting £0.00
BT Connection Charge £495.00
Deductions
-£750.00
-£250.00
£24,512.00+VAT (reclaimable)
-£2500 Gigabit Voucher
The phrase 'Ouch!' sprung to mind, especially as I got a reduction from £29,100 to £12,500 following survey.
2 miles from exchange, 1 mile to nearest residential area, where ducting is likely, I think it is on poles for the rural stretch. The civils costs seems extraordinary for the length of route on a quiet country lane. I would view the installation as very similar to mine but twice the price. If you want Google Maps YO18 8EE (Barker Stakes Farm B&B).
Input welcome.
|
|
|
Noting that with a coupler and a length of simplex single mode SC cable (probably APC judging by all the green connectors I have seen in photos), you could move the ONT to anywhere in the house you want after the Openreach engineers have left.
https://www.fs.com/uk/products/74343.html
https://www.fs.com/uk/products/11894.html
UPC cables and couplers are a bit cheaper. You are going to pay more for postage than the cable and coupler are worth though.
|
|
|
Noting that with a coupler and a length of simplex single mode SC cable (probably APC judging by all the green connectors I have seen in photos), you could move the ONT to anywhere in the house you want after the Openreach engineers have left.
https://www.fs.com/uk/products/74343.html
https://www.fs.com/uk/products/11894.html
UPC cables and couplers are a bit cheaper. You are going to pay more for postage than the cable and coupler are worth though.
So you are recommending folks break the Openreach/CP t&c�s by moving the ONT? Nice......
|
|
|
So you are recommending folks break the Openreach/CP t&c�s by moving the ONT? Nice......
It is possible that people broke the T&Cs on the copper wired solutions. Is it much different if they break them for fibre? I suppose it could be more costly if they break stuff.
I do have a nice shiny 19inch rack with all my kit in. Including a UPS, and then on the wall I have two boxes with 63 wires between them (Fibre-In, Telephone out, CAT5 out, Power in to Battery, Power Out from Battery, Power to ONT (on the side not the bottom with the others). The fibre in is below and too the left of the ONT. Why wasn't it designed to come into the case in the first place (One benefit of ONTv2 is the enclosure).
A simple fibre port and then a rack mount ONT would have been a nice option. Even the ONT on a shelf would be neater.
|
|
|
|
Hi
With fibre there is more potential to knock other people offline as it's shared, you could take down your whole street with an ONT that isn't compatible or is slightly out of spec. With ADSL or VDSL that couldn't happen.
Still, if terms and conditions wanted to be enforced by BT should they be so concerned with their kit being tampered with, they would have put tamper evident seals or locks on it like they do with electricity or gas meters. I also expect as time goes by and properties have the fibre connection already, it will become more self install, i.e. you just get a router/hub and plug the fibre into it. Also BT didn't want you messing with their wires to help protect staff, i.e. in case a wire gets shorted to mains and electrifies part of the network, with fibre that can't happen.
People have been breaking BTs terms and conditions for decades with moving phones and installing dodgy extensions direct into the master socket or termination point and I don't think anyone has got into trouble for it, at worse they just pay the engineer to put it right if they've messed up.
If its moved and noticed by the engineer then I guess the worst case is being charged for any work to correct faults, but you could just move it back for the fix.
Regards
Phil
|
|
|
and installing dodgy extensions direct into the master socket or termination point and I don't think anyone has got into trouble for it, at worse they just pay the engineer to put it right if they've messed up.
Yup. There are two master sockets in our office on the same line! I doubt both were put there by Openreach. All the extensions were on bell wire, not to spec, removing them upped the broadband speed by 50% 4 to 6Mbps!
But good point on the upload time slicing, it could break the whole thing. Now who would create a system where a simple action, plugging a different router onto the fibre rather than the ONT, could affect multiple customers.
|
|
|
|
Technically you are not even allowed to remove it from the wall for decorating purposes which is unsustainable in the medium to long term. An extra few metres of fibre optic and a coupler are immaterial. Fibre optics are not some magic super secret proprietary stuff that if you touch is going to cause the end of the world.
If one wanted to [censored] the neighbours off you could just disconnect the fibre from the ONT and fire a laser down the cable. You can get a 1310nm single mode fibre coupled laser diode for not much money these days.
Heck for kicks and giggles you could pick a suitable CO2 laser and burn out the photodiode on the OLT.
|