pfSense HW 2019 - Appliance or DIY?

HolyK

Ninja Turtle
Moderator
Joined
May 26, 2011
Messages
654
@John Doe Yes but i want to keep my network mgmt and NAS physically separated. I am OK with "extending" the pure NAS purpose by few more services and VMs/jails but including network/firewall is too much. From "security" point of view as well as availability (NAS maintenance = whole network outage).
 

HolyK

Ninja Turtle
Moderator
Joined
May 26, 2011
Messages
654
Just a small update about cooling. As mentioned i got Minisys NUC J3160 with mSATA SSD (bought separately) and 8GB of RAM i already had. It just works (did not enabled VPN yet) but i had a feeling that the heatsink comes quite hot after a while even when the device is not under any massive load. I had ~57°C reported in pfSense and similar temperature for cores. The J3160 has 90°C as max temp so there was more than enough space but still.... The summer is getting quite hot in central europe in recent years and as i have the device hidden in a small cabinet under TV with small ventilation hole at the back i was afraid that the temps could jump quite high decreasing the device lifespan.

So how to cool it down a bit AND keep it silent? Well ... that Minisys board has micro JST power for SATA device i am not using so that is ideal source of 5/12V.

I bought 92mm Noctua NF-A9 FLX , pack of 4pin micro JST connectors and found one FAN extension cable in my magic box of leftovers. Few min of work with wire cutters and pair of shrink tubes to cover a Lineman's Splice and tadaaa we have a FAN power source.

Note that on native 12V the FAN gets on full 1600RPM which is too much. On 5V the FAN does not start at all. Well just in case someone does not know you can use both 5V and 12V for the FAN which gives you 7V of effective power. That's just perfect Voltage to have the Noctua on slow speed to blow away the heat from heatsink while keeping it perfectly silent.

The best part is that i did not had to drill any hole into the Minisys case. There is a hole for Kensington security cable which is enough. Only thing i had to do is carefully dismantle the FAN 3pin connector (Use needle to press the small piece of metal while gently pulling the cables out) and push the cables through. Click the connector back, connect everything and close the baby. Final touch with pair of zipties and cover grid and we're ready to go back online :]

Few photos (click for big size)
001_resize.jpg 002_resize.jpg 003_resize.jpg 004_resize.jpg 005_resize.jpg

Result is just perfect :]
006.PNG
 

John Doe

Guru
Joined
Aug 16, 2011
Messages
635
very nice.
could you do some measurements about power consumption?
 

HolyK

Ninja Turtle
Moderator
Joined
May 26, 2011
Messages
654
Finally I had some time to setup the VPN and frankly i am quite surprised about the performance of J3160 . I can max out my 100Mbps connection and the CPU barely gets over 30% huh ... crypto is AES 256 GCM.

stats1.PNG


stats2.PNG
 

cJZ

Dabbler
Joined
May 29, 2019
Messages
17
Hello everyone,
Passionate about computer security, I recovered a UTM Netasq U70S which no longer has a license today.
In order to recycle it, I would like to know if it would be possible to install OPNsense on this famous UTM?
Thank you in advance for your answers: D

______________________________________________
Appvalley TutuApp Tweakbox
Hi. I came across this tidbit of information. Looks like the switch firmware can be controlled from the serial port, you'll need a serial cable. I believe the U70S uses a VIA processor, which would be i386, so you'll need the appropriate image. (not amd64)

https://forum.opnsense.org/index.php?topic=9842.msg58092#msg58092
 

proto

Patron
Joined
Sep 28, 2015
Messages
269
Finally I had some time to setup the VPN and frankly i am quite surprised about the performance of J3160 . I can max out my 100Mbps connection and the CPU barely gets over 30% huh ... crypto is AES 256 GCM.

uoh! 39C only.
My fitlet2 (4 gbe / J3455 CPU), no VPN + snort + pfblockerNG, is burning at 56C and increasing.

I like that fan hack and I wish I could adapt it to my box...
 

HolyK

Ninja Turtle
Moderator
Joined
May 26, 2011
Messages
654
@proto Actually there is still a (non-desctructive) way for you. Noctua has 5V FANs which you can power from USB port. Look for NF-A8 5V model which is a 80mm 5V FAN. Then you just need this kind of cable (or build your own with desired length). What could be the issue is the noise as the FAN will run on its max 2200 rpm.

Another way would be to get one of the 12V ULN models. Either NF-A8 ULN which has 1400rpm or NF-R8 redux-1200 which has only 1200rpm. Then get something like this (I've never used these so i no idea about the quality/real usage!) to get 12V output from USB port. Then get the FAN extension cable, cut it in half and hook the two pins onto it like i did. You will end up with a chain .... USB (5V) -> convertor (12V) -> +/- cable -> cable with FAN connector -> 12V FAN.

Good luck!
 

proto

Patron
Joined
Sep 28, 2015
Messages
269
Actually there is still a (non-desctructive) way for you.

I'll go for this! It's a noisy room so there is no problem :smile: Many many thanks!

I didn't even think that those cables existed, but in fact there is so much stuff powered by USB, including those fans, lamps, etc. that connect to laptops.
My preparation on anything to do with electricity is pretty poor!
 

HolyK

Ninja Turtle
Moderator
Joined
May 26, 2011
Messages
654
I'll go for this! It's a noisy room so there is no problem :) Many many thanks!
Nice! Just don't forget to add the "Protective Grill" or whatever the name is. You don't want to get random cables (or animals) stuck in the FAN :D
 

proto

Patron
Joined
Sep 28, 2015
Messages
269
Nice! Just don't forget to add the "Protective Grill" or whatever the name is. You don't want to get random cables (or animals) stuck in the FAN :D

Sure!
Meanwhile...
I found a "lost" gift in a box, of which I had forgotten the existence - so ugly and useless ... yet with this USB fan I just managed to decrease the temperature by at least 12 degrees! Now it's on 44C and as you can see from my poor quality pictures I couldn't even mount it on the appliance due to lack of space.
But it's working and I really think that as soon as I have the pieces to assemble the Noctua fans that you have indicated to me, the situation can only improve!
It's really hot here...

IMG_1985.png
IMG_1986.png
 

HolyK

Ninja Turtle
Moderator
Joined
May 26, 2011
Messages
654
Sure!
But it's working and I really think that as soon as I have the pieces to assemble the Noctua fans that you have indicated to me, the situation can only improve!
Actually you don't even need the costly Noctua if you don't care about the noise. Check ebay for "80mm 5V USB FAN" and just grab one of them fro few bucks. Hook it on the pfSense box with few zipties and done. As long as it has at least some airpressure it will be sufficient to blow the heat away from heatsink and you will end up somewhere between 30 and 40 degree.
 

proto

Patron
Joined
Sep 28, 2015
Messages
269
Actually you don't even need the costly Noctua if you don't care about the noise.

Yeah, not a problem here. My switch and UPS fans are far more noisy than ever
 
Top