Skip to content
  • MySensors
  • OpenHardware.io
  • Categories
  • Recent
  • Tags
  • Popular
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. General Discussion
  3. Advisory: put IOT devices on a separate LAN/vLAN for better security

Advisory: put IOT devices on a separate LAN/vLAN for better security

Scheduled Pinned Locked Moved General Discussion
40 Posts 11 Posters 435 Views 10 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mfalkviddM mfalkvidd

    @monte yes I did.

    opnsense is so much slower because of BSD. pfsense has the same problem. I don't know the details, but it boils down to some important part of the BSD networking stack being single-threaded. It seems to be a well-known problem in the router world. I applied multiple tweaks to the BSD kernel, but they did not make any significant difference.

    monteM Offline
    monteM Offline
    monte
    wrote on last edited by
    #29

    @mfalkvidd one more question. Did you measure throughput WAN-LAN or LAN-LAN?

    mfalkviddM 1 Reply Last reply
    0
    • monteM monte

      @mfalkvidd one more question. Did you measure throughput WAN-LAN or LAN-LAN?

      mfalkviddM Offline
      mfalkviddM Offline
      mfalkvidd
      Mod
      wrote on last edited by
      #30

      @monte LAN-LAN

      1 Reply Last reply
      0
      • NeverDieN Offline
        NeverDieN Offline
        NeverDie
        Hero Member
        wrote on last edited by NeverDie
        #31

        Two things convinced me to have a box dedicated to pfsense (or whatever I end up using):

        1. @monte 's earlier advice on the subject, and
        2. The need for it to keep working during a lightning storm, during which I typically unplug any expensive or delicate machines but also during which I still want to maintain wifi internet access. Meaning: it could still get nuked by an electrical surge from a nearby lightning strike, but at least the replacement cost would be low. Hmmm... I suppose better still would be switching to some kind of completely wireless internet access during such storms, by maybe converting my cell phone into a hotspot or using a Verizon jetpack.... In that case, having the router be low power would be very nice indeed, because then it could run on batteries during the storm and thereby have no lightning risk at all.
        1 Reply Last reply
        0
        • NeverDieN Offline
          NeverDieN Offline
          NeverDie
          Hero Member
          wrote on last edited by NeverDie
          #32

          My plan is to put pfSense onto this Supermicro motherboard, which has 6 software programmable gigabit ethernet ports plus a seventh for IPMI access:
          https://www.supermicro.com/products/motherboard/atom/x10/a1srm-ln7f-2758.cfm

          I'm not sure what "software programmable" means in this context, but it connotes that maybe not everything needs to be routed through the CPU.

          It consumes at most 20 watts when under load, but, IIRC, roughly 6 or 8 watts when idling. The Intel atom processor is built-in to the motherboard. The atom doesn't have much single thread oomph, but it does have 8 cores and all the features required to run a hypervisor, which might be worthwhile, especially if it turns out that the software programmable ethernet ports can be configured to manage all the routing on their own.

          If I didn't already own this board, I'd probably pick up a similar Supermicro board that has six 10-gigabit ports on it. Right now there are a ton of used ones on ebay for around $80 per board, some including an E3-1200 processor in the $80 price. i.e. they cost even less than the pcengine board. Probably more than 20 watts TDP, but considering its a SuperMicro motherboard and each of the six ports supports RJ45 10gbe.... Heck, at that price for a 10Gbe node, I should buy 3 and build an HA ProxMox cluster.

          skywatchS 1 Reply Last reply
          1
          • NeverDieN NeverDie

            My plan is to put pfSense onto this Supermicro motherboard, which has 6 software programmable gigabit ethernet ports plus a seventh for IPMI access:
            https://www.supermicro.com/products/motherboard/atom/x10/a1srm-ln7f-2758.cfm

            I'm not sure what "software programmable" means in this context, but it connotes that maybe not everything needs to be routed through the CPU.

            It consumes at most 20 watts when under load, but, IIRC, roughly 6 or 8 watts when idling. The Intel atom processor is built-in to the motherboard. The atom doesn't have much single thread oomph, but it does have 8 cores and all the features required to run a hypervisor, which might be worthwhile, especially if it turns out that the software programmable ethernet ports can be configured to manage all the routing on their own.

            If I didn't already own this board, I'd probably pick up a similar Supermicro board that has six 10-gigabit ports on it. Right now there are a ton of used ones on ebay for around $80 per board, some including an E3-1200 processor in the $80 price. i.e. they cost even less than the pcengine board. Probably more than 20 watts TDP, but considering its a SuperMicro motherboard and each of the six ports supports RJ45 10gbe.... Heck, at that price for a 10Gbe node, I should buy 3 and build an HA ProxMox cluster.

            skywatchS Offline
            skywatchS Offline
            skywatch
            wrote on last edited by
            #33

            @NeverDie Quite a lot of this thread is very interesting even though it all goes way over my head. Do you think one of these would do?

            https://www.ebay.co.uk/itm/HPE-Synergy-12000-10x-480-Gen10-Platinum-D3940-38TB-SSD-2x-40GB-16GB-FC-Frame/283693062050?hash=item420d6c97a2:g:XK0AAOSwbqdd4Rl0

            :}

            NeverDieN 1 Reply Last reply
            0
            • skywatchS skywatch

              @NeverDie Quite a lot of this thread is very interesting even though it all goes way over my head. Do you think one of these would do?

              https://www.ebay.co.uk/itm/HPE-Synergy-12000-10x-480-Gen10-Platinum-D3940-38TB-SSD-2x-40GB-16GB-FC-Frame/283693062050?hash=item420d6c97a2:g:XK0AAOSwbqdd4Rl0

              :}

              NeverDieN Offline
              NeverDieN Offline
              NeverDie
              Hero Member
              wrote on last edited by
              #34

              @skywatch said in Advisory: put IOT devices on a separate LAN/vLAN for better security:

              @NeverDie Quite a lot of this thread is very interesting even though it all goes way over my head. Do you think one of these would do?

              https://www.ebay.co.uk/itm/HPE-Synergy-12000-10x-480-Gen10-Platinum-D3940-38TB-SSD-2x-40GB-16GB-FC-Frame/283693062050?hash=item420d6c97a2:g:XK0AAOSwbqdd4Rl0

              :}

              No.

              1 Reply Last reply
              0
              • monteM Offline
                monteM Offline
                monte
                wrote on last edited by
                #35

                @NeverDie I would like to know where did you find those for 80$ and even with cpu included?! I want one! :)
                Anyway just to throw in this one if you haven't seen it yet, there are pfsense boxes from the netgate themselves https://shop.netgate.com/products/2100-base-pfsense. I know there is ongoing controversy with netgate as an entity, but you may consider this as an option even though I prefer to build things myself.

                NeverDieN 1 Reply Last reply
                1
                • monteM monte

                  @NeverDie I would like to know where did you find those for 80$ and even with cpu included?! I want one! :)
                  Anyway just to throw in this one if you haven't seen it yet, there are pfsense boxes from the netgate themselves https://shop.netgate.com/products/2100-base-pfsense. I know there is ongoing controversy with netgate as an entity, but you may consider this as an option even though I prefer to build things myself.

                  NeverDieN Offline
                  NeverDieN Offline
                  NeverDie
                  Hero Member
                  wrote on last edited by
                  #36

                  @monte https://www.ebay.com/itm/X10SLH-N6-ST031-Supermicro-E3-1200-v3-LGA1150-Motherboard-3x-X540-T2-6x-10GbE/184546263249?hash=item2af7d080d1:g:CCUAAOSwoP1gSWhO

                  monteM NeverDieN 2 Replies Last reply
                  1
                  • NeverDieN NeverDie

                    @monte https://www.ebay.com/itm/X10SLH-N6-ST031-Supermicro-E3-1200-v3-LGA1150-Motherboard-3x-X540-T2-6x-10GbE/184546263249?hash=item2af7d080d1:g:CCUAAOSwoP1gSWhO

                    monteM Offline
                    monteM Offline
                    monte
                    wrote on last edited by monte
                    #37

                    @NeverDie oh yeah, of course I was looking for the wrong one :)
                    I personally have Intel DQ77KB that I use as my home server, but planning to make it a pfsense or opnsense box. It's also LGA1150 and has two ethernets onboard, and I don't think I really need to use a firewall as a switch.

                    NeverDieN 1 Reply Last reply
                    0
                    • monteM monte

                      @NeverDie oh yeah, of course I was looking for the wrong one :)
                      I personally have Intel DQ77KB that I use as my home server, but planning to make it a pfsense or opnsense box. It's also LGA1150 and has two ethernets onboard, and I don't think I really need to use a firewall as a switch.

                      NeverDieN Offline
                      NeverDieN Offline
                      NeverDie
                      Hero Member
                      wrote on last edited by NeverDie
                      #38

                      @monte said in Advisory: put IOT devices on a separate LAN/vLAN for better security:

                      Intel DQ77KB

                      It doesn't support ECC memory, but maybe it makes no difference, since each packet would contain its own error correction anyway.

                      What kind of switches are you using to create and manage your vlans? In an earlier post I mentioned I was planning to use relatively cheap 1gbe managed netgear switches, but if I could get 10gbe transfer rates using the ebay supermicro boards for just a little more money plus some memory and a powersupply, I'm inclined to do it. I could certainly live with 1gbe, but to speed along backups or vme migration or restoration from a backup server, 10gbe would be a nice luxury because it's a good match for the read/write rates of pci-e 4.0 nVME drives. Or, some of these older ebay Supermicro boards can be had with gobs of ram (128GB or even 192GB of RAM), where you could easily run entire virtual machines inside of just RAM. Then there's no nVME drive to wear out, and you could pretty much transfer files or VM's as fast as the ethernet will carry it. Or a file server with such outlandish amounts of RAM could have a positively enormous RAM cache to facilitate ultra fast file transfer rates. Then maybe you don't need much nVME on the local machine and just boot from the network instead. It might be a good way to amortize the cost of the RAM expenditure. I don't know for sure how well it would work in real life, as I haven't tried it, but that's the theory. Anyway, for doing those kinds of things, 1gbe just wouldn't be fast enough compared to local nvme, but 10gbe just might be, even after deducting for the ~20% ethernet overhead. This back of the envelope calculation assumes no meaningful network contention, but I'm comfortable with that assumption, because on a home network there wouldn't be.

                      monteM 1 Reply Last reply
                      0
                      • NeverDieN NeverDie

                        @monte said in Advisory: put IOT devices on a separate LAN/vLAN for better security:

                        Intel DQ77KB

                        It doesn't support ECC memory, but maybe it makes no difference, since each packet would contain its own error correction anyway.

                        What kind of switches are you using to create and manage your vlans? In an earlier post I mentioned I was planning to use relatively cheap 1gbe managed netgear switches, but if I could get 10gbe transfer rates using the ebay supermicro boards for just a little more money plus some memory and a powersupply, I'm inclined to do it. I could certainly live with 1gbe, but to speed along backups or vme migration or restoration from a backup server, 10gbe would be a nice luxury because it's a good match for the read/write rates of pci-e 4.0 nVME drives. Or, some of these older ebay Supermicro boards can be had with gobs of ram (128GB or even 192GB of RAM), where you could easily run entire virtual machines inside of just RAM. Then there's no nVME drive to wear out, and you could pretty much transfer files or VM's as fast as the ethernet will carry it. Or a file server with such outlandish amounts of RAM could have a positively enormous RAM cache to facilitate ultra fast file transfer rates. Then maybe you don't need much nVME on the local machine and just boot from the network instead. It might be a good way to amortize the cost of the RAM expenditure. I don't know for sure how well it would work in real life, as I haven't tried it, but that's the theory. Anyway, for doing those kinds of things, 1gbe just wouldn't be fast enough compared to local nvme, but 10gbe just might be, even after deducting for the ~20% ethernet overhead. This back of the envelope calculation assumes no meaningful network contention, but I'm comfortable with that assumption, because on a home network there wouldn't be.

                        monteM Offline
                        monteM Offline
                        monte
                        wrote on last edited by
                        #39

                        @NeverDie my setups are quiet simpler. On one location I don't use vlans at all, as I don't use third-party iot devices that I need to actively separate from my network. On the other location I use Mikrotik RB260GS as a managed switch plus I have 3 LAN ports on my pfsense server, where one of them is used for dedicated subnet for outdoor cameras and wifi's.
                        I would like to have hardware that could take advantage of 10gbe network, but for now I just keep things simple and slow :)

                        1 Reply Last reply
                        1
                        • NeverDieN NeverDie

                          @monte https://www.ebay.com/itm/X10SLH-N6-ST031-Supermicro-E3-1200-v3-LGA1150-Motherboard-3x-X540-T2-6x-10GbE/184546263249?hash=item2af7d080d1:g:CCUAAOSwoP1gSWhO

                          NeverDieN Offline
                          NeverDieN Offline
                          NeverDie
                          Hero Member
                          wrote on last edited by NeverDie
                          #40

                          @NeverDie said in Advisory: put IOT devices on a separate LAN/vLAN for better security:

                          @monte https://www.ebay.com/itm/X10SLH-N6-ST031-Supermicro-E3-1200-v3-LGA1150-Motherboard-3x-X540-T2-6x-10GbE/184546263249?hash=item2af7d080d1:g:CCUAAOSwoP1gSWhO

                          Lest I mislead anyone, I subsequently contacted to the seller and, despite the wording, it doesn't include an E3-1200 with the board. He just meant that as shorthand to refer to the processor family that's compatible with the board. That said, there are a ton of inexpensive used LGA1150 CPU's on ebay that could serve the purpose.

                          1 Reply Last reply
                          0
                          Reply
                          • Reply as topic
                          Log in to reply
                          • Oldest to Newest
                          • Newest to Oldest
                          • Most Votes


                          19

                          Online

                          11.7k

                          Users

                          11.2k

                          Topics

                          113.1k

                          Posts


                          Copyright 2025 TBD   |   Forum Guidelines   |   Privacy Policy   |   Terms of Service
                          • Login

                          • Don't have an account? Register

                          • Login or register to search.
                          • First post
                            Last post
                          0
                          • MySensors
                          • OpenHardware.io
                          • Categories
                          • Recent
                          • Tags
                          • Popular