This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Hardware recommendations for Home license - exaggerated?

Hi,

The thing is, I have been going through some of the threads here and elsewhere and it seems that if one really wants to use what Sophos UTM can offer, people recommend beefy hardware, nothing short of an Core i3 to run the system on. I wonder why this is. A quick check of Sophos' own offers indicates, an up to date Atom or BayTrail should do just fine.  For example: 


  • SG105 --> Intel Atom E3826 1.46GHz | 2GB RAM
  • SG135 --> Rangeley C2558 2.4GHz | 6GB RAM
  • SG210 --> Celeron 2.7GHz | 8GB RAM
  • SG 310 --> Core i3 3.5GHz | 12GB RAM


when I look at what throughput Sophos rates these babies at (including VPN, IPS, all >>100Mbit/s) I can't fathom how even a PowerUser at home would have the need to get beefier hardware to run this. 
I didn't think I'd open a new thread since there is tons on home user hardware already but the fact that so many posts claim one needs an Intel core i3 processor to run the full feature-set of UTM buffles me a bit. Are Sophos' hardware appliances running on some different version, somehow way more optimized to the hardware, multi-threaded... while the home user edition is not?

I have been running an astaro and now Sophos UTM at home for four years now on an Atom Dualcore N450 with 2GB of RAM. Switching on all the gimmicks slows things down substantially ( WAN & LAN) for a DMZ/guest net and a Cloudserver but VLANs could do the trick too. 
We constantly use IPsec and SSL VPN on our private laptops, phones and tablets. We might upgrade our provider bandwith to 100Mbit/s down and hopefully >10Mbit/s up at some point but I doubt it could get any faster anytime soon.

I'm happy for any tips and recommendations.

My current pick for a new setup (excluding SSD & 8GB RAM) would be:

  • Supermicro J1900 board (X10SBA) 2x Intel NIC  180€
  • Supermicro C2558 board (A1SRi-2558F ) 4x Intel NIC - 350€ (cheapest I could find with >2 NICs [:(]

would that not suffice?


This thread was automatically locked due to age.
  • I have A LOT of features on:

     

    In Network Protection > Firewall I block all IPV6, a scanner list of around 200 IP adresses (in and out)

    In Intrusion prevention > Attack Patterns I have rule age "no time limit" for Windows, Linux and Others , 24 months for Attack against servers (DNS, FTP, SSH, SNMP, RADIUS, CVS) and 12 months for attacks against client software and no time limit for Protocol anomaly and malware

    In web protection - > Web filtering profiles > filter actions  I block WEAPONS, CRIMINAL ACTIVITIES, GAMBLES, DRUGS, EXTREMISTIC SITES, NUDITY, and then I add this list : http://mirror1.malwaredomains.com/files/justdomains

  • I bought 2 modules of 8GB DDR4 2666Mhz ECC 19 DIMM KSM26ES8/8ME , for a total of 16GB of ECC ram (it's overkill but I didn't found  2x 4GB DDR4 ECC ...I doubt that ram so little is still sold on DDR4)

  • Hoi,

    You're not paying me for advice, but the following is aimed at others just as much as at you...

    I doubt you can do anything to speed up your UTM with your current configuration.  Adding a list of over 26 thousand sites is not the best way to use the UTM.

    At Check Single URL, you can get a free membership that allows you to check 100 sites at a time.  That should give you the additional categories you might want to block instead of blocking a list like the one in the TrustedSource database.

    A well-cared for environment shouldn't need IPS rules older than 12 months.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • A well-cared for environment shouldn't need IPS rules older than 12 months.    : I know but don't forget that i'm using it at home and behind the UTM I have Linux receivers like two GIGABLUE 800 SE in which the linux based distributions are very old. 

    I doubt you can do anything to speed up your UTM with your current configuration.  Adding a list of over 26 thousand sites is not the best way to use the UTM.   I never counted them but you are right ....I counted them now and there are 26855 lines....

    At Check Single URL, you can get a free membership that allows you to check 100 sites at a time.  That should give you the additional categories you might want to block instead of blocking a list like the one in the TrustedSource database.  : I didn't knew that such service exist ....thanks