This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Another "is this enough hardware" question

I played with UTM a few years back through work, and we're about to become foster carers, so I now feel the need to control what the home internet connection is used for. I don't want to spend millions - the wife would veto that - but I want something relatively saleable.

The basic idea is that I use my existing Asus router as an access point, then monitor/filter/log everything except traffic from designated MACs/IPs.

I have a 400mbit down 22mbit up internet connection, so I'm conscious that I need to be aware of CPU usage etc.

Load will be various mobile devices, tablets, TVs streaming Netflix etc, a few computers connected by LAN, up to 5 total users.

I'm looking at this:

http://www.mini-itx.com/~JBC420

Only 2 LAN but I will use my existing Asus router as a switch/access point.

The N3160 is Braswell so supports AES-NI etc. I have mSATA SSDs and RAM for it kicking around already.

Is this likely to be a bottleneck?



This thread was automatically locked due to age.
Parents
  • Note that Jason appears to have been multitasking and gave you an answer for the XG solution and that his download speed is only 10% of your 400Mbps.  Your limit will be around 40Mbps per connection with Intrusion Prevention active.  If you have ten users downloading simultaneously, you might be able to fill the pipe.  Check out the recent posts in the "Unofficial HCL" pinned to the top of this forum.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Note that Jason appears to have been multitasking and gave you an answer for the XG solution and that his download speed is only 10% of your 400Mbps.  Your limit will be around 40Mbps per connection with Intrusion Prevention active.  If you have ten users downloading simultaneously, you might be able to fill the pipe.  Check out the recent posts in the "Unofficial HCL" pinned to the top of this forum.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
  • Thanks Bob.

    I'm now using the Qotom box, with the i5 5250U, 8GB Ram, and a 256GB SSD.

    This is working quite well, the CPU definitely has a lot more heft to it. I've solved the heating issue by enabling TDP-Down in the bios, taking it from 15W TDP to 9.5W TDP. Obviously this will have a performance impact, but it performs much better than I actually need anyway.

    I've turned off IPS, and this is giving me speedtests in the 380mbit range with very little CPU load.

    Web filtering is active, with the exception of requests from my desktop and server.

    I had blocked outgoing port 53 (DNS) as I was using a static entry for www.google.com to forcesafesearch.google.com, but this actually broke the chromecasts which have hardcoded google dns.

    I added a DNAT rule in to translate all outgoing DNS requests to the router IP (192.168.2.100) and this seems to have solved it, while maintaining my filtering.