Starting pfsense for New Users

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
32,560
Reaction score
10,113
can check with you, what type of ram or ssd they are using? say if i get 8 or16gb and their ssd? is it reliable ? else get my own brand like crucial ram and my own ssd?

i think i get 2.5G, no point getting 10gpe, even the switch is so expensive and my nic also need to be 10g and i have no plan to get fiber 10gbe, only the cheapest plan, maybe simba 10gbe when my m1 500 plan is force by m1 to change plan or starhib brought over m1, but it will be cheapest ont plan

they have 2 version, which one is better QC?

https://detail.tmall.com/item.htm?id=719772687903

https://detail.tmall.com/item.htm?id=714619184058

many thanks

1. The recommendation is to get the bare-bone version if you want better reliability. I have not opened the two CWWK Intel N100 boxes I have to check myself, but I do not think they will use very good one because of the pricing.

I have opened the previous Intel J4105 mini PC (8GB, 256GB, not from CWWK though) I used between early 2021 to late2023, it is using no-brand SSD and RAM.

2. Pricing of 10G switches from China brand are pretty okay now (S$100 to S$150 for 8-ports SFP+ port; S$160 to S$300 for 8-ports 10G RJ45 ports, something in between for 4+4 mixed version ), 2.5G/10G switches are even cheaper (S$30 to S$50 for a switch with quad 2.5G ports and two SFP+ ports).

https://forums.hardwarezone.com.sg/...and-switch-rj45-version-no-sfp-ports.7072646/
https://forums.hardwarezone.com.sg/...port-switch-and-vq-xgs-pon-onu-stick.7047645/

3. The three CWWK versions (先锋版 vs 精英版 vs 锋尚版) should be quite similar in terms of Quality Check. But the features are a bit different.

I bought the Intel N100 先锋版 16GB/512GB for RMB 1560 (now cheaper) in Sept 2023 and it has been running stable since Oct 2023 and 24x7. But I will recommend 精英版 now as it has better interfaces configuration (eg: USB 3.0 ports). When I bought it, there was no 精英版.

I have another CWWK Intel N100 -- X86-P5 (16GB/512GB version at RMB1289, now cheaper) which was bought at the same time and it was also running 24x7 since Oct 2023 to now.

At that time I did not expect XGS-PON based plan to drop price so fast in 2024, and I was waiting for true 2.5Gbps plan to be launched to replace my Singtel 1Gbps plan (contract would only expire in August 2024). So I invested quite a bit on the 2.5Gbe stuff, including a TP-Link 8-port 2.5Gbe switch and later a few 2.5G capable China WiFi 7 routers. I have to invest quite a bit on 10G stuff this year and I think I could have saved some money on the 2.5Gbe stuff and use that fund for 10Gbe stuff. But anyway,

You may want to check out the differences between the three versions: 先锋版 vs 精英版 vs 锋尚版.


4. There are quite some other choices, CWWK is just one of them. You may want to check them out as well.

5. Miniroute R1 Intel N100 version is the one I am using for my Singtel 5Gbps plan. But it has some quality issues -- one of the 2.5G port is dead now. I did not open the box to check what is the problem. But initially I also encounter other issues -- WiFi 7 adapter did not work and the vendor is saying that there is BIOS issues. So you may want to avoid that one since it is also being sold by CWWK and a few other shops, as being the cheapest 10G capable Intel N100 mini PC.
https://miniroute.com/products/mini...pc-2x10gbe-ports-portable-soft-route-computer
 

The_King

High Supremacy Member
Joined
Mar 3, 2003
Messages
26,644
Reaction score
9,882
1. The recommendation is to get the bare-bone version if you want better reliability. I have not opened the two CWWK Intel N100 boxes I have to check myself, but I do not think they will use very good one because of the pricing.

I have opened the previous Intel J4105 mini PC (8GB, 256GB, not from CWWK though) I used between early 2021 to late2023, it is using no-brand SSD and RAM.

2. Pricing of 10G switches from China brand are pretty okay now (S$100 to S$150 for 8-ports SFP+ port; S$160 to S$300 for 8-ports 10G RJ45 ports, something in between for 4+4 mixed version ), 2.5G/10G switches are even cheaper (S$30 to S$50 for a switch with quad 2.5G ports and two SFP+ ports).

https://forums.hardwarezone.com.sg/...and-switch-rj45-version-no-sfp-ports.7072646/
https://forums.hardwarezone.com.sg/...port-switch-and-vq-xgs-pon-onu-stick.7047645/

3. The three CWWK versions (先锋版 vs 精英版 vs 锋尚版) should be quite similar in terms of Quality Check. But the features are a bit different.

I bought the Intel N100 先锋版 16GB/512GB for RMB 1560 (now cheaper) in Sept 2023 and it has been running stable since Oct 2023 and 24x7. But I will recommend 精英版 now as it has better interfaces configuration (eg: USB 3.0 ports). When I bought it, there was no 精英版.

I have another CWWK Intel N100 -- X86-P5 (16GB/512GB version at RMB1289, now cheaper) which was bought at the same time and it was also running 24x7 since Oct 2023 to now.

At that time I did not expect XGS-PON based plan to drop price so fast in 2024, and I was waiting for true 2.5Gbps plan to be launched to replace my Singtel 1Gbps plan (contract would only expire in August 2024). So I invested quite a bit on the 2.5Gbe stuff, including a TP-Link 8-port 2.5Gbe switch and later a few 2.5G capable China WiFi 7 routers. I have to invest quite a bit on 10G stuff this year and I think I could have saved some money on the 2.5Gbe stuff and use that fund for 10Gbe stuff. But anyway,

You may want to check out the differences between the three versions: 先锋版 vs 精英版 vs 锋尚版.


4. There are quite some other choices, CWWK is just one of them. You may want to check them out as well.

5. Miniroute R1 Intel N100 version is the one I am using for my Singtel 5Gbps plan. But it has some quality issues -- one of the 2.5G port is dead now. I did not open the box to check what is the problem. But initially I also encounter other issues -- WiFi 7 adapter did not work and the vendor is saying that there is BIOS issues. So you may want to avoid that one since it is also being sold by CWWK and a few other shops, as being the cheapest 10G capable Intel N100 mini PC.
https://miniroute.com/products/mini...pc-2x10gbe-ports-portable-soft-route-computer

thanks a lot for all the detail.

just order my 6 port CWWK

i think i will choose the one with 6 port bare and get my own ram and ssd, the 6 port will save myself from getting a switch and it should should be more then enough port for me and my router as ap, will also be a backup router when needed


as for 10gbe maybe i change when i really feel there a need for it and bookmark this for future need
 

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,727
Reaction score
3,373
**GOOD RECAP: Site to Site VPN using WireGuard using pfsense**
A good cross-check for those implementing site-to-site WireGuard VPN using pfsense. Some key configurations which Tom from Lawrence System have set which is useful:​
  1. MTU Encapsulation set at 1420 (you should have done so if you've been following the pfsense forum)
  2. Adjust the subnet mask to your needs. /24 may be too wide
  3. Set the connecting site IP as the monitoring IP to track its uptime



**GOOD WATCH: CVE from Palo Alto Network Firewalls**
 

effer315

Junior Member
Joined
Jan 21, 2020
Messages
35
Reaction score
11
To all experts here, how to configure router on a stick using pfsense 2.7? I have a mini pc with single network card and a 4 ports L2 switch. Port 1 connected to pfsense (mini pc) follow by port 2-3 clients and port 4 to ONT.
 

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,727
Reaction score
3,373
To all experts here, how to configure router on a stick using pfsense 2.7? I have a mini pc with single network card and a 4 ports L2 switch. Port 1 connected to pfsense (mini pc) follow by port 2-3 clients and port 4 to ONT.

You can check out this video tutorial. Just replace his "router" with your "pfsense". Do check out the pfsense tutorial if you are new to it.​

 

effer315

Junior Member
Joined
Jan 21, 2020
Messages
35
Reaction score
11
You can check out this video tutorial. Just replace his "router" with your "pfsense". Do check out the pfsense tutorial if you are new to it.​


You can check out this video tutorial. Just replace his "router" with your "pfsense". Do check out the pfsense tutorial if you are new to it.​


Thanks for sharing the video will try it later on.
 

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,727
Reaction score
3,373
Thanks for sharing the video will try it later on.​

Forumers trying these setup should have (or at least learn) some foundation knowledge on vlans tagging and how to go about configuring it correctly on their network appliances (switch and router). If by just following without understanding, you might spend more time trouble-shooting in the future when met with problem like poor speed or whole network down. This is usually caused by "broadcast storm" or running into a "network loop" situation.

Such use cases are usually the 懂的人不会这么作,作的人不一定懂。​
 
Last edited:

effer315

Junior Member
Joined
Jan 21, 2020
Messages
35
Reaction score
11

Forumers trying these setup should have (or at least learn) some foundation knowledge on vlans tagging and how to go about configuring it correctly on their network appliances (switch and router). If by just following without understanding, you might spend more time trouble-shooting in the future when met with problem like poor speed or whole network down. This is usually caused by "broadcast storm" or running into a "network loop" situation.

Such use cases are usually the 懂的人不会这么作,作的人不一定懂。​
Now my mini pc (pfsense) can not get the wan address from ONT? Any idea?
 

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,727
Reaction score
3,373
**LATEST UPDATE: pfsense CE 2.8.0 Stable Update running FreeBSD 15.0**
It's been a while, pfsense CE 2.8.0 stable update running FreeBSD 15.0 has just been released. I updated my home pfsense firewall smoothly without any hiccups. You may need to manually switch the Branch to "Current Stable Version (2.8.0)" to trigger the update. Feel free to update and give it a try. I still suggest backing up your configuration, just in case.

NTwX0KK.png

Trz93AN.jpeg
 

xxnewbiexx

Junior Member
Joined
Jul 24, 2021
Messages
97
Reaction score
16
Any folks have experience to share in place upgrade from 2.7.2 to 2.8? From web was advised to uninstall packages to have a more smooth upgrade due to many components changes in new version.
 

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,727
Reaction score
3,373
Any folks have experience to share in place upgrade from 2.7.2 to 2.8? From web was advised to uninstall packages to have a more smooth upgrade due to many components changes in new version.

I just did an in place upgrade for my home setup. Now probs with mine. After the upgrade, it just auto update my other packages without hiccups after the reboot. YMMV.​
 

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,727
Reaction score
3,373
**GOOD WATCH: pfSense CE 2.8 Is Finally Here. What’s New and What You Need to Know!**
For those lazy to read the change logs before the upgrade. A quick breakdown from Tom of Lawrence Systems. As advised, it might be time to move to "KEA DHCP" if you still using "ISC DHCP", which has been deprecated. I have made the switch much earlier on 2.7.2, and the features seem more complete now to make the change.
 

xxnewbiexx

Junior Member
Joined
Jul 24, 2021
Messages
97
Reaction score
16
I am also happy to report that I have manage to do an in-place upgrade with no issue. I did not uninstall any packages and just selected the upgrade option. :):):)
 

xxnewbiexx

Junior Member
Joined
Jul 24, 2021
Messages
97
Reaction score
16
The new broadband plan are mostly 3 / 5 / 10 GB. My current Pfsense box has support up to 1 GB port.

I am wondering how do folks here deal with this? Get a lower broadband plan? Or upgrade my Pfsense box?

I am happy with my current Pfsense, IP6 configured, accelerator for my gaming working well. If I need to upgrade, I think I may just go to Omada VPN gateway product.

Any thoughts / comment?
 

firesong

Supremacy Member
Deluxe Member
Joined
Jan 17, 2001
Messages
8,646
Reaction score
4,654
**GOOD WATCH: pfSense CE 2.8 Is Finally Here. What’s New and What You Need to Know!**
For those lazy to read the change logs before the upgrade. A quick breakdown from Tom of Lawrence Systems. As advised, it might be time to move to "KEA DHCP" if you still using "ISC DHCP", which has been deprecated. I have made the switch much earlier on 2.7.2, and the features seem more complete now to make the change.

Interestingly, Opn is going with Dnsmasq instead of KEA. It switched to KEA with v.24.1 until it moved with v.25.7.

I was resisting the move to KEA because it was feature incomplete. Now I'm not sure about Dnsmasq.
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ. Forum members and moderators are responsible for their own posts.

Please refer to our Community Guidelines and Standards, Terms of Service and Member T&Cs for more information.
Top