Home

swapping out the router maybe?

$$17641
https://sh.itjust.works/u/muusemuuse posted on Mar 25, 2026 14:10

I have a firewalla purple. it’s idiot mode networking and I love it, but I have never been too thrilled with it’s cloud shit and really don’t to rely on it as my only option right now.

A while back I tried spinning up a VM with opnsense and never got good performance off my home ryzen server. I tried multiple NICs and even bare metal installs and while bare metal was a little more performant, it was never able to reach gigabit on WAN. the firewalla falls just a hair short of gigabit WAN but its still way ahead of my more muscular server. I notice the CPU load spikes high. it seems nothing I do can bring down that CPU load for opnsense. openwrt performed a bit better but still never hit gigabit speeds and was still below the firewalla’s performance. bare metal was again a bit better but still not matching the firewalla.

The firewalla is a heavily optimized amlogic based pi. it’s not special. but it works right and my crap doesnt. I have other SBCs I can use if folding into the home server as a VM just isnt practical but the server is always on anyway and already has extra resources I can throw into this so I’d like to just throw it all in there, snapshot a working config and be done with it if I can.

I walked away from this a while back thinking I would have a fix if I took a break and came back to it later but I’m still stumped. How are other people doing this?

https://sh.itjust.works/post/57393940
Reply
$$17651
https://lemmy.zip/u/frongt posted on Mar 25, 2026 14:28
In reply to: https://sh.itjust.works/post/57393940

What CPU? If it was hitting 100% then that was probably your bottleneck. It just couldn’t handle the packets that fast.

Also note that the more features you turn on (firewalling, routing, inspection, etc.) the more processing has to be done on each packet.

Also also note that due to network overhead, gigabit speed for a real-world download is about 800 Mbps.

https://lemmy.zip/comment/25481808
Reply
$$17663
https://scribe.disroot.org/u/drkt posted on Mar 25, 2026 14:53
In reply to: https://sh.itjust.works/post/57393940

I can easily push gigabit speeds out of a Pentium G3220 running OPNSense so that sounds like a virtualization performance issue.

https://scribe.disroot.org/comment/10161222
Reply
$$17666
https://lemmy.ca/u/cecilkorik posted on Mar 25, 2026 14:58
In reply to: https://sh.itjust.works/post/57393940

Running it as a VM also introduces many other potential sources of inefficiency. I always recommend running a firewall on dedicated bare metal hardware, it is a very specialized task with very particular requirements on behalf of both the hardware and the software. That doesn’t mean you need to use a pre-built appliance, but it does explain why it’s so common, and running it on a VM on a server that is doing other stuff is likely contributing to your issues significantly.

Personally, I run my firewall/router on a very stripped-down Debian with almost no non-essential services and a custom built kernel. I hand-picked a multi-port PCIe x4 Intel NIC with good Linux compatibility and drivers, and I’m using foomuuri to handle the routing and kea to handle DHCP/DNS for my internal network. This is a very minimal, bare-bones configuration and I wouldn’t really recommend it unless you really know what you’re doing, and it’s absolutely not “idiot mode networking” and if that’s what you want you’re going to have a real bad time. But it works for me, so it’s proof that it is possible.

https://lemmy.ca/comment/22406856
Reply
$$17685
https://lemmy.world/u/irmadlad posted on Mar 25, 2026 15:24
In reply to: https://sh.itjust.works/post/57393940

$409.00 The firewalla is a heavily optimized amlogic based pi. it’s not special.

Damn sure seems special. WOW! What features are/were you running on Opnsense?

I looked for specs on the Firewalla Purple. However, to compare, I’m running pFsense on an Intel Celeron CPU J3160 @ 1.60GHz/4 core/32gb RAM with pfblockerng, suricata, ntopng, and Tailscale, unbound, with customized and publicly available DNSBL lists.

Load average 0.80, 0.51, 0.45

As @frongt@lemmy.zip said, the more ‘things’ you have running, the more load, and 800 Mbps is about what I can do even with a gigabit connection and CAT6 pulled for every connection. If I were try to run huge generic block lists, I will start peeking, which is why I run mostly slimmed down, targeted, custom lists. When you stop and think about it, the amount of list checking, resolving, etc, it’s really pretty amazing.

I tried a while back to see if I could better the 800 Mbps, but nothing produced any thing much higher than the standard 800 Mbps which frustrated me. I just finally accepted the fact that getting as close to a gigabit connection would be the best I could do with what I’ve got. Being the type of person I am, I was rather verklempt I couldn’t squeeze that extra 200 Mbps.

https://lemmy.world/comment/22861655
Reply
$$17976
https://sh.itjust.works/u/muusemuuse posted on Mar 25, 2026 23:14
In reply to: https://lemmy.zip/comment/25481808

ryzen 5800xt. it didnt matter if it was booted bare metal either, it would max out 1 or 2 cores and never hit gigabit speeds

https://sh.itjust.works/comment/24494409
Reply
$$17977
https://sh.itjust.works/u/muusemuuse posted on Mar 25, 2026 23:16
In reply to: https://scribe.disroot.org/comment/10161222

it happened bare metal too, booted off USB and with opnsense hitting the hardware directly

https://sh.itjust.works/comment/24494441
Reply
$$17981
https://lemmy.decronym.xyz/u/Decronym posted on Mar 25, 2026 23:20
In reply to: https://sh.itjust.works/post/57393940

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

Fewer Letters More Letters
DHCP Dynamic Host Configuration Protocol, automates assignment of IPs when connecting to a network
DNS Domain Name Service/System
PCIe Peripheral Component Interconnect Express

[Thread #193 for this comm, first seen 25th Mar 2026, 23:20] [FAQ] [Full list] [Contact] [Source code]

https://lemmy.decronym.xyz/comment/20868
Reply
$$18121
https://piefed.blahaj.zone/u/irotsoma posted on Mar 26, 2026 06:18
In reply to: https://sh.itjust.works/post/57393940

Wow, I run opnsense in proxmox along with a pihole and a couple of other small services and never hit 100% CPU on an Intel N100. My miniPC box has 4 2.5 gigabit network ports though I only use 2 of them, one for LAN and one to the modem. I do also have a managed switch, though, that has a couple of 10 gigabit ports a couple of 2.5 and the rest 1. Likely the switch is taking some of load off of the router I suppose. Might try getting a low-end managed switch. If you’re in the US do it quick, though as a lot of networking equipment is about to spike in price since the administration banned all new foreign made equipment and none is made I’m he US.

https://piefed.blahaj.zone/comment/3880594
Reply
$$18149
https://lemmy.world/u/Coleslaw4145 posted on Mar 26, 2026 09:53
In reply to: https://sh.itjust.works/post/57393940

I run Opnsense in a VM in proxmox and I passthrough an Intel X540 (2x 10Gb NIC) card into it. I have 5Gb fibre and i get that full speed on Opnsense. The CPU is an Intel N100 and I never see any CPU spikes.

I’ve had it setup for a few years now and I’ve had no issues with it.

https://lemmy.world/comment/22876098
Reply
$$18164
https://feddit.uk/u/Cyber posted on Mar 26, 2026 11:43
In reply to: https://sh.itjust.works/post/57393940

I think you have enough people here stating their pfSense / OPNSense works fine, so I’d guess you have something unique with your setup - maybe it’s a dodgy cable, or you’re running both In & Out traffic over vlans on the same NIC on your PC and getting problems with unmanaged switches dealing with that…

I had an issue with my pfSense box not negotiating to 1Gb on a Cat6 cable to a switch. I tried all sorts of diagnostics and it turned out to be a problem with the wall socket crimping, so hardware issues do need to be checked… I’m obviously assuming you didn’t use the exact same cables as your firewalla…

Just some different angles to think about…

https://feddit.uk/comment/24101825
Reply
$$18205
https://sh.itjust.works/u/muusemuuse posted on Mar 26, 2026 13:55
In reply to: https://piefed.blahaj.zone/comment/3880594

I have a smart switched. It’s kind of got man managed features like villains and stuff like that but it’s not a full managed switch

https://sh.itjust.works/comment/24503970
Reply
$$18330
https://piefed.blahaj.zone/u/irotsoma posted on Mar 26, 2026 19:31
In reply to: https://sh.itjust.works/comment/24503970

If configured properly, it can usually bypass the router altogether. In my setup I have several VLANs for different traffic, so for me it’s important to have a Layer 3 switch that can handle the routing between VLANS. But if you don’t use VLANs, a layer 2 switch will build a mac address table and bypass the router once it knows where the traffic is going. That way only your DNS queries and similar get sent to the router for internal traffic on the LAN. Then the issue is just traffic going to the internet.

For the internet side you just need to configure the firewall to drop packets on ports (not reject, just drop/ignore) you don’t use and use something like fail2ban or crowdsec to make your router outright drop malicious and LLM bot kinds of traffic to ports you do use that otherwise have to be processed. That generally will reduce processing load unless you have self-hosted services that really generate a ton of traffic in which case you can move those to VPSs outside of your network.

Those are my general strategies at a very high level.

https://piefed.blahaj.zone/comment/3888767
Reply
$$18393
https://lemmy.dbzer0.com/u/zer0squar3d posted on Mar 26, 2026 21:57
In reply to: https://sh.itjust.works/comment/24494409

5800xt is a gpu; what does the bios say when you boot into it about cpu and memory specs?

https://lemmy.dbzer0.com/comment/25187373
Reply
$$18437
https://sh.itjust.works/u/muusemuuse posted on Mar 27, 2026 00:09
In reply to: https://lemmy.dbzer0.com/comment/25187373

No it is a CPU. https://www.amd.com/en/products/processors/desktops/ryzen/5000-series/amd-ryzen-7-5800xt.html

https://sh.itjust.works/comment/24514114
Reply
$$18438
https://sh.itjust.works/u/muusemuuse posted on Mar 27, 2026 00:11
In reply to: https://piefed.blahaj.zone/comment/3888767

I do use VLANs. But in testing even without them going laptop->server->WAN and nothing else it could not do it.

https://sh.itjust.works/comment/24514147
Reply
$$18459
https://lemmy.dbzer0.com/u/zer0squar3d posted on Mar 27, 2026 01:43
In reply to: https://sh.itjust.works/comment/24514114

My bad you are correct.

https://lemmy.dbzer0.com/comment/25190825
Reply