|
|
|
|
|
by drnick1
26 days ago
|
|
> How about OPNSense on open hardware of your choice Yes, it's a possibility, but if you want to tinker, I think a plain Linux distro like Debian is better. Turning it into a router is literally a couple of kernel parameters and a few iptables rules to set up NAT. Nowadays that's less than fives minutes of work with Claude. This buys you much better performance and hardware compatibility relative to a BSD system, as well as lower resource usage and attack surface (no GUI or other unnecessary additions). WiFi support on BSD is bad, but on Linux you can use hostapd and almost immediately get an access point for free. And of course Linux is also better if you intend to run other stuff on the same hardware. |
|
I suppose it comes down to what you said - "if you intend to run other stuff on the same hardware." Is it a good idea to run all sorts of extra stuff on your literal firewall/router? And if you did, I'd assume using a hypervisor is safer anyway? That way you can have the GUI and reliability of OPNsense but have a Linux distro beside it.
You also said that Linux has much better performance vs BSD, which seems rather far fetched. Got any data for that?
One other thing: OPNsense comes with a ton of helpful rules to eliminate bot traffic, allow IPv6, different NATs, VLANS, etc which you'd have to add manually. Not the end of the world, but worth considering.