My Quest for the Ultimate Home Office Firewall — Ok, well, Part 2

Hey everyone! Back in 2019, I decided it was time to give my home network a boost.

All about Home lab Inspiration

This image, below, served as my original inspiration. I’m not sure exactly which post it was from, but 99% sure I found it on r/homelab as well as lots of insight on r/selfhosted.

This was where the initial inspiration began, I saved this photo and even though a firewall device was not yet a part of the plan, I dreamed about recreating something similar:

War of the Routers

I started with the Ubiquiti EdgeRouter 10X, which was a fantastic entry-level device for the price:

Despite its affordability, it packed quite a punch with its feature set, including dual-wan failover. It had some firewall capabilities, but over time as my experience with it grew, it lacked the robust traffic inspection and comprehensive control I wanted to explore.

Fast-forward to 2022, I upgraded to a Peplink Balance 20X, primarily because I wanted to upgrade from 2 ISPs to 3 for a multi-WAN failover set up. The Balance 20x, by way of it’s algorithms, handled 3 ISPs like a champ!

But as internet reliability improved on my island, I found myself scaling back to two ISPs, eventually dropping the SIM-based one.

pfSense Firewall FTW?

Now, I’m ready to take things up a notch with a hardware firewall appliance. I’m leaning towards pfSense CE or OPNsense on a device rocking the very power-efficient-while-packing-a-punch N100 CPU.

I’m 90% sure that I’ll be running pfSense and if that is the case, I will be sure to share my experience and feedback. For now, I’ve cleared the first hurdle: Hardware!

Hardware, Hardware, Hardware

After, much debate, discussions, research and rise and repeats… I have finally, yes finally, just yesterday, ordered this rack-mountable N100 based firewall appliance which includes 4x 2.5 G RJ45 and 2x 10G SFP 4xi226-V for $265.55 + shipping to my island (mine has only 2 SFP ports not 4):


This is turning out to be quite the journey, and I can’t wait to share the next steps with you all.

Previous home lab journey in more detail:

Oh? What about Firewalla or the UDM-PRO?

Well, Firewalla came down to cost. At $600.00 I could not justify the cost. This was my Reddit post 2 years ago. Told you, it’s been a lot of searching and questioning. :smile:

Now, let’s compare the Firwalla Gold Plus CPU with the Intel N100:
image

As for the UDM-Pro (or even the Pro-Max), in addition to having less freedom and fewer features compared to pfSense or OPNsense, the CPU also much slower.

It’s not all about CPU performance!

I’m not solely thinking about CPU performance, but I need OpenVPN or WireGuard to be connected to NordVPN 24x7 at 300 Mbps. Firewalla Gold Plus can achieve this @ $600, while the UDM-Pro-Max also at $600 is even slower:

So, it came down to finding suitable hardware for pfSense, OPNsense, or Sophos XG home.

I will continue updates here. — subscribe for updates and bookmark this post below.

2 Likes