This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

most powerful hardware for Sophos XG home

Hi,

 

I know there are heaps of thread asking what hardware suits best for the home edition of Sophos XG. However I think my requirements are a little different. Most threads ask for the cheapest, least power consuming units. I rather go for the most powerful one to max out the limitations of 4 cpus and 6gb of RAM.

Currently I am running Sophos XG on an ESXI Server with E3-1265L V2. The Appliance got 4 vCPUs and 5GB of RAM.

I have about 40 live users (serveral servers, pc's and IOT devices) in average, Mainly clientless users. I run 5 Vlans and about 15 Firewall Rules. I already deactivated some Firewall feature in order to push the CPU load average below 4. Currently the average is around 3.5 with regular peaks over 4 which apparently leads to CPU Queuing. 

Since used RAM is around 50%, I believe the virtual CPU Power is just not sufficient for my purposes. Of course I know that vCPUs perform worse than bare metal.

 

Therefore, I am looking for a fanless/silent barebone/mini pc with 4 NIC and a 4 Core CPU with enough power. Furthermore it should be possible to have 6GB of RAM (probably 8GB with 2 GB unused).

I read a lot about the Celerons J1900 as recommodations but I assume that couldn't be enough for my setup.

What CPU do you recommend and is there a nice ready to use barebone suiting these needs? I saw some Jetway units which could be a good option. e.g. https://www.minipc.de/catalog/il/2289

 

thx and Best 

Pete



This thread was automatically locked due to age.
Parents Reply
  • the QOTOM-Q375G4 with I7-5500U seems to be the most powerful from the given links. Since the main difference between i5 and i7 is hyperthreading, maybe even i5 i sufficient.

    with 8gb of RAM and 128 SSD (is this enough?)

    Since the Wifi Option is almost for free, does it make sense to get it in terms of compatibility with Sophos XG?

     

    this comes down to 430$ plus tax and custom fees.

     

     

    Furthermore, has anyone tested this Unit with Sophos XG?

     

     

     

Children
  • On the one (of three) Qotom units I had that worked (for an hour) I had to disable USB3 in the BIOS to get the USB installer to boot. During load, the installer could not find the mSATA drive, but that may have just been due to my unit being defective. I swapped out the mSATA for regular SATA (a nice feature of these micro machines) but could not get the unit to boot again so was unable to test further.

  • ok, that doesn't sound promising.

  • In this case both the i5 and i7 are dual core with hyper threading. The main difference is the base frequency. The i7 has a MUCH higher base frequency of 2.4GHz instead of 1.6GHz. And the i7 will top out at 3GHz instead of 2.6GHz.

     

    Also the built in wifi is not compatible with Sophos XG. So get the no-wifi option. 8Gb of RAM and 128Gb SSD should be more than enough. In fact a 64Gb SSD should be fine as long as you don't keep logs saved for too long.

    I am running UTM 9.5 with a 128Gb SSD and 8Gb of RAM and it is more than plenty even with web filtering and intrusion prevention running. RAM never goes above 45% and that's with a total of 6.8 Gb RAM available due to graphics memory set aside. So this should give you an idea.

  • They make work fine, but Qotom sacrifices build quality to keep the price down. I'm guessing they had a bad batch of the i5 units and each time I would RMA a defective one, I just got the next on the shelf from the same production run. Who knows. The actual hardware used should be just fine with XG and the only BIOS issue I'm aware of is the USB3 problem.

    Personally, I would take an honest assessment of your needs and reconsider a lower-powered unit. I'm very happy with the quality of the Protectli builds and their BIOS doesn't suffer from the USB3 issue. The 4 port quad core Atom based version is serving me well right now with a boat load of IOT devices, multiple streaming platforms that seem to be entertaining empty rooms all day long, and a few servers and VPN connected work devices while averaging 10% CPU (spikes to 30%) and 45% RAM usage (out of 8GB installed, 6GB used). This is with 18 rules, most of which have AV scanning and policy applied.

    Just food for thought.

    Gary

  • alright. thanks for all the answers and recommendations. I'll investigate a little further and see what's the best option for me.

     

    best

    Pete

  • I bought an intel atom 3845 with 4 lan ports from

    https://www.pondesk.com/product/Intel-Atom-E3845-4-LAN-AESNI-3G4G-Fanless-Firewall-Router_MNHO-048

    ships from London,

    I'm very happy with my home setup, consumption is under 7 W,

     

    but I don't know if its cpu is enough for your needs

  • I  bought this one - fully conpatible - installation without problems - localwifi, core I7-4670K - console - 8 LAN Ports - VGA 

      

    https://www.pondesk.com/product/8-LAN-1-COM-4-Fiber-SFP-4G-NGFW-Firewall-1U-Rackmount-Server_NSHO-001

    (hope it is allowed to post a direct product link here)

     Product has  great support, my first unit was damaged by the parcel service, got a new one within a week.

  • sorry, just saw you are looking for a quiet one ! this one is rather noisy.

  • What you a really looking for is a quad core machine with a very fast CPU, it does not have to be i5 or i7 both of which are overkills.

    Your e3-1265l v2 as a bare metal machine should be more than adequate - 2.5ghz to 3.5ghz.

    Ian

  • (just to explain my choice)

     

    have a direct switched 1 GBit connection to the internet at home, just wanted to be on the safe side, at least i can say that with my system mentioned above i have an up- and download rate of about 90 MByte per second all security features of Sophos XG enabled.

    But in fact i am locking for a not so noisy gateway with enough performance for my internet connection  as backup so started following this thread.