This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Chinese mini PC J1900 + 4 Intel NIC

Hi fellow Sophos users. I am thinking to upgrade from UTM Free license running on UTM 110/120 rev.5 to the XG firewall.

I already know, that the Atom in the old appliance will not handle the home use (4 people with laptops and mobiles, Internet connectivity 80/20 Mbit)

Can someone confirm I can install the XG on a Intel Celeron J1900 + 4x Intel NIC based generic Mini PC with good performance?

I plan to use Web filter, firewall rules of course, NAT (port forward) rules, VPN server, antivirus.

Thanks in advance for reply.

I plan to buy this cheap Chinese thing or maybe the Quotom one - though a bit more expensive:

https://www.aliexpress.com/item/Celeron-J1900-Mini-pc-free-shipping-micro-sd-two-usb-and-four-lan-laptop-overwatch-Computer/32794678352.html?spm=a2g0s.8937460.0.0.57592e0ejFKjsc



This thread was automatically locked due to age.
  • Hi,

    it does work, but make sure the version you purchase has intel nics not realtek or intel 219v.

    I have one and was using it, but found the GUI too slow (I do a lot of changing while testing), but suspect that is a bug which will be fixed in mr3 due for release shortly.

    Ian

  • Thanks for your reply. I will indeed make sure it is Intel NICs in that little box for sure.

    Can you please give me your Internet line speed and approximate number of devices behind the XG, what services you use and what speeds are you able to achieve?

    Maybe what is the CPU utilization during peak hours ?

  • Hi,

    before I swapped the box out I was running 50/20, 13 rues, 28 clienteles users, about 20 active, IPv6 and IP4. IPS, application and web rules. I use mail scanning (IMAPS), https and http, have rules for NTP blocking specific sites and countries. I have an AP55 with 4 SSIDs.

    i was able to achieve the 50/20 using speed tests and download of apple updates. I currently have a 100/40 but not tried the service with the little box.

    CPU was about 10%, but went way over 30% during configuration processes and was very slow in performing updates, waiting for mr3 before putting the little box back online

    Ian

  • Thanks again. That helped me a lot in terms of performance. I now know I will be absolutely fine with only a dozen devices in any case.

    BTW, do you use the quotom box or the cheaper unbranded one (in the original topic link) ?

  • Hi Pavol.

    I use the cheaper aliexpress box because it came with slightly higher performance and 4 intel NICs where as the qotom one had the wrong NICs.

    Ian

    refreshed my info on  your choice and it appears to be different to the one I was looking at, seems slightly newer.

  • Speaking of UTM to XG - I have read a lot of forums but never found this hot topic:

    Is there any way to at least partially migrate the configuration from UTM to XG?

    I have some 50-ish firewall rules, some 30-ish forwarding rules, some DHCP static mappings, many hosts, many services defined.

    It would take me few days to manually configure all these in the XG.

  • There was a trial beta version issued to some commercial customers, but I don't think it is available for home users.

    You seem to have a rather if not excessive number of firewall rules and port forwarding. What do you mean by port forwarding, incoming traffic to a server?

    Ian

  • With port forwarding I mean Static NAT rules, or if you wish - virtual server.

    Nevertheless, I am now playing with SFOS in a VM trying to manually configure things up front, but what I experience is a very very user unfriendlyness all around.

    For example, I have to define a DHCP static mapping and then a network IP Host. in SG you do it with one shot.

    And there is more of strange things.

    I was also reading some forums where people explain in detail what bugs they came thru and ended up with using SG without any hassle.

    So for now, I will re-think my move to XG and stay with what I have.

    Maybe I will purchase this box and migrate my UTM 9.5 to it, as it will be fanless and more power saving and more powerful.

    Thanks for you responses.

    I will come back here as soon as I have any news in this.

  • One item I have noticed since moving back to the E3 is the load has dropped. On the J1900 the load was in the high 2 low 3 now with the E3 the load sits around 2.

    Ian

  • I have noticed some differences in the throughput (depending the active features) today; don´t know if this could / will be really such a significant difference:

    UTM Throughput Performance

    CPU:                                     Intel Celeron G1820

    WebProtection:               No

    AV Proxy:                            No

    Throughput:                      230MBit/s

     

    WebProtection:               Yes

    AV Double Scan:               Yes

    Throughput:                      212MBit/s

     

    Difference                          92,17%

    ----------

    CPU:                                     Intel Celeron J1900

    WebProtection:               No

    AV Proxy:                            No

    Throughput:                      155MBit/s                         

     

    WebProtection:               Yes

    AV Double Scan:               Yes

    Throughput:                      148MBit/s                          278Mbit/s (2 Threads)

     

    Difference:                        95,48%

     

    For testing I used single threaded downloads (speed test tools); if I was using two threads (different sites). The throuput was like in the "2 Threads" - Statement.