Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Home Firewall Hardware - 200Mbps ISP

Hi Guys,

Sorry if this might have been asked before.

I'm looking to run XG firewall on a mini PC. Would the below machine run with all security features turned on.

I have virgin 200Mbps download / 20Mbps upload.

Zotac ZBOX nano C ZBOX-CI323NANO-BE Desktop Computer - Intel Celeron N3150 1.60 GHz DDR3L SDRAM - Mini PC - Intel HD Graphics Graphics - Wireless LAN - Bluetooth - HDMI - 5 x Total USB Port(s)

Thanks

Harps



This thread was automatically locked due to age.
  • Hi Harps,

    It will work, although a better CPU would not hurt you. Try to get Maybe try to get something in the 2+ GHz range.

  • I use a re-purposed HP server. You can find them 3-5 years old on ebay for a few hundred USD.

    They have two NICs already installed which is a requirement for a router like XG.

    I added two more for $25 with another ebay purchase - authentic HP part.  I'm running Server 2016 and my XG runs in a Hyper-V (virtual machine).

    Overall it's the same size as a normal mid-tower PC case and since it runs as a virtual machine it takes no more space than my server already used.

     

    For something smaller with at least two NICs you would need a "small form factor" PC which will probably only have one NIC and will need to add another with a "low profile" PCIe NIC.

    You might even get a "mini" like the Lenovo to work but would have to use a USB Ethernet adapter for a second NIC.  I've not tested these configurations for compatibility.

  • I run a i7 4500 with gigabit Fios and have no problems with 6GB of memory.

    I run full traffic shaping, do some web filtering and may have a OpenVPN connected. 

    Memory sits around ~45% utilization.

    I've found after testing the same hardware with pfSense, OPNSense, Untangle, and ipFire that Sophos XG worked the best for me. I miss not having UPNP for my consoles as I have to create a few port forwards to make the XBox work, but not really a big deal for the overall benefits.

  • I hope you limited the UPNP port access to the XBOX only otherwise you have left a security hole in your defenses?

  • UPNP doesn't exist on the Sophos XG. I was referring to some specific XBox port mappings in place of UPNP.

     

    Thanks.