This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Help Choosing Hardware for Heavy Home Use

Hi everyone,

I've been reading threads and researching the Sophos XG firewalls for some time now, but I keep running in circles in regard to my hardware choice.

I'm an IT professional, who works from home, but also has a family that heavily utilizes the internet (tons of web traffic and media streaming, upwards of 1TB+ per month). I also run a Plex media server and an ESX rig with multiple heavily utilized guests that have applications which are externally accessible. An average number of users is 4, but can be 10+ on many occasions. Wireless is also not an issue, as I have multiple Unifi AC-PRO's already in place.

Currently, my internet connection is 60/10, but there's a real chance I'll have access to synchronous 1Gbps in the near future, so I'm trying to future proof. From a module perspective, I'm looking to run basically all of the available modules, except for maybe Security Heartbeat. I'm not sure if I could really utilize it since most of my users are using tablets, phones, and other smart devices, and it was my understanding that was more desktop/server focuses (could be wrong, though?).

Anyway, I think my best option would be an XG-115 if I bought the hardware (about $750 with a 1-year license from CDW), but I didn't know if that was overkill. I was considering the XG-85 (about $550 from CDW with 3-year license) but didn't know if that was enough horsepower.

The other option is to build a mini-ITX machine with the following specs, and then load up the home edition:

Intel Core i5-7500. 4-cores (8 threads) @3.4Ghz

8GB of DDR4-2400 (I know home version can only run 6GB)

128GB Samsung EVO m.2 SSD

Dual Intel GigE NIC's

Cost - about $600

Thanks for all your help everyone!!

- J



This thread was automatically locked due to age.
  • Hi,

    My XG has a high speed cpu, 3.3ghz with for speed and power saving.. IPS on the XG is supposed to be better than the UTM but very hard to tell. I have some features of IPS enabled.

    You can tune the IPS so it does not affect your downloads, would need a faster link to do the testing. I supposed across the internal nics would tell.

    Ian

  • Hi,

    I recently went through the same and ended up with a cheap board off aliexpress and it seems to be running fine for now. 

    I'm running sophos XG 17.02 MR-2 with 4GB Ram and a 120GB SSD.

    Memory hovers around 60% 

    CPU is around 20%

    Saying that, I only have a 20mbit/1mbit ADSL connection.

    I'm using HTTP scanning and Safe search and a couple policies.

    It's a nice small little board which can be mounted.

    I went the four port 1gb connections so I could use LAGs across 4.

    ended up using 1 for a Bridge to my DSL modem and 3 for a LAG group for my network's vlans.

    not sure of the policy of links so I'll just put what it's called.. 

    J1900 Mini ITX Motherboard fanless Pfsense itx board Q1900G4-M

    Product Description
    TYPE
    Description
     
    Mechanical standard
    NANO ITX Industrial Motherboard
    120mm x 120mm
     
    Processor
    Intel® Celeron® Processor J1900 2M Cache, up to 2.42 GHz)
    With up to 10 W TDP
     
    BIOS
    AMI BIOS
    64MBit BIOS
     
    Memory
    One 204-pin DDR3 SDRAM Small Outline (SO-DIMM) socket
    Support DDR3L 1600 MHz SO-DIMM 1.35V
    Support 8GB Max
     
    Graphics
    Intel HD Graphics
    Display: VGA Video One Display
    1 x VGA
    Lan
    4* Intel I211AT - 10/100/1000
     
    USB
    3 x On-board USB 2.0
    1 x On-board USB 3.0
     
     
     
     
    Internal Connectors
    • 1 x Minipcie port (for mSATA SSD)
    • 1 x Minipcie port (for WIFI/BLUETOOT Module,only for USB singal)
    • 1 x DDR3L SO-DIMM Memory Slot
    • 1 x SATA Port
    • 1 x SATA power connector
    • 1 x Automatically boot jumper
    • 1 x RS232 header (optional)
    • 1 x SIM Card slot (optional)
     
    Front Panel
    1 x Push button for Power ON/OFF
    1 x Power LED
    1 x VGA Port
    1 x USB 3.0 ports
    3 x USB 2.0 ports
     
     
    Black Panel
    1 x DC in connector
    Power LED,HDD LED
    4 x RJ-45 Ports
    DC 12V
     
    Working condition
    Operation Temperature -10º-50ºC
    Operation Humidity 10%-90% Relative Humidity,
    Non-Condensing
        Accessories
    Cable for SATA HDD
    1
    12V DC in connector
    2
    HDD led/Power led
    3
    4 * Lan connector
    4
    3* USB 2.0 ports, 1* USB 3.0 port
    5
    VGA connector
    6
    Front panel audio header (optional)
    7
    Power led
    8
    Power button
    9
    CPU fan header (optional)
    10
    RS232 header (optional)
    11
    Automatically boot jumper
    12
    USB header (optional)
    13
    Processor
    14
    SATA 3.0 Port
    15
    SATA power connector
  • I picked up one of these kits (an am very happy!

    https://www.pcengines.ch/apu2c4.htm

    Quad Core AMD, Super low power AND hardware encryption all for about $200!

    I have 100/10 Internet and it has no problem pushing full speed without breaking a sweat.

    You could also do something like this, just need to add a PCI NIC:

    https://www.ebay.com/itm/Fast-HP-8200-Elite-3-10GHz-Intel-Core-i5-2400-Small-Form-Desktop-PC/282482616694?ssPageName=STRK%3AMEBIDX%3AIT&var=581631172472&_trksid=p2060353.m2749.l2649

    Or get the hopped up one with 16GB of RAM and go VM, or not!

    Something like this would work well too:

    https://www.amazon.com/Jetway-JBC313U591W-3160-B-Braswell-Celeron-Barebone/dp/B01M25WO36/ref=sr_1_1?s=electronics&ie=UTF8&qid=1514526186&sr=1-1&keywords=dual+nuc+celeron

    Hope these help!

    Good luck!

    -Rogue