this post was submitted on 29 Nov 2023
0 points (50.0% liked)
Homelab
380 readers
9 users here now
Rules
- Be Civil.
- Post about your homelab, discussion of your homelab, questions you may have, or general discussion about transition your skill from the homelab to the workplace.
- No memes or potato images.
- We love detailed homelab builds, especially network diagrams!
- Report any posts that you feel should be brought to our attention.
- Please no shitposting or blogspam.
- No Referral Linking.
- Keep piracy discussion off of this community
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
The hardware Mikronik has does not do L3 on-chip so it will be CPU based, and will be horrible. I also find RouterOS really hard to use compared to things like JunOS. I'm bias here.
Why can't you use OPNsense if you for some reason dont want to sit in the same boat as PFsense? I have not followed whatever happens there as I left PFSense years ago.
Having L3 at the access switch layer have other benefits.
Thx. for the response. I bit the bullet and bought a second identical machine (lenovo tiny m720q) to what I'm running now with pfsense. When it gets here and I get it together I'll run the second machine with opnsense, in parallel to the current pfsense setup. I'll probably do something like a double-nat and use opnsense for my esxi and homelab stuff so I can keep pfsense running the rest of the house.
What do you mean other benefits? ACLs? I have pfsense (2x sfp+ lan lacp, 1x mobo gigabit wan), then a Cisco SG500X-24 in L2 mode, then from there I've got the mikrotik crs317 and a bunch of cisco sg300 switches. If I make a change I'd probably offload the dhcp server too. What else am I missing?
Should I try to replace pfsense 1:1 with opnsense for now, and then make changes later (or don't change anything once I'm comfortable)? I've been using essentially the same setup for so long I don't really know much else.