Tips for getting cheap used x86-based firewall with full Gbit NAT (a PC Engines APU) if you are in the US

1 Like

Sorry, I'm trying not to be overly pedantic, but please can we stop talking about brand new $200 mini PCs in a "cheap used x86 firewall" thread? That review tests a $400 variant, ffs.

3 Likes

I agree, perhaps we should add a max $$$ to the topic name ?

1 Like

Yes, I fully agree. However, this is at least a really good review of what others were talking about.

BTW: I got a VeloCloud EDGE 500-N for cheap aka 5 bucks on eBay and will report back with more pictures and my experience once I receive it.

5 Likes

You can already see my results of a tear-down of the VeloCloud on WikiDevi

1 Like

Fujitsu S920 Thin Client

just need an additional dual/quad LAN card, like below

https://www.ebay.fr/itm/265322747878
https://www.ebay.com/itm/265532620553 <-- in order to see the network card.

Fujitsu FUTRO S920 AMD GX-222GC SOC 2.20GHz 4GB RAM 64GB SSD mSATA MLC
https://www.ebay.fr/itm/353938078746

+30 for the PCIe riser
+120 for the ethernet card
this gets expensive fast (for those prices, one could easily buy a used Sophos sg1xx/ xg1xx with four 1000BASE-T ports onboard), power consumption (spec sheet says ~12.7 watts plus probably ~4 watts for the addon ethernet card) shouldn't be bad, but not spectacular either (no idea how well performances would compare).

The necessary addon prices (PCIe riser in particular) would worry me most, as those are semi-hidden costs showing up after you already purchased the device (similar situation with the SBC like solutions (RPi, rockchip, etc), the costs for PSU/ case/ additional ethernet cards etc. usually double the initial price); the upfront price of 250 EUR takimata found would be an easy hard-pass though.

1 Like

The thing with dual/quad cards is it costs extra interrupts when traffic is flowing between clients unlike when you use a switch. So you need a beefier CPU.
Better get a cheap Intel i210/211 network card + (smart) management switch.

I thinking about the Thin Client route but ...
The CPUs are quite old, modern CPUs are way more efficient and have better power management.

Where to get those QCA 9984 4x4 MIMO Wireless cards for cheap?
Even on alibaba/aliexpress they costs are fortune.
I found one austrian company. But they only sell to companies and not to consumers.

Still resolves for me here in the US. Perhaps its a regional thing?

Most of the Sophos XG/SG devices can be upgraded. The 105/115 to 8GB of RAM and the 125/135 to 16GB. If shopping for a 105 or 115 look for the Ver 1 as it will have the PCIe slot even if not a wireless model. For the Ver 2 the PCIe is not populated on the non-wireless devices. Ver 3 currently doesn't have OpenWrt specific support and adds a SFP slot shared with port 4. The version 3 also has different port numbering.

I recently sent a pull request to add the XG 85 and XG 86 which use Realtek RTL8111G for Ethernet so not as desirable. The XG 85 is limited to a fixed 2GB of RAM, but the XG 86 is upgradeable to 8GB.

2 Likes

i added this link only for the picture with the quad lan card, as other links are devices without it. i edited the my post.

who said I had one? :joy:

it was mainly because of the price.
i thought : between 50-83€ for the device + 76€ for the additionnal network card, was a good price.
i didn't thought about the pcie riser. :thinking:

80 bucks for realtek card.
Kinda ripoff...

You can get everything really cheap if you get lucky. I made a post over at STH a while ago: https://forums.servethehome.com/index.php?threads/fujitsu-futro-s920-thin-client-as-opnsense-firewall.31087
Under 100€ for a quad core version with an additional quad port Intel nic. I could have cotton away with 25€ less if I went with the original SSD and no additional RAM.
I can recommend the setup, but I am running OpnSense on it. I have never tried OpenWrt on x86.

EDIT: check out this thread for OEM versions of networking cards: https://forums.servethehome.com/index.php?threads/list-of-nics-and-their-equivalent-oem-parts.20974/

I also have the Fujitsu version of the Intel i350-t4. These OEM parts go for very cheap on eBay.

3 Likes

Does anyone have a Roqos RC10?
Can you show me some pictures of the initial antenna connections?
I removed the wireless chipset without taking pictures so I don't know what the original connection was like.

Any update on the VeloCloud EDGE 500-N? Were you able to load OPENWRT?

Getting that working would create serious development work, expect months of rather dedicated work (and even more to convince upstream that the necessary patches should be merged). If you care about this device, you will have to get your hands dirty doing low-level kernel/ networking development for MDIO access on Intel's igb network driver yourself - it's a reasonable target, but far from easy and might never be done.

--
Don't get me wrong, it's still a very interesting device for a convincing price. It 'helps' that it's only available on the other side of the Atlantic, preventing me from pulling the trigger and sinking my own time into such an endeavour. But asking for "are we there yet" is unlikely to result in success, this really is difficult and may never come to fruition (to be fair, this is the most likely outcome, given that this hardware is rather special - and similar (yes, only 4 ports), but fully supported, alternative devices can be found for reasonable money (patience or a more relaxed budget needed).

1 Like

They use regular mpcie cards for the wifi, so I guess they're U.FLs.

Getting the ones I bought next week, can send you one.

4 Likes