Search results

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

  1. Christos

    Converting a Cisco Ironport C170 to Opnsense router

    The option Serve Expired on Unbound will give you a significant speed bust, as it will always answer the DNS query from cache and then ask Quad9 for a data refresh. I also use Quad9 together with pfblockerNG of ad blocking.
  2. Christos

    Cisco wireless 150AX accesspoint

    They are not working together with previous models like the CWB 140. I wouldn't trust this line.
  3. Christos

    Firewalla Gold

    It has a Talos-Snort list. It is true that it cannot block an app on layer7. However, you can add a feed from github that contain let's say Facebook's list of domains and IPs and you can block them on firewall and on DNS level. Here is an example.
  4. Christos

    Firewalla Gold

    I don't do IPS/IDS as it requires SSL decryption on router side, in order to work properly. However, I use pfblocker that creates firewall IP lists using feeds from Talos, Spamhaus and many more. It aslo creates rules for porn and ad blocking. This combined with Quad9 for malware, creates a very...
  5. Christos

    Converting a Cisco Ironport C170 to Opnsense router

    Since the release of pfSense+ with a free license for home/lab, I see no reason for someone to choose opnsense anymore. pfSense is very stable and with the ZFS snapshots they added recently, you can try and break anything and it will come back to its previous state with a simple reboot...
  6. Christos

    Wired router buying advice

    This seems impossible. Search and you will find them.
  7. Christos

    Next Steps from Cisco RV340

    Does Cisco Meraki MX line have a long life until it reaches EOL and stops being updated?
  8. Christos

    Next Steps from Cisco RV340

    How much does the licence cost for Firepower 1010?
  9. Christos

    Wired router buying advice

    Then get another Asus router and set it as the Primary AiMesh router. The Asus RT-AC86U set it as AiMesh node. The RT-AX86U PRO would be a good choice because of the 2.5G port.
  10. Christos

    Firewalla Gold

    Firewalla is like a pre-configured pfsense box. You can do exectly the same things with pfsense + unbound + pfBlockerNG (IP + DNS) + Openvpn/Wireguard. The only benefits you get with Firewalla is the mobile app and the 2.5G ports on the latest model.
  11. Christos

    To Bridge or not to Bridge

    The ISP router may cause problems if does not support many states or have small timeouts for tcp and udp connections. I vote for the bridge setup, with vlans.
  12. Christos

    Next Steps from Cisco RV340

    Avoid opening ports and use vpn instead to access your lan. This will also protect your internal devices that may not been patched yet.
  13. Christos

    need a new wifi router - old tech. vs. new?

    I would put latency as the requirement with the highest priority, because of the gaming and home-office work. So you may need a router that supports FQ_Codel quality of service. My suggestions are 2: a) seperate router from wifi. Get a pfsense appliance (starting from 190$) or a mini pc with...
  14. Christos

    need a new wifi router - old tech. vs. new?

    Since you don't have a lot of neighbours who interfere on 5GHz, 802ac would be a good choice. it is cheap and stable/mature at this moment. "Possible concurrent devices use WiFi: 3-4 but that's the rare case mostly 1-2 devices". Then 2x2 or 3x3 would be fine.
  15. Christos

    Next Steps from Cisco RV340

    I believe that in the case of a big and exploited security vulnerability, Cisco will provide a fix to this router. At this moment it is hard to find a netgate appliance anyway, so you can wait for 6-9 months and make a resercah then. pfSense is not hard, considering your experience with Vlans etc.
  16. Christos

    AdGuardHome AdGuardHome Blocklists

    I use Quad9 DNS for malware + OISD Basic for ads. Very safe and efficient combination with no false positives.
  17. Christos

    Alternatives to EdgeRouter-X?

    The Edgerouter line continues to receive security updates, so if the ER-X is fine for your internet speed, I see no reason to replace it.
  18. Christos

    ISP planning to abandon bridge-mode in their issued cable modems

    They still offer PPPoE passthrough, that is similar to bridge mode.
  19. Christos

    Three Dumb Routers concept inroduced by Steve Gibson (2016)

    I agree with Tech Junky. Just create a guest SSID and use it for iOT and anything not trusted.
  20. Christos

    Router that can do full-speed Gigabit qos?

    You only need QoS on the upload path (25Mbit). Any router can do that.
Top