For Pfsense/Opensense do can I just use the following hardware or do I need to buy a switch?
You already have 4-port switch (5-port in AP Mode) on your All-in-One (router, switch, access point) GT-AX11000 "router". What you don't have is VLAN support. You need AP with VLAN support for isolated from main LAN/WLAN Guest Network with pfSense/OPNsense.
from what i read, you can install pfSense or OPNsense on your Hunsn Firewall appliance. That would mean you have to degrade your Asus to an AP.
What do I connect to what?
If you are asking questions like this - pfSense/OPNsense firewall is not for you. The setup requires above average networking knowledge.
Okay, back to the drawing board here. What is it that you are trying to achieve, it sounds to me as if you are intending to use the pfsense box as just a "transparent firewall" (there are videos on YouTube about doing this). For a home network, this seems overkill (you could run Skynet on the Asus router, and for a small business network you'd be better off using the pfsense box as router/firewall with APs!
Unhelpful! I believe that I will be able to do it
Just the opposite - I'm trying to save you the frustration. Your thread title is "Pfsense/Opensense help". Both are written incorrectly to begin with (pfSense/OPNsense). You don't need router/firewall OS help at the moment. You need basic connections between devices help. Good luck.
1st reason for doing this is to get better internet and wifi performance.
2nd reason is more customization and control over my network.
You most likely won't get better Internet and Wi-Fi performance. The modem will provide what you have as ISP plan, nothing more. The Asus router will provide still the same Wi-Fi as before. It's the same Asus router after all.
What customization and control you are after? With no VLAN support AP and switch (your home router) network separation is out of question. Asuswrt on your Asus router has good for home router set of control tools and easy to use.
I'm trying to get closer to my Comcast/Xfinity speed of 1.2 gig download.
The feature I am interested in right now is the IPS with Suricata.
Your Asus router can handle this ISP, but you can't push that speed over Wi-Fi unless you have AX clients with 160MHz wide channel support and 160MHz is actually working in your area. You gain speed, but lose coverage in this case. Your existing AX 80MHz capable clients and all AC/N clients will work in exactly the same way. In most cases no device will see >800Mbps on Wi-Fi and Gigabit wired.
Most of Internet communication today is encrypted and IDS/IPS (Suricata or Snort) will see nothing unless you run a SSL proxy Man In The Middle style (with Squid) with associated with it issues. If your idea is inspecting traffic with Suricata - forget about it, it won't work for most of your traffic. The same as AiProtection in Asuswrt it can react on URL rules, but won't see any encrypted data.
So I won't benefit from buying a new router?
If you want more visibility ditch the sense idea and roll Linux.
specs of your box you're planning on using
Thread starter | Title | Forum | Replies | Date |
---|---|---|---|---|
C | Pfsense wins awards | Routers | 34 | |
R | OPNsense + Omada SDN Proxmox container | Routers | 2 | |
C | Help me identify device - ARM, BCM4708, BCM4366, ASUS, LINKSYS, OR ??? | Routers | 3 |
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!