Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: After years of running virtual pfSense/opnSense  (Read 4129 times)

dee.jay

  • Helpful
  • Kitizen
  • *
  • Posts: 1148
After years of running virtual pfSense/opnSense
« on: February 07, 2026, 04:17:29 PM »

I replaced my main switch in my living room with a Mikrotik RB5009. Mostly because: -

1. The fan in the CRS310 was noisy despite me replacing it with a Noctua one
2. Running a virtual firewall is fine, but it gets annoying sometimes as you are beholden on the computers the VM's are running on
3. I had my eye on the RB5009 for a long time, but could not make it work as it only has the 1 x copper 2.5Gbps LAN port so I could connect my Openreach ONT, and only a single SFP+ port so I could have run my VM WAS-110 in there. I would have needed a second device, I do have a CRS305 lying around but it is passive. Probably would have been fine.
4. I need a SFP+ port to connect to the rest of the network upstairs as I run fibre out the house to upstairs into the office where the rest of my 10Gbps networking runs. This allows me to run computers and harness both WAN's at 2.6 Gbps combined

But, dropping my VM connection and going for giffgaff on 1Gbps answers point 3. and point 4., the ONT you get is copper. giffgaff on a speedtest returns 1.1Gbps, so dropped 100Mbps, but it's not like I am struggling for speeds.

A dedicated internet router means I'm not stuck troubleshooting a hypervisor or computer issue, the 5009 now handles all internet. I don't run millions of filtering rules or am not too bothered about hosting, but I'd only need a single rule or two, so I really need a router first + firewall, not a firewall that happens to route.

Now means I'm nearly 100% Mikrotik on the LAN side, got a Netgear out the garden office but that was because I struggled to find a decent Mikrotik PoE switch. I've since found one but it's a 1xx series which I find way more annoying to configure.

EDIT: Wait, I can run Unifi as a container on my RB5009?! waaaat!

« Last Edit: February 07, 2026, 04:20:45 PM by dee.jay »
Logged
routed by mikrotik RB5009, dual WAN.

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5592
    • Thinkbroadband Quality Monitors
Re: After years of running virtual pfSense/opnSense
« Reply #1 on: February 07, 2026, 11:32:58 PM »

Fair enough, I have a ton of rules that would be a royal PITA to move from pfSense to anything else.
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + GL.iNet GL-X3000
Network: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX WiFi: Zyxel NWA210AX + Ubiquity NanoHD
Broadband History & Ping Monitor

dee.jay

  • Helpful
  • Kitizen
  • *
  • Posts: 1148
Re: After years of running virtual pfSense/opnSense
« Reply #2 on: February 07, 2026, 11:40:24 PM »

I realised I literally don’t need any open, I can just put everything behind WireGuard.

Logged
routed by mikrotik RB5009, dual WAN.