[guide] pfsense VM on QNAP in 2020

Introduce yourself to us and other members here, or share your own product reviews, suggestions, and tips and tricks of using QNAP products.
Locked
User avatar
Qmann
Easy as a breeze
Posts: 302
Joined: Mon Jun 08, 2020 8:09 am
Location: USA

Re: [guide] pfsense VM on QNAP in 2020

Post by Qmann »

Moogle Stiltzkin wrote: Sat Oct 24, 2020 2:03 pm
if they are on separate vlans, they both can have internet access. difference is, they can't talk to each other.

so your pc cannot talk to your chromecast, vice versa. but both have internet access. however they can talk to other devices on the same vlan. so you can separate out private network vs iots, vs wireless guest
I have phones and PCs that all use chromecast, and homeassistant that needs to run IoT but accessible on PC and phones to signal devices,,,, so I've never been able to VLAN anything . It seems they all need to be on the same network. Seems like there has to be a way to bridge certain traffic over to the other VLAN by some type of rule, but that is far beyond my mojo. :lol:

I could do guest wifi, but seems like that's about it.
Model: TVS-872XT 64GB (Crucial 64GB Kit CT2K32G4SFD8266)
2 x 1TB XPG 1TB NVMe (ASX8200PNP-1TT-C) [RAID-1]
5 x 16TB EXOS [RAID-5]
Borg Backup running to an offisite pi, AND to the local TS-569L
Model: TS-569L Borg server for backups
6 x 8TB Ironwolf [RAID-5]
Qotom-Q355G4 Fanless Mini Micro PC running pSense in front of everything
haproxy for anything inside the LAN
User avatar
Moogle Stiltzkin
Guru
Posts: 11448
Joined: Thu Dec 04, 2008 12:21 am
Location: Around the world....
Contact:

Re: [guide] pfsense VM on QNAP in 2020

Post by Moogle Stiltzkin »

o.... ur using expressvpn.

that kind of vpn only tunnels your internet traffic so that your ip uses the one of your vpn provider. (i use mullvad)
https://www.youtube.com/watch?v=oja3UzuuqGQ

this is different from the vpn server you run from your own router, then provide your client elsewhere e.g. desktop, laptop, smartphone, so they can connect to your router via vpn for a secure encrypted tunnel. NO Vpn subscription required for this. Lawrence explains how to setup this kind of vpn for remote access
https://www.youtube.com/watch?v=PgielyUFGeQ

Qmann wrote: Sat Oct 24, 2020 2:28 pm
Moogle Stiltzkin wrote: Sat Oct 24, 2020 2:03 pm
if they are on separate vlans, they both can have internet access. difference is, they can't talk to each other.

so your pc cannot talk to your chromecast, vice versa. but both have internet access. however they can talk to other devices on the same vlan. so you can separate out private network vs iots, vs wireless guest
I have phones and PCs that all use chromecast, and homeassistant that needs to run IoT but accessible on PC and phones to signal devices,,,, so I've never been able to VLAN anything . It seems they all need to be on the same network. Seems like there has to be a way to bridge certain traffic over to the other VLAN by some type of rule, but that is far beyond my mojo. :lol:

I could do guest wifi, but seems like that's about it.
i watched lawrence's video, he says it may be possible using the avahi, so that devices on your private lan can communicate with your guest vlan, but not the otherway. or maybe i misundertood what he meant was possible with that kind of setup :' he even cites usage for chromecast in a vlan segmented network. i highly recommend you watch this video

https://www.youtube.com/watch?v=HW9mUrF1ZgU
NAS
[Main Server] QNAP TS-877 (QTS) w. 4tb [ 3x HGST Deskstar NAS & 1x WD RED NAS ] EXT4 Raid5 & 2 x m.2 SATA Samsung 850 Evo raid1 +16gb ddr4 Crucial+ QWA-AC2600 wireless+QXP PCIE
[Backup] QNAP TS-653A (Truenas Core) w. 4x 2TB Samsung F3 (HD203WI) RaidZ1 ZFS + 8gb ddr3 Crucial
[^] QNAP TL-D400S 2x 4TB WD Red Nas (WD40EFRX) 2x 4TB Seagate Ironwolf, Raid5
[^] QNAP TS-509 Pro w. 4x 1TB WD RE3 (WD1002FBYS) EXT4 Raid5
[^] QNAP TS-253D (Truenas Scale)
[Mobile NAS] TBS-453DX w. 2x Crucial MX500 500gb EXT4 raid1

Network
Qotom Pfsense|100mbps FTTH | Win11, Ryzen 5600X Desktop (1x2tb Crucial P50 Plus M.2 SSD, 1x 8tb seagate Ironwolf,1x 4tb HGST Ultrastar 7K4000)


Resources
[Review] Moogle's QNAP experience
[Review] Moogle's TS-877 review
https://www.patreon.com/mooglestiltzkin
MikeLagit
Easy as a breeze
Posts: 332
Joined: Fri Mar 22, 2013 11:40 pm

Re: [guide] pfsense VM on QNAP in 2020

Post by MikeLagit »

You can do both.

Client: Express VPN in pfsense tunnels outgoing traffic to a public shared IP.

While

Server: Is configured in pfsense so you can connect back into the network remotely with Openvpn client on a phone and laptop. You don't expose any ports on the pfsense except 1194 for incoming OpenVPN.


Model: TVS-872XT 16GB
Model: TS-877-1700 16GB
User avatar
Qmann
Easy as a breeze
Posts: 302
Joined: Mon Jun 08, 2020 8:09 am
Location: USA

Re: [guide] pfsense VM on QNAP in 2020

Post by Qmann »

Thanks for the IoT tip! I figured it could be done, I just hadn't spent the time on it yet.
Model: TVS-872XT 64GB (Crucial 64GB Kit CT2K32G4SFD8266)
2 x 1TB XPG 1TB NVMe (ASX8200PNP-1TT-C) [RAID-1]
5 x 16TB EXOS [RAID-5]
Borg Backup running to an offisite pi, AND to the local TS-569L
Model: TS-569L Borg server for backups
6 x 8TB Ironwolf [RAID-5]
Qotom-Q355G4 Fanless Mini Micro PC running pSense in front of everything
haproxy for anything inside the LAN
User avatar
patricepm
Getting the hang of things
Posts: 65
Joined: Mon Jul 03, 2017 9:29 am

Re: [guide] pfsense VM on QNAP in 2020

Post by patricepm »

Hi everybody,

I’d like to know your experiences with having pfsense virtualized, and configured the OpenVPN client in pfsense with a vpn provider.

I’ve got it all up and running but the download speed is soooo slow, nearly 30mbps while connecting to the same vpn server using qvpn gives me over 300mbps.

I’d like to hear your comments on this one.
Thank all!


==================================================
QNAP TVS-473
- 4x WD Red Pro 6TB (RAID 10)
- 16GB Memory
- Firmware: QTS 4.5.1
==================================================
QNAP TVS-473
- 4x WD Red Pro 6TB (RAID 10)
- 2x WD SA510 1TB (RAID 1)
- 2x Samsung 970 Evo plus m.2 1TB (RAID 1)
- 40GB Memory
- Firmware: QTS 5.1.1.2491
User avatar
Qmann
Easy as a breeze
Posts: 302
Joined: Mon Jun 08, 2020 8:09 am
Location: USA

Re: [guide] pfsense VM on QNAP in 2020

Post by Qmann »

I didn't have any issues with speed using Express VPN and got around 170mbps down on my 200 mbps connection. That's using 256-bit encryption on my TS-877.

Verify your cpu is aesni, and you have hardware crypto enables properly in pfsense.

Model: TVS-872XT 64GB (Crucial 64GB Kit CT2K32G4SFD8266)
2 x 1TB XPG 1TB NVMe (ASX8200PNP-1TT-C) [RAID-1]
5 x 16TB EXOS [RAID-5]
Borg Backup running to an offisite pi, AND to the local TS-569L
Model: TS-569L Borg server for backups
6 x 8TB Ironwolf [RAID-5]
Qotom-Q355G4 Fanless Mini Micro PC running pSense in front of everything
haproxy for anything inside the LAN
matthewoliver
Getting the hang of things
Posts: 76
Joined: Tue Nov 17, 2009 5:05 am

Re: [guide] pfsense VM on QNAP in 2020

Post by matthewoliver »

Hi,

Trying to install pfsense on my nas, except I can't as I can't find a proper keyboard mapping for my mac... Any ideas? (I've been struggling with other linux VMs but I eventually managed) or should I buy a usb keyboard to plug in the nas. If so, which one would you recommend?
Thx!
Current:
TVS-h1288X
Intel Xeon W-1250 w/ 64GB Ram
2x Samsung 980 NVMe 1TB
4x Samsung 860 EVO 1TB
8x Seagate IronWolf 10TB
QXP-T32P
Previous:
TS-469L
TS-219
finalwish
Starting out
Posts: 12
Joined: Wed Jan 12, 2011 3:16 am

Re: [guide] pfsense VM on QNAP in 2020

Post by finalwish »

anyone try to enable traffic shaper on their setup?
When I enable traffic shaping using altq, it causes slower download and upload speed.
If I used limiter, there is no issue with speed.
FastLaneJB
Starting out
Posts: 19
Joined: Sat Aug 14, 2021 3:03 am

Re: [guide] pfsense VM on QNAP in 2020

Post by FastLaneJB »

Quick question on this but do people have issues on reboot with their NAS when running a virtual firewall? I'm new to QNAP but had the 4.5.x builds on my TVS-h1288X (Running QTS and not Hero) and it seemed fine. I upgraded to QTS 5 and had a hell of a lot of issues with it that I've wiped it and set it up cleanly but without OPNsense on it at the moment so just using ISP's basic router. Looking in some of their init scripts they have stuff happening on the NAS which is all Internet focused before Virtual Station comes up and hence the virtual router so it has no access.

This seems to cause issues with some things on bootup I think, I think it might be the cause of the nvidia-udm device missing on bootup as it seems to be working fine when it doesn't have a virtual router on it. So for instance the Nvidia Kernel driver has a ton of wget's in it's script, those no doubt take ages and then fail. Not an issue itself if the drivers are all loaded before hand but it does take a lot longer though. If that's not up and the Nvidia GPU before Container Station comes up which creates the nvidia-udm device then it doesn't seem to appear. It seems hit and miss with a virtual router but seems OK without at least in a few reboots I've tested it so far. Basically I think with the virtual router the Container Station is then starting before the Nvidia side is ready because it's stuck trying to pull data from the Internet when it cannot.

Wondering if others have issues or it all works fine other than taking a lot longer to come live?

Maybe I'll give up on OPNsense and just use something like gluetun and a VM for any sites that need VPN access, it was more nicer though having OPNsense handle all that automatically in the background though.

My other thought is to use another router into NAS, then just have OPNsense with double NAT on-top of that so I can control the rest of the network via it but the NAS would end up bypassing it. It doesn't feel ideal though as that traffic won't be visable to OPNsense so things like shaping / limiting won't be possible. With containers on the NAS it'll be generating a lot of traffic itself.
User avatar
Moogle Stiltzkin
Guru
Posts: 11448
Joined: Thu Dec 04, 2008 12:21 am
Location: Around the world....
Contact:

Re: [guide] pfsense VM on QNAP in 2020

Post by Moogle Stiltzkin »

Qmann wrote: Sat Oct 24, 2020 2:22 pm Yeah, I need entire network protection over VPN, so the Qotom does it all on the fly for all traffic. Client to manage the traffic, while Server so i can remote in and work on the network as well.

https://www.expressvpn.com/support/vpn- ... n-openvpn/
there is an update, if u need something like a qotom but has 2.5gbe ports
https://www.youtube.com/watch?v=wUcDg_ms0is


i imagine this is for people needing a router for high speed broadband in the 1gbps or better :'

i only use 100 mbps so i don't need it urgently. but i could use 2.5gbe for my local lan networking speed :D
NAS
[Main Server] QNAP TS-877 (QTS) w. 4tb [ 3x HGST Deskstar NAS & 1x WD RED NAS ] EXT4 Raid5 & 2 x m.2 SATA Samsung 850 Evo raid1 +16gb ddr4 Crucial+ QWA-AC2600 wireless+QXP PCIE
[Backup] QNAP TS-653A (Truenas Core) w. 4x 2TB Samsung F3 (HD203WI) RaidZ1 ZFS + 8gb ddr3 Crucial
[^] QNAP TL-D400S 2x 4TB WD Red Nas (WD40EFRX) 2x 4TB Seagate Ironwolf, Raid5
[^] QNAP TS-509 Pro w. 4x 1TB WD RE3 (WD1002FBYS) EXT4 Raid5
[^] QNAP TS-253D (Truenas Scale)
[Mobile NAS] TBS-453DX w. 2x Crucial MX500 500gb EXT4 raid1

Network
Qotom Pfsense|100mbps FTTH | Win11, Ryzen 5600X Desktop (1x2tb Crucial P50 Plus M.2 SSD, 1x 8tb seagate Ironwolf,1x 4tb HGST Ultrastar 7K4000)


Resources
[Review] Moogle's QNAP experience
[Review] Moogle's TS-877 review
https://www.patreon.com/mooglestiltzkin
User avatar
Qmann
Easy as a breeze
Posts: 302
Joined: Mon Jun 08, 2020 8:09 am
Location: USA

Re: [guide] pfsense VM on QNAP in 2020

Post by Qmann »

Pretty cool little box! I wish I had the 2.5G on my Qotom as I do backups with borg across the interfaces to a different network.

-Q
Model: TVS-872XT 64GB (Crucial 64GB Kit CT2K32G4SFD8266)
2 x 1TB XPG 1TB NVMe (ASX8200PNP-1TT-C) [RAID-1]
5 x 16TB EXOS [RAID-5]
Borg Backup running to an offisite pi, AND to the local TS-569L
Model: TS-569L Borg server for backups
6 x 8TB Ironwolf [RAID-5]
Qotom-Q355G4 Fanless Mini Micro PC running pSense in front of everything
haproxy for anything inside the LAN
User avatar
Moogle Stiltzkin
Guru
Posts: 11448
Joined: Thu Dec 04, 2008 12:21 am
Location: Around the world....
Contact:

Re: [guide] pfsense VM on QNAP in 2020

Post by Moogle Stiltzkin »

Qmann wrote: Tue Mar 22, 2022 6:06 am Pretty cool little box! I wish I had the 2.5G on my Qotom as I do backups with borg across the interfaces to a different network.

-Q
looks better than the official pfsense boxes
https://www.youtube.com/watch?v=Kg1tKcohsQE


you pay more for less. basically you're just paying for the brand rather than the hardware. this is why i rather get something like a qotom -ish device that has good hardware and i know i can install pfsense onto it :D

pfsense still works on non official pfsense hardware still for now :D
https://www.youtube.com/watch?v=cDgF6UoyThQ

-M
NAS
[Main Server] QNAP TS-877 (QTS) w. 4tb [ 3x HGST Deskstar NAS & 1x WD RED NAS ] EXT4 Raid5 & 2 x m.2 SATA Samsung 850 Evo raid1 +16gb ddr4 Crucial+ QWA-AC2600 wireless+QXP PCIE
[Backup] QNAP TS-653A (Truenas Core) w. 4x 2TB Samsung F3 (HD203WI) RaidZ1 ZFS + 8gb ddr3 Crucial
[^] QNAP TL-D400S 2x 4TB WD Red Nas (WD40EFRX) 2x 4TB Seagate Ironwolf, Raid5
[^] QNAP TS-509 Pro w. 4x 1TB WD RE3 (WD1002FBYS) EXT4 Raid5
[^] QNAP TS-253D (Truenas Scale)
[Mobile NAS] TBS-453DX w. 2x Crucial MX500 500gb EXT4 raid1

Network
Qotom Pfsense|100mbps FTTH | Win11, Ryzen 5600X Desktop (1x2tb Crucial P50 Plus M.2 SSD, 1x 8tb seagate Ironwolf,1x 4tb HGST Ultrastar 7K4000)


Resources
[Review] Moogle's QNAP experience
[Review] Moogle's TS-877 review
https://www.patreon.com/mooglestiltzkin
User avatar
Moogle Stiltzkin
Guru
Posts: 11448
Joined: Thu Dec 04, 2008 12:21 am
Location: Around the world....
Contact:

Re: [guide] pfsense VM on QNAP in 2020

Post by Moogle Stiltzkin »

Qmann wrote: Tue Mar 22, 2022 6:06 am Pretty cool little box! I wish I had the 2.5G on my Qotom as I do backups with borg across the interfaces to a different network.

-Q
update
https://www.youtube.com/watch?v=IJhlqb4iGn4

:D
NAS
[Main Server] QNAP TS-877 (QTS) w. 4tb [ 3x HGST Deskstar NAS & 1x WD RED NAS ] EXT4 Raid5 & 2 x m.2 SATA Samsung 850 Evo raid1 +16gb ddr4 Crucial+ QWA-AC2600 wireless+QXP PCIE
[Backup] QNAP TS-653A (Truenas Core) w. 4x 2TB Samsung F3 (HD203WI) RaidZ1 ZFS + 8gb ddr3 Crucial
[^] QNAP TL-D400S 2x 4TB WD Red Nas (WD40EFRX) 2x 4TB Seagate Ironwolf, Raid5
[^] QNAP TS-509 Pro w. 4x 1TB WD RE3 (WD1002FBYS) EXT4 Raid5
[^] QNAP TS-253D (Truenas Scale)
[Mobile NAS] TBS-453DX w. 2x Crucial MX500 500gb EXT4 raid1

Network
Qotom Pfsense|100mbps FTTH | Win11, Ryzen 5600X Desktop (1x2tb Crucial P50 Plus M.2 SSD, 1x 8tb seagate Ironwolf,1x 4tb HGST Ultrastar 7K4000)


Resources
[Review] Moogle's QNAP experience
[Review] Moogle's TS-877 review
https://www.patreon.com/mooglestiltzkin
User avatar
Qmann
Easy as a breeze
Posts: 302
Joined: Mon Jun 08, 2020 8:09 am
Location: USA

Re: [guide] pfsense VM on QNAP in 2020

Post by Qmann »

Very cool! Those boxes are such a great solution for a hardware firewall.

The only watch out with this one would be if you have a very fast connection in which you want to run VPN. You might need more than the celeron to get your full throughput with something like 256 bit encryption.

-Q
Model: TVS-872XT 64GB (Crucial 64GB Kit CT2K32G4SFD8266)
2 x 1TB XPG 1TB NVMe (ASX8200PNP-1TT-C) [RAID-1]
5 x 16TB EXOS [RAID-5]
Borg Backup running to an offisite pi, AND to the local TS-569L
Model: TS-569L Borg server for backups
6 x 8TB Ironwolf [RAID-5]
Qotom-Q355G4 Fanless Mini Micro PC running pSense in front of everything
haproxy for anything inside the LAN
User avatar
Moogle Stiltzkin
Guru
Posts: 11448
Joined: Thu Dec 04, 2008 12:21 am
Location: Around the world....
Contact:

Re: [guide] pfsense VM on QNAP in 2020

Post by Moogle Stiltzkin »

Qmann wrote: Tue Apr 19, 2022 12:39 am Very cool! Those boxes are such a great solution for a hardware firewall.

The only watch out with this one would be if you have a very fast connection in which you want to run VPN. You might need more than the celeron to get your full throughput with something like 256 bit encryption.

-Q
my best router to date for the past 2 decades. rely liking pfsense :D

i'm still not a full expert, but once you set it up, you don't have to mess with it. at most u just need to know how to maintain it by backing up the config, and how to update it. for initial setups there are many guides on youtube out there that show u what to do :D

and you're right, for people wanting to use vpn on it for high speed, then you have to be particular about the cpu u get. if u dont use suricate, pfblocker, vpn, then the low power cpu should be fine, it will even save you on electricity bill.
NAS
[Main Server] QNAP TS-877 (QTS) w. 4tb [ 3x HGST Deskstar NAS & 1x WD RED NAS ] EXT4 Raid5 & 2 x m.2 SATA Samsung 850 Evo raid1 +16gb ddr4 Crucial+ QWA-AC2600 wireless+QXP PCIE
[Backup] QNAP TS-653A (Truenas Core) w. 4x 2TB Samsung F3 (HD203WI) RaidZ1 ZFS + 8gb ddr3 Crucial
[^] QNAP TL-D400S 2x 4TB WD Red Nas (WD40EFRX) 2x 4TB Seagate Ironwolf, Raid5
[^] QNAP TS-509 Pro w. 4x 1TB WD RE3 (WD1002FBYS) EXT4 Raid5
[^] QNAP TS-253D (Truenas Scale)
[Mobile NAS] TBS-453DX w. 2x Crucial MX500 500gb EXT4 raid1

Network
Qotom Pfsense|100mbps FTTH | Win11, Ryzen 5600X Desktop (1x2tb Crucial P50 Plus M.2 SSD, 1x 8tb seagate Ironwolf,1x 4tb HGST Ultrastar 7K4000)


Resources
[Review] Moogle's QNAP experience
[Review] Moogle's TS-877 review
https://www.patreon.com/mooglestiltzkin
Locked

Return to “Users' Corner”