A few questions: 1. Is your OPNsense instance configured as an invisible passthrough firewall? I recently set this up with zenarmor and it has been working wonders on a very low power Atom appliance. Would you recommend keeping this device physical (since it is on the WAN side of the network, and essentially invisible to the internet and my gateway). I feel like mapping physical WAN ports to a VM could be a little risky and I figured a physical airgap would be better. Management interface is on a secure vlan. 2. What kinds of workloads do you run between your two PM clusters? I currently run a VMware vCenter cluster across three hosts at home, but will probably downscale because I only run 5-10 VM's, and Power is very expensive here in CA. Wanted to see what you host for some inspiration to expand my setup. Keep up the content.
@beamnetworks12 ай бұрын
1. I'm not sure exactly what an invisible passthrough firewall is. But, I can say I am passing the nics through proxmox to the OPNsense VM. There is a higher attack surface from doing that, but it's been working fine for me especially since the nics are solely used for passing through the connections to OPNsense and nothing else. 2. Just a bunch of self hosted services, webservers, etc. Nothing super crazy (yet). I've got probably 20-30 total VMs at the moment all on the proxmox cluster at the datacenter. I've recently been beginning to run some highly available services for DNS, proxies, etc. Those have been fun. i also run Cloudron, Unifi controller, and some other things I can't think of off of the top of my head. I appreciate the support.