@niko there's a reason why #tnsr uses graph-based instead if packet-& interrupt-based filtering and routing to get 53+ GBit/s instead of ~2\GBit/s per thread (as in #pfSense)…

@merlin consider #pfSense, #OPNsense, #ipFire or if you go > 10GBit/s, #tnsr instead.

@tanquist @toddo previsely that is why #Microsoft, #Adobe, #Oracle, #Cisco et. al. are basically handing out free #licenses (or absurdly discounted bulk licensing deals) to #education institutions given they don't teach competing technologies (i.e. #Linux, #Affinity, #PostgreSQL & #tnsr in these cases)...

  • And I wish I was joking but this is the sad truth!

To answer @pearl's original question:

Maybe @geerlingguy is having a closer look at #CI / #CD-ing #SDN distros.

asyncmeow (pearl) (@[email protected])

networking nerds of fedi are there any good software-based routers that i can easily configure with tools like terraform? im sick of manually managing stuff in the opnsense web ui... the features i need supported on the router and configurable via terraform would be (using the terminology opnsense has for everything where applicable) - virtual IPs - NAT between a WAN network and several internal networks (incl. port forwarding and SNAT based on source subnet) - wireguard VPNs - DHCP static leases - internal DNS from DHCP leases - BGP routing - simple routing between many internal networks, with firewalling between the networks (ie. networks should be mostly isolated, but there's a few holes punched through for some shared services)

rrr.sh
@jwp I mean, it can be pretty fast as evidenced by #tnsr...
https://www.youtube.com/watch?v=nAY1SV74S88
What is TNSR?

YouTube

@alterelefant @HauntedOwlbear nodds in agreement

I rarely see any setup that maxes out the 2 GBit/s per CPU core with #AESni and optimized #IPsec parameters to for that, but if there ever is one that'll need more than what the average 1U 65W EPYC / Xeon can handle + a QAT card, then there's likely budget to get #tnsr #subscriptions waived through...

https://www.youtube.com/watch?v=nAY1SV74S88

What is TNSR?

YouTube

@alterelefant @HauntedOwlbear OFC that's also a common strategy, as is using hardware crypto accelerators to optimize cryptographic throughput…

And since that feature only requires being able to shove two ports WAN & LAN side and have one ethernet cable & interface per machine to link them together, it's even possible to setup in tight spaces with a narrow thermal and energy envelope to work in (I.e. with some #amd64-based #SBC's stuck on a DIN-Rail.)…

  • Also it is a good way to safely update & upgrade software as worst-case one still has a spare up and running and isn't pressured with lack of time to ghettohack a solution if something goes sideways…
Netgate CPIC-8955 Cryptographic Accelerator Card with QAT

@TechSupport @ryze
And once one has to deal woth multiple WANs and entire IPv4-Subnets on that, they really crap out...

Whereas #pfSense & #OPNsense will work fine even in Multi-GBit/s setups.

Only once someome goes full carriergrade #tnsr is wothoit real alternatives.

@xtaran @bjo @33dBm also ich kenne genug Hardware die 25GBit/s schaufeln kann...

Notfalls nen #DIY mit #pfSense oder gar #tnsr aufsetzen...

The Role of U.S. Diplomacy in Countering Russia’s Nuclear Threats and Misbehavior – TNSR Vol 6 Iss 2 Spring 2023
The Role of U.S. Diplomacy in Countering Russia’s Nuclear Threats and Misbehavior
Vol 6, Iss 2 Spring 2023 

Rose Gottemoeller
With t
https://mynomadnotes.nomadaenaustralia.com/2023/03/24/the-role-of-u-s-diplomacy-in-countering-russias-nuclear-threats-and-misbehavior-tnsr-vol-6-iss-2-spring-2023/
#Blog #Russia #Ucrania #USA #Nuclear #Russia #TNSR #Ukraine-Russia #USA