this post was submitted on 06 Feb 2025
55 points (96.6% liked)

Selfhosted

42055 readers
503 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I'm thinking about moving my router to be a VM on a server in my homelab. Anyone have any experience to share about this? Any downsides I haven't thought of?

Backstory: My current pfSense router box can't keep up with my new fibre speeds because PPPOE is single threaded on FreeBSD, so as a test, I installed OpenWRT in a VM on a server I have and using VLANs, got it to act as a router for my network. I was able to validate it can keep up with the fibre speeds, so all good there. While shopping for a new routerboard, I was thinking about minimizing power and heat, and it made me realize that maybe I should just keep the router virtualized permanently. The physical server is already on a big UPS, so I could keep it running in a power outage.

I only have 1 gbps fibre and a single GbE port on the server, but I could buff the LAN ports if needed.

Any downsides to keeping your router as a VM over having dedicated hardware for it?

you are viewing a single comment's thread
view the rest of the comments
[–] GameGod@lemmy.ca 6 points 4 days ago* (last edited 4 days ago)

I appreciate the advice. I have like 3 spare routers I can swap in if the server fails, plus I have internet on my phone lol. It's a home environment, not mission critical. I'm glad you mentioned this though, as it made me realize I should have one of these routers configured and ready-to-go as a backup.

My logic is partly that I think a VM on an x86 server could potentially be more reliable than some random SBC like a Banana Pi because it'll be running a mainline kernel with common peripherals, plus I can have RAID and ECC, etc (better hardware). I just don't fully buy the "separation of concerns" argument because you can always use that against VMs, and the argument for VMs is cost effectiveness via better utilization of hardware. At home, it can also mean spending money on better hardware instead of redundant hardware (why do I need another Linux box?).

There are also risks involved in running your firewall on the same host as all your other VM’s

I don't follow. It's isolated via a dedicated bridge adapter on the host, which is not shared with other VMs. Further, WAN traffic is also isolated by a VLAN, which only the router VM is configured for.