this post was submitted on 02 Nov 2025
3 points (80.0% liked)

Self Hosted - Self-hosting your services.

16852 readers
1 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules

Important

Cross-posting

If you see a rule-breaker please DM the mods!

founded 4 years ago
MODERATORS
 

cross-posted from: https://sh.itjust.works/post/49034430

Looking for some advice / recommendations / considerations on running OPNsense on bare metal vs virtualized, and if virtualized how best to do so.

I currently have OPNsense running bare metal on a Protectli FW6E Vault, with the following specs:

  • Intel i7-8550U CPU @ 1.80GHz
  • 120GB mSATA (1% utilization)
  • 16GB RAM (6.5% utilization)
  • 6 Gigabit Ethernet NIC ports

The Vault running OPNsense is the primary firewall and router, any wireless devices connect through a dumb AP running OpenWRT. Connected over Ethernet I have a RPi running HomeAssistant OS (would probably also move to virtual if that's the chosen direction) as well as a TrueNAS setup.

How much of a performance hit would be expected running in some sort of container vs the current bare metal setup? Are there any other concerns with running the main firewall / router virtually vs bare metal to take into account?

you are viewing a single comment's thread
view the rest of the comments
[–] scarecrow365@reddthat.com 1 points 1 month ago

I've run mine as a VM for several years now. I haven't noticed any appreciable impact on performance vs bare metal. I am able to max out my 1000/40 WAN.

That being said, the platform you use to virtualize it on will have an impact. I am running mine on a 3 node proxmox cluster with 10gig networking and SSD backed Ceph storage, so my benchmarks for performance grossly outweigh what my WAN bandwidth can accommodate.