Enter the Mini-ITX.com online store

News Browser
Follow us on Twitter!

September 14, 2017
ZOTAC introduces two new ZBOX Mini PC

September 08, 2017
pfSense to require AES-NI from 2.5

September 06, 2017
Gigabyte's GTX 1080 Mini ITX OC 8G Graphics Card

September 05, 2017
ASRock launches DeskMini GTX/RX mini PC

September 05, 2017
Gigabyte's Denverton Mini-ITX motherboards

September 05, 2017
Choosing the right DC-DC PSU

October 24, 2016
JBC313 and JBC323 Mini PCs with Dual Intel LAN and AES-NI

July 13, 2016
Gigabyte and Zotac's Mini-ITX sized GTX 1070 and GTX 1060

April 05, 2016
Mini-STX Roundup

September 02, 2015
Intel introduce 5x5 boards

Buy stuff from us!
Mini-ITX Online Store

Archived News
August 2015
January 2015
October 2014
April 2014
February 2013
May 2012
June 2011
April 2011
January 2011
August 2010
February 2010
January 2010

Full Archive

pfSense to require AES-NI from 2.5: how it affects you
September 08, 2017

pfSense Logo

Earlier this year Netgate - the maintainers of pfSense, the popular open source firewall/router distribution based on FreeBSD - announced that they would be dropping support for CPUs without AES-NI starting from version 2.5.

AES-NI is an extension to the x86 instruction set used to hardware-accelerate AES encryption and decryption.

Desktop CPUs have supported AES-NI for several years, though the lower power consumption Atom and Celeron CPUs used in many Mini-ITX boards and appliances have not until more recently.

Netgate plan to remove the monolithic PHP layer in pfSense 3.0 altogether and expose the configuration instead as a REST API. An all-new javascript based GUI will talk to the back-end of the local device or to a cloud-based back-end to orchestrate (potentially) multiple instances. This will absolutely require strong end-to-end encryption. When AES is implemented in software it is much more susceptible to side-channel attacks. From this point of view it makes a lot of sense to reduce the risk of thousands of pfSense instances being compromised.

How does this affect my existing Mini-ITX pfSense Firewall?

It won't, unless you want to upgrade. If your CPU has AES-NI, you can continue upgrading to 2.5 and beyond. If your CPU does not support AES-NI then you will be able to go no further than 2.4, which will still be available for download. Support for 2.4 will continue for many months afterwards and of course your firewall will continue to function, though without any features introduced from 2.5 onwards.

If your motherboard has a CPU from the following list it has AES-NI:
N3050, N3150, N3160, N3350, N3450 and later

If your motherboard has a CPU from this list it does NOT have AES-NI:
D510, D525, D2550, N2600, N2800, 845, 1047, J1800, J1900, N2807, N2930

If you don't know your CPU type it will show in your pfSense dashboard. We can't list every CPU here. Intel owners can check on ARK whether their processor supports AES-NI: type "ark" followed by the CPU name into Google and look for "AES" on the first resulting page. AMD owners may want to try their luck with cpu-world.com

When will this happen?

At the time of writing, 2.3.4 is still the official release and later versions are still in beta. pfSense 2.5 will be built on FreeBSD 12 - which won't be released until early/mid 2018. A pfSense 2.5 release is most likely much later in 2018.

Are there any alternatives to pfSense?

There are many. VyOS, Untangle, IPFire, Sophos UTM, ZeroShell, Shorewall, DDR-WRT to name but a few... or plain old IPTables.

Links:
pfSense 2.5 AES-NI announcement and Roadmap
Relevant comment thread on reddit

Store Links:
Mini PCs we supply that support AES-NI
Motherboards we supply that support AES-NI

m Permalink | mini-link

Recent Stories

ZOTAC introduces two new ZBOX Mini PCs 14 Sep 17
pfSense to require AES-NI from 2.5: how it affects you 08 Sep 17
Gigabyte's GTX 1080 Mini ITX OC 8G Graphics Card 06 Sep 17
ASRock launches DeskMini GTX/RX mini PC with GTX 1080 05 Sep 17
Gigabyte's Denverton MA10 Mini-ITX motherboards 05 Sep 17
Guide: Choosing the right DC-DC PSU 05 Sep 17
Video: JBC313 and JBC323 Mini PCs with Dual Intel LAN and AES-NI 24 Oct 16
Gigabyte and Zotac first out of the blocks with Mini-ITX sized GTX 1070 and GTX 1060 13 Jul 16
Mini-STX (5x5) Roundup 05 Apr 16
Intel introduce 5x5 boards: Socket CPUs supported up to 65W TDP, Smaller than Mini-ITX, Larger than NUC 02 Sep 15

News Archives

September 2017
Full Archive

*Advert* Tiny ARTiGO Pico-ITX Kits! *Advert*
Plenty in stock at the Mini-ITX.com Online Store. We serve the UK, Europe, USA and beyond. Order in-stock items before 7.30PM GMT and we'll ship same day!

* Back to Mini-ITX.com *


Board Finder
Case Finder
Mini PC Finder
Quick Links
Mini-ITX Online Store

Mailing Lists:
Mini-ITX Store

Mini-ITX 101
Mini-ITX History
Advertising

Projects:

Show Random
How to submit
your project

Most Viewed Today

ITX-Laptop

XBMC-ION

Mini-Cluster

NAS4Free

Windows XP Box

Accordion-ITX
Aircraft Carrier
Ambulator 1
AMD Case
Ammo Box
Ammo Tux
AmmoLAN
amPC
Animal SNES
Atari 800 ITX
Attache Server
Aunt Hagar's Mini-ITX
Bantam PC
BBC ITX B
Bender PC
Biscuit Tin PC
Blue Plate
BlueBox
BMW PC
Borg Appliance
Briefcase PC
Bubbacomp
C1541 Disk Drive
C64 @ 933MHz
CardboardCube
CAUV 2008
CBM ITX-64
Coelacanth-PC
Cool Cube
Deco Box
Devilcat
DOS Head Unit
Dreamcast PC
E.T.PC
Eden VAX
EdenStation IPX
Encyclomedia
Falcon-ITX
Florian
Frame
FS-RouterSwitch
G4 Cube PC
GasCan PC
Gingerbread
Gramaphone-ITX-HD
GTA-PC
Guitar PC
Guitar Workstation
Gumball PC
Hirschmann
HTPC
HTPC2
Humidor 64
Humidor CL
Humidor II
Humidor M
Humidor PC
Humidor V
I.C.E. Unit
i64XBOX
i-EPIA
iGrill
ITX Helmet
ITX TV
ITX-Laptop
Jeannie
Jukebox ITX
KiSA 444
K'nex ITX
Leela PC
Lego 0933 PC
Legobox
Log Cabin PC
Lunchbox PC
Mac-ITX
Manga Doll
Mantle Radio
Mediabox
Mega-ITX
Micro TV
Mini Falcon
Mini Mesh Box
Mini-Cluster
Mobile-BlackBox
Moo Cow Moo
Mr OMNI
NAS4Free
NESPC
OpenELEC
Osh Kosh
Pet ITX
Pictureframe PC
Playstation 2 PC
Playstation PC
Project NFF
PSU PC
Quiet Cubid
R2D2PC
Racing The Light
RadioSphere
Restomod TV
Robotica 2003
Rundfunker
SaturnPC
S-CUBE
SEGA-ITX
SpaceCase
SpacePanel
Spartan Bluebird
Spider Case
Supra-Server
Teddybear
Telefunken 2003
TERA-ITX
The Clock
ToAsTOr
Tortoise Beetle
Tux Server
Underwood No.5
Waffle Iron PC
Windows XP Box
Wraith SE/30
XBMC-ION

How to submit
your project

Reviews:
CF-S688 E-Note
Cubid 2677R
Cubid 2688R
Cubid 3688
GAlantic GA610i
Hush Mini-ITX
Lian Li PC-402A
Jetway B860T
VIA M 10000
VIA MII 12000
VIA Nano-ITX
VIA Pico-ITX
Sigma XCard
Travla C137

Guides & Tips:
5.1 EPIA Audio
Cubid Tips
EPIA CL Firewall
EPIA COM IR
EPIA SCART
Extra USB Ports
IPCop Gateway
Overclocking
PowerLCD

Drivers:
EPIA  EPIA V
EPIA M  EPIA MII
EPIA CL  EPIA PD
EPIA TC
.

Mini-ITX Online Store

Contact Us

Store: +44 (0) 845 475 8 475

Store enquiries: store@mini-itx.com

Other enquiries: feedback@mini-itx.com

Visit the Store

Click here to enter the online store

Social

Follow us on Twitter!

Join our Mailing List

Copyright: All content on this site is Copyright © 2002-2017 Mini-ITX.com and respective owners, all rights reserved.