Pfsense on a Virtual machine. NIC question

nsafreak

Diamond Member
Oct 16, 2001
7,093
3
81
A while back I posted about my router hitting a bandwidth limitation due to CPU usage ( Asus Rt-n16 for reference) and I've been waiting for a deal on a decent newer router. It recently occurred to me that I have a server with more than enough spare resources to run pfsense in a VM. The question is whether I should get an Intel dual interface server nic from Amazon ( usually all of $35) and dedicate that to the VM. Or would it be just fine to create a pair of virtual interfaces on my onboard realtek nic and go from there? Advantages or disadvantages to either approach? Server specs are in Sig if needed.
 

thecoolnessrune

Diamond Member
Jun 8, 2005
9,673
580
126
Your virtual interfaces idea only works if you have switches that can do VLANs. You'll need to tag your WAN side, (and untag it on the egress port going to your modem unless your modem supports it too), and you'll need the traffic tagged going into your computer's nics so that the tagged traffic gets to the tagged port on your WAN. If you don't have infrastructure that can do tagged VLANs, then you'll need to go the more direct route and have a dedicated NIC port for the WAN side, and the LAN side.

I currently do Cable Modem --> WAN VLAN Switch Port where traffic is tagged / untagged --> Travel to back room via LACP links --> Exit WAN traffic tagged into ESXi Servers --> Outside WAN Port Group with the WAN VLAN --> PFSense Virtual Machine link on the outside port group --> PFSense Virtual machine link on the inside LAN port group.

Works just fine that way, but like I said, you have to have switching at least on the modem side that allows VLAN tagging / untagging if your modem doesn't allow you to set VLANs. After that, you just need to have switching / nics that will pass VLAN information.
 

nsafreak

Diamond Member
Oct 16, 2001
7,093
3
81
I do have a HP Procurve 3500yl switch that does support vlans so I should be able to set that up.
 

kevnich2

Platinum Member
Apr 10, 2004
2,465
8
76
Pfsense can easily handle virtual interfaces via vlan, but it also can complicate things when trying to troubleshoot. I would highly recommend a minimum of two interfaces to atleast have the option for dedicated WAN and LAN interfaces. Pfsense is a very nice scalable platform
 

thecoolnessrune

Diamond Member
Jun 8, 2005
9,673
580
126
You can do VLANS while still having separate vNICs on the VM. That's what I do as it makes it easy to shut down and turn up the WAN interface. Also makes it simple to route traffic as I just have an entire port group on the WAN VLAN. That lets me have a redundant pfSense box on another host ready to go.

Sent from my Nexus 6P using Tapatalk
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |