On Wed, Apr 4, 2012 at 9:29 AM, Ugo Bellavance <[email protected]> wrote:

> On 2012-04-04 09:19, Michael Schuh wrote:
>
>>
>>
>> Am 4. April 2012 14:47 schrieb Ugo Bellavance
>> <[email protected]
>> <mailto:[email protected]>>:
>>
>>
>>    Hi,
>>
>>    Setting up pfsense on a physical server with 2 onboard NICs.  The
>>    available bandwidth is more than enough (gigabit interfaces for a
>>    10mbps WAN and 100mbps LAN).  I think I should do an LAGG interface,
>>    then put VLAN interfaces on it, but is the added redundancy worth
>>    the hassle?
>>
>>    Thanks,
>>
>>    Ugo
>>
>>    ______________________________**___________________
>>    List mailing list
>>    [email protected]
>>    <mailto:[email protected]**>
>>    
>> http://lists.pfsense.org/__**mailman/listinfo/list<http://lists.pfsense.org/__mailman/listinfo/list>
>>
>>    
>> <http://lists.pfsense.org/**mailman/listinfo/list<http://lists.pfsense.org/mailman/listinfo/list>
>> >
>>
>>
>> Hi Ugo,
>>
>> to reach which target?
>>
>
> For all the interfaces
>
>
>  There is some lack of Information to give you any advice.
>>
>> a Firewall with 2 physical interfaces has only wan and lan, so no lagg
>> needed?
>>
>
> Hmm, theoretically, I think my idea may work, but I think in practice it
> is not possible to configure an lagg interface without having at least one
> (temporary) nic available during the configuration.
>
>

If your only interfaces are LAN and WAN, you really should keep them
physically separate.
As has been mentioned by many others on this list before, a simple
configuration change, whether intentional or not, (or plugging a cable into
the wrong port) will expose your internal network to your external network,
completely bypassing the firewall.  If you have other people with physical
access to your switch and your switch has any open ports, you run this
risk.  In one school where I volunteer, they have students playing with the
cables create a loop and bring down the whole network at least one a month.
 (I have almost convinced them to buy boxes with locks for the network
switches instead of leaving them open on a table).  They had a new IP phone
system installed and the phone installer misconfigured some of the switch
ports to be on the wrong VLAN.  It happens and it's best to avoid, even for
small home systems, as a matter of principle.

Moshe

--
Moshe Katz
-- [email protected]
-- +1(301)867-3732
_______________________________________________
List mailing list
[email protected]
http://lists.pfsense.org/mailman/listinfo/list

Reply via email to