On Wed, Apr 4, 2012 at 9:29 AM, Ugo Bellavance <[email protected]> wrote:
> On 2012-04-04 09:19, Michael Schuh wrote: > >> >> >> Am 4. April 2012 14:47 schrieb Ugo Bellavance >> <[email protected] >> <mailto:[email protected]>>: >> >> >> Hi, >> >> Setting up pfsense on a physical server with 2 onboard NICs. The >> available bandwidth is more than enough (gigabit interfaces for a >> 10mbps WAN and 100mbps LAN). I think I should do an LAGG interface, >> then put VLAN interfaces on it, but is the added redundancy worth >> the hassle? >> >> Thanks, >> >> Ugo >> >> ______________________________**___________________ >> List mailing list >> [email protected] >> <mailto:[email protected]**> >> >> http://lists.pfsense.org/__**mailman/listinfo/list<http://lists.pfsense.org/__mailman/listinfo/list> >> >> >> <http://lists.pfsense.org/**mailman/listinfo/list<http://lists.pfsense.org/mailman/listinfo/list> >> > >> >> >> Hi Ugo, >> >> to reach which target? >> > > For all the interfaces > > > There is some lack of Information to give you any advice. >> >> a Firewall with 2 physical interfaces has only wan and lan, so no lagg >> needed? >> > > Hmm, theoretically, I think my idea may work, but I think in practice it > is not possible to configure an lagg interface without having at least one > (temporary) nic available during the configuration. > > If your only interfaces are LAN and WAN, you really should keep them physically separate. As has been mentioned by many others on this list before, a simple configuration change, whether intentional or not, (or plugging a cable into the wrong port) will expose your internal network to your external network, completely bypassing the firewall. If you have other people with physical access to your switch and your switch has any open ports, you run this risk. In one school where I volunteer, they have students playing with the cables create a loop and bring down the whole network at least one a month. (I have almost convinced them to buy boxes with locks for the network switches instead of leaving them open on a table). They had a new IP phone system installed and the phone installer misconfigured some of the switch ports to be on the wrong VLAN. It happens and it's best to avoid, even for small home systems, as a matter of principle. Moshe -- Moshe Katz -- [email protected] -- +1(301)867-3732
_______________________________________________ List mailing list [email protected] http://lists.pfsense.org/mailman/listinfo/list
