On 2012-04-04 18:05, Michael Schuh wrote:


Am 4. April 2012 15:29 schrieb Ugo Bellavance
<[email protected]
<mailto:[email protected]>>:

    On 2012-04-04 09:19, Michael Schuh wrote:



        Am 4. April 2012 14:47 schrieb Ugo Bellavance
        <[email protected]
        <mailto:[email protected]>
        <mailto:[email protected]
        <mailto:[email protected]>>>:


            Hi,

            Setting up pfsense on a physical server with 2 onboard NICs.
          The
            available bandwidth is more than enough (gigabit interfaces
        for a
            10mbps WAN and 100mbps LAN).  I think I should do an LAGG
        interface,
            then put VLAN interfaces on it, but is the added redundancy
        worth
            the hassle?

            Thanks,

            Ugo

            ___________________________________________________
            List mailing list
        [email protected]
        <mailto:[email protected]>
        <mailto:[email protected]
        <mailto:[email protected]>__>
        http://lists.pfsense.org/____mailman/listinfo/list
        <http://lists.pfsense.org/__mailman/listinfo/list>

        <http://lists.pfsense.org/__mailman/listinfo/list
        <http://lists.pfsense.org/mailman/listinfo/list>>


        Hi Ugo,

        to reach which target?


    For all the interfaces


        There is some lack of Information to give you any advice.

        a Firewall with 2 physical interfaces has only wan and lan, so
        no lagg
        needed?


    Hmm, theoretically, I think my idea may work, but I think in
    practice it is not possible to configure an lagg interface without
    having at least one (temporary) nic available during the configuration.


Can you please try to describe your idea a bit better?

At this time we (i) know:

You have one physical Box ( or two? if one, than i guess that other
posting from you is for the same box?)
that you like to use it as Firewall with pfsense.
This box has 2 physical interfaces (NIC's). Those NICs are Gigabit NICs
and you get a 10MBit/s Wan-Connection from your Provider.
Further I know your LAN-Setup has only a 100MBit/s Switch ( i guess so
based on your Informations).

OT (related to another post on this list):
 From that other Post i figure you get/got a /28 IP-Subnet ( i hope its
a real /28 and not just the count of the IP's, like adam described it
earlier)
You like to set up 1:1 NAT for a Part of that Subnet for the usage
within your Servers to provide some Internet-Services(Protocols) to the
outside of your IP-World.

Where you like to put your lagg group/s there to gain which
effort/functionality/state?
what do you like to aggregate to get what? Failover for what?
Loadbalance for what/which load ( sorry - loooool )?

for beeing complete:

Your VLAN-Setup depends on the local network VLAN-Setup, as mentioned
earlier. And yes of course the VLAN-Stuff works since years now very
good and stable.
If your switches aren't managed: Don't care, just ignore it and do not
use any VLAN-Setup. ( i guess no VLAN-Setup needed if the two posts are
for one box, than No VLAN/No LAGG).

So there are a way to much guesses, so i think we need more detailed
informations from you?

Hi,

You got most of the info right, and you even created some ;).

But what I want to do is not possible anyway without putting another NIC in the server (because while configuring the lagg on my 2 onboard interfaces, I'll loose connectivity). Also, Mosche recommends keeping it separate for security reasons. In my case, the security issues involved do not really apply, but in any way, I don't think it is worth all the hassle so I'll put the WAN on one NIC and my internal VLANs on the other.

Thanks,

Ugo


_______________________________________________
List mailing list
[email protected]
http://lists.pfsense.org/mailman/listinfo/list

Reply via email to