pfSense Install Planning - Help


Recommended Posts

Greetings folks. I am prepping to do a pfSense install, but am confused and have questions. I have watched Spaceinvader Ones video series and am confident I can get it up and running but I want to make sure I understand how everything is working, rather than just blindly following a guide. My system has 7 gigabit interfaces. One onboard Intel NIC on the motherboard, an Intel dual port NIC card, and an Intel quad port NIC card. In almost all the guides or tutorials they have me hardware passthrough the NIC that will be used for pfSense. So, remove the interfaces from UnRaid to even see. In Spaceinvaders video he even deletes the virtual interface of the VM.

When I hardware passthrough the interface(s), I am essentially setting up a standalone system, as far as networking is concerned. In this type of install, can pfSense talk to UnRaid internally or does any traffic go out the pfSense interface to my switch and in through an interface of UnRaid? An example would be any internet traffic would come in pfSense wan interface, out pfSense lan interface, to switch, and back in an UnRaid lan interface.

UnRaid VM setup gives me the option to just allocate interfaces to the VM. Why is this a bad way to do the setup?

If I want to use a link aggregated interface in pfSense, would I create the bonded interface in UnRaid and pass it through or would I have passthrough the interface and create the bonded linterface in pfSense?

Thanks for any info.

Link to comment
8 minutes ago, Speedious said:

When I hardware passthrough the interface(s), I am essentially setting up a standalone system, as far as networking is concerned. In this type of install, can pfSense talk to UnRaid internally

no, not unless you add a virtual Nic to pfsense that is managed by the server. I also remove this as I prefer to keep traffic out/off my server after leaving the router.

8 minutes ago, Speedious said:

or does any traffic go out the pfSense interface to my switch and in through an interface of UnRaid?

yes

 

 

9 minutes ago, Speedious said:

UnRaid VM setup gives me the option to just allocate interfaces to the VM. Why is this a bad way to do the setup?

technically, you'd be exposing your server to the internet between server starting until the vm boots. It's not long, but it is what it is. I've always "felt" safer using a card that is isolated from the server and passing it to the network. the word "isolation" is a little comforting. 

 

12 minutes ago, Speedious said:

passthrough the interface and create the bonded linterface in pfSense?

that. but unless you have gigabit+ internet, there is no need because it sounds like pfsense isn't standing in as a switch on your network. so you'd never pass more data than 1gbps.

 

 

 

 

  • Thanks 1
Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.