pfsense..... Stubbing NICs My head is bursting..


pm1961

Recommended Posts

Forgive the (maybe stupid) question....

 

My mb has two NICs..... so ithought I'd give pfsense in a VM a go and so I watched all the videos etc...

 

But they all seem to deal with add in NIC cards rather than utilising what I already have....

 

My confusion is that, if I stub through my NICs to the VM, am I not denying the use of them to my bare metal server whilst it does its primary job of being my NAS?

 

So, is it even possible to have a VM pfsense running as well as my server?

 

If so, how do I arrange the two NICs?

 

Thanks in advance

Link to comment
1 hour ago, pm1961 said:

Forgive the (maybe stupid) question....

 

My mb has two NICs..... so ithought I'd give pfsense in a VM a go and so I watched all the videos etc...

 

But they all seem to deal with add in NIC cards rather than utilising what I already have....

 

My confusion is that, if I stub through my NICs to the VM, am I not denying the use of them to my bare metal server whilst it does its primary job of being my NAS?

 

So, is it even possible to have a VM pfsense running as well as my server?

 

If so, how do I arrange the two NICs?

 

Thanks in advance

If the NICs are in their own IOMMU groups you should be able to pass one but not the other.

Link to comment

Funnily enough..... I've just tried.... And they are in their own IOMMU groups ..... and they both stubbed "successfully"

 

I say "successfully" because whilst they showed up in the VM edit and I was able to tick the boxes, pfsense couldn't detect both.... just em0.....

 

em0 did show as "Link Up" when I connected either the WAN cable or the LAN cable, but I can't get pfsense to recognise both NICs.

 

Sooooo.......... still baffled!

Link to comment
13 minutes ago, pm1961 said:

Funnily enough..... I've just tried.... And they are in their own IOMMU groups ..... and they both stubbed "successfully"

 

I say "successfully" because whilst they showed up in the VM edit and I was able to tick the boxes, pfsense couldn't detect both.... just em0.....

 

em0 did show as "Link Up" when I connected either the WAN cable or the LAN cable, but I can't get pfsense to recognise both NICs.

 

Sooooo.......... still baffled!

Unraid needs a nic. It sounds like you need 3 total for what you are trying to do.

Link to comment

Ah, my understanding was that I only needed two..... one for the WAN and one for the LAN.......

 

so if I have three NICs on my server, might it look something like this...........?

 

                              Unraid                               Switch 

                            Bare Metal

                             _________                            _____

                             |   NIC 1    |  ---------------------------> |   1  |

                             |              |                            |   2  | ------------------------->

                             |              |                            |   3  |-------------------------->

                             |              |                            |   4  | ------------------------->  Various LAN devices

                             |  _pfVM   |                            |    5 |-------------------------->

WWW  ----------------->  |  | NIC 2|  |                            |    6 |-------------------------->                       

                             |  |         |  |                            |    7 | ------------------------->

                             |  | NIC 3|  |   --------------------------> |    8 |

                             |  ______  |                            ----------

Link to comment

Hi my configuration is similar.

I've been using pfSense for about a year as a virtual machine on unRaid as my main router.
Because I have two internet providers, in my case I have three network cards in total, two built-in the motherboard and one additional (external).
In addition, unRaid also creates a virtual network card that is available to virtual machines and gives them access to the LAN (in my case it's called "br0")
In my case an additional external card is used by unRaid as the main network card for LAN.
Two cards from the motherboard are forwarded to pfSense and are used as WAN ports (in unRaid OS configuration they are blocked and "not available" for unRaid). For everything to work well in the pfSense configuration, this internal link br0 is also available as LAN.

 

obraz.thumb.png.e1682b51e235bf651ffefe947b88d417.png

 

I hope you can see this on the image above.

 

obraz.thumb.png.fee812b103a2bf775a2eb159071fcb1d.png

 

And this is how it looks in my case.
I hope I helped a little.
Regards Janusz

 

 

 

Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.