Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    1541 HA throughput and port configuration problem

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    7 Posts 2 Posters 664 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      Rod21
      last edited by

      Hello there,
      I am studying the hardware upgrade for one of my clients who works in video surveillance and connects their network to their clients' networks via IPSEC to access camera video streams. They have 2 fibers capable of providing speeds higher than 1 Gbps, so I need to connect them to 10G ports. I also need to connect the internal switches at 10G, totaling 4 ports.
      The current configuration is on the verge of saturation, and they are consuming about 400 Mbps in IPSEC VPN. I would like to propose a solution based on the 1541 HA model.
      - On the 1541 model page, the advertised speeds in IPSEC VPN IMIX (1.77 Gbps) seem to be achieved with the CPIC-8955 accelerator card. What are the speeds obtained without the card (as I believe I won't be able to have 4 ports 10G and the card simultaneously)?
      - Do you have a solution for connecting both 4 ports 10G and the accelerator card simultaneously?
      Thanks in advance.

      stephenw10S 1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Yes, there is only one available slot in the 1541 so you cannot use the CPIC card with an expansion NIC.

        However the measured IMIX IPSec performance without it is not that much lower, ~1.5Gbps. The inclusion of IIMB in recent versions helps. You're more likely to be restricted by the link than the encryption rate

        Steve

        1 Reply Last reply Reply Quote 0
        • R
          Rod21
          last edited by

          Thanks @stephenw10 for your reply.

          I thought of another solution: what about using one 10G port for WAN and the other one for LAN? Behind the WAN port, I could plug in a 10G switch that handles the 2 fibers with VLANs.
          1541 HA with 2 10G ports.png

          I'll have to share the 10G port bandwidth between the 2 fibers, of course. But 1/ is it possible to configure pfSense for this solution? And 2/ my client has a pool of public IPv4 IPs, 6 for the first fiber (subnet mask of 29 bits) and 14 for the second one (subnet mask of 28 bits). There are 20 IPv4 IPs to configure inside pfSense; is it possible too?

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Yes, you can do that. The WANs are 1G so having those as VLANs on a 10G port isn't really an issue.

            R 1 Reply Last reply Reply Quote 0
            • R
              Rod21 @stephenw10
              last edited by

              @stephenw10 said in 1541 HA throughput and port configuration problem:

              The WANs are 1G

              What do you mean ? I'm not sure to understand...

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator @Rod21
                last edited by

                @Rod21 said in 1541 HA throughput and port configuration problem:

                They have 2 fibers capable of providing speeds higher than 1 Gbps,

                My mistake, I misread that. How fast are the WANs? If it's less than, say, 3Gbps it should be fine.

                1 Reply Last reply Reply Quote 0
                • R
                  Rod21
                  last edited by

                  @stephenw10 said in 1541 HA throughput and port configuration problem:

                  If it's less than, say, 3Gbps it should be fine

                  3Gbps for each fiber, so 6Gbps ? It provides a good margin from now I think. Currently, each fiber is at 800Mbps.

                  1 Reply Last reply Reply Quote 1
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.