Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Which structure is best?

    Scheduled Pinned Locked Moved Hardware
    8 Posts 6 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dgiorgio
      last edited by

      I have future plans to install VPN.

      The image "1.", better do dhcp by the router, or pfsense?

      OR

      1 Reply Last reply Reply Quote 0
      • L
        localhostx
        last edited by

        pfSense should be your router. Option 1 doesn't make any sense to me.

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Another vote for option 2.  :)

          Steve

          1 Reply Last reply Reply Quote 0
          • D
            dgiorgio
            last edited by

            ok, thank you all

            1 Reply Last reply Reply Quote 0
            • J
              jasonlitka
              last edited by

              Option 1 would likely result in double NAT (which is bad).

              I can break anything.

              1 Reply Last reply Reply Quote 0
              • T
                tirsojrp
                last edited by

                2

                1 Reply Last reply Reply Quote 0
                • D
                  dgiorgio
                  last edited by

                  put a backup firewall would be a good idea?

                  In this case, it would be nice to have a router?

                  1 Reply Last reply Reply Quote 0
                  • J
                    JoelC707
                    last edited by

                    Option 2 is best. Pfsense can handle multiple connections like that just fine and would be best for redundancy and load balancing. Option 1 is certainly doable but you would want to disable NAT on it and just do static routing. This would be similar to using a Cisco router in front of a PIX/ASA firewall (which don't really support multi-wan IIRC). Given that pfsense does support multi-wan, I see no reason to do option 1.

                    If you had at least a /29 on one of those connections you could do a redundant pfsense setup. Only the circuit with the /29 range would be available on both firewalls, the other circuit would be on the primary firewall only.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.