Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Redundant network recommendations

    General pfSense Questions
    2
    4
    1.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cyberfinn
      last edited by

      Hey

      We are going to deploy a new hosting location. The datacenter provides us with two WAN interfaces for redundancy. One active/one backup.

      My plan is to setup two WAN switches, two pfSense-servers and two DMZ switches, as you can see at my attachment.

      I have some questions:

      • Should we configure a WAN LAGG interface and a DMZ LAGG interface, so both serveres is connected to both switched on both side?

      • Would it be okay, to connect the WAN-lines dirrectly to the two pfSense serveres or should it be connect to at WAN Switch?

      • If we should use LAGG interfaces, which LAGG configuration would you recommend for redundancy and high performance? (failover, failover, roundrobin)

      Are there anything else we should consider?

      Thanks in advance.

      /Jacob
      network.PNG
      network.PNG_thumb

      1 Reply Last reply Reply Quote 0
      • C
        cyberfinn
        last edited by

        Anyone?

        1 Reply Last reply Reply Quote 0
        • C
          cyberfinn
          last edited by

          Would it be possible to order commercial support and use the included time the get recommendations for correct network setup?

          1 Reply Last reply Reply Quote 0
          • J
            JoelC707
            last edited by

            I have not setup LAGG on pfsense yet so I can't really comment on that, though I believe it is what you will want to do on both the WAN and LAN/DMZ sides. For the WAN links, I would have them on switches like you have it diagramed. This allows either server to have access to both links. Do you have at least 3 distinct IP addresses on EACH circuit? You will need that for carp redundancy (if you have your own IPs and are using BGP or something to announce them over the links then you would just need the one set of 3, otherwise you need two sets of 3, one for each).

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.