Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall 10gb

    Firewalling
    6
    19
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      JamesAdams
      last edited by

      Hello,

      I would like to install a 10gb firewall on my network to protect my Unraid server, I have an 8gb WAN connection and I would like to know if it is possible to make a firewall with pfsense which supports 10gb because I inquired about the purchase a unifi dream machine pro and with the firewall active it only supports 2.5GB no more.

      thank you in advance for your help

      JKnottJ Cool_CoronaC DaddyGoD 3 Replies Last reply Reply Quote 0
      • JKnottJ
        JKnott @JamesAdams
        last edited by

        @jamesadams

        That would depend on whether the hardware is fast enough.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        J 1 Reply Last reply Reply Quote 0
        • J
          JamesAdams @JKnott
          last edited by

          @jknott what is the minimum to have to have 8gb? cpu and memory

          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @JamesAdams
            last edited by

            @jamesadams

            That I couldn't tell you. My firewall was previously on an HP computer, with an Athlon 3200+ CPU & 4 GB memory. It had no problem keeping up with 500 Mb. The replacement I've ordered is an i5 & 4 GB. Also, routers designed for higher bandwidth will often have layer 3 switches, to take the load off the CPU. A lot will also depend on how you use the Internet. If you simply have a 10 Gb connection, but don't using it much, that's quite different from a lot of usage and several VPNs that need encryption.

            So, the bandwidth of the connection is just a small part of the equation.

            What hardware do you have?

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            J 1 Reply Last reply Reply Quote 0
            • Cool_CoronaC
              Cool_Corona @JamesAdams
              last edited by

              @jamesadams How big is your average package and how many do you see on your WAN connection pr. second??

              10gbe is a lot of things depending on the scenario on which to implement it.

              J 1 Reply Last reply Reply Quote 0
              • J
                JamesAdams @Cool_Corona
                last edited by

                @cool_corona for the package it's a little too technical for me I couldn't tell you

                And my wan connection :

                f0c158b6-a6b9-43bc-bb51-9c768be30e1e-image.png

                Cool_CoronaC JKnottJ 2 Replies Last reply Reply Quote 0
                • Cool_CoronaC
                  Cool_Corona @JamesAdams
                  last edited by

                  @jamesadams It important to know the load and what packages IDS/IPS is supposed to run on it afterwards?

                  10 gbit routing is easy.... 10 gbit IDS is difficult.

                  J 1 Reply Last reply Reply Quote 0
                  • J
                    JamesAdams @JKnott
                    last edited by

                    @jknott said in Firewall 10gb:

                    What hardware do you have?

                    what hardware ? Sever, modem...

                    JKnottJ 1 Reply Last reply Reply Quote 0
                    • JKnottJ
                      JKnott @JamesAdams
                      last edited by

                      @jamesadams

                      I'll give you an example. I have a 500/20 Mb connection. I recently upgraded from 75/10, but my usage hasn't changed. Is pfsense working harder? Perhaps for short bursts, but overall no.

                      PfSense running on Qotom mini PC
                      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                      UniFi AC-Lite access point

                      I haven't lost my mind. It's around here...somewhere...

                      1 Reply Last reply Reply Quote 0
                      • J
                        JamesAdams @Cool_Corona
                        last edited by

                        @cool_corona said in Firewall 10gb:

                        IDS/IPS

                        I don't yet know which IDS / IPS I'm going to run, because I haven't yet configured a firewall ๐Ÿ˜

                        @JKnott I would say the maximum that I happen to use at the same time is 3-4GB

                        1 Reply Last reply Reply Quote 0
                        • JKnottJ
                          JKnott @JamesAdams
                          last edited by

                          @jamesadams

                          I assume the modem is capable of providing a 10 Gb connection, as is the NIC in the server. However, that says nothing about the performance of those devices. One thing that affects this is all the buffers used in the computer. The packets can be stuffed into a buffer faster than the system can handle. TCP responds to that by slowing down the throughput. So, your hardware may be capable of a 10 Gb connection, but not sustained 10 Gb traffic. Again, it boils down to expected load and what the hardware is capable of.

                          This question is similar to "how high is up"?

                          PfSense running on Qotom mini PC
                          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                          UniFi AC-Lite access point

                          I haven't lost my mind. It's around here...somewhere...

                          J 1 Reply Last reply Reply Quote 0
                          • J
                            JamesAdams @JKnott
                            last edited by

                            @jknott said in Firewall 10gb:

                            This question is similar to "how high is up"?

                            how high is up ? I did not understand

                            JKnottJ 1 Reply Last reply Reply Quote 0
                            • JKnottJ
                              JKnott @JamesAdams
                              last edited by

                              @jamesadams

                              The point is without data about such things as intended load, hardware performance, etc., it's impossible to answer your question.

                              PfSense running on Qotom mini PC
                              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                              UniFi AC-Lite access point

                              I haven't lost my mind. It's around here...somewhere...

                              J 1 Reply Last reply Reply Quote 0
                              • J
                                JamesAdams @JKnott
                                last edited by JamesAdams

                                @jknott the only thing I can tell you is

                                My modem : Freebox delta s (provided by my internet operator)

                                My serveur :

                                • Ryzen 9 3950X

                                • 64Go of ram

                                • Network card: Asus XG-C100CF SFP+

                                Maximum consumption seen 3000 mbps

                                1 Reply Last reply Reply Quote 0
                                • ?
                                  A Former User
                                  last edited by A Former User

                                  Real world traffic (imix) can be forwarded (routed not filtered) at 10Gb with Xeon D class chips according to Netgate. Also according to Netgate the same traffic is going to be limited to ~6Gb when filtered (firewalled).

                                  So, the lesson to be learned is real world 10Gb performance (LAN<->WAN) with pfSense as it currently exists is not possible with any reasonable hardware you would want to use as an on 24/7 device. Of course, you could build something that could do that but the cost would be a lot of power consumption and the required fan-noise to keep it from melting down. I guess you could water cool... but would you want that running 24/7?

                                  Netgate mentioned that part of the move to pfSense plus would be improvements to pf. That would filter up to FreeBSD and be of benefit to all. Also, TNSR was developed for the purpose of moving traffic loads greater than 10Gb.

                                  An ASIC based HW router (think big expensive Cisco/Juniper and the like) does 10Gb and beyond routinely.

                                  J 1 Reply Last reply Reply Quote 1
                                  • J
                                    JamesAdams @A Former User
                                    last edited by

                                    @jwj ok thanks for all your informations :)

                                    S 1 Reply Last reply Reply Quote 0
                                    • S
                                      SteveITS Galactic Empire @JamesAdams
                                      last edited by

                                      For some comparison points see the higher end models here:
                                      https://www.netgate.com/products/appliances/
                                      The 1541 shows:
                                      L3 Forwarding: 15.41 Gbps
                                      Firewall: 6.10 Gbps
                                      (10k ACLs)
                                      IPsec VPN: 2.81 Gbps
                                      (AES-128-GCM / AES-NI)

                                      Also, higher speeds are what TNSR is for, Netgate's other product. (the second table)

                                      "Can't find a firewall for my massively high speed connection" is definitely a "first world problem"!

                                      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                      Upvote ๐Ÿ‘ helpful posts!

                                      ? 1 Reply Last reply Reply Quote 0
                                      • ?
                                        A Former User @SteveITS
                                        last edited by

                                        @teamits said in Firewall 10gb:

                                        is definitely a "first world problem"!

                                        Indeed!

                                        1 Reply Last reply Reply Quote 0
                                        • DaddyGoD
                                          DaddyGo @JamesAdams
                                          last edited by

                                          @jamesadams said in Firewall 10gb:

                                          I would like to know if it is possible to make a firewall

                                          Hi,
                                          Studying these will definitely be a good starting point and help ๐Ÿ˜‰

                                          https://calomel.org/freebsd_network_tuning.html
                                          https://calomel.org/network_performance.html

                                          Cats bury it so they can't see it!
                                          (You know what I mean if you have a cat)

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.