Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall 10gb

    Firewalling
    6
    19
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JKnottJ
      JKnott @JamesAdams
      last edited by

      @jamesadams

      I'll give you an example. I have a 500/20 Mb connection. I recently upgraded from 75/10, but my usage hasn't changed. Is pfsense working harder? Perhaps for short bursts, but overall no.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      1 Reply Last reply Reply Quote 0
      • J
        JamesAdams @Cool_Corona
        last edited by

        @cool_corona said in Firewall 10gb:

        IDS/IPS

        I don't yet know which IDS / IPS I'm going to run, because I haven't yet configured a firewall ๐Ÿ˜

        @JKnott I would say the maximum that I happen to use at the same time is 3-4GB

        1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott @JamesAdams
          last edited by

          @jamesadams

          I assume the modem is capable of providing a 10 Gb connection, as is the NIC in the server. However, that says nothing about the performance of those devices. One thing that affects this is all the buffers used in the computer. The packets can be stuffed into a buffer faster than the system can handle. TCP responds to that by slowing down the throughput. So, your hardware may be capable of a 10 Gb connection, but not sustained 10 Gb traffic. Again, it boils down to expected load and what the hardware is capable of.

          This question is similar to "how high is up"?

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          J 1 Reply Last reply Reply Quote 0
          • J
            JamesAdams @JKnott
            last edited by

            @jknott said in Firewall 10gb:

            This question is similar to "how high is up"?

            how high is up ? I did not understand

            JKnottJ 1 Reply Last reply Reply Quote 0
            • JKnottJ
              JKnott @JamesAdams
              last edited by

              @jamesadams

              The point is without data about such things as intended load, hardware performance, etc., it's impossible to answer your question.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              J 1 Reply Last reply Reply Quote 0
              • J
                JamesAdams @JKnott
                last edited by JamesAdams

                @jknott the only thing I can tell you is

                My modem : Freebox delta s (provided by my internet operator)

                My serveur :

                • Ryzen 9 3950X

                • 64Go of ram

                • Network card: Asus XG-C100CF SFP+

                Maximum consumption seen 3000 mbps

                1 Reply Last reply Reply Quote 0
                • ?
                  A Former User
                  last edited by A Former User

                  Real world traffic (imix) can be forwarded (routed not filtered) at 10Gb with Xeon D class chips according to Netgate. Also according to Netgate the same traffic is going to be limited to ~6Gb when filtered (firewalled).

                  So, the lesson to be learned is real world 10Gb performance (LAN<->WAN) with pfSense as it currently exists is not possible with any reasonable hardware you would want to use as an on 24/7 device. Of course, you could build something that could do that but the cost would be a lot of power consumption and the required fan-noise to keep it from melting down. I guess you could water cool... but would you want that running 24/7?

                  Netgate mentioned that part of the move to pfSense plus would be improvements to pf. That would filter up to FreeBSD and be of benefit to all. Also, TNSR was developed for the purpose of moving traffic loads greater than 10Gb.

                  An ASIC based HW router (think big expensive Cisco/Juniper and the like) does 10Gb and beyond routinely.

                  J 1 Reply Last reply Reply Quote 1
                  • J
                    JamesAdams @A Former User
                    last edited by

                    @jwj ok thanks for all your informations :)

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      SteveITS Galactic Empire @JamesAdams
                      last edited by

                      For some comparison points see the higher end models here:
                      https://www.netgate.com/products/appliances/
                      The 1541 shows:
                      L3 Forwarding: 15.41 Gbps
                      Firewall: 6.10 Gbps
                      (10k ACLs)
                      IPsec VPN: 2.81 Gbps
                      (AES-128-GCM / AES-NI)

                      Also, higher speeds are what TNSR is for, Netgate's other product. (the second table)

                      "Can't find a firewall for my massively high speed connection" is definitely a "first world problem"!

                      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                      Upvote ๐Ÿ‘ helpful posts!

                      ? 1 Reply Last reply Reply Quote 0
                      • ?
                        A Former User @SteveITS
                        last edited by

                        @teamits said in Firewall 10gb:

                        is definitely a "first world problem"!

                        Indeed!

                        1 Reply Last reply Reply Quote 0
                        • DaddyGoD
                          DaddyGo @JamesAdams
                          last edited by

                          @jamesadams said in Firewall 10gb:

                          I would like to know if it is possible to make a firewall

                          Hi,
                          Studying these will definitely be a good starting point and help ๐Ÿ˜‰

                          https://calomel.org/freebsd_network_tuning.html
                          https://calomel.org/network_performance.html

                          Cats bury it so they can't see it!
                          (You know what I mean if you have a cat)

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.