Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFsense as L3 Router

    Scheduled Pinned Locked Moved General pfSense Questions
    13 Posts 5 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      echellis
      last edited by

      Looking to replace our aging HP 5406 switch with something more updated. We currently use Unifi access points in some of our schools so started our search for a new core switch with Ubiquiti. Below is a picture of our concept idea on how to setup our core switch. We are aware that the Unifi line doesn't do L3 switching, so we will be passing that off to a PFsense box that will handle all VLAN routing. The school has about 1200 devices on any given day. Just wanted to get peoples advice on this config and if PFsense could handle all the VLAN routing. We would be building a PFsense box on an Intel Xeon server with 32gb RAM and raided SSDs

      20190619_141545.jpg

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Doesn't matter how many devices are on the network (aside from addressing concerns).

        What matters is what they are doing, throughput, packets per second, etc.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        E 1 Reply Last reply Reply Quote 0
        • kiokomanK
          kiokoman LAYER 8
          last edited by

          someone will answer your question but in the meantime you should know that
          I will not be able to sleep peacefully tonight without knowing where IDF-C is
          😂

          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
          Please do not use chat/PM to ask for help
          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

          E 1 Reply Last reply Reply Quote 0
          • E
            echellis @Derelict
            last edited by

            @Derelict all devices are chromebooks doing web browsing and some video streaming from youtube Netflix etc.

            DerelictD 1 Reply Last reply Reply Quote 0
            • E
              echellis @kiokoman
              last edited by

              @kiokoman IDF C is actually the MDF.

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate @echellis
                last edited by

                @echellis That doesn't really give any indication. Any Xeon should be fine though. Use good (Intel) NICs.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Are you purely routing? No firewall, no NAT?

                  If you can disable pf and route only then you will close to 10Gb I would think, if that's what you're asking here.

                  Steve

                  E 1 Reply Last reply Reply Quote 0
                  • E
                    echellis @stephenw10
                    last edited by

                    @stephenw10 It would be doing routing, firewall, and nat

                    1 Reply Last reply Reply Quote 0
                    • A
                      akuma1x
                      last edited by akuma1x

                      @echellis said in PFsense as L3 Router:

                      We currently use Unifi access points

                      Just curious... how many Unifi access points are you using? Are those 48 port POE switches with the blue lines in your diagram? If I do the math, that's almost 300 access points.

                      Also, what's the Aruba Controller doing?

                      Jeff

                      E 1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Then you would want something fast/very fast to get close to 10G throughput.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • DerelictD
                          Derelict LAYER 8 Netgate
                          last edited by Derelict

                          @echellis said in PFsense as L3 Router:

                          all devices are chromebooks doing web browsing and some video streaming from youtube Netflix etc.

                          Do you have 10G internet? If not then don't sweat it. The Xeon will be fine.

                          But, personally, if it were me and if you do not require any filtering between the devices I would get a Layer 3 switch (or a pair of layer 3 switches) and use them to go to the IDFs. Run a transit network up to the firewall HA pair and out to the internet from there.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          E 1 Reply Last reply Reply Quote 0
                          • E
                            echellis @Derelict
                            last edited by

                            @Derelict No we only have a 1gb internet connection

                            1 Reply Last reply Reply Quote 0
                            • E
                              echellis @akuma1x
                              last edited by

                              @akuma1x the PoE switches are serving Aruba WAPS as well as VoIP phones and cameras. The switches will not be maxed out maybe 20% utilized for each one.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.