Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSync interface: better to use dedicated or VLAN tagged, but LACP redundant?

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    3 Posts 2 Posters 478 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tm_an
      last edited by

      we currently consider a new network design:

      Would it be better to put the pfsync on a physical net port (as suggested around the net) or would the increased bandwidth and security of a LACP bond outweigh the considerations behind that, even if that would bean using a tagged VLAN for pfSync?

      Thanks for your input
      Tobias

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Best to be on its own physical port if possible. The busier the firewall the busier the pfSync interface will be handling state data updates and you will find that when combined with user traffic it would severely limit your throughput if it's all combined.

        If your throughput and/or user count is fairly low then it may not matter, but I would still push for a dedicated interface if possible.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 1
        • T
          tm_an
          last edited by

          Thanks for the insight.

          The other traffic on that physical interface will be negletible (only management data), so we will go for redundancy with VLAN.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.