• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

ESXI - pfsense and FreeNAS

Scheduled Pinned Locked Moved Virtualization
24 Posts 9 Posters 8.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    Keljian
    last edited by Aug 17, 2015, 2:07 PM

    It is less trouble setting up direct path than it is a new vswitch, but hey, just go with what works for you

    1 Reply Last reply Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator
      last edited by Aug 17, 2015, 2:41 PM Aug 17, 2015, 2:35 PM

      that is your opinion.  Go with what works for you - but if you ask my opinion having vswitches tied to your specific nics with them labeled is much easier to manage then worried about what what specific nic is passed through to a specific vm.

      Also very difficult to passthru a multiport nic and use one port as passthru and another port tied to a vswitch for use with other vms or lan side of your router vm.

      When phyical tied to a vswitch I can bring up different copies of pfsense or other router distros tied to the vswitch and switch between them pretty much just turning off one vm and turning on different vm.  Very easy to leverage port 1 for vswitch X and port 2 for vswitch Y, etc. etc.  Especially if I use the same mac on my router vm wan vnics.. My public IP doesn't even change that way.. I can bring up different version of pfsense or untangle or ipcop or any of the other router/firewall distros in a matter of couple of minutes.  Shutdown vm 1, turn on vm 2 and now my network is using different firewall/router distro for testing, etc.

      When tied to a vswitch I can connect any vm I want to the "wan" for say sniffing the traffic seen on the wan.. So I can use stuff like ntop or ids to monitor that traffic without having to run it on my pfsense vm.

      To me your making it more complicated and reduced functionality for some perceived added security.

      physical passthru also makes it difficult to use any sort of vmotion.  Which I am currently not using in my home setup, but clearly passthru reduces the feature set of a Visualization setup.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      1 Reply Last reply Reply Quote 0
      • K
        KOM
        last edited by Aug 17, 2015, 3:09 PM

        physical passthru also makes it difficult to use any sort of vmotion.

        I was just going to mention this part.  No real benefit for passthrough but a major drawback.

        1 Reply Last reply Reply Quote 0
        • K
          Keljian
          last edited by Aug 18, 2015, 2:37 AM Aug 18, 2015, 12:21 AM

          Ok I stand corrected - and appreciate the dialogue!

          1 Reply Last reply Reply Quote 0
          24 out of 24
          • First post
            24/24
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received