• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Interface bridging and performance (in pfSense)

Zarathustra[H]

Extremely [H]
2FA
Joined
Oct 29, 2000
Messages
42,415
hey all,

Does anyone have any experience with this?

I have a setup in which I may need to bridge two networks using my pfSense setup.

I have read that bridging never performs as well as a switch would, but just how bad is it?

I actually don't care very much about the performance between the two networks, as long as it is not awful.

My primary concern is that traffic from either network to the pfSense box performs well.

My guess would be that traffic from one network to the other may experience a performance drop, but that traffic to the system with the bridged network interfaces should be just as if there were no bridge at all.

Is this the case?

Also, does anyone know if I can bridge adapters of different speeds? In this case, I need to bridge a gigabit and a 10gbe device.

appreciate any input.

--Matt
 
As far as I've seen you can do that. Performance probably won't be anywhere near GigE due to processing overhead, but I'm sure that you'd easily get 300-400+mbps out of it. You'll just need adequate proc behind it. I can get almost 500mpbs routed between vlans in my lab at home using pfSense with 2 cores of a Xeon 5520 (2.26Ghz) without much tweaking, so I'd bet that bridging performance would be better. My only expereince with pfSense bridging was for internet access on a 40mbps TW Cable line, but that's not really in the same ball park.
 
Thanks for the input.

I probably should have been more specific. The plan is to bridge two lan interfaces. Both networks will have internet access through the pfsense wan interface, and will need to be able to sustain about 150mbps full duplex through to the wan without slowdown.


I'm not too concerned about the speed between the two networks. They need to talk to each other, but as long as the bridge is fast enough to support console ssh use and some http configuration pages it is fine.

Both networks need to be able to push data through to wan though, so as long as bridging the interfaces doesn't slow that down it should work for me.

Thanks again!
 
Last edited:
Zarathustra[H];1041460875 said:
I'm not too concerned about the speed between the two networks. They need to talk to each other, but as long as the bridge is fast enough to support console ssh use and some http configuration pages it is fine.
If its just one or 2 people needing to do that I would use vpn to the pc to bridge the networks for security reasons.
 
If its just one or 2 people needing to do that I would use vpn to the pc to bridge the networks for security reasons.

Thanks for the suggestion.

I actually have no security reasons for keeping these networks separate.

They are separate due to limitations in the free version of ESXi and how it deals with NIC teaming.

In the free version, if you do any NIC teaming on a vswitch, all physical network adapters connected to that vswitch must be a part of that team.

In order to get around this, I have created a separate vswitch for a few machines that need to use a different NIC than the team on my primary vswitch. They need internet access, so I figured I'd just bridge them into pfsense on the LAN side.
 
As far as I've seen you can do that. Performance probably won't be anywhere near GigE due to processing overhead, but I'm sure that you'd easily get 300-400+mbps out of it. You'll just need adequate proc behind it. I can get almost 500mpbs routed between vlans in my lab at home using pfSense with 2 cores of a Xeon 5520 (2.26Ghz) without much tweaking, so I'd bet that bridging performance would be better. My only expereince with pfSense bridging was for internet access on a 40mbps TW Cable line, but that's not really in the same ball park.
Is that with snort running or similar? As I could do 1gig intervlan with an i3-540 so i'm surprised you can't get the same from the xeons. Hell, I currently manage 500-600 with a D2500 atom.
 
Back
Top