Announcement

Collapse
No announcement yet.

Single 10Gbe and Vlans instead of multiple 1Gbit NICs

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Single 10Gbe and Vlans instead of multiple 1Gbit NICs

    We are a K-12 school with about 1500 active users at any time with a very high session count. We currently run Untangle under ESXi on a dual CPU Xeon server with 128GB of RAM.

    Earlier in the year we struggled under morning load and with the help of Untangle support we optimised some settings (particularly bypassing some traffic) and this helped.

    The server is due for a refresh and we are considering moving to physical to remove any ESXi tuning issues / overhead.

    I would look at an Untangle appliance but we are in Australia so warranty and return is a hassle. Additionally the appliance CPU specs are very low by today's standards, even on the highest end units.

    So looks like we may use our own hardware.

    In my testing, I have tested the option of using a single 10Gbe port and using tagged VLANs for the 5 network interfaces our production Untangle has.

    Seems to work OK in a test environment. Greatly reduces cable clutter and makes it easy to add any number of new interfaces.

    Does anyone have experience with doing this ?

    Would this negatively impact on performance as opposed to using 5 physical nics ?​

    Thanks
    Phil

  • #2
    We do this on almost all of our Arista/Untangle NGFW deployments. We use Supermicro 1U XEON servers with dual 10GB SFP+ Intel NICS, dual 10GB Copper NICs and dual 1GB copper NICs... SFP+ 10GB DAC to our HPE and Aruba L3 managed switches and we use VLANs for all of our networks over that 10GB interface (MGMT, Guest, VOIP, IOT, etc)... runs great, zero issues what so ever. Most times, we have our FIBER WAN on the other SFP+ interface and use one of the 10GB Intel copper nics for our 2nd failover WAN

    Only network we typical use a separate 1GB physical NIC for is our HD CCTV network which is on its own physical network and separate camera switch...so we can access all the camera hardware remotely over VPN if need be for and maintenanc, diagnostis, etc... keeps the HD video streams off our main network, interface and switches
    Last edited by defcomllc; 05-05-2023, 05:25 AM.

    Comment


    • #3
      Thanks heaps for the reply. Could you please advise the chipsets you use for the 10Gbit and 1Gbit NICS ?

      Comment


      • #4
        I do similar... and you can disable the "bearer" nic and just have the vlans addressed on top of it.

        Comment


        • #5
          Originally posted by BestGear View Post
          I do similar... and you can disable the "bearer" nic and just have the vlans addressed on top of it.
          This is what i do also in physical and VM installations.

          Comment

          Working...
          X
          😀
          🥰
          🤢
          😎
          😡
          👍
          👎