I am currently in the process of building a pfsense box (I got a really good deal on a Dell 9020 sff system). This has a 16xPCIe 3.0 expansion slot. I have already sitting around another HP branded dual port mellanox connectx-3 VPI card (and I will probably need to hack some cooling/fan to go over the card). That said, I don't want to use up 2 qsfp+ ports on my switch when my WAN link is currently only 1gbps (possibly getting doubled to 2gbps soon).
I wanted to ask around here to see if anyone believes this is a really bad idea, or if I should try and find qsfp+ to sfp+ converters and/or a qftp+ to sfp+ DAC (mellanox makes one I believe) and connect both ports at 10gbps on the connectx-3. The reason I was trying to avoid that it would essentially defeat the purpose of using the connectx-3 card I have since it would most likely be cheaper to buy a dual 10gbps card for the added price of the cables and/or converter to go from qsfp+ to sfp+. I don't believe there is any kind of bandwidth issue in allowing the traffic to all go over the same physical 40gbps connection with VLAN tagging as the reason (to my understanding) that you typically want 2 ports is so that you can handle the incoming and outgoing data without taxing the ports (so if you want 1gbps routing, you really need 2x1gbps of bandwidth, but in my case, I will have 40gbps). Again, anyone know of any gotchas that I need to look out for or if there is some reason this would not work well?
So my network would essentially be like this (at least this is what I am thinking for eventual rules):
VLANS:
WAN_VLAN (obviously this is used only for the WAN link and the pfsense system)
GUEST_VLAN (routeable to the internet for guests connecting to my wired and wireless)
IOT_VLAN (routeable to the internet for "internet of things" devices that need internet access to properly function)
IOT_ISO_VLAN (not routeable to the internet, but can be accessed from both the PROD_VLAN or MANAGEMENT_VLAN, but can not initiate the connection to those VLANs)
PROD_VLAN (routeable to the internert, and can be connected to from the MANAGEMENT_VLAN)
MANAGEMENT_VLAN (can connect to the PROD_VLAN, will not be able to connect into from internet)
WAN/cable-modem 1gbps ethernet ---> WAN_VLAN tagged port on switch
pfsense box 40gbps qsfp+ dac (configure all VLANs needed in my network, such as WAN_VLAN, GUEST_VLAN, IOT_VLAN, IOT_ISO_VLAN, PROD_VLAN, MANAGEMENT_VLAN) ---> Trunk port with all VLANs on switch
pfsense box 1gbps ethernet --> MANAGEMENT_VLAN tagged port on switch
Thanks.
I wanted to ask around here to see if anyone believes this is a really bad idea, or if I should try and find qsfp+ to sfp+ converters and/or a qftp+ to sfp+ DAC (mellanox makes one I believe) and connect both ports at 10gbps on the connectx-3. The reason I was trying to avoid that it would essentially defeat the purpose of using the connectx-3 card I have since it would most likely be cheaper to buy a dual 10gbps card for the added price of the cables and/or converter to go from qsfp+ to sfp+. I don't believe there is any kind of bandwidth issue in allowing the traffic to all go over the same physical 40gbps connection with VLAN tagging as the reason (to my understanding) that you typically want 2 ports is so that you can handle the incoming and outgoing data without taxing the ports (so if you want 1gbps routing, you really need 2x1gbps of bandwidth, but in my case, I will have 40gbps). Again, anyone know of any gotchas that I need to look out for or if there is some reason this would not work well?
So my network would essentially be like this (at least this is what I am thinking for eventual rules):
VLANS:
WAN_VLAN (obviously this is used only for the WAN link and the pfsense system)
GUEST_VLAN (routeable to the internet for guests connecting to my wired and wireless)
IOT_VLAN (routeable to the internet for "internet of things" devices that need internet access to properly function)
IOT_ISO_VLAN (not routeable to the internet, but can be accessed from both the PROD_VLAN or MANAGEMENT_VLAN, but can not initiate the connection to those VLANs)
PROD_VLAN (routeable to the internert, and can be connected to from the MANAGEMENT_VLAN)
MANAGEMENT_VLAN (can connect to the PROD_VLAN, will not be able to connect into from internet)
WAN/cable-modem 1gbps ethernet ---> WAN_VLAN tagged port on switch
pfsense box 40gbps qsfp+ dac (configure all VLANs needed in my network, such as WAN_VLAN, GUEST_VLAN, IOT_VLAN, IOT_ISO_VLAN, PROD_VLAN, MANAGEMENT_VLAN) ---> Trunk port with all VLANs on switch
pfsense box 1gbps ethernet --> MANAGEMENT_VLAN tagged port on switch
Thanks.