1
General Discussion / Re: Thinking of making a change...
« on: November 03, 2022, 09:25:49 pm »
As compared to a single virtual firewall for each client vlan. I'm not calling it super as in its the biggest thing on planet earth, just replaces 50 virtual firewalls essentially. It's only a dual E5-2620v4 with 64GB of ram, and 4 SATA SSDs in a cached RAID10. But you can reasonably call 50 vlans with 50 SSLVPN servers and 4 internet pipes a bit unusual. Neat trick is the !rfc1918, so you can allow all traffic that isn't rfc1918 on all of those interfaces and avoid crosstalk and keep the number of rules down.
Although I found with >32 interfaces, pfSense kind of gets a little squirrelly. Not just in the GUI, but in saving changes and such it is a bit laggy.
I had a few Sonicwall SuperMassives back in the day, and my one client is a Hospital with Palo Altos - they don't have 700 vlans, but they have a few hundred, 250 - 300 somewhere around that.
Although I found with >32 interfaces, pfSense kind of gets a little squirrelly. Not just in the GUI, but in saving changes and such it is a bit laggy.
I had a few Sonicwall SuperMassives back in the day, and my one client is a Hospital with Palo Altos - they don't have 700 vlans, but they have a few hundred, 250 - 300 somewhere around that.