OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of Cheezio »
  • Show Posts »
  • Topics
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Topics - Cheezio

Pages: [1]
1
General Discussion / VLAN Trunk Help
« on: November 15, 2024, 04:58:57 pm »
Quick Description:
I have a DEC740 that I have set up two trunk ports.  This setup works fine.
I am trying to add another firewall for an HA setup.  It is virtual via Proxmox.  I am having issues getting traffic to pass the trunk here.

Details:
Each firewall will have 3 connections, Outside, Inside, and Opt1.
I will use Opt1 here for the rest of the descriptions.
The layout is pretty flat.  Outside ----  Firewalls --- L2 Switch
No fancy routing on any of the firewalls, except for Outside.
Opt1 on both firewalls is physically connected to a UniFi Layer 2 switch. (Virtual connected to E0/8, DEC740 connected to e0/9)
Both are using the same port profile that allows vlan 28, 29, 35, and 38.  No untagged vlan is defined.
VLAN 28 Example: On the DEC, I have vlan28 (Interfaces, Other, VLAN, named vlan0.2.28 and attached to igb1 interface)
This works  IP is set to 192.168.28.2 (And has a carp address of .1)

Beautiful

For the virtual, the interface is defined in proxmox at the host level enp2s0f0np0.  I have a bridge (vmbr2) that has vlan aware checked.  I attached vmbr2 to the guest, as "net2/vtnet2", VIRTIO, no vlan tag, and I edited the interface to be "trunks=28;29;35;38"
I have vlan28 (Interfaces, Other, VLAN, named vlan0.2.28 and attached to vtnet2 interface)
IP is set to 192.168.28.3, and I have not defined carp yet.

In the firewall ruleset for the interface for vlan 28, I have IP Any Any > Pass defined.

I cannot get arp across the interface.  Can anyone tell me what I am missing?

2
Hardware and Performance / DEC 740 Performance Guide
« on: March 15, 2022, 09:40:46 pm »
Hi, is there a document to read that helps one understand the settings that can be enabled for performance on a DEC 740?

System > Tunables
 Anything here really
System > Miscellaneous
 Swap file    Add a 2 GB swap file to the system
Interfaces > Settings
 Hardware CRC    Disable hardware checksum offload
 Hardware TSO    Disable hardware TCP segmentation offload
 Hardware LRO    Disable hardware large receive offload
 VLAN Hardware Filtering

Pages: [1]
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2