Anyone managed to set up pfsense on Xen before?
I kinda want to do it, but I'd like some opinions before I go buy a network card.
Also need to move my existing linux install into a vm, and have it be able to access physical drives, but apparently that's not very straightforward with xen.
Why not kvm? I have it running under kvm as a router
>>62061000
I was thinking of type-1 hypervisors, never considered type-2. No idea why.
Is there a guide or something? If it's fast enough, going with kvm will save me from having to move the linux install.
>>62061039
Kvm is type 1
https://www.ibm.com/developerworks/community/blogs/ibmvirtualization/entry/kvm_myths_uncovering_the_truth_about_the_open_source_hypervisor?lang=en
>>62061064
How is host-guest networking?
This may sound strange but can it provide an additional interface for the host to connect to WAN, separate from the LAN (and its route to WAN)?
>>62061039
Super duper easy. Got up and running with kvm 30 mins. Networking is pretty solid, if pass-through works on your nic
>>62061127
I'm planning on buying a Intel GbE NIC. Chinks have it for cheap.
>>62061123
Create a bridge on host network adapter, attach both host and vm to bridge and you'll get a dhcp adres on both.
>>62061142
Nah man. Get a proper Nic off ebay. Spend 150 for a 4 port Intel server grade.
I'm not rich, so no 10GbE Intel NIC
What's a good alternative with good bsd/linux drivers?
>>62061186
Well I'll figure the network thing out later. What I really meant is basically access to 2 WANs for the host, with one connected to the main LAN (and the other its own LAN or just pppoe passthrough)
>$150
That's a bit too much. Would something like this work?
>>62061332
Probably fine desu
>>62061733
Also should I just passthrough the nic to the vm? Or use a virtual device?
>>62061740
Well, why would you want your host in front of your firewall? Just direct pass-through to the pfsense vm and create a new bridge to attach host. Then create a LAN and DMZ and whatever else you want to do with 4 ports
>>62061332
>I'll figure the network thing out later
Your literally creating your network infrastructure you dimwitted idiot. Think what you want before buying anything.
Think before you do
>>62061127
I had to turn off all hardware offloading to get higher speed than 1Mbps
>>62061186
>intel nics are not proper nics
quit your bullshit, used nics are complete ok 90% of the time (and you just refund if something is wrong)
>>62061740
>>62061860
this, passthrough is much better
>>62062028
Well I hope the adapter and my MB supports VT-d then. The CPU does but not too sure about the MB.
>>62062065
you mean chipset
if your cpu supports it you're probably find
i dont know, i only use amd and xeon systems for hw virt
>>62062065
>>62062086
the "adapter"(nic) doesnt need to support vt-d at all
as far as its concerned the host machine doesnt exist
>>62062086
Apparently it depends on the MB manufacture as well. Mine has a B85 chipset.
>>62062093
That's good to hear. I read somewhere that it doesn't have some fancy feature that may make it not work with pci passthrough.