10Gig connection throguh 1Gig NIC firewall rules

The rule won’t matter because it is layer 2 traffic so it never has to go through the firewall to get to the other devices.

Got it. I will try to make some changes. Thanks.

Hey, let’s say I sell all 10G rj45 equipment and go to sfp+ route, is there a cable limit I can use from switch to devices as some of the devices are far from switch.

define “far”.
Fiber connectivity supports multi kilometer distances (or miles if you pay for the converter).
The workaround is in buying pre-terminated lengths, running it through conduit (or Smurf Tube) rather than just stringing it. It needs to be handled more carefully than just pulling lubed Cat6a through some holes bored through the wall plate.
I could check my purchase history but OM3 MMF pre-terminated 15M length (LC) was $19 last year: https://www.amazon.com/gp/product/B089JWXPY9/ (don’t forget to use the Lawrence Systems referral link).
since I’m looking at orders here is what I used in the server cabinet: https://www.amazon.com/gp/product/B00WHS3NCA/ $17 . yeah. no. 1M length was a PITA. go for something a bit longer.

I thought sfp+ and fiber is different thing. Sorry for stupid question, but trying to understand what if I buy all new sfp+ nic for four pc I have and go layer 3 switch with sfp+ ports. My pc is 25 feet away from my rack, but when I move to new place, it can be around 60 to 100 feet depending on where I will keep my rack.

happy to answer this one.
SFP+ is the adapter interface instead of RJ-45 built into the unifi 10 GigE aggregation switch.
The same model but pro has both SFP+ and RJ-45 ports (12, 4 respectively).
you could insert a DAC which has integrated SFP+ adapters included in the build for short runs.
you could insert an SFP+ adapter that has either pair of LC ports or an RJ-45 adapter.
So SFP+ to RJ-45 is a thing.
https://www.amazon.com/gp/product/B08BP57TRJ/
Cat6 is rated to support 10 GigE speeds up to 55m. 6a rated to 100m.
There are 3 things that Fiber will get you:

  1. less heat. an SFP+ RJ-45 generates quite a bit of heat under load.
  2. lightning arresting. using a Fiber interconnect between switches if you have external video cameras can effectively decouple your main stack (your 10 GigE stuff) from your 1 GigE PoE switch that supports your cams.
  3. upgrade ability / future proofing. I’d like to run cable once and be done with it. ServeTheHome put some 100 GigE adapters in an HP microserver in a build. there will be a time that we’re replacing 1 GigE kit with newer faster models. I hope that I don’t have to go back into the attic again doing battle with insulation.

Thanks for info.

I am gonna ask follow up question as any noob will ask.

I knew about those adapter, but they are expensive when you have to buy sfp+ adapter.

https://www.amazon.com/10Gtek-SFP-10G-T-S-Compatible-10GBase-T-Transceiver/dp/B01KFBFL16/ref=sr_1_3?keywords=10g+sfp%2B+rj45&qid=1651104456&s=electronics&sprefix=10g+sfp%2B%2Celectronics%2C58&sr=1-3

For one of them, and from what I read, I believe 10G sfp+ doesn’t even work if you want to switch to 1G sfp adapter for 1g connection for regular devices. You need to buy different adapter for 1g connection. I believe it get quite expensive really quick.

Let’ say I do go buy sfp+ switch, what cheap sfp+ nic would you recommend from ebay. I have four pc which will need that for now. I will buy layer 3 sfp+ switch so I can do inter VLAN connection.

This evening was as good as any to test a link failure in a LAGG.
I pulled an SFP+ adapter from one of the SFP+ ports on a Unifi USW-24 switch (gen2, not pro).
it is a 10Gtek ASF86-24-X2-D 1000Base-SX and had a 0.2m LC OM3 cable plugged into it.
This is currently $19/ea on Amazon. Amazon.com
The first floor switch has a pair of 10Gtek ASF-GE-T 1000Baset-T SFP RJ-45 adapters as I didn’t run fiber between floors yet. only one is active. I do intend to do that before the attic gets hot again but the single run of Cat6 is working. note that this is SFP not SFP+ $19. Amazon.com and only supports 1 GigE.

the SFP+ adapter in the 10 GigE switch and QNAP Thunderbolt3 to SFP+ is a 10Gtek AXS85-192-M3 10GBase-SR SFP+ which are $38/pair https://www.amazon.com/10GBase-SR-Transceiver-Compatible-SFP-10G-SR-MA-SFP-10GB-SR/dp/B08BP55663/

back at ya.
Going to go look at the logs of the link being downed but seeing as I’m still typing looks like it failed then went back online just fine.

For 10 GigE SFP+ dual port PCIe I picked up 3 HP cards used from ebay. I’ll get you a link. For the synology I sprung for an Intel X520.

check this out: 10Gbe 10GB SFP+ transceiver for UniFi Switch 16 XG 10G 16port Ubiquiti US-16-XG | eBay $8 USD ea. that was too good of a deal so I picked up a few.

PCIe dual port SFP+:
HP NC552SFP 2-Port 10Gb SFP+ PCI-Ex8 Standard Profile Server Adapter 615406-001 they were 3 for $81.

Primo dual port SFP+:
GENUINE INTEL X520-DA2 E10G42BTDA 10Gb Dual Port Ethernet Server Adapter | eBay GENUINE INTEL X520-DA2 E10G42BTDA 10Gb Dual Port Ethernet Server Adapter $100

I am so thankful to you for all this info. So, I can use DAC or use one of 10GBase-SR SFP+ Transceiver and use fiber cable between for long run?

something like this for combo?

https://www.amazon.com/10Gtek-SFP-10G-SR-Transceiver-10GBASE-SR-300-meter/dp/B00U8Q7946/?th=1

and for cable!

https://www.amazon.com/VANDESAIL-Gigabit-Cables-Multimode-OM3-5Pack/dp/B07MDJRBH3/ref=pd_day0fbt_sccl_2/134-0100744-9916270?pd_rd_w=Awhwe&pf_rd_p=bcb8482a-3db5-4b0b-9f15-b86e24acdb00&pf_rd_r=5RYQR0KCJT96QY94XJ4N&pd_rd_r=25a173c9-4d76-4ce8-a2ca-cde7a6057940&pd_rd_wg=WFgyH&pd_rd_i=B07MDJRBH3&th=1

or something like this?

https://www.amazon.com/10GBase-SR-Transceiver-Fiber-Patch-Cable/dp/B094QR287X

the 3rd option is a more expensive SFP+ transceiver.
make sure that the transceiver works for your switch.
I made do with the $19/ea SFP+ transceivers.
they work for me in my environment.
I used all MMF cables. I checked the frequencies used by the transceivers and the cables.

Were you able to find link for this hp sfp+. Besides, any of sfp+ nic should work, right?

Something like this or

selection of an optimal PCIe NIC is largely dependent upon driver support in the operating system to be deployed. avoidance of Realtek chipsets is your utmost concern as it can lead to a frustrating experience with some OSes namely pfSense - not with a hard failure at installation time but in later behaviors that lead one towards leaving IT and taking up the manufacture of shaker furniture via hand tools.

My main use for truenas core and scale, proxmox and pos os for main desktop.

Do you think this will work?

https://www.ebay.com/itm/284791709771?epid=21020161540&hash=item424ee8a04b:g:TJ8AAOSwXeVibBEA

https://www.ebay.com/itm/165418962776?hash=item2683bd0f58:g:2WMAAOSwHr9iTHMZ