• 0 Votes
    15 Posts
    2k Views
    J
    @chrismacmahon : Thanks, I appreciate any help/info provided. I'm aware we are not currently on paid support so no expectations.
  • SG-3100 Slow OpenVPN Speeds <20Mbps

    4
    0 Votes
    4 Posts
    1k Views
    chrismacmahonC
    I would look into using IPSEC instead of the OpenVPN client connection you are using, you will see a speed improvement. My unit's getting around 100Mbps when on AES-128-CBC (UDP), adding SHA1 auth drops me to ~80Mbps. Same link using IPSec (IKEv2, AES-128-GCM), I get around 150Mbps
  • Netgate SG-5100 More Space

    3
    0 Votes
    3 Posts
    865 Views
    S
    Aside from an older bug https://forum.netgate.com/topic/130980/suricata-not-limiting-log-sizes-by-default Suricata shouldn't use much disk space. I checked a client's SG-3100 and Disk Usage on the pfSense home page shows "24% of 7.0GiB."
  • SG-5100 - Hardware watchdog? (watchdogd)

    14
    1 Votes
    14 Posts
    2k Views
    luckman212L
    Ok, I'll try a fresh install of 2.4.4-p1 today and report back. Much appreciated
  • Problem with VLAN on SG-3100

    3
    0 Votes
    3 Posts
    783 Views
    M
    Yes, thanks. I went back to my backup before the changes, redid it from the start again and this time it worked.
  • Possible hardware failure sg-3100

    2
    1 Votes
    2 Posts
    641 Views
    RicoR
    In your place I'd drop some Ticket to the support guys: https://go.netgate.com -Rico
  • SG-3100, OpenVPN and crypto settings

    Moved sg-3100 openvpn crypto
    5
    0 Votes
    5 Posts
    2k Views
    RicoR
    Yes I know, AES-128-CBC was the maximum Speed for my SG-3100. -Rico
  • Quick question about SG-5100 M.2 SATA Installation

    9
    0 Votes
    9 Posts
    1k Views
    A
    Good to know. Thank you so much. I am gonna pursue the matter on the other thread. As for what I wanted to know initially, you answered me beautifully. All the best.
  • SG-5100 package contents mystery

    24
    0 Votes
    24 Posts
    4k Views
    A
    @luckman212 said in SG-5100 package contents mystery: BiWIN C6308 Hi guys, Were any of you successful in eventually finding a M.2 SSD that would work with the SG-5100?
  • SG-3100 Slow Throughput

    47
    0 Votes
    47 Posts
    12k Views
    G
    @sean-allen said in SG-3100 Slow Throughput: @rico Interesting. You'd sacrifice 80-90% of the links speed to get the flexibility OpenVPN offers? That really says something...like I'm going to hate it if I try IPSec. It may appear to be 80-90% because 100Mb of 1000Mb but in reality IPSEC on the 3100 is only going to do @300. So yea, you’re giving up 66% in speed but only compared 300Mb. In my use, primarily mobile, I like OpenVPN for it “stay connectedness” vs IPSEC which can be less resilient to connection changes. OpenVPN vs IPSEC security I will let others speak on.
  • SG-2440 future-proof for 2.5?

    3
    0 Votes
    3 Posts
    748 Views
    B
    Pretty sure the crypto chip in the sg-3100 will allow it to work with 2.5. Thought I read on here that was one of the reasons they included it, besides the cpu not supporting aes-ni.
  • SG-3100 expected idle temperature

    9
    0 Votes
    9 Posts
    4k Views
    johnpozJ
    I just looked at my 2 sg3100 both in IDF rooms at their locations and 1 is running 51C and the other is at 55C.
  • SG-3100: How many years will it be usable?

    2
    0 Votes
    2 Posts
    633 Views
    G
    product lifecycle
  • Console for XG-7100 1U on Raritan Dominion DKX3-108

    3
    1 Votes
    3 Posts
    667 Views
    hexadecagramH
    Hi and thanks for responding. I think the solution lies with the following device, which may have been discontinued. They were running upwards of $500 a pop but I managed to pick up 2 of them, which I have used successfully for a number of other serial terminals. https://www.raritan.com/products/kvm-serial/accessories/dominion-serial-access-modules I think it would just be a simple matter of cutting off one end of a USB mini cable and crimping a CAT-5 connector to it, wired in the correct order, but I've had to put this project on the backburner. I also exchanged my XG-7100 for an SG-5100, but both devices have a USB Mini console port (my old FW-7551 had a CAT-5 jack for console so it was a no-brainer with the DSAM). I will be needing to drop the SG-5100 into place within the next month or so and I will be sure to post my results. Feel free to follow up if you beat me to the punch!
  • Upgrade failed; SG-2220 won't boot from USB

    Moved
    8
    0 Votes
    8 Posts
    1k Views
    G
    Last update to this — the vendor confirmed that USB is no longer working but was able to repair the appliance by installing a small SSD and put the recovery image on the eMMC just in case. This turned out to be more cost effective than buying a new unit and should buy me some time until new hardware is released and the whole microchip/licensing future becomes clearer.
  • Netgate SG-3100 - Can it host multiple internal LANs (NOT vlans)

    5
    0 Votes
    5 Posts
    1k Views
    A
    @derelict Thank you. That could be a candidate for the fastest response time in the year 2018.
  • XG-7100 SFP+ not connecting to Cisco Meraki Switch

    2
    0 Votes
    2 Posts
    660 Views
    L
    To answer my own question: the reason is simple. MS120 series does not have SFP+ (10Gbe) but SFP (1Gbe) cages.
  • multicore processors

    2
    0 Votes
    2 Posts
    320 Views
    DerelictD
    You would probably better off with 4 faster cores than 16 slower cores based on typical workloads.
  • Setup for trunk via OPT1 port of SG-3100

    Moved
    22
    0 Votes
    22 Posts
    3k Views
    M
    This seems overly complicated. Let the Ubi switch do switching (vlans) and let the pfsense do routing. Can you hookup everything to the Ubi switch instead? Then, you only need 1 cable on the sg3100 lan to the switch. Put all vlans in that (trunk) port. LAN configs between the sg3100 & switch should then match. Just my $0.02.
  • How to add swap memory to Netgate SG-3100

    3
    0 Votes
    3 Posts
    940 Views
    BBcan177B
    @dgall said in How to add swap memory to Netgate SG-3100: I was messing around with the pfblocker geoip and it keeps saying I do not have enough memory when I try to block countries. You don't need more memory for GeoIP. Just increase the pfSense > System > Advanced > Firewall & NAT > Firewall Maximum Table Entries > 2000000 DNSBL on the other hand needs more memory depending on the number of domains added and if wildcard blocking is enabled (The TLD option).
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.