• Boot won't finish until I connect to console

    6
    0 Votes
    6 Posts
    988 Views
    R
    @cloew You're welcome!
  • SG-1100 issues

    3
    0 Votes
    3 Posts
    745 Views
    stephenw10S
    You should see the black diamond LED light as well as the green circle: https://docs.netgate.com/pfsense/en/latest/solutions/sg-1100/io-ports.html#led-patterns Is it actually passing any traffic? Try connecting to the serial console to see if it's booting completely: https://docs.netgate.com/pfsense/en/latest/solutions/sg-1100/connect-to-console.html Open a ticket with us if you have not already: https://www.netgate.com/tac-support-request Steve
  • XG-2758 / 22.05: Firmware Update fails

    10
    0 Votes
    10 Posts
    1k Views
    stephenw10S
    It's very unlikely. There was a much older bug that presented like that: https://redmine.pfsense.org/issues/8047 It was fixed long ago though and showed a different error: Incorrect flash image file size. Failed to update OEM section, exiting ... Steve
  • Unable to change the rules and rules are not loading

    11
    0 Votes
    11 Posts
    2k Views
    stephenw10S
    Yes, you should upgrade. There's every chance the bug that allowed that invalid ruleset to be created has been fixed in the 4 years since 2.4.4. Along with numerous security fixes! Steve
  • 1100 slow speed

    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S
    Yes, it certainly looks like that but those ports don't necessarily indicate it's actually NATing. Having tested it myself numerous times I would be very surprised to see 800Mbps with NAT and filtering enabled. There are a lot of variables but 500Mbps is around what I expect to see in a local iperf3 test between WAN and LAN. Steve
  • SFP+ XG-1537 - no carrier

    11
    0 Votes
    11 Posts
    2k Views
    stephenw10S
    When you use a 10/1G SFP+ module you will see 1G is an available setting: [22.09-DEVELOPMENT][admin@6100.stevew.lan]/root: ifconfig -vm ix1 ix1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 description: IX1 options=8138b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER> capabilities=f53fbb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,TSO4,TSO6,LRO,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER,VLAN_HWTSO,NETMAP,RXCSUM_IPV6,TXCSUM_IPV6> ether 00:08:a2:12:17:7f inet6 fe80::208:a2ff:fe12:177f%ix1 prefixlen 64 scopeid 0x6 inet 192.168.79.2 netmask 0xffffff00 broadcast 192.168.79.255 media: Ethernet autoselect status: no carrier supported media: media autoselect media 1000baseSX media 10Gbase-SR nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> plugged: SFP/SFP+/SFP28 10G Base-SR (LC) vendor: FINISAR CORP. PN: FTLX8571D3BCV-CK SN: ANL1C1V DATE: 2012-11-21 module temperature: 40.65 C Voltage: 3.33 Volts RX: 0.01 mW (-17.28 dBm) TX: 0.63 mW (-1.99 dBm) And the speed/duplex field in the gui will reflect that. Steve
  • Netgate 2100 ARP problem after replugging WAN port

    38
    1
    0 Votes
    38 Posts
    5k Views
    S
    @stephenw10 I think you're right. I've set the Firewalll Optimization to normal, which should've set the time out for "FIN WAIT" to 900 seconds, but it still doesn't kill the state. So I guess back to the roots to find out what the problem is. EDIT Well uhm, somehow it solved my problem automatically without restarting the VPN tunnel. I think the Firewall Optimization worked, need to do more testing though.
  • 6100 BIOS/Legacy boot?

    2
    0 Votes
    2 Posts
    714 Views
    stephenw10S
    No, the 6100/4100 are UEFI only. Blinkboot will not boot a legacy image. Steve
  • 0 Votes
    15 Posts
    2k Views
    stephenw10S
    Thanks. I apologise it looks like human error. The form was submitted as an SG-1000 but we should have caught that. I have sent you the correct firmware image for the 1100. Steve
  • 3100 High CPU since 22.05

    7
    0 Votes
    7 Posts
    1k Views
    R
    @jts2045 There's a patch specifically for the 22.05 issues for DEVEL, no need to downgrade that I am aware of.
  • Can the 2100 run snort and pfblocker?

    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S
    Yeah, I would not recommend using RAM disks with Snort/Suricata. It can be made to work but they do not expect to see RAM disks. 4GB is enough to run Snort/Suricata and pfBlocker. Though, as stated, it will reduce the maximum throughput. Steve
  • Netgate 2100 Combo WAN Port

    3
    0 Votes
    3 Posts
    632 Views
    stephenw10S
    You can do it without a reboot: [22.09-DEVELOPMENT][root@2100-2.stevew.lan]/root: ifconfig mvneta0 mvneta0: flags=8a43<UP,BROADCAST,RUNNING,ALLMULTI,SIMPLEX,MULTICAST> metric 0 mtu 1500 description: WAN options=800bb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,LINKSTATE> ether 00:e0:ed:b6:13:59 inet6 fe80::2e0:edff:feb6:1359%mvneta0 prefixlen 64 scopeid 0x1 inet 172.21.16.220 netmask 0xffffff00 broadcast 172.21.16.255 media: Ethernet autoselect (1000baseSX <full-duplex>) status: active nd6 options=23<PERFORMNUD,ACCEPT_RTADV,AUTO_LINKLOCAL> [22.09-DEVELOPMENT][root@2100-2.stevew.lan]/root: ifconfig mvneta0 mvneta0: flags=8a43<UP,BROADCAST,RUNNING,ALLMULTI,SIMPLEX,MULTICAST> metric 0 mtu 1500 description: WAN options=800bb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,LINKSTATE> ether 00:e0:ed:b6:13:59 inet6 fe80::2e0:edff:feb6:1359%mvneta0 prefixlen 64 scopeid 0x1 inet 172.21.16.220 netmask 0xffffff00 broadcast 172.21.16.255 media: Ethernet autoselect (none) status: no carrier nd6 options=23<PERFORMNUD,ACCEPT_RTADV,AUTO_LINKLOCAL> [22.09-DEVELOPMENT][root@2100-2.stevew.lan]/root: ifconfig mvneta0 mvneta0: flags=8a43<UP,BROADCAST,RUNNING,ALLMULTI,SIMPLEX,MULTICAST> metric 0 mtu 1500 description: WAN options=800bb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,LINKSTATE> ether 00:e0:ed:b6:13:59 inet6 fe80::2e0:edff:feb6:1359%mvneta0 prefixlen 64 scopeid 0x1 media: Ethernet autoselect (1000baseT <full-duplex>) status: active nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> [22.09-DEVELOPMENT][root@2100-2.stevew.lan]/root: ifconfig mvneta0 mvneta0: flags=8a43<UP,BROADCAST,RUNNING,ALLMULTI,SIMPLEX,MULTICAST> metric 0 mtu 1500 description: WAN options=800bb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,LINKSTATE> ether 00:e0:ed:b6:13:59 inet6 fe80::2e0:edff:feb6:1359%mvneta0 prefixlen 64 scopeid 0x1 inet 172.21.16.220 netmask 0xffffff00 broadcast 172.21.16.255 media: Ethernet autoselect (1000baseT <full-duplex>) status: active nd6 options=23<PERFORMNUD,ACCEPT_RTADV,AUTO_LINKLOCAL> Steve
  • Netgate SG-3100 cannot retrieve packages

    3
    0 Votes
    3 Posts
    727 Views
    S
    @senseinyc said in Netgate SG-3100 cannot retrieve packages: it says on latest version (I know it's not). When I try to install new packages Also, don't ever install "current" packages on an older pfSense version, so it doesn't try to, say, upgrade PHP or some other dependency.
  • 4100 Max - cpu temps

    Moved
    10
    3
    0 Votes
    10 Posts
    2k Views
    keyserK
    @michmoor said in 4100 Max - cpu temps: @keyser Thanks! I appreciate the replies. So basically an inefficient chip as compared to an i3 but still the overall performance should still be solid and temps shouldnt be an issue? I feel more at ease now about it. Well No, not really inefficient. Sure compared to the latest 11th or 12th generation i3, they are less efficient due to Being manufactured on an older silicon die node, But thats evolution for you. Compared to “same age i3’s” i would rather use the Word different. I3’s and higher are made for high single core single performance - achieved by turboing the frequency. This can make cpu performance fairly unpredictable because sometimes its fast, sometimes its in a throttle back State due to heat. The atoms are made for all day predictable performance, and have some optimizations for network/server type workloads that they can do with hardware assist. So they are a fairly good cpu in a “lower power” envelope for this kind of work.
  • cordbuc device

    9
    0 Votes
    9 Posts
    1k Views
    dennypageD
    @stephenw10 Thanks Steve. Much appreciated.
  • Migration from SG3100 to NetGate 6100

    5
    0 Votes
    5 Posts
    1k Views
    stephenw10S
    Yes, we can do that but going in that direction is usually less of an issue. If you have VLANs configured for the switch ports in the 3100 you can just reassign those interfaces to the discrete NICs in the 6100 when you import it. Steve
  • Setting up SG2100

    5
    0 Votes
    5 Posts
    989 Views
    S
    @rcoleman-netgate said in Setting up SG2100: @simon_lefisch said in Setting up SG2100: mvneta1.xx tells me that all the switch ports are bridged. Is that actually the case? Is there any way to not have them bridged? I know on a Cisco Firepower 1010 you can set the interfaces separately or have them set as Bridged Virtual interfaces (BVI). They are a single ethernet chip LAGGed as a switch. There is no way to break the LAGG and use them individually. Worth noting that the only systems this is the case on are: 1100, 2100, 3100 and 7100 models. All others have discrete interfaces. Thanks for that info, I did not know that. I appreciate you taking the time to let me know this
  • Introducing the New Rack Mount for Netgate 4100 / 6100

    11
    3 Votes
    11 Posts
    2k Views
    P
    I love this got it for my 6100. I still setup up my rack put this is the start. [image: 1659335749958-rack_setup-resized.jpg]
  • 3100 High CPU Utilization after 22.05 upgrade?

    10
    0 Votes
    10 Posts
    2k Views
    W
    Thank you all!! Properly editing the file fixed the issue. I had a small typo. The CPU usage may be lower than it has been for a while and now the temp is also down a tad. Going to monitor this for a bit. I know I had an issue with the WiFi. Going to see if that is cleared up as well.
  • Netgate 1100 internet problem

    4
    0 Votes
    4 Posts
    868 Views
    S
    @danholley That is weird. And as you say bizarre if 8.8.8.8 was reachable. :) But you're welcome.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.