• IPSEC speed issue - 2 Netgate Fws 7100 and 5100

    Moved
    8
    0 Votes
    8 Posts
    1k Views
    stephenw10S
    Were you able to see any improvement here? That's between New York and New Jersey? What latency do you see across the tunnel? I would certainly expect to see more than 85Mbps provided the WAN connections at each end allow it. Steve
  • 1100 WAN Port Issues

    1100 wan port crossover autosensing
    7
    0 Votes
    7 Posts
    1k Views
    stephenw10S
    Hmm, that is odd. The switch chip in the 1100 connects to all the ports and is auto MDI/MDIX. Do you see link with a straight through cable to the unmanaged external switch? It shouldn't make any difference. Do you see a link with the laptop connected to the LAN or OPT ports? Those should also be identical. Steve
  • IPSec not working between SG1100s

    ipsec sg1100
    17
    0 Votes
    17 Posts
    2k Views
    stephenw10S
    The only thing that could present a difference here is the hardware crypto in the safexcel driver. But you said you tried using a cipher that does not effect (blowfish) so it can't be that directly. So I'm left trying to think of something you might have had set in the old device that's somehow incompatible with the SG-1100. I can't see what that could be though. The fact setting the tunnel to use ports 600/4600 allowed it to come up implies something in the path blocking the standard ports. The crypto hardware doesn't care what ports are in use for example. It really 'feels' like the upstream device trying to do something clever with IPSec traffic. Are we able to review the config you are importing to the 1100? If you open a ticket with us and reference this thread the guys will make sure I see it. It's hard to see how this could be a hardware issue. If we swapped it out I would expect another device to do exactly the same thing given the same config. Steve
  • This topic is deleted!

    2
    0 Votes
    2 Posts
    140 Views
  • Netgate 2100 still safe to buy?

    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S
    Yes, it's still safe to buy. We have no plans to stop selling it I'm aware of and even when we do it will still be supported with updates for a long while after that. (years) Steve
  • XG-7100 dpinger Not Working?

    5
    0 Votes
    5 Posts
    694 Views
    stephenw10S
    If you only have one WAN they can be the same. Or should be able to. The important thing to realise is that both of those settings create a static route for that IP via the gateway it's assigned to. So if you have multiple gateways and you try to use the same IP for monitoring and DNS on different gateways that creates a routing conflict. Steve
  • Why does the SG-1100 change settings when restarted?

    12
    0 Votes
    12 Posts
    2k Views
    stephenw10S
    That's possible, though that particular thread deals with a real USB Ethernet NIC. Really it depends what is actually happening here. If the modem requires some manipulation before it appears as an Ethernet device. If it's just timing you can probably add a delay to prevent it. It's possible to just exclude USB Ethernet devices from the interface check at boot but doing so risks unknown behaviour in the event it's actually disconnected. Steve
  • SG-2100 Installation Halved My WAN Speed

    8
    0 Votes
    8 Posts
    1k Views
    stephenw10S
    Mmm, that sort of throttling looks like a speed/duplex mismatch but I can't see where it would be. The switch on the WAN side test rules that out. And that would affect all clients.
  • Interfaces on the SG-6100

    5
    0 Votes
    5 Posts
    1k Views
    stephenw10S
    It has 8 NICs with no switch. 4x igc NICs at up to 2.5G 4x ix NICs where 2 are 10G SFP+ and 2 are 1G combo ports. [21.09-RC][admin@6100.stevew.lan]/root: ifconfig -am igc0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8120b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,WOL_MAGIC,VLAN_HWFILTER> capabilities=f53fbb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,TSO4,TSO6,LRO,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER,VLAN_HWTSO,NETMAP,RXCSUM_IPV6,TXCSUM_IPV6> ether 00:08:a2:12:17:7a media: Ethernet autoselect (2500Base-T <full-duplex>) status: active supported media: media autoselect media 2500Base-T media 1000baseT media 1000baseT mediaopt full-duplex media 100baseTX mediaopt full-duplex media 100baseTX media 10baseT/UTP mediaopt full-duplex media 10baseT/UTP nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> igc1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8120b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,WOL_MAGIC,VLAN_HWFILTER> capabilities=f53fbb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,TSO4,TSO6,LRO,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER,VLAN_HWTSO,NETMAP,RXCSUM_IPV6,TXCSUM_IPV6> ether 00:08:a2:12:17:7a hwaddr 00:08:a2:12:17:7b media: Ethernet autoselect (2500Base-T <full-duplex>) status: active supported media: media autoselect media 2500Base-T media 1000baseT media 1000baseT mediaopt full-duplex media 100baseTX mediaopt full-duplex media 100baseTX media 10baseT/UTP mediaopt full-duplex media 10baseT/UTP nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> igc2: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 description: OPT3 options=8120b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,WOL_MAGIC,VLAN_HWFILTER> capabilities=f53fbb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,TSO4,TSO6,LRO,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER,VLAN_HWTSO,NETMAP,RXCSUM_IPV6,TXCSUM_IPV6> ether 00:08:a2:12:17:7c inet6 fe80::208:a2ff:fe12:177c%igc2 prefixlen 64 scopeid 0x3 media: Ethernet 10baseT/UTP <full-duplex> status: active supported media: media autoselect media 2500Base-T media 1000baseT media 1000baseT mediaopt full-duplex media 100baseTX mediaopt full-duplex media 100baseTX media 10baseT/UTP mediaopt full-duplex media 10baseT/UTP nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> igc3: flags=28943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST,PPROMISC> metric 0 mtu 1500 description: OPT4 options=8120b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,WOL_MAGIC,VLAN_HWFILTER> capabilities=f53fbb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,TSO4,TSO6,LRO,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER,VLAN_HWTSO,NETMAP,RXCSUM_IPV6,TXCSUM_IPV6> ether 00:08:a2:12:17:7d inet6 fe80::208:a2ff:fe12:177d%igc3 prefixlen 64 scopeid 0x4 inet 192.168.78.1 netmask 0xffffff00 broadcast 192.168.78.255 media: Ethernet autoselect status: no carrier supported media: media autoselect media 2500Base-T media 1000baseT media 1000baseT mediaopt full-duplex media 100baseTX mediaopt full-duplex media 100baseTX media 10baseT/UTP mediaopt full-duplex media 10baseT/UTP nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> ix0: flags=8802<BROADCAST,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8138b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER> capabilities=f53fbb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,TSO4,TSO6,LRO,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER,VLAN_HWTSO,NETMAP,RXCSUM_IPV6,TXCSUM_IPV6> ether 00:08:a2:12:17:7e media: Ethernet autoselect status: no carrier supported media: media autoselect nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> ix1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 description: IX1 options=8138b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER> capabilities=f53fbb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,TSO4,TSO6,LRO,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER,VLAN_HWTSO,NETMAP,RXCSUM_IPV6,TXCSUM_IPV6> ether 00:08:a2:12:17:7f inet6 fe80::208:a2ff:fe12:177f%ix1 prefixlen 64 scopeid 0x6 inet 192.168.79.2 netmask 0xffffff00 broadcast 192.168.79.255 media: Ethernet autoselect status: no carrier supported media: media autoselect nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> ix2: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 description: LAN options=8138b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER> capabilities=f53fbb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,TSO4,TSO6,LRO,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER,VLAN_HWTSO,NETMAP,RXCSUM_IPV6,TXCSUM_IPV6> ether 00:08:a2:12:17:80 inet6 fe80::208:a2ff:fe12:1780%ix2 prefixlen 64 scopeid 0x7 inet 192.168.241.1 netmask 0xffffff00 broadcast 192.168.241.255 media: Ethernet autoselect status: no carrier supported media: media autoselect media 10baseT/UTP media 100baseTX media 1000baseT nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> ix3: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 description: WAN options=8138b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER> capabilities=f53fbb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,TSO4,TSO6,LRO,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER,VLAN_HWTSO,NETMAP,RXCSUM_IPV6,TXCSUM_IPV6> ether 00:08:a2:12:17:81 inet6 fe80::208:a2ff:fe12:1781%ix3 prefixlen 64 tentative scopeid 0x8 inet 172.21.16.246 netmask 0xffffff00 broadcast 172.21.16.255 inet 172.21.16.247 netmask 0xffffffff broadcast 172.21.16.247 vhid 5 carp: MASTER vhid 5 advbase 1 advskew 0 media: Ethernet autoselect (1000baseT <full-duplex,rxpause,txpause>) status: active supported media: media autoselect media 10baseT/UTP media 100baseTX media 1000baseT nd6 options=2b<PERFORMNUD,ACCEPT_RTADV,IFDISABLED,AUTO_LINKLOCAL> Steve
  • SG 3100 managing carrier WAN/LAN block

    3
    0 Votes
    3 Posts
    621 Views
    S
    @johnpoz thank you! This was extremely helpful.
  • SG-1100 dies, problem appears to be pcscd

    5
    0 Votes
    5 Posts
    978 Views
    M
    Just applied the patch afcc0e9c97c1993ae6b95f886665fcb4375d26c7 and rebooted. It started with the service disabled, thanks. Device and firmware: 21.05.1 / SG-3100. [image: 1632326004783-fbafb584-8916-4c50-b990-7817727697a3-image.png]
  • Configuring Dual Wan ports on SG-3100

    11
    0 Votes
    11 Posts
    1k Views
    stephenw10S
    Yup, that will cover it.
  • Factory firmware for SG-5100

    2
    0 Votes
    2 Posts
    621 Views
    RicoR
    Sign up for the Service Desk Portal here: https://go.netgate.com/support/signup Then create a ticket. -Rico
  • XG-7100 Cannot access Console Port

    5
    0 Votes
    5 Posts
    883 Views
    Z
    @stephenw10 very strange - had it set to 115200, still gibberish, come back a day later, and it's fine. thanks for the help!
  • Migrating from CE Software to your hardware appliance

    3
    0 Votes
    3 Posts
    545 Views
    stephenw10S
    Yup, that^. You can import a CE config into any of our appliances. If it has an internal switch it's easier to add that config section first, we can help you with that. Steve
  • XG-7100 LACP port options

    Moved
    4
    0 Votes
    4 Posts
    682 Views
    stephenw10S
    Not other than the modules we have in our store. Most Intel compatible modules will work. Copper RJ-45 modules are incompatible. DAC cables usually work fine at 10G but have no way to force 1G which can be an issue. Steve
  • Is the SG-3100 the right box for Gigabit fiber?

    5
    0 Votes
    5 Posts
    1k Views
    S
    @stephenw10 As mentioned, I'm not doing rocket-surgery with the 1100, but bandwidth is the primary reason for the upgrade questions. Looks like a 3100 will do what I'd want/need.
  • Intermittent load balancing issue

    7
    0 Votes
    7 Posts
    880 Views
    U
    @stephenw10 Forgot to say thank you. I knew I had read that this had been changed but never messed with it because for over a year the tiered thing seemed to work but this makes sense. thanks for taking the time to respond.
  • SG-3200… When?

    1
    3 Votes
    1 Posts
    621 Views
    No one has replied
  • Netgate 3100 + PHP Crashes

    9
    9 Votes
    9 Posts
    9k Views
    jimpJ
    Yes
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.