• SG1100 dead NICs

    13
    0 Votes
    13 Posts
    2k Views
    K
    @stephenw10 Looks like bandartogel is trying to use your forum to advertise!
  • NetGate 7100 Crypto Acceleration

    5
    0 Votes
    5 Posts
    817 Views
    F
    @stephenw10 Thanks stephenw10 and yes, its from the same (mobile) client. Sounds like the Windows client requesting certs for every CA it has for some reason. That makes sense. On the other hand i explicitly have selected the CA certificate in the IPSec profile setup @ Win10. Would just like to know if i can do anything to avoid that. Seems a little bit much overhead for going through every CA that is located in the Trusted Root CAs, which are indeed exactly 33.
  • xg-7100 Don't boot

    4
    0 Votes
    4 Posts
    700 Views
    stephenw10S
    Hmm, that's all that appears? That's not good. I would open a ticket with us if you have not already: https://go.netgate.com/ Steve
  • is SG-2100 the updated version of SG-2400?

    3
    0 Votes
    3 Posts
    847 Views
    B
    @bigsy thank you for your reply. i had thought i had replied ... my apologies for such a late thank you to you.
  • sg-3100 running hot?

    6
    1
    0 Votes
    6 Posts
    1k Views
    M
    @akuma1x thanks for posting that link. Very "cool".
  • Netgate 3100 - Kernel Error in Logs

    8
    0 Votes
    8 Posts
    1k Views
    stephenw10S
    For future reference, when you reinstall it sets the boot env to the chosen install media. It is possible to set that manually from the uboot prompt though. For example: setenv bootcmd 'run setLED; run emmcboot;' saveenv reset You would only ever need to do that if for some reason you need to change boot media without reinstalling. Steve
  • SG-2100 Hangs Every Few Minutes for a few seconds

    15
    1
    0 Votes
    15 Posts
    2k Views
    S
    Hey everyone, thanks for your kind suggestions. At the same time I was working with Netgate directly as I personally became convinced pretty quickly that this was a hardware issue. After 2 days of installing new firmware from console, resetting settings, and turning things off, Netgate eventually agreed it was hardware and gave me an RMA. Now I'm in the waiting game between shipping the device back and getting a new one. I have to say, having to pay return shipping for a dead on arrival device kinda blows. So does 2 days of hours spent troubleshooting (a few times with techs who clearly were convinced the fault was me misconfiguring things). New customer here, not sure if I'll be a repeat one after this experience. What's worse: Ubiquiti where they lie about being hacked (which is why I picked netgate over the EdgeRouter) or this? But I can say the community (y'all who replied above) seem pretty great!
  • Picked up another SG-4860 as a backup.... ZFS?

    2
    0 Votes
    2 Posts
    561 Views
    stephenw10S
    The advantage currently is the increased resilience to filesystem damage from a power loss. There is not (yet) any integration for things like snapshots or boot environments but that is on the cards. ZFS will install and run fine on that box with the default settings. I've been running it here on numerous things for a long time. Steve
  • XG1541 10G throughput

    2
    0 Votes
    2 Posts
    626 Views
    JeGrJ
    Additional insights: Version is 21.05.1 BIOS is 1.2c no NAT done, pfSense is internal firewall/router in front of their core switches ix0/ix1 are combined to lagg0 and connected to a core switch each (no crossover cabling) lagg0 is running normally (both channels active) rules on test VLAN interfaces are simple and to test were pass alls so nothing out of the ordinary that would hinder traffic flow or performance
  • Download 21.02 for Netgate SG-4860

    Moved
    3
    0 Votes
    3 Posts
    682 Views
    johnpozJ
    @lralvarez what @bmeeks said - but why would you want 21.02 vs 21.05.1 which is current? Running 21.05.1 on my sg4860.. They normally respond with link to image and instructions within a few minutes.
  • 1541 throughput

    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S
    Ok, the best thing here is probably going to be to open a ticket with our sales guys. You can just email sales@netgate.com. They should be able to help you out with whatever numbers you need. Steve
  • SG-3100 NIC offload?

    3
    0 Votes
    3 Posts
    851 Views
    L
    @stephenw10 OK, thanks for the info
  • 1541 and 6100 ALTQ limitations with 10Gbe

    3
    0 Votes
    3 Posts
    766 Views
    L
    @stephenw10 said in 1541 and 6100 ALTQ limitations with 10Gbe: FQ_CoDel as a buffer bloat mitigation is usually applied via Limiters which can work on any interface. In fact AltQ traffic shaping can now be used on ix NICs directly. Those docs are being updated: https://github.com/pfsense/pfsense/blob/RELENG_2_5_2/src/etc/inc/interfaces.inc#L7006 Steve Excellent - thank you.
  • IPSEC speed issue - 2 Netgate Fws 7100 and 5100

    Moved
    8
    0 Votes
    8 Posts
    1k Views
    stephenw10S
    Were you able to see any improvement here? That's between New York and New Jersey? What latency do you see across the tunnel? I would certainly expect to see more than 85Mbps provided the WAN connections at each end allow it. Steve
  • 1100 WAN Port Issues

    1100 wan port crossover autosensing
    7
    0 Votes
    7 Posts
    2k Views
    stephenw10S
    Hmm, that is odd. The switch chip in the 1100 connects to all the ports and is auto MDI/MDIX. Do you see link with a straight through cable to the unmanaged external switch? It shouldn't make any difference. Do you see a link with the laptop connected to the LAN or OPT ports? Those should also be identical. Steve
  • IPSec not working between SG1100s

    ipsec sg1100
    17
    1
    0 Votes
    17 Posts
    2k Views
    stephenw10S
    The only thing that could present a difference here is the hardware crypto in the safexcel driver. But you said you tried using a cipher that does not effect (blowfish) so it can't be that directly. So I'm left trying to think of something you might have had set in the old device that's somehow incompatible with the SG-1100. I can't see what that could be though. The fact setting the tunnel to use ports 600/4600 allowed it to come up implies something in the path blocking the standard ports. The crypto hardware doesn't care what ports are in use for example. It really 'feels' like the upstream device trying to do something clever with IPSec traffic. Are we able to review the config you are importing to the 1100? If you open a ticket with us and reference this thread the guys will make sure I see it. It's hard to see how this could be a hardware issue. If we swapped it out I would expect another device to do exactly the same thing given the same config. Steve
  • This topic is deleted!

    2
    0 Votes
    2 Posts
    140 Views
  • Netgate 2100 still safe to buy?

    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S
    Yes, it's still safe to buy. We have no plans to stop selling it I'm aware of and even when we do it will still be supported with updates for a long while after that. (years) Steve
  • XG-7100 dpinger Not Working?

    5
    0 Votes
    5 Posts
    773 Views
    stephenw10S
    If you only have one WAN they can be the same. Or should be able to. The important thing to realise is that both of those settings create a static route for that IP via the gateway it's assigned to. So if you have multiple gateways and you try to use the same IP for monitoring and DNS on different gateways that creates a routing conflict. Steve
  • Why does the SG-1100 change settings when restarted?

    12
    0 Votes
    12 Posts
    2k Views
    stephenw10S
    That's possible, though that particular thread deals with a real USB Ethernet NIC. Really it depends what is actually happening here. If the modem requires some manipulation before it appears as an Ethernet device. If it's just timing you can probably add a delay to prevent it. It's possible to just exclude USB Ethernet devices from the interface check at boot but doing so risks unknown behaviour in the event it's actually disconnected. Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.