• 7100-1U VLAN Issues

    2
    0 Votes
    2 Posts
    443 Views
    stephenw10S

    If you are using ix0/ix1 the VLANs work exactly like any other pfSense install.

    Can you show us how you have them configured?

    Steve

  • This topic is deleted!

    Moved
    1
    0 Votes
    1 Posts
    18 Views
    No one has replied
  • Hardware appliance choice

    3
    0 Votes
    3 Posts
    574 Views
    stephenw10S

    Yup, I would say the same. Any firewall will handle it, even the 1100, but if you want to use VPNs, filtering, traffic shaping etc and have that many clients I'd go for the 5100. Or the 6100 now.

    Steve

  • New 7100 setup

    Moved
    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S

    @andyrh said in New 7100 setup:

    I moved the WAN by changing the parent interface for the default WAN VLAN.

    The VLAN on WAN, 4090 by default, only applies to the internal switch. So simply moving the VLAN parent to ix0 or igb3 would only work if VLAN 4090 is defined correctly on the external switch they are connected to.
    If that's not the case the new WAN interface would be directly ix0 or igb3 without a VLAN.

    Steve

  • Versions of pfSense software Plus vs CE

    Moved
    3
    0 Votes
    3 Posts
    1k Views
    stephenw10S

    Yes, it's because you are running the Factory Edition.
    On that particular hardware you can re-install as CE if you really wanted to but I would not recommend it:
    https://nyifiles.netgate.com/mirror/downloads/pfSense-CE-memstick-ADI-2.5.2-RELEASE-amd64.img.gz

    Steve

  • SG-3100 - No web GUI or internet

    2
    0 Votes
    2 Posts
    394 Views
    stephenw10S

    If it's still flashing all three blue LEDs then it has not booted completely.
    If it's still flashing orange then it's still seeing an available update so I'd say it didn't complete the upgrade for some reason.

    I would re-install 21.05.1 clean from there and restore the config. If it didn't complete the upgrade you can never be sure what state it's in otherwise.
    Check the routing tables: netstat -rn
    Make sure you have a default route and it's the right one.

    Steve

  • How do I enable LAN access on additional ports for SG-2100?

    Moved
    10
    0 Votes
    10 Posts
    1k Views
    B

    @trevorftard Look at Interfaces > Switches > Ports

    Screenshot 2021-08-25 at 05.51.11.png

  • reset sg-1100 to factory default

    4
    0 Votes
    4 Posts
    1k Views
    I

    Hello, looks like I had to reinstall the OS.
    Opened a ticket with negate support and they were able to guide me through the procedure.
    Thank you

  • SG-3100 After SSD Upgrade SSH not working

    4
    0 Votes
    4 Posts
    535 Views
    R

    @gertjan Thank you. Did the reinstall and now i can login via SSH.

  • sg-1100 breakage: exposing internal devices to the WAN

    Moved
    12
    0 Votes
    12 Posts
    1k Views
    M

    @cyberminion
    The SG2100: the default configuration all the ports labelled LAN are on the switch. If you don't do anything all the ports are on the LAN segment. The WAN is a distinct device; default mode is like a good old WRT54G: WAN goes to the Internet, all the LAN ports in the back are switched together. If you want to create a LAN and OPT1 (your original picture) you have to do explicit configuration to create VLANs and Tagging for the different ports on the Switch itself.

    Unit with separate NICs. Hard to say, it may depend on how the separate NIC devices are connected. Easy to see them connected to an unmanaged switch, if there is no explicit configuration, I think again you wind up with the $5 unmanaged switch from the store.

    I'm currently behind a SG2440 that has distinct NICs for WAN, LAN/OPT1/OPT2 and I am not going to break my configuration to test the theory :) ( wife would get annoyed at me )

    Sometimes the switch devices let you have pullup/pulldown resistors on pins to force a configuration after power on. I don't have the Netgate schematics or the datasheets so can't say if anything like this is being done, but most switch devices I've used default to unmanaged mode after a power cycle.

    If you have the serial console cable if it breaks you should be able to get to a shell and poke around. If I'm recalling correctly, basically look for a 0 byte config.xml and then look for a backup of config.xml that is non-zero length and simply copy that over to fix it.

  • ssl certificate verification failed

    Moved
    9
    0 Votes
    9 Posts
    2k Views
    stephenw10S

    Yes, rebooting is a good idea before an upgrade to be sure it will return from that.
    You should not need to power cycle it normally though. This was a bug in the driver that could put the hardware into a condition it could not recover from. That should have been fixed in 21.05 though.

    The only time I would expect to need a power cycle is after updating uboot/coreboot.

    Steve

  • SG-1100 unresponsive

    6
    0 Votes
    6 Posts
    855 Views
    stephenw10S

    Ah, good to hear. 👍

  • [Solved] XG-7100 Expansion card status incorrect

    Moved
    3
    0 Votes
    3 Posts
    470 Views
    S

    @stephenw10 Thanks, this is exactly my case. I'll update that come next maintenance period.

    <interfaces> <wan> <enable></enable> <if>igb0</if> <blockpriv></blockpriv> <blockbogons></blockbogons> <switchif>switch0.port1</switchif> ...
  • Netgate SG-3100 LEDs

    54
    0 Votes
    54 Posts
    37k Views
    wgstarksW

    @jchonig said in Netgate SG-3100 LEDs:

    @renegade Are you using lockf in your cron script? That's supposed to prevent it from consuming resources.

    I'm pretty sure the root problem is a kernel bug causing the sysctl and gpioctl commands to hang. I need to find the time to do some debugging.

    This worked for me for about 18 hours but now the system is completely locked up with the same error so lockf doesn’t appear to do the trick.

    Edit: Here is the command I was using (just for reference)-

    /usr/bin/lockf /var/run/gw_leds.lock /root/gw_leds -b WAN_DHCP -A 0,0,16 -C 0,0,16
  • Snort signal 10 crash on SG-3100

    6
    0 Votes
    6 Posts
    882 Views
    bmeeksB

    Good news for Snort users on the SG-3100! The Netgate team has pulled the latest Snort fix for the Signal 10 problem into the pfSense+ 21.05.1 branch: https://redmine.pfsense.org/issues/12157#change-55832. So you should see an updated Snort package show up soon.

  • SG-2100 Upgrade failure from 21.05 to 21.05.1

    Moved
    6
    0 Votes
    6 Posts
    688 Views
    stephenw10S

    Suricata should run fine on the SG-2100. Just be sure to set log file size limits including a total size limit.

    Steve

  • Netgate 3100 + Bridge

    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S

    Ok, if you're doing that I would put the bridge between WAN and OPT and use LAN for management. That removes the switch from the connection.

  • 7100U connecting to a L2 switch

    3
    0 Votes
    3 Posts
    424 Views
    F

    Thank you stephen. I guess we already talked over e-mail about this issue, i appreciate your answer here too though.
    I could also add one of the 4 port 1Gbps PCIe NICs that are supported by the 7100U and not being limitied to load balancing laggs only, right?

    In any case and this is a little bit off-topic but bear with me for a second.
    I am really interested about the future of pfsense+. Been a long timer user of the community edition and from a business perspective the move to pfsense+ was understandable and probably the right one.

    Of course i wish that the CE edition will still remain and receives regular updates but i guess that remains to be seen.
    I am also looking forward to pfsense+ on VMs or 3rd party hardware and i would be very happy to see this come to fruition in 2021.

    Thanks again. :)

  • 5100: wan throughput dropped

    3
    0 Votes
    3 Posts
    489 Views
    D

    @stephenw10 thanks! that path ultimately lead to a damaged port igd0! remaining ports in good shape, so did a quick right-shift from Interfaces, Assignments...

  • M.2 PCIe Lanes in 3100-SG

    4
    0 Votes
    4 Posts
    537 Views
    stephenw10S

    There's no provision for using multiple drives in pfSense so you would need to boot from m.2 SSD
    or add your own scripts to enable it. There's a pretty good chance you would fill the drive accidentally and cause problems for the firewall. Hard to recommend doing that.

    Either way though, the m.2 slot is not NVMe so no PCIe lines.

    Steve

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.