• Errors reinstalling pfSense on an SG-1100

    4
    0 Votes
    4 Posts
    930 Views
    stephenw10S

    Thanks for spotting that. I have opened a ticket to get it corrected.
    https://redmine.pfsense.org/issues/12266

    Steve

  • Testing strategy for Plus versus CE

    7
    0 Votes
    7 Posts
    888 Views
    stephenw10S

    It shows that because you're on a version that is now several versions old. It needs to update the package that contains the available repos but can't get the latest version of that from the 2.4.4 branch.
    If you run the update though you will probably go straight to 2.5.2 or 21.05.1 since it will be able to update the repo package as soon as it starts to pull in new packages.

    Steve

  • 0 Votes
    9 Posts
    896 Views
    dennis_sD

    I am going to lock this thread as you have received an answer to your questions through the support ticket you had open.

  • upgrade fails

    Moved
    4
    0 Votes
    4 Posts
    771 Views
    S

    @rico said in upgrade fails:

    run usbrecovery

    perfect i resolve the problem. tks

  • pfSense on Netgate hardware and power outages

    11
    0 Votes
    11 Posts
    2k Views
    stephenw10S

    Depending on what packages you have running you may be able to use ram disks.
    I've yet to see a filesystem problem on any device that has ram disks enabled.
    You can't really use it with Snort, Suricata or pfBlocker though unless you're very careful with tuning.

    Steve

  • Prepurchase Question

    19
    0 Votes
    19 Posts
    1k Views
    S

    @bmeeks said in Prepurchase Question:

    Suricata on SG-3100 appliances have apparently been solved

    In fact I did two upgrades to 21.05.01 on 3100s today and they both offered the suricata package (package 6.x, Suricata 5.x), not the suricata4 package.

  • old netgate/pfsense router/firewall still usable?

    11
    0 Votes
    11 Posts
    1k Views
    stephenw10S

    Those pics don't seem to have uploaded correctly.

    I think the reset procedure from the APU was the same. It's been a while though!
    In which case this applies: https://youtu.be/Cwz7vWu_KO0

    Steve

  • 2100 reboot loop

    4
    0 Votes
    4 Posts
    630 Views
    bmeeksB

    It's a tradeoff for performance and features versus a fully fault-tolerant hardware/software setup that is immune to sudden power failures. The full disk subsystem used in the pfSense appliances allows for better logging and installation and use of third-party packages that need a read-write disk subsystem.

    The professional way to deploy these and other pro-level firewall appliances is to power them with a UPS. Can be a relatively small and inexpensive one. Just make sure it offers a USB communications ability to send status info to a monitoring daemon. On pfSense, you then install either the apcupsd or nut package to monitor the UPS and gracefully shutdown the firewall when the UPS signals that power is lost and the battery is almost exhausted.

    The ZFS filesystem option is more fault-tolerant, and if you want to perform a complete reinstall, you can enable that option. I think there is a move afoot to make ZFS the default setup in coming future version updates. ZFS is not immune to issues caused by sudden power loss, but it is more resilient to the same as compared to UFS.

  • 2 Votes
    18 Posts
    2k Views
    B

    @johnpoz I offered to test an evaluation model ahead of time -- they wouldn't do that either. And somewhat tongue in cheek, if a company is charging a fee more than Cisco, that's a sure sign it's really exorbitant. 🙄 Bottom line -- it is not reasonable of a company to expect a consumer to take a $200+ risk that their performance metric claims are legitimate. It is reasonable to expect proof / substantiation that the equipment and not the environment is the problem, and I am willing to do whatever it takes to satisfy them in that regard.

    @flyzipper Your point is well taken, but in my case, I do consistently get speeds I cited directly through the modem. But if push came to shove, I would certainly be willing to put a another device on another port of the 6100 and do strictly local iperf3 tests through the 6100 to prove the point. Netgate wasn't interested in that either. I really think their position is untenable.

  • SG-3100 21.05.1 kern.ipc.maxpipekva exceeded; see tuning(7)

    Moved
    10
    0 Votes
    10 Posts
    1k Views
    stephenw10S

    Hmm, the only thing I'm aware of that may be related is the additional gpio device that is detected in 21.0X compared with 2.4.X. We had to make some changes to our driver for that I believe. The active device was incremented. That must be working for you though or it wouldn't work at all. Not something that would fail after some time.

    Steve

  • Netgate 5100 - after reboot no config

    13
    0 Votes
    13 Posts
    2k Views
    S

    @hebein said in Netgate 5100 - after reboot no config:

    old logs from suricata that filled up the filesystem

    A couple years ago, give or take, there was an issue where the Suricata GUI would show log rotation was enabled but it actually wasn't by default. That was fixed back then, and I would think if you are on 21.01 you'd have a newer package and this doesn't apply to you. But IIRC the workaround was just to save the Suricata log page settings so it did actually enable. Except for that we haven't had any such issues with its log rotation.

    If it's a high traffic site you might consider unchecking "Enable HTTP Log" on the interface.

  • XG-7100 1U WAN throughput

    3
    0 Votes
    3 Posts
    571 Views
    stephenw10S

    That level of throttling is almost always something low level like a speed/duplex mismatch or an IP address conflict.

    Check Status > Interfaces for errors/collisions especially when using the expansion card.

    Check the system logs for any errors shown.

    Steve

  • Blocked from making anymore tickets

    Moved
    9
    0 Votes
    9 Posts
    947 Views
    stephenw10S

    The anonymous, privacy centric nature of Protonmail is always going to attract spammers unfortunately. And spam filters are far from perfect. That's just the trade-off you make.

    Steve

  • Failure to re-start properly, possibly since 21.05

    Moved
    8
    0 Votes
    8 Posts
    1k Views
    stephenw10S

    Thanks for the follow up. 👍

  • Trying to submit firmware request ticket

    4
    0 Votes
    4 Posts
    595 Views
    stephenw10S

    I unblocked that email anyway in case you need to use it in future.

    Steve

  • FreeBSD 13 in pfSense+

    2
    0 Votes
    2 Posts
    494 Views
    jimpJ

    That is the plan when the timing is right. Won't be the next version of pfSense (Plus or CE), but soon.

  • CARP/HA not working

    Moved
    28
    0 Votes
    28 Posts
    3k Views
    stephenw10S

    Lose that how?

    If CARP is functioning correctly you might lose, for example, a single ping during the failover. For pings with a 1s period that is.

    Steve

  • 0 Votes
    6 Posts
    1k Views
    stephenw10S

    You can only choose a switch port on one interface as you found. If you leave unset it will use the actual VLAN status which takes it's state from the parent interface. In this case though that's the in internal port which is always UP.

    No, there's no private VLAN type function. That would need to be on a switch where hosts are connected directly.

    Steve

  • SG-3100 no routing/NAT after reboot

    7
    0 Votes
    7 Posts
    806 Views
    stephenw10S

    Hmm. Re-running the Setup Wizard would re-apply the interface settings on WAN and LAN. Something there must have been lost somehow. Losing the default route when the gateway is set as auto is probably most common but I have sometimes seen other things remove the default route. Hard to say without data from the time.

    Steve

  • Looking for some help and suggestions

    8
    0 Votes
    8 Posts
    1k Views
    P

    @stephenw10

    Alright, thank you Steve.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.