• 2100 reboot loop

    4
    0 Votes
    4 Posts
    679 Views
    bmeeksB
    It's a tradeoff for performance and features versus a fully fault-tolerant hardware/software setup that is immune to sudden power failures. The full disk subsystem used in the pfSense appliances allows for better logging and installation and use of third-party packages that need a read-write disk subsystem. The professional way to deploy these and other pro-level firewall appliances is to power them with a UPS. Can be a relatively small and inexpensive one. Just make sure it offers a USB communications ability to send status info to a monitoring daemon. On pfSense, you then install either the apcupsd or nut package to monitor the UPS and gracefully shutdown the firewall when the UPS signals that power is lost and the battery is almost exhausted. The ZFS filesystem option is more fault-tolerant, and if you want to perform a complete reinstall, you can enable that option. I think there is a move afoot to make ZFS the default setup in coming future version updates. ZFS is not immune to issues caused by sudden power loss, but it is more resilient to the same as compared to UFS.
  • 2 Votes
    18 Posts
    2k Views
    B
    @johnpoz I offered to test an evaluation model ahead of time -- they wouldn't do that either. And somewhat tongue in cheek, if a company is charging a fee more than Cisco, that's a sure sign it's really exorbitant. Bottom line -- it is not reasonable of a company to expect a consumer to take a $200+ risk that their performance metric claims are legitimate. It is reasonable to expect proof / substantiation that the equipment and not the environment is the problem, and I am willing to do whatever it takes to satisfy them in that regard. @flyzipper Your point is well taken, but in my case, I do consistently get speeds I cited directly through the modem. But if push came to shove, I would certainly be willing to put a another device on another port of the 6100 and do strictly local iperf3 tests through the 6100 to prove the point. Netgate wasn't interested in that either. I really think their position is untenable.
  • SG-3100 21.05.1 kern.ipc.maxpipekva exceeded; see tuning(7)

    Moved
    10
    0 Votes
    10 Posts
    1k Views
    stephenw10S
    Hmm, the only thing I'm aware of that may be related is the additional gpio device that is detected in 21.0X compared with 2.4.X. We had to make some changes to our driver for that I believe. The active device was incremented. That must be working for you though or it wouldn't work at all. Not something that would fail after some time. Steve
  • Netgate 5100 - after reboot no config

    13
    0 Votes
    13 Posts
    2k Views
    S
    @hebein said in Netgate 5100 - after reboot no config: old logs from suricata that filled up the filesystem A couple years ago, give or take, there was an issue where the Suricata GUI would show log rotation was enabled but it actually wasn't by default. That was fixed back then, and I would think if you are on 21.01 you'd have a newer package and this doesn't apply to you. But IIRC the workaround was just to save the Suricata log page settings so it did actually enable. Except for that we haven't had any such issues with its log rotation. If it's a high traffic site you might consider unchecking "Enable HTTP Log" on the interface.
  • XG-7100 1U WAN throughput

    3
    0 Votes
    3 Posts
    607 Views
    stephenw10S
    That level of throttling is almost always something low level like a speed/duplex mismatch or an IP address conflict. Check Status > Interfaces for errors/collisions especially when using the expansion card. Check the system logs for any errors shown. Steve
  • Blocked from making anymore tickets

    Moved
    9
    0 Votes
    9 Posts
    1k Views
    stephenw10S
    The anonymous, privacy centric nature of Protonmail is always going to attract spammers unfortunately. And spam filters are far from perfect. That's just the trade-off you make. Steve
  • Failure to re-start properly, possibly since 21.05

    Moved
    8
    0 Votes
    8 Posts
    1k Views
    stephenw10S
    Thanks for the follow up.
  • Trying to submit firmware request ticket

    4
    0 Votes
    4 Posts
    643 Views
    stephenw10S
    I unblocked that email anyway in case you need to use it in future. Steve
  • FreeBSD 13 in pfSense+

    2
    0 Votes
    2 Posts
    503 Views
    jimpJ
    That is the plan when the timing is right. Won't be the next version of pfSense (Plus or CE), but soon.
  • CARP/HA not working

    Moved
    28
    0 Votes
    28 Posts
    3k Views
    stephenw10S
    Lose that how? If CARP is functioning correctly you might lose, for example, a single ping during the failover. For pings with a 1s period that is. Steve
  • 0 Votes
    6 Posts
    2k Views
    stephenw10S
    You can only choose a switch port on one interface as you found. If you leave unset it will use the actual VLAN status which takes it's state from the parent interface. In this case though that's the in internal port which is always UP. No, there's no private VLAN type function. That would need to be on a switch where hosts are connected directly. Steve
  • SG-3100 no routing/NAT after reboot

    7
    0 Votes
    7 Posts
    880 Views
    stephenw10S
    Hmm. Re-running the Setup Wizard would re-apply the interface settings on WAN and LAN. Something there must have been lost somehow. Losing the default route when the gateway is set as auto is probably most common but I have sometimes seen other things remove the default route. Hard to say without data from the time. Steve
  • Looking for some help and suggestions

    8
    0 Votes
    8 Posts
    1k Views
    P
    @stephenw10 Alright, thank you Steve.
  • Netgate 2100 bricked on upgrade

    Moved
    4
    0 Votes
    4 Posts
    746 Views
    stephenw10S
    Yup we will always help you recover by re-installing if you need to, you don't need support for that. Just open a ticket if you haven't already: https://go.netgate.com/ Steve
  • SG-4860 risk of failure again?

    3
    0 Votes
    3 Posts
    590 Views
    P
    @stephenw10 said in SG-4860 risk of failure again?: It would depend exactly when it was replaced. Do you have a ticket number I can check? Steve (Sent via PM)
  • SG-4860 Frozen with Red Status Light

    7
    0 Votes
    7 Posts
    939 Views
    X
    @stephenw10 thanks for that. Now registered and will raise a ticket. Appreciate the support.
  • Can't Access Pfsense Web Interface

    Moved
    4
    0 Votes
    4 Posts
    819 Views
    A
    @aznricebox Update: issue resolved. Found that it was my anti-virus causing the issue. Once I put an exception for the IP of the SG-1100 I was able to get to the page and log in. Probably due to the cert that is automatically generated by pfsense that my anti-virus didn't like.
  • Swapfile on SG-1100 running 21.05?

    9
    0 Votes
    9 Posts
    993 Views
    stephenw10S
    @f1d094 said in Swapfile on SG-1100 running 21.05?: were so laden with adware and trackers that I said "tough cookies" Ha, sounds fair. I mean, yeah, it looks like it's definitely working for you. Steve
  • Unable to check for update netgate sg-2220 release 21.05

    5
    0 Votes
    5 Posts
    864 Views
    stephenw10S
    The SG-2220 does not have an RTC clock battery so if it's been off for some time it may revert to the initial time/date. If you do not have at least one NTP server defined by IP and you have DNSSec enabled in Unbound and no other DNS servers set then you have a chicken/egg situation. The firewall cannot recolve any time servers because DNS doesn't work when the clock is wrong! Setting either a fixed NTP server or an alternative DNS server will prevent that. Steve
  • How do I connect a sg-5100 to an existing sg-3100 for testing?

    5
    0 Votes
    5 Posts
    605 Views
    stephenw10S
    Yeah subnet conflict is most likely there. If the both have the same LAN subnet the 5100 would end up with the same subnet on WAN and LAN creating a conflict. Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.