• Firewall rules to create a guest network

    29
    0 Votes
    29 Posts
    11k Views
    C

    As requested I will post screenshots, but I think this is still a WIP as some of these rules are set automatically internally, so I could cleanup, and I notice also that I have ALTQ queues defined when ALTQ is off now, but hopefully gives you an idea what I meant.

    Managementports alias points to ports 80,443,22 to block ssh, and webui access to firewall.

    guest_ntp_dns points to ports 53,123,853 to allow dns/ntp access on firewall.

    The nolog rule near bottom is to disable logging for some extra packets that get blocked from the walled garden setup, and were been logged because I decided to log the blocked packets, so that was to disable logging for those packets.

    Guest_ports is allowed ports on walled garden, its an expansive list as I include ports for some android and social media apps as well as email. Will attach pic for it also.

    Also as has been pointed out, you need to have the ability to have an isolated WAP setup that uses the guest VLAN. Unless you ok with all wifi clients been on the main LAN.

    alt text

    alt text

  • VK T40E upgrade path?

    9
    0 Votes
    9 Posts
    686 Views
    stephenw10S

    Ok, the 3100 is probably ideally suited there then. It will do ~100Mbps OpenVPN and closer to 300Mbps IPSec if required.

    Steve

  • setting up new ha device and port forward

    Moved
    2
    0 Votes
    2 Posts
    281 Views
    stephenw10S

    A pair of XG-1537s work fine in an HA setup. CARP is only part of that along with pfSync and config sync. There should be no issues there if they are configured correctly.

    I'm not sure what you mean with the port forwards question. A diagram may help here.

    You can setup port forwards through an HA pair certainly.

    Steve

  • SG 1100 MGMT port

    2
    0 Votes
    2 Posts
    349 Views
    stephenw10S

    If you disconnect the LAN port by default the SG-1100 will show the LAN interface, with the IP on it, as down. You can change that in the LAN interfaces setup. Set the Switch port to monitor for state changes to the default value (no port) and LAN will always be up.
    However you can also just access the webgui on the OPT interface IP. Or indeed the WAN IP, the webgui listens on all available IPs.

    Steve

  • Porting OpenBSD UMB(4) to FreeBSD for MBIM Support

    2
    0 Votes
    2 Posts
    654 Views
    stephenw10S

    We are not currently accepting paid development work. However we have an internal ticket open for this already, I'll add your voice there. It would be very nice to have that driver.

    umb was ported to NetBSD more recently and the same developer was at one time working on a FreeBSD port but appeared to abandon the effort. He's probably in the best place to port this. I have no idea if he's open to offers.

    Steve

  • SG-3100 backordered indefinitely?

    2
    0 Votes
    2 Posts
    357 Views
    jimpJ

    There are still supply chain disruptions from COVID-19 happening. They are coming as soon as possible and backorders are filled as soon as new units arrive.

  • No WAN IP on new XG-7100 - with DrayTek Vigor 130 Bridged VDSL

    12
    0 Votes
    12 Posts
    807 Views
    stephenw10S

    It should appear imediately below the client config section when you enable advanced config:
    Selection_880.png

    It's normally hidden by client side script. Try a different browser if you don't see it or check your browser plugins, something may be blocking it.

    Steve

  • netgate sfp+ 7100xg

    Moved
    11
    0 Votes
    11 Posts
    831 Views
    stephenw10S

    It depends what you're forwarding of course. It's not something I have tested myself (or is often used) but there are some numbers for forwarding only on the product page:
    https://store.netgate.com/XG-7100.aspx

    Steve

  • Snort Error Bogon Rules

    12
    0 Votes
    12 Posts
    1k Views
    styxlS

    @stephenw10 sure, will give 400K a try and see. Thanks

  • Support user blocked

    2
    0 Votes
    2 Posts
    272 Views
    stephenw10S

    I have unblocked that. Please try to open a ticket again if you still need the firmware.

    Steve

  • SG-1100 always that flaky or I got a dud?

    14
    0 Votes
    14 Posts
    2k Views
    DaddyGoD

    @pi said in SG-1100 always that flaky or I got a dud?:

    That’s funny. I’m a couple of months into pfSense and I’m still breaking it, probably weekly.

    Unfortunately, I can't do that anymore because there are a lot of production environments in which we use pfSense.

    All success can be gained through a lot of experience 😉

    Go for it...

  • Use my SG-2440 config on an SG-1000 ?

    3
    0 Votes
    3 Posts
    689 Views
    billlB

    @dotdash sorry for the late response, and thanks for your reply!
    I ended up going with an SG-1100, and it seems to be holding up pretty well. I have yet to install pfBlockerNG on it though, so not sure if it will be enough for that. If anyone else is looking at doing this, it was a little tricky getting familiar with the fact that all of the ports belong to an internal switch, but I was able to work through it with a little help from the internet :)
    Bill

  • SG-1100 drops clients, lease time issue?

    14
    0 Votes
    14 Posts
    744 Views
    D

    Thank you @stephenw10 and @keyser.

    @keyser, based on your comment I looked up my Netgear (R7000, I am using the router as a wifi AP). It seems like many people online complain about dropped connections. Based on online advice, I reverted it back to a previous firmware version.

    If that works, I'll come back and post details so future readers in a similar situation can benefit. For now, fingers crossed.

  • SG-3100 Hangs after internet outage

    5
    0 Votes
    5 Posts
    957 Views
    GertjanG

    @digitalvt said in SG-3100 Hangs after internet outage:

    I couldn't even connect via browser to the pfSense?!

    When you visit the GUI dashboard, the information isn't all static. Most of it is collected "at the source' and some of that isn't available "on site".
    Example, package version info is compared with available versions on the 'Netgate' package server. A working connection is needed (read = DNS, amongst other, should work). If the connection is lost, the GUI behaves somewhat like any other web site that is off line. The GUI dashboard will show up, after some (DNS) time outs.

    Start finding the answer to this question :

    cc44ab7e-0d97-4f33-8d28-9734d86217ce-image.png 0612055684

    Why is the Resolver restarting so often ?
    When it restarts, DNS will be off line for several moments.
    A reason might be, as you showed : if dpinger 'thinks' restarts the Internet connection is bad (very high latency, or even pings lost) then it restarts the WAN interface - and packages / processes like unbound.
    Discover why your uplink (ISP) is bad, and you should be close to a solution.

  • Router randomly power cycles

    Moved
    14
    0 Votes
    14 Posts
    1k Views
    V

    I use a lot of PC Engines APU2D4 which has an AMD GX-412TC 1Ghz CPU, 4GB DDR3-1333 soldered memory, supports AES-NI, (3) I210 ethernet ports. These boxes run notoriously hot. The worst I've seen (hot environment) is it chugging along at 71C (159F?) with no problem. In a cool environment the box still runs at 50C.

  • SG-1100 WAN MAC Spoofing Guide?

    Moved
    13
    0 Votes
    13 Posts
    2k Views
    V

    @Derelict Now there's wisdom -- would have saved me a lot of time even if the ISP support queues are long, etc.

  • Enabling OPT interface on SG-1100

    8
    0 Votes
    8 Posts
    2k Views
    stephenw10S

    The DHCP lease list will not show them if they are statically assigned and do not request a lease.

    The correct way to do this is set the DHCP range on OPT so it does not include any of the fixed IP devices. Then as a static dhcp lease for each of them manually in pfSense. They should never ask for that lease but if one of them default's to dhcp pfSense will then give it to them. The static leases are listed on the DHCP status page and they will show on-line if they have current ARP table entries.

    Steve

  • SG-2440 red status light

    3
    0 Votes
    3 Posts
    710 Views
    A

    Thank you, opened ticket.

  • XG-7100 Questions

    2
    0 Votes
    2 Posts
    565 Views
    stephenw10S

    The XG-7100 will route traffic at >10Gbps (depending on packet sizes etc) but that's probably not what you mean. If you are using it as a firewall and include NAT it's closer to 6Gbps, again depending on the traffic.
    See: https://www.netgate.com/products/appliances/

    You can add the expansion card yourself but you would need to order the fitting kit (contact sales):
    https://docs.netgate.com/pfsense/en/latest/solutions/xg-7100-1u/optional-expansion-card-installation.html

    Indeed, the eMMC is slower but that really only significantly affects boot time. You would want to use an SSD if you plan to run any packages that need to write to the drive such as Squid or something that logs a lot like Snort.

    8GB is sufficient for almost everything. It's possible to upgrade that too, the SODIMM slot is on the top of the board.

    The Intel NICs in it will work with a wide variety of SFP+ modules but those we sell in the store are tested to work.

    Steve

  • SG-1100 SpeedTest Capped ~300 Mbps

    2
    0 Votes
    2 Posts
    1k Views
    stephenw10S

    The SG-1100 can usually pass 450-500Mbps so there may be some optimising to do there. It won't pass 716Mbps though.
    The SG-3100 can pass traffic at or very close to Gigabit line rate (941Mbps) so should be fine there.

    There are always variables here, precise numbers are hard to give.

    Steve

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.