Too stupid to own a 6100
-
I added a new user account and disabled the admin account on a new 6100. Upon next log in system informs me "no page assigned to this user"... Okay rookie move. Now I just want to factory reset the unit. Following directions for other Netgate appliances I power cycle with the power button, wait 10 seconds, the use a pin to hold the reset button for 30+ seconds. Ive tried varing the time buttons are held, nondice.
System boots and no access from the admin account. Okay, let's try ssh... I can't install the drivers for the console connection. Admittedly I'm tired and frustrated, but no excuses. However, any recommendations are welcome. -
@jmds65536 An alternative might be just to reinstall it.
-
"Too stupid to own a 6100 "
haha - To be honest that pops into my mind a lot around here. I sometime wish there was a test required to be passed before most user could even download pfsense ;)
"Reset button behavior varies by hardware. Check the appropriate product manual to confirm support and button behavior before attempting this procedure."
I doubt the 6100 falls under that, maybe something like the 1000, or the 1100 that might be an option.
I can't install the drivers for the console connection
You would have consult the instructions for your OS your using to console from..
https://docs.netgate.com/pfsense/en/latest/solutions/netgate-6100/connect-to-console.html
I have personal experience with 2440, 3100, 4860 - and access to console is a client thing your using, and not really anything to do with the device your connecting to.. You have to make sure your using the correct com port that your OS is seeing..
I do believe all appliances come with what they call
"Complimentary 24x7 zero-to-ping support from Netgate Global Support"It is for sure listed on the 6100 info page.
If your having an issue getting your appliance booted, running, able to access the gui sort of access. I would suggest you contact their actual support... I am fairly sure they will pretty much bend over backwards to get you going with a basic config.. Now asking them more complicated how to do that, how to do that more than likely requires a support contract, but installing pfsense on their appliance I do believe falls to their zero-to-ping support..
-
@jmds65536 said in Too stupid to own a 6100:
System boots and no access from the admin account. Okay, let's try ssh..
Yeah, great, but not so.
A pfSense in 'resetted state' can have no interface assigned. Only the console "serial" interface would work. The 6100 as a Netgate appliance is probably an exception, the dedicated firmware knows how to set up the upfront known NIC,s so it assigns a WAN and LAN after root.
Still, the ssh daemon has to be activated in the GUI first.As @johnpoz said, you have to have the console interface working. It's not some sort of geek or gadget interface. It's the most important interface.
Right after you have the console access up and running - get your hands on a USB drive and get that copy of the firmware. Write it to the drive as per instruction (the documentation). An test booting from it with your pfSense.
As soon as this is done, you're officially lost some minute of your time, and you'll never need it again.@jmds65536 said in Too stupid to own a 6100:
I added a new user account and disabled the admin account on a new 6100. Upon next log in
Yeah, that's a known way of 'protection'. But also a bit BS.
User names and passwords get remembered in browsers.
If you think your LAN devices are non trusted, throw them on another LAN interface without 'pfsense admin' access.
You have a 6100 so use it ( !! ) reserve one interface, the first initial LAN for admin access for admin access only. Do not use = connect any other devices to it. Use all the other interface for your day-to-day LAN interfaces, and add a firewall rule on each of them : no connect to port 80-443 TCP pfSense LANx interface. And your done. -
@gertjan said in Too stupid to own a 6100:
As @johnpoz said, you have to have the console interface working. It's not some sort of geek or gadget interface. It's the most important interface.
I'd like to second/third/upvote/whatever you want to call it for this statement.
-
Thank you for the responses. I just needed to walk away for a bit. I was too busy kicking myself for doing something dumb and wasn't thinking straight. This morning I installed the proper driver for UART adaptor. PuTTy in and rest is history. I've successfully reset the unit, re-added the user account and assigned the group properly.
I never did get the reset to work. I may still contact netgate to hear what they say.
-
The reset config procedure in the 6100 is a little more involved that other devices. And it fact I would only attempt it in 21.05.2 if you have no other option. The timing is such that it's difficult unless you can see the console output and at that point just use the console!
This is fixed in 22.01 where the feedback from the LEDs make the process relatively easy.The reset is a two step process:
Power on the device. After a few seconds, when the green circle LED changes from orange to blue, hold the reset button for 5 seconds. This 'short-press' initiates the reset.Then after the drive has mounted the system recognises the reset has been initiated and asks you to confirm the reset. In 22.01 this is indicated by all three LEDs turning red. Hold the reset button until all three LEDs start flashing, ~13s.
The system then resets the config and reboots.
Steve