• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Installing pfSense on Sophos XG 105 rev. 2

Hardware
24
55
38.3k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    gtj @stephenw10
    last edited by gtj Jun 12, 2022, 2:13 PM Jun 12, 2022, 2:11 PM

    @stephenw10 said in Installing pfSense on Sophos XG 105 rev. 2:

    @gtj said in Installing pfSense on Sophos XG 105 rev. 2:

    WAN IP shows 0.0.0.0

    Usually that means it's configured as DHCP but cannot pull a lease, is that the case?

    What is it connected to? Check the dhcp logs for dhclient entries.

    Steve

    It is Indeed but so is my Backup configuration I loaded from the man pfsense router. That one connects to the web no problem.

    1 Reply Last reply Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Jun 12, 2022, 2:12 PM

      So what is it connected to?

      If it's a cable modem is that locked to the MAC of the other pfSense WAN?

      G 1 Reply Last reply Jun 12, 2022, 2:16 PM Reply Quote 0
      • G
        gtj @stephenw10
        last edited by Jun 12, 2022, 2:16 PM

        @stephenw10 said in Installing pfSense on Sophos XG 105 rev. 2:

        So what is it connected to?

        If it's a cable modem is that locked to the MAC of the other pfSense WAN?

        It is a cable modem from those all in one devices the ISPs provide. I want to use it as a modem with PPPoE passthrough and use pfsense to handle the routing and WiFi.

        C 1 Reply Last reply Jun 12, 2022, 2:40 PM Reply Quote 0
        • S
          stephenw10 Netgate Administrator
          last edited by Jun 12, 2022, 2:29 PM

          Well I would try spoofing the WAN MAC address to the same as the old device then.

          You could also connect it to some other device with a DHCP server in it to check it will pull a dhcp lease at all.

          1 Reply Last reply Reply Quote 1
          • C
            CCPFLDN @gtj
            last edited by CCPFLDN Jun 12, 2022, 2:41 PM Jun 12, 2022, 2:40 PM

            @gtj Most ISP modems will issue the Public IP to the MAC address of the device that is connected when it is turned on. You can't then swap it for another router because it will have a different MAC, as the Public IP has been issued to that MAC.

            On some ISPs (E.g Virgin Media in the UK) it is a simple fix; you just have to restart the modem between switching routers (so the modem doesn't go through it's boot process with the old router connected).

            On other ISPs there may be some different processes, e.g notifying them of the MAC address manually. In that case MAC spoofing is your only option.

            1 Reply Last reply Reply Quote 1
            • G
              gtj
              last edited by gtj Jun 12, 2022, 3:43 PM Jun 12, 2022, 3:43 PM

              Thanks for your invaluable help guys.
              I will try either restarting the modem or spoofing the MAC address.

              My ISP modem is indeed a Virgin UK superhub but in this instance, I'm trying to prepare a fresh pfsense installation to move it to my parents house in Greece when I go there in July.

              From what I gathered the connection there is a 100/10 cable PSTN with a Speedport Entry 2i modem/router .

              By spoofing it within the WAN settings of pfsense, do you mean that I have to manually set the MAC address which corresponds to the Sophos Igb0 I have assigned as WAN port?

              C 1 Reply Last reply Jun 12, 2022, 5:27 PM Reply Quote 0
              • C
                CCPFLDN @gtj
                last edited by Jun 12, 2022, 5:27 PM

                @gtj Well it sounds like the issue you have is that you didn't restart the Virgin Cable Modem when you switched the routers? so you won't need to do any spoofing, but if you did, yes you would be setting the WAN MAC to match the WAN MAC of the router that you swapped out.

                G 1 Reply Last reply Jun 12, 2022, 5:35 PM Reply Quote 1
                • G
                  gtj @CCPFLDN
                  last edited by gtj Jun 12, 2022, 5:36 PM Jun 12, 2022, 5:35 PM

                  @ccpfldn said in Installing pfSense on Sophos XG 105 rev. 2:

                  @gtj Well it sounds like the issue you have is that you didn't restart the Virgin Cable Modem when you switched the routers? so you won't need to do any spoofing, but if you did, yes you would be setting the WAN MAC to match the WAN MAC of the router that you swapped out.

                  No I haven't indeed. So I presume when I revert back to my main APU2C4 pfsense I'll have to restart the modem again prior to connecting the router back?

                  What baffles me is that in my current main APU pfsense I also can't see the WAN MAC address under WAN settings. The space is empty like it's the case with the Sophos one.

                  C 1 Reply Last reply Jun 12, 2022, 5:51 PM Reply Quote 0
                  • C
                    CCPFLDN @gtj
                    last edited by CCPFLDN Jun 12, 2022, 5:52 PM Jun 12, 2022, 5:51 PM

                    @gtj That's correct yes. The Virgin Media Superhub in modem mode can only issue one Public IP at a time to one MAC address at a time, and must be restarted in order to change the connected device.

                    You will have to follow a process every time you switch between routers or the second one you connect will be unable to obtain an IP, as you have found out.

                    This has actually been the case for about 20 years with all the previous generations of Ambit Cable modem they provided back when they were NTL/Telewest and it applies to some other ISPs around the world as well.

                    I go through the process methodically with any ISP provided device, disconnecting the old router, turning the ISP modem off for 10 seconds, then back on and waiting for it to boot up before connecting the new router just to make sure it can't lock to any other device.

                    G 1 Reply Last reply Jun 12, 2022, 6:22 PM Reply Quote 1
                    • G
                      gtj @CCPFLDN
                      last edited by Jun 12, 2022, 6:22 PM

                      @ccpfldn said in Installing pfSense on Sophos XG 105 rev. 2:

                      @gtj That's correct yes. The Virgin Media Superhub in modem mode can only issue one Public IP at a time to one MAC address at a time, and must be restarted in order to change the connected device.

                      You will have to follow a process every time you switch between routers or the second one you connect will be unable to obtain an IP, as you have found out.

                      This has actually been the case for about 20 years with all the previous generations of Ambit Cable modem they provided back when they were NTL/Telewest and it applies to some other ISPs around the world as well.

                      I go through the process methodically with any ISP provided device, disconnecting the old router, turning the ISP modem off for 10 seconds, then back on and waiting for it to boot up before connecting the new router just to make sure it can't lock to any other device.

                      Thank you so much for the detailed and comprehensive response. Much appreciated!

                      Hope the same will apply to the other modem overseas.

                      1 Reply Last reply Reply Quote 0
                      • F fireodo referenced this topic on Dec 27, 2022, 1:42 PM
                      • D
                        deanfourie
                        last edited by Jan 5, 2023, 9:42 AM

                        I just got my hands on a Sophos XG106 and looking at getting pfSense installed. I got it for nothing so getting pfSense installed on it would be a great bounus.

                        First thing i've noticed is, I dont get anything from the HDMI port, no signal whatsoever.

                        Is it possible to do this entire process via serial?

                        Thanks

                        C 1 Reply Last reply Jan 5, 2023, 1:21 PM Reply Quote 0
                        • C
                          CLEsports @deanfourie
                          last edited by Jan 5, 2023, 1:21 PM

                          @deanfourie Yes, it's possible to install pfSense using only the serial port. Use 115200 for the speed on the COM port for pfSense. If you want to get into the BIOS on your Sophos box for any reason, use 38400

                          D 1 Reply Last reply Jan 5, 2023, 7:53 PM Reply Quote 1
                          • D
                            deanfourie @CLEsports
                            last edited by Jan 5, 2023, 7:53 PM

                            @clesports Excellent, thanks.

                            Are there any tricks or catches I should know about.

                            eg. How to enter BIOS?, if the install hangs etc.

                            Also, does this work for all sophos models including the XG and XGS models do we know?

                            Thanks

                            C 1 Reply Last reply Jan 5, 2023, 8:52 PM Reply Quote 0
                            • C
                              CLEsports @deanfourie
                              last edited by CLEsports Jan 5, 2023, 8:54 PM Jan 5, 2023, 8:52 PM

                              @deanfourie Don't remember what key off-hand, but it'll say on the screen. Worked on my XG 310. Didn't need to go into the BIOS on mine, but the option was there. As far as I know, it works on all models

                              1 Reply Last reply Reply Quote 0
                              • D
                                dermicha
                                last edited by Feb 7, 2023, 10:26 PM

                                Just installed pfSense 2.6.0 on Sophos SG 105 Rev 2 Hardware.

                                Image: pfSense-CE-memstick-serial-2.6.0-RELEASE-amd64.img

                                Written to memdrive by raspberry pi imager, on Mac OS 13.1.

                                Disabled the "Port 60/40 emulation" Thing in Bios

                                Connected to console via USB to Serial Adapter with HPE Serial DB9 cable.

                                Only thing to do, change com port speed to 115200 to recieve some data.

                                VGA Image didn't work due to several issues made me curse.

                                1 Reply Last reply Reply Quote 0
                                • D
                                  dkzsys
                                  last edited by dkzsys Apr 2, 2023, 1:16 PM Apr 2, 2023, 1:14 PM

                                  Thanks for the tips here. I managed to install pfSense 2.6.0 on an Sophos XG125w successfully. However, having some challenges with the eth port connections - "no carrier" status for all ports.

                                  Some help/advise would be much appreciated. Details here @ pfSense on Sophos XG125w - "no carrier" on all eth interfaces

                                  Thanks in advance.

                                  1 Reply Last reply Reply Quote 0
                                  • jimpJ jimp moved this topic from Problems Installing or Upgrading pfSense Software on Apr 3, 2023, 12:10 PM
                                  • A
                                    Aggregating_Netgator
                                    last edited by Aggregating_Netgator Jun 18, 2023, 1:22 AM Jun 18, 2023, 1:10 AM

                                    I wonder if anyone of you champs who has installed pfSense on Sophos XG 105 rev.2, could advise how's the OPEN VPN download speed.

                                    SOPHOS websites indicates it's 360 Megabytes per second, as seen in the below link, but then again it's measured under their own software, and not under pfSense.

                                    https://www.enterpriseav.com.au/XG-Firewall.asp

                                    Thanks!

                                    1 Reply Last reply Reply Quote 0
                                    • S
                                      stephenw10 Netgate Administrator
                                      last edited by Jun 18, 2023, 8:08 PM

                                      The Atom E3826 is the same CPU used in the MBT-2220 so you might want to check posts for that too.

                                      1 Reply Last reply Reply Quote 0
                                      • xXNorthXXX
                                        xXNorthXX
                                        last edited by xXNorthXX Sep 22, 2023, 1:10 AM Sep 22, 2023, 1:09 AM

                                        Another model reference.

                                        The Sophos SG 115w (rev 2) - Intel E3827 (@ 1.74GHz), 4GB DDR3L, and 64GB SSD (SATA 6Gbps).

                                        Bios adjustments

                                        1. change boot order so usb stick is first
                                        2. disable the 60/40 emulation
                                        3. changed the comm port speed to 115200

                                        Installed the pfSense v2.7 CE memstick build without any complaints.

                                        eth0 = wan
                                        eth1 = lan
                                        eth2 = OPT1
                                        eth3 = OPT2
                                        ath0 = Wireless

                                        Only issue I had with the few units was the cmos battery needed to be re-taped down, otherwise no issues.

                                        1 Reply Last reply Reply Quote 1
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.