Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Netgate SG1100 Setup Assistance

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    13 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      merrilr @Gertjan
      last edited by

      @Gertjan

      The isp router is on 172.16.0.1 ip and the lan port is 172.16.10.1.

      I can ping google DNS 8.8.8.8 but I can open any website.

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @merrilr
        last edited by

        @merrilr

        What is the WAN IP of pfSense ?
        See Status > Interfaces

        On the same page : LAN details ?

        On your PC : IP details ?
        If it's a Windows PC : go to 'cmd' and execute

        ipconfig /all
        

        Did it get an IP from pfSense ( see also Status > DHCP Leases )
        The gateway is the LAN IP of pfSEnse ?
        Same for DNS ?

        Did you add or change any DNS settings (normally, you shouldn't ) ?

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        M 2 Replies Last reply Reply Quote 0
        • M
          merrilr @Gertjan
          last edited by

          @Gertjan
          a2f29028-1684-4ea4-a95b-359cfe7af566-image.png

          The wan ip is the dhcp address given by the ISP router,.

          Yes the PC is a windows PC and the IP address it got was one from the DHCP setup for the LAN port/

          I have change and DNS settings. Only added the google DNS servers during the setup wizard,

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @merrilr
            last edited by

            @merrilr

            Your LAN settings page should be :

            02df8ba6-9924-4625-b4ea-e179647611c5-image.png

            ( for now, set IPv6 configuration to "none" :

            fb0604ac-70ef-413c-be9f-fc70694de0ba-image.png
            )

            System > Routing > Gateways

            08916dd6-16f4-48a2-b644-271fd02f6a1c-image.png

            where my gateway shows "192.168.10.1", your should be "172.16.0.1".
            The Monitoring IP should be a known upstream IP that you trust - or just blank or 'automatic'.

            @merrilr said in Netgate SG1100 Setup Assistance:

            Only added the google DNS servers during the setup wizard,

            Not really important now, but Netgate didn't ask you to add 8.8.8.8 - or any other IP for that matter. If that was needed, it would be there in the first place.
            pfSense uses a resolver. It doesn't need any 8.8.8.8 or 1.1.1.1 or the ISP dns : it works all about of the box, nothing needed.
            For some very special Internet connection, you need to enter DNS server IP. But again : not needed for the main 99,999 % of all cases.

            Go to : Diagnostics > DNS Lookup
            and look up, for example, netflix.com

            2deb6297-969e-427a-b065-8e8b74d40640-image.png

            Did you get an answer ?

            If ok, do the same thing on your PC :
            'cmd'
            and then

            nslookup netflix.com
            

            The answer looks fine ?

            Go here : Firewall > Rules > LAN

            You have the perfect firewall rule :

            dfdb243f-88be-4071-9289-fd35f07e4bba-image.png

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              I note you have a real IPv6 address and pfSense will try to use that by default if it can. If you don't actually have IPv6 connectivity that can cause problems.

              Steve

              M 1 Reply Last reply Reply Quote 0
              • stephenw10S stephenw10 referenced this topic on
              • M
                merrilr @stephenw10
                last edited by

                @Gertjan

                When I change IPv6 to none. I get the following error:

                2f0c213b-1b03-4e6f-bb4a-3d2c1ed1dc09-image.png

                During the setup wizard it prompted for DNS IPs. Should I have left them blank.

                88431f89-a754-46a3-bd4a-0ca45d2c6485-image.png

                Is it correct that my monitor ip is the same as the Gateway?
                How do I delete the DGCP6 as I do not use it

                GertjanG stephenw10S 2 Replies Last reply Reply Quote 0
                • GertjanG
                  Gertjan @merrilr
                  last edited by

                  @merrilr

                  00ef80e2-428c-4b14-9f77-0646dac50516-image.png

                  To put things easy : the DHCP6 (for IPv6) was handing out 'public' IPv6 on your LAN network.
                  For this to work, you have to have also a working IPv6 'uplink', on the pfSense WAN side.

                  So, disable DHCP6 : un check :

                  b636e4cf-dc53-49eb-bee3-410599fb7537-image.png

                  and save,

                  then : go to Router advertisement, select disabled

                  4f9a53b1-8196-4a2c-9cee-ca090affaeb0-image.png

                  and save.

                  Now you can disable IPv6 on the LAN interface - and the WAN interface.
                  Save.
                  Apply.
                  Reboot for good matters.

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  M 1 Reply Last reply Reply Quote 1
                  • stephenw10S
                    stephenw10 Netgate Administrator @merrilr
                    last edited by

                    First go to Services > DHCPv6 Server and RA and disable the DHCPv6 server on LAN.

                    1 Reply Last reply Reply Quote 0
                    • M
                      merrilr @Gertjan
                      last edited by

                      @Gertjan I removed all the DHCPv6 entries and set the setting none where applicable.

                      I also removed the google DNS from the setup screen:

                      0036e24c-44d2-468b-8c29-9a9bcb6c3e3c-image.png

                      All is working now and I can browse the net.

                      Thank you so much for all the help and patience you had with me.

                      GertjanG 1 Reply Last reply Reply Quote 1
                      • GertjanG
                        Gertjan @merrilr
                        last edited by

                        @merrilr said in Netgate SG1100 Setup Assistance:

                        I also removed the google DNS from the setup screen:

                        Ok.

                        But then :

                        451a3de4-ae52-4e7e-b46f-2a78c82679a7-image.png

                        this will put in place the (ISP) DNS severs you received when establishment the WAN connection.
                        This option exists also for historical reasons.
                        By default, this option is not checked neither - you (pfSense) doesn't need it.
                        Btw : I'm not saying it's 'wrong'.

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        1 Reply Last reply Reply Quote 0
                        • M
                          merrilr @Gertjan
                          last edited by

                          @Gertjan

                          I do have that ticked.

                          I have connected my switch the firewall. And when assigned all to the port I can access the net, however when I assign one of the VLANS i do not have access to the net. I only have one firewall rule to allow all traffic. Is there something I could have done wrong when creating the VLANS or is the problem in the switch setup?

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.