Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Successful Install on Watchguard Firebox X700!

    Hardware
    151
    690
    964.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      Valhalla1
      last edited by

      ugh.. just had to add a few rules to the firewall and it ended up being a multi-reboot network outage due to watchdog timeout freezeups..   box had been up for a couple weeks, transferring tens of gigs of data per day, but soon as I need to poke around the webgui, the lan interface decides to puke all over itself

      1 Reply Last reply Reply Quote 0
      • R
        ridnhard19
        last edited by

        @Valhalla1:

        ugh.. just had to add a few rules to the firewall and it ended up being a multi-reboot network outage due to watchdog timeout freezeups..   box had been up for a couple weeks, transferring tens of gigs of data per day, but soon as I need to poke around the webgui, the lan interface decides to puke all over itself

        Hey Valhalla1,

        This is what i've been battling with now for a number of weeks. There is an issue with the driver support in Freebsd and with the 8139C+ RealTek chip used for the network card's in this box.  Its been a real headache trying to figure out. I'll be pulling mine out of the main network and setting it off to the side soon but have been trying a number of things.

        What I've done so far:
        -Update pfSense to use the 6.3 RELEASE of freebsd didn't help
        -Update the pfSense to use the 6-Current (latest 6.3) drivers for the realtek network controller (re)
        -Disabled ACPI - as I had thought this fixed it a while ago but I was fooled
        -I'm out of ideas.

        1 Reply Last reply Reply Quote 0
        • V
          Valhalla1
          last edited by

          @ridnhard19:

          @Valhalla1:

          ugh.. just had to add a few rules to the firewall and it ended up being a multi-reboot network outage due to watchdog timeout freezeups..   box had been up for a couple weeks, transferring tens of gigs of data per day, but soon as I need to poke around the webgui, the lan interface decides to puke all over itself

          Hey Valhalla1,

          This is what i've been battling with now for a number of weeks. There is an issue with the driver support in Freebsd and with the 8139C+ RealTek chip used for the network card's in this box.  Its been a real headache trying to figure out. I'll be pulling mine out of the main network and setting it off to the side soon but have been trying a number of things.

          What I've done so far:
          -Update pfSense to use the 6.3 RELEASE of freebsd didn't help
          -Update the pfSense to use the 6-Current (latest 6.3) drivers for the realtek network controller (re)
          -Disabled ACPI - as I had thought this fixed it a while ago but I was fooled
          -I'm out of ideas.

          well I appreciate the efforts, I got into pfsense really due to seeing this original post and just had to get me one of these pretty red boxes.  managed to snag one on ebay for $51.. a fantastic value considering I paid twice that a few years ago for a 486 cpu soekris with half the network interfaces.  fwiw it works great as long as I don't need to use the webgui a lot.  also I (usually) dont have to reboot pfsense when it happens if I hit stop on the browser and close the tab and wait a few second
          are the realtek drivers in freebsd 7 any different than the 6.3 RELEASE drivers?

          jmcentire said he stopped getting the watchdog timeouts after switching to hp procurve switches.  mine is connected to just a 24 port d-link unmanaged switch on the lan interface I get the timeouts on.  maybe I'll pick up one on the cheap, wanted to play with vlans anyway

          1 Reply Last reply Reply Quote 0
          • D
            drvcrash
            last edited by

            My timeouts went away when I upgraded my switch to one of the higher end netgear managed ones and a cisco one on my other one. I got 3 of these running now. Its sad One is a v60 that I paid over 10k for in 2002. the others are x1000 and x700 i picked up off ebay for under 200 each.

            i working on doing a full install on one now using cf and a laptop drive for the paritions that write alot . Like /var/log and swap

            1 Reply Last reply Reply Quote 0
            • R
              ridnhard19
              last edited by

              Hum, you guys bring up a good point. I have an SMC managed switch which always had seemed to work well. I just changed the port configurations on the switch which the firebox is plugged into, disabling the autonegotiation for those set of ports and manually set then to full duplex 100.

              I hope this will do the trick.

              1 Reply Last reply Reply Quote 0
              • R
                ridnhard19
                last edited by

                Well I tried manually setting the port speeds to 100 full-duplex in pfsense and on the SMC switch and got the same watchdog timeouts. I'm going to try a net gear switch i've got laying around and see if that does anything.  I'll post back the results of that.

                1 Reply Last reply Reply Quote 0
                • S
                  Sifter
                  last edited by

                  Hello, would it be possible to snap some pictures of the inside of the x700?  Id like to see the layout of the board, clearance, and such.  Thanks.

                  Nevermind, I found a high res picture on another site.

                  1 Reply Last reply Reply Quote 0
                  • S
                    Sifter
                    last edited by

                    @jmcentire:

                    Anyway, if anyone else is interested in these watchguards, the X500, X700, X1000, and X2500 are all the same hardware, they just have different licenses to allow higher throughput.

                    It looks like the mini pci slot could be used for a wifi card, so you could choose if you wanted a vpn card or wifi card in that slot.  Granted, both have to be recognized by pfsense.

                    1 Reply Last reply Reply Quote 0
                    • V
                      Valhalla1
                      last edited by

                      @ridnhard19:

                      Well I tried manually setting the port speeds to 100 full-duplex in pfsense and on the SMC switch and got the same watchdog timeouts. I'm going to try a net gear switch i've got laying around and see if that does anything.  I'll post back the results of that.

                      any updates on that SMC switch on the watchdog timeouts ?   I'm looking to buy a managed switch that works with these watchguards without the timeouts, preferably as cheap as I can get away with.

                      there are reports in this thread that some cisco switches had the errors, but someone else said theirs don't on cisco switches (what models?)
                      also netgear has been reported with the problems, but not a higher end model which got rid of the errors (which higher end model?)
                      my d-link causes them.. hp procurve has been mentioned as error free but not sure which models (any managed procurve switch?)

                      looking for something I can find under $200 on ebay preferably.. what about a dell 2716 'webmanaged' switch those are cheap but support vlan, link aggregation, port mirroring..

                      and back to a different subject, the VPN accelerator card.  anyone tried 1.3 ALPHA ALPHA pfense on their watchguard boxes ?  I would but mine is in production use at the moment.  maybe since its freebsd 7 it might add support for the vpn card in these watchguards?

                      1 Reply Last reply Reply Quote 0
                      • jahonixJ
                        jahonix
                        last edited by

                        The watchguard seems to have a bunch of Realtec NICs onboard.
                        That's where I'd expect the troubles to start…

                        The DeLL 5224 or 5324 switches basically are rebranded SMCs.
                        They can be found on eBay regularly if you don't mind the additional ports.

                        1 Reply Last reply Reply Quote 0
                        • D
                          drvcrash
                          last edited by

                          @Valhalla1:

                          there are reports in this thread that some cisco switches had the errors, but someone else said theirs don't on cisco switches (what models?)
                          also netgear has been reported with the problems, but not a higher end model which got rid of the errors (which higher end model?)
                          my d-link causes them.. hp procurve has been mentioned as error free but not sure which models (any managed procurve switch?)

                          Im using a couple Netgear GSM712's I bought off ebay. Ive tested my watchguard v60 and x700's and no timeout problems. Also I used them thru my cisco 3548xl with no problems. I do have Dell 5324's at work . which is were these firewall are headed in the end but I havent had a chance to test them on the dells.

                          1 Reply Last reply Reply Quote 0
                          • V
                            Valhalla1
                            last edited by

                            thanks for those model #'s gives me some stuff to look for

                            1 Reply Last reply Reply Quote 0
                            • D
                              David_W
                              last edited by

                              It may be that the cheapest way ahead is to get a good brand 8 port web managed (or L2 managed) switch and hook that up to the rest of your network.

                              As a data point, I'm using ZyXEL level 2 switches in my very large home office network; at the moment, I've got two GS-2024 switches, which are linked by fibre. They're not HP, though they're little more than a third of the price of HP - around £350 as opposed to nearly £900 for an L2 managed 24 Gigabit port HP Procurve. There's a few rough edges, but they do work OK. I've had a fan failure which resulted in an RMA, also I had two DoA 1000BASE-SX GBICs (misshapen latch on one, no link on the other), but things have been OK since.

                              The biggest rough edge I know of is that there's no support for port trunking in the STP implementation; with HP you can set STP parameters for the trunk. ZyXEL doesn't support STP for trunks, though I hope it will be added in a future firmware version. That problem aside, the 3.80 firmware for the Dimension range is pretty feature rich, with new features in 3.80 including SNMPv3.

                              There's some new ES-2024 switches on eBay right now for just under $200 - these are 24 port Level 2 managed 10/100 plus 2 port 10/100/1000 copper or SFP devices. I suspect that's more ports than you want or could use, and I expect if you're spending that money you'd rather have fewer ports that are Gigabit. Overall, I'd expect ZyXEL to be a minority brand for switches in the US, much as their DSL routers are more common, but it's another direction that you could look in.

                              I have no idea about the "Watchguard problem" on these switches; my production firewall is a Dell PowerEdge R200.

                              1 Reply Last reply Reply Quote 0
                              • K
                                Krisstian
                                last edited by

                                someone asked for pictures… this is an Firebox x700

                                ![DSC_0030 (Medium).JPG](/public/imported_attachments/1/DSC_0030 (Medium).JPG)
                                ![DSC_0030 (Medium).JPG_thumb](/public/imported_attachments/1/DSC_0030 (Medium).JPG_thumb)
                                ![DSC_0045 (Medium).JPG](/public/imported_attachments/1/DSC_0045 (Medium).JPG)
                                ![DSC_0045 (Medium).JPG_thumb](/public/imported_attachments/1/DSC_0045 (Medium).JPG_thumb)
                                ![DSC_0046 (Medium).JPG](/public/imported_attachments/1/DSC_0046 (Medium).JPG)
                                ![DSC_0046 (Medium).JPG_thumb](/public/imported_attachments/1/DSC_0046 (Medium).JPG_thumb)

                                1 Reply Last reply Reply Quote 0
                                • S
                                  Sifter
                                  last edited by

                                  Has anyone tried to replace the crypto mini-pci card with a wifi mini-pci card?

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    Sifter
                                    last edited by

                                    So are most of you taking the HD tray out completely?  Do you know where to get a HD that fits in the bracket and slides into place using the connector?

                                    1 Reply Last reply Reply Quote 0
                                    • V
                                      Valhalla1
                                      last edited by

                                      @Sifter:

                                      So are most of you taking the HD tray out completely?  Do you know where to get a HD that fits in the bracket and slides into place using the connector?

                                      my hard drive is in the tray, which if I recall is kind of loose inside there but I had to use it, otherwise the hard drive would just be laying on the motherboard directly, and this caused a short of some kind and it wouldn't power up
                                      a regular sized ide hard drive might fit properly in the removeable cage, the laptop ones are obv. too small

                                      1 Reply Last reply Reply Quote 0
                                      • S
                                        Sifter
                                        last edited by

                                        Ive gone ahead and purchased a 4gig hitachi microdrive.  Id like to use this in the x700.  Can I do a full install to the microdrive from my other computer, then slide it into the cf slot in the x700?

                                        1 Reply Last reply Reply Quote 0
                                        • M
                                          moep
                                          last edited by

                                          I replaced our Firebox X500 for pfsense a few months ago and never noticed this thread.
                                          Selling the box isn't worth it so I ripped into it and cleaned it today.

                                          Now I'm wondering if anyone has tried installing a 1024 MB PC-133 stick in it?
                                          I'd like to run a couple of packages on the box (squid in particular, i guess it's too weak for snort ) so the more RAM the better I'd guess.

                                          Also, what's the smartest solution when it comes to the installation?
                                          I think I'll go with the "connect cdrom-drive and do the installation via serial console"-route.
                                          And I'm definitely going to put a harddrive in there, should I get rid of the CF card and do the full installation on the HD or install the base system on a CF and while leaving all busy partitions on the HD?

                                          1 Reply Last reply Reply Quote 0
                                          • V
                                            Valhalla1
                                            last edited by

                                            @moep:

                                            I replaced our Firebox X500 for pfsense a few months ago and never noticed this thread.
                                            Selling the box isn't worth it so I ripped into it and cleaned it today.

                                            Now I'm wondering if anyone has tried installing a 1024 MB PC-133 stick in it?
                                            I'd like to run a couple of packages on the box (squid in particular, i guess it's too weak for snort ) so the more RAM the better I'd guess.

                                            Also, what's the smartest solution when it comes to the installation?
                                            I think I'll go with the "connect cdrom-drive and do the installation via serial console"-route.
                                            And I'm definitely going to put a harddrive in there, should I get rid of the CF card and do the full installation on the HD or install the base system on a CF and while leaving all busy partitions on the HD?

                                            not sure anyones reporting attempting a cdrom install,  it might have problems recognizing or booting from a cdrom unless you can get into the motherboard BIOS config, but good luck.  You can always install the system on another machine and swap the disk out

                                            here's a question, I just got around to installing phpsysinfo on my Firebox x500 and noticed the temperature sensors seem outragous, is this false info or is something inside my box about to spontaneously combust?  This seemingly hasn't caused any problems but doesn't look pretty

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.