Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NETASQ U70 pfsense 2.3.2 install, network interface problem

    Scheduled Pinned Locked Moved Hardware
    24 Posts 5 Posters 7.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • dotdashD
      dotdash
      last edited by

      Short answer is that it won't work.
      If it has the Broadcom switch and not the Vitesse, someone did some work on a switch framework some years ago, but nothing seems to have ever come of it. There is still some old code available, not sure if it's functional.
      Get another device to run pfSense on.
      If you are interested for purely academic reasons, here are some links-
      https://wiki.freebsd.org/AleksandrRybalko/Switch%20Framework
      http://mailing.freebsd.arch.narkive.com/JrQXZEPu/ethernet-switch-framework

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        It could still be potentially configured as port based VLANs by default. Easy enough to test that with a packet capture.

        I agree though that hardware is really an interesting project only at this point.

        Steve

        1 Reply Last reply Reply Quote 0
        • ?
          Guest
          last edited by

          It seems like a crappy overpriced device to me. Still goes for 1k+ on eBay. Sell it and get proper hardware instead?

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Really? Wow.
            Then sell it on ebay and visit our shop.  ;)

            Steve

            1 Reply Last reply Reply Quote 0
            • K
              krystian
              last edited by

              @stephenw10:

              That's something of a big ask!  ;)

              It's possible the switch is already configured with VLANs though by default. Try running a packet capture on the em0 interface whilst having some things connected to the front ports.

              If you see the VLAN tagged packets arriving on em0 you can create VLAN interfaces to match that and use them directly.

              It may also be configured with a custom ASIC for forwarding the traffic much faster, a separate control plane and data plane. If that is the case there's probably no way of accessing those ports directly.

              What CPU does it have? Internal photos?

              Steve

              Thank You for answer.
              How Can I running a packet capture on em0 interface?

              Maybe then will be found 6 network ports?

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Indeed it won't find ports directly.
                If you're lucky the eprom that configures the switch may have it setup for VLANs by default in which case you can assign VLAN interfaces in pfSense and use the ports however they are configured.
                If not then you'd have to program the switch from within pfSense and that's…... challenging!

                Plug some stuff in to the switch ports and set some pings running. They will fail but you should generate some ARP traffic that may make it to em0.

                At the CLI on the console run:

                tcpdump -nei em0
                

                Cross your fingers and hope you see something like:

                18:18:37.748681 00:08:a2:09:39:a9 > ff:ff:ff:ff:ff:ff, ethertype 802.1Q (0x8100), length 46: vlan 22, p 0, ethertype ARP, Request who-has 10.20.2.10 tell 10.20.2.1, length 28
                
                

                Then you know the VLAN number or numbers configured.

                Steve

                1 Reply Last reply Reply Quote 0
                • K
                  krystian
                  last edited by

                  Steve thank You for answer.
                  I check this command and I see it:

                  What can I do it now?

                  1 Reply Last reply Reply Quote 0
                  • ?
                    Guest
                    last edited by

                    There are at least 2 vlans, so it's possible to get something working. Since they use very low ID's you may be able to get away with just adding VLAN's 1 to 6 or something like that. You won't be able to see interface status but you can at least try it this way.

                    It is possible that it has relays for bypass functionality, or maybe the switch is configured as a default pass-all switch. In that case, one port is VLAN1 and all the others are VLAN2.

                    1 Reply Last reply Reply Quote 0
                    • K
                      krystian
                      last edited by

                      Ok but i set IP 192.168.1.1/24 on em0_vlan1 or em0_vlan2 and not working.
                      I put cable to 1-6 ports and nothing. Ping not found…

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Ok, some progress.  :)

                        However that MAC address, 00:0d:b4:04:58:1b, appears to be a Netasq MAC. Is that the interface sending DHCP requests out?
                        Run ifconfig em0 at the CLI and check the MAC of that.

                        It's interesting that IPv4 traffic appears to be on VLAN1 and IPv6 on VLAN2. The fact you're seeing any VLAN traffic at all though means the switch may be configured in some useful way.

                        What did you have plugged into the switch ports at that time? Did you try all the switch ports?

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • ?
                          Guest
                          last edited by

                          Hello there,

                          I am answering on a private message, much late but I was really busy in the last month.

                          If the LAN Port is an EM that is supported and the PHY behind it is perhaps let us imagine
                          a (Pericom PI7C9X2G608GP Gen 2 Switch) that isn´t supported you will only see one LAN
                          Port such the EM Port. If the PHY (Switch) behind is full supported by pfSense you will see
                          all LAN Ports available to use. Thats it in my eyes.

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Never heard back. Did you give up krystian?
                            Understandable since there is other much more suitable hardware available. However you are seeing two VLANs there so the switch is configured somehow. Unless you configured those VLANs in pfSense and both are set to DHCP. Which would explain why it looks like the Netasq MAC sending.

                            Steve

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              Potentially slightly easier to get working with today blog post announcement.

                              Still coding to be done though as that switch does not appear to be one supported by etherswitch.
                              https://github.com/freebsd/freebsd/tree/master/sys/dev/etherswitch

                              Steve

                              1 Reply Last reply Reply Quote 0
                              • L
                                lubousa
                                last edited by

                                Suddenly view this tread. I have many of this netsq u70. There is switch witch is connect to serial port 2. use " cu -s 9600 -l ttyu1" command to configure switch. You can assign ip on the switch and configure everything thru web. You can create vlan for WAN port and use other port for lan. EM0 its connected to port 1.

                                1 Reply Last reply Reply Quote 1
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.