Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG-1100 Traffic loss when WAN enabled

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    10 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sidiov
      last edited by

      I bought a SG-1100 to replace a dead ER-x and while all the links/addresses are working, I get disappearing packets as soon as I plug in the WAN link. The network configuration should be the same as the old device, so I either missed something obvious or there is some difference I am not taking into account.

      alt text

      The 10.99.98.1 is the sg1100 default gateway, there is nothing else in that vlan - I have an ER-X on the other side using the 10.99.99.1 gateway on another transit vlan without issue.

      The 192.168.2.x is the management vlan, the er-x (2.1) is the default gateway out to the internal network for that. There is a static route on the sg-1100 for 192.168.0.0/16 -> 2.1

      As soon as i plug in the wan link the management connections (web/ssh) become sporadic, and the wan initiated links also become sporadic (curl from the sg-1100, etc..) I dont comprehend why it would do this, I wasnt sure if I was missing a routing loop somewhere, but its a really simple topology and I plugged a spare er-x into the same spot with the same addresses and no issue.

      I dont see anything unusual in packet captures, both sides just show no packets for a few seconds every so often, I dont have a way to capture from the switch at the moment.

      Anyone have an idea what I am doing wrong?

      1 Reply Last reply Reply Quote 0
      • S
        sidiov
        last edited by

        guess i cant post images, i made a bad one at:
        https://ibb.co/P4by566

        1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan
          last edited by Gertjan

          It guess it's me, but after reading I would ask for an image.
          I just saw the image ... I'm lost.
          What happened to "the keep it simple and straight forward" method ?

          I can assure you, that when I plugin a WAN cable into an upstream router, my pfSense works.
          (after testing this == WAN plug ok, etc) you should start VLANning ... set by step.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          S 1 Reply Last reply Reply Quote 0
          • S
            sidiov @Gertjan
            last edited by sidiov

            It appears I just expected to much from it. I cant do any sort of commands or GUI clicking around without it dropping traffic. It looks like if I stay out of it I can get 500mb or so testing with iperf, but as soon as I click around, the throughput drops to < 100mb and packets are lost.
            Guess I'll just eat the return cost for it.

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @sidiov
              last edited by

              @sidiov said in SG-1100 Traffic loss when WAN enabled:

              Guess I'll just eat the return cost for it.

              Because of a severe routing and/or VLAN problem ?
              A 10K$ box wouldn't do any better.

              ASG-1100 can handle a "close to a GB" - hard to beat for the price.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              S 1 Reply Last reply Reply Quote 0
              • S
                sidiov @Gertjan
                last edited by sidiov

                @gertjan It's not a vlan/routing issue. It happens when directly connected to the outside router as you suggested. I also have 2 other routers (er-x) that arent having the issue in the same ports, and 1,600 routers in individual locations without issues. My original thought was to use the sg-1100 to start replacing the old ubiquitis but they dont seem to handle the same amount of traffic.
                --Well , they do sort of handle it.. but only as long as I dont log in and try to do anything at the same time. Thats a little excessive for me even if we dont have to log into them but rarely.

                1 Reply Last reply Reply Quote 0
                • GertjanG
                  Gertjan
                  last edited by

                  Ah, ok.

                  If login into the GUI somewhat bring the device on it's knees, then that's not good at all.

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    sidiov @Gertjan
                    last edited by sidiov

                    @gertjan Just FYI, lied.. its not a performance issue. It's the fact that the SG-1100 uses a switch for all 3 interfaces, and you cant assign a different MAC to each interface or VLAN.
                    I thought it was because i was logging into the GUI, but that was just a symptom of the arp table updating, so no matter what device you plug it into its trouble. From searching, I guess this is a FreeBSD limitation so pfsense+switch boxes is out for me.
                    Sorry for the confusion.

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      Limitation of mac address wouldn't be an issue unless your plugging your wan and opt/lan interface into the same L2?

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      S 1 Reply Last reply Reply Quote 0
                      • S
                        sidiov @johnpoz
                        last edited by

                        Not exactly, the 'switch'ing device in the middle in our case is SVL and they (and all vlans) are controlled by another entity. I'd have to get some FID entries in there, but it'll just be easier to stick with devices with separate NICs (or the ability to mac spoof).

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.