Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Problem enabling OPT port

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    8 Posts 4 Posters 809 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      NGUSER6947
      last edited by

      Having a problem enabling the OPT port on my SG-1000.

      I am setting up an isolated network, for working at home. I want it totally isolated from the LAN network (my stuff) both ways (neither should be able to transfer data from the other).

      So to start, I set up the OPT port, mostly mimicking the LAN port setup:

      e7ff36de-bd35-48ab-8169-f5d0924e8d01-image.png

      f83de224-fb0b-42be-9522-c761e34f81fe-image.png

      But the PC I'm using to test this won't connect. It's a Ubuntu box, and plugging into a switch on my LAN port works just fine. When plugged directly into the OPT port on the SG-1000, it reports "Wired - unable to connect" (or something like that). I have tried 2 different ethernet cables, but still no luck.

      Do I have the OPT port configured right, to start with? Thanks!

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        You need to add Firewall Rules in the OPT tab to allow any traffic.

        -Rico

        1 Reply Last reply Reply Quote 0
        • N
          NGUSER6947
          last edited by

          Here's how I have the rules set for OPT:
          13db1a28-508d-4933-89b3-60f74f73e1f9-image.png

          And on the LAN side:
          da89a4b0-d5f4-405f-bf1c-4cad1edbd9a8-image.png

          1 Reply Last reply Reply Quote 0
          • A
            akuma1x
            last edited by

            You need to change your first block rule on the OPT network.

            Make it read like this:
            Source is OPT net, destination is LAN net

            The way it reads now, it doesn’t block anything.

            Jeff

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by johnpoz

              @NGUSER6947 said in Problem enabling OPT port:

              OPT port on my SG-1000.

              The sg1000 doesn't have an OPT port, do you mean the 1100 I take it?

              Did you enable dhcp on your new interface? This would seem more like the error you describe about not able to connect?

              Validate you get lights on the interface.. Does your pc get an IP on this 192.168.2 network?

              As already mentioned by @akuma1x you need rules.. Lan net would never be a source into opt..

              Rules are evaluated as traffic enters and interface from the network its attached to. Top down, first rule to trigger wins, no other rules are evaluated.

              You have it correct on your lan interface.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • N
                NGUSER6947
                last edited by

                Yes I meant SG-1100.

                So I fixed (I think) the rule for OPT. Then I checked Services/DHCP server. I only see a tab for the LAN interface, not one for the OPT interface. So that is likely the reason a PC on that interface cannot connect. What am I doing wrong such that I don't have the DHCP tab to configure for OPT?

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  If you don't she dhcp available, means the interface not actually enabled. Or you have say a /32 mask vs something like /24... With a /32 (default to this) would have no addresses for dhcp to be enabled with.

                  You cut off in your screenshot what the mask is on that 192.168.2.1 address you set.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  1 Reply Last reply Reply Quote 1
                  • N
                    NGUSER6947
                    last edited by

                    Yes the /32 mask was the problem... changed to /24, enabled DHCP, and good. Thank you all!

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.