Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Watchguard XTM 5 Series

    Scheduled Pinned Locked Moved Hardware
    1.1k Posts 130 Posters 1.5m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      It's an odd place to stop. For reference on mine at that point:

      fxp0: Ethernet address: 00:90:7f:87:dc:74
      isab0: <PCI-ISA bridge> at device 31.0 on pci0
      isa0: <ISA bus> on isab0
      atapci0: <Intel ICH7 UDMA100 controller> port 0x1f0-0x1f7,0x3f6,0x170-0x177,0x376,0xffa0-0xffaf at device 31.1 on pci0
      ata0: <ATA channel> at channel 0 on atapci0
      ahci0: <Intel ICH7 AHCI SATA controller> port 0x7c00-0x7c07,0x7880-0x7883,0x7800-0x7807,0x7480-0x7483,0x7400-0x740f mem 0xfe4ffc00-0xfe4fffff irq 19 at device 31.2 on pci0
      ahci0: AHCI v1.10 with 4 3Gbps ports, Port Multiplier supported
      ahcich0: <AHCI channel> at channel 0 on ahci0
      ahcich1: <AHCI channel> at channel 1 on ahci0
      ahcich2: <AHCI channel> at channel 2 on ahci0
      ahcich3: <AHCI channel> at channel 3 on ahci0
      acpi_button0: <Power Button> on acpi0
      uart0: <16550 or compatible> port 0x3f8-0x3ff irq 4 flags 0x10 on acpi0
      uart0: console (115200,n,8,1)
      uart1: <16550 or compatible> port 0x2f8-0x2ff irq 3 on acpi0
      ppc0: <Parallel port> port 0x378-0x37f irq 7 on acpi0
      

      The SATA controller is running in AHCI mode so it shows slightly differently to yours.
      The next thing that shows is the power button (is yours stuck maybe?) but then the console....

      Can you interrupt it at the boot loader menu to reach the loader prompt?

      If it has some console problem you might try forcing VGA console. You will get no output but it should still boot completely allowing you webgui access.

      Steve

      S 2 Replies Last reply Reply Quote 0
      • S
        shawl01 @stephenw10
        last edited by

        @stephenw10 Hi Steve, I tried the nanobsd last night and it stuck it exactly the same place, can you give a little more detail on how to force the VGA method please.

        Thanks
        Luke

        1 Reply Last reply Reply Quote 0
        • S
          shawl01 @stephenw10
          last edited by

          @stephenw10 Should have added both internal and external power buttons can turn the unit on and off ok. Could you clarify what jumpers you have in place please?

          Thanks
          Luke

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Booting to VGA console as primary:
            https://docs.netgate.com/pfsense/en/latest/hardware/boot-troubleshooting.html#booting-with-an-alternate-console

            You should still hear the boot tune if it is able to fully boot using that.

            Steve

            S 1 Reply Last reply Reply Quote 0
            • S
              shawl01 @stephenw10
              last edited by

              @stephenw10 Hi Steve, apologies for the delay in coming back to you. Well I have tried the VGA boot with no joy I have also tried all the other settings such as safe mode, verbose, single user, all with no joy and all stop at the same place. I have also tried booting with no console cable attached, nothing good.

              The seller I bough from ebay has other units for auction so have contacted him about purchasing a second unit to confirm if unit number one is faulty as they have a returns policy so could return it.

              1 Reply Last reply Reply Quote 0
              • chpalmerC
                chpalmer
                last edited by

                Try hooking a sata drive up to it and see if it will load that way.

                Triggering snowflakes one by one..
                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                S 1 Reply Last reply Reply Quote 0
                • S
                  shawl01 @chpalmer
                  last edited by

                  @chpalmer Yep that's what I have done, installed sata drive in a VM and confirmed it boots without any prompts, but in the XTM I get the freeze at the same place with versions 2.4.4, 2.3.5, i386, amd64, nanobsd, memstick, on CF or SATA

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Hmm, but you were able to interrupt the boot loader and enter characters which implies the console is working fine at that point. Hard to say then, I don't recall anything stopping at that point previously. ๐Ÿ˜•

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • L
                      ledufakademy
                      last edited by ledufakademy

                      hello,

                      first very impressed of the activity for this redbox AND pfsense : woahhhh !
                      secondly :
                      i have 3 of thix box running fine for a long time.
                      But with a fourth, i just buy , big problem.
                      motherboard is FW-7580 W REV 1.0

                      1 - i can't install if not flashing to xtm5_83.rom : i need to pass ATA from IDE to AHCI , why ?
                      2 - but with new BIOS (Pfsense 1.8) : just LAN NIC is working all other can't acces WAN (internet)
                      3 - how can i come back to my bios backup ? (if no web access , for downloading flashrom ... obtain flashrom binary, and install how to do that ?!!)

                      i really need your help !

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        So only the fxp port is working?

                        You can still set that as the WAN and use that to pull in flashrom. If you only have one port defined it will be WAN.

                        Were the other ports working before you flashed the BIOS? I have never seen that be an issue. I'm not sure how it would break the NICs. Unless that board is completely different, which seems unlikely.

                        Steve

                        L 1 Reply Last reply Reply Quote 0
                        • L
                          ledufakademy @stephenw10
                          last edited by

                          @stephenw10
                          hello stephnew10 : happy to see you here !!!
                          What a marvellous adventure pfsense on Watchguard . pfffiiiouuuu ;-)

                          Yep with bios WG 1.3 , just laste nic em5 was probably out of order.
                          But with xtm5_83.rom ... lol !
                          just one.

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Hmm, well hard to explain how that could be. It would be good to know which one still works. I'm guessing it's the 100M port (fxp0) since that's completely different.
                            Whichever it is you should be able to use it as WAN to connect out and install flashrom.

                            Steve

                            L 1 Reply Last reply Reply Quote 0
                            • L
                              ledufakademy @stephenw10
                              last edited by

                              @stephenw10
                              hello, sorry for delay.

                              root@OPNsense:~ # pkg install flashrom
                              Updating OPNsense repository catalogue...
                              Certificate verification failed for /C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
                              2813191321208:error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/s3_clnt.c:1269:
                              Certificate verification failed for /C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
                              2813191321208:error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/s3_clnt.c:1269:
                              Certificate verification failed for /C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
                              2813191321208:error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/s3_clnt.c:1269:
                              pkg: https://pkg.opnsense.org/FreeBSD:11:amd64/20.1/latest/meta.txz: Authentication error
                              repository OPNsense has no meta file, using default settings
                              Certificate verification failed for /C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
                              2813191321208:error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/s3_clnt.c:1269:
                              Certificate verification failed for /C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
                              2813191321208:error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/s3_clnt.c:1269:
                              Certificate verification failed for /C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
                              2813191321208:error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/s3_clnt.c:1269:
                              pkg: https://pkg.opnsense.org/FreeBSD:11:amd64/20.1/latest/packagesite.txz: Authentication error
                              Unable to update repository OPNsense
                              Error updating repositories!
                              
                              chpalmerC 1 Reply Last reply Reply Quote 0
                              • chpalmerC
                                chpalmer @ledufakademy
                                last edited by

                                @ledufakademy said in Watchguard XTM 5 Series:

                                Unable to update repository OPNsense

                                Your not running pfsense. Without knowing the particulars of that product nobody here would be able to guess correctly.

                                Triggering snowflakes one by one..
                                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  @ledufakademy said in Watchguard XTM 5 Series:

                                  root@OPNsense

                                  Umm... yup, can't help you with that. ๐Ÿ˜‰

                                  L 1 Reply Last reply Reply Quote 0
                                  • L
                                    ledufakademy @stephenw10
                                    last edited by ledufakademy

                                    @stephenw10
                                    ok i will flash the card F with last pfsense ๐Ÿ‘Œ

                                    with pfsense : boot stuck at :

                                    em5: <Intel(R) PRO/1000 Network Connection 7.6.1-k> port 0xac00-0xac1f mem 0xfe7e0000-0xfe7fffff,0xfe7dc000-0xfe7dffff irq 17 at device 0.0 on pci2 : solved.

                                    same issue :

                                    [2.4.3-RELEASE][root@pfSense.localdomain]/root: pkg update
                                    Updating pfSense-core repository catalogue...
                                    pkg: Repository pfSense-core load error: access repo file(/var/db/pkg/repo-pfSense-core.sqlite) failed: No such file or directory
                                    Certificate verification failed for /C=GB/ST=Greater Manchester/L=Salford/O=Sectigo Limited/CN=Sectigo RSA Domain Validation Secure Server CA
                                    34405266376:error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed:/builder/ce-243/tmp/FreeBSD-src/crypto/openssl/ssl/s3_clnt.c:1269:
                                    pkg: https://pkg.pfsense.org/pfSense_v2_4_3_amd64-pfSense_v2_4_3/packagesite.txz: Authentication error
                                    Unable to update repository pfSense
                                    Error updating repositories!
                                    
                                    1 Reply Last reply Reply Quote 0
                                    • D
                                      Dufflepod
                                      last edited by

                                      This is really a 'thank-you' to those forum contributors who did all the heavy lifting
                                      investigating this box and getting pfSense running with all the hardware whistles & bells configured.

                                      After lurking for a few weeks and on this thread and others concerning the XTM 5 series, I took the
                                      plunge and bought one from eBay for ยฃ45 for my home setup.

                                      I installed the latest pfSense 2.4.5 on a ZFS mirror with two cheapo 120 Gb SSDs, flashed the
                                      BIOS with xtm5_83.rom without any drama, and had no problems accessing the BIOS screens with a
                                      serial cable. The 4G RAM upgrade and E5700 CPU upgrade also went without a hitch.

                                      I built a 64 bit WGXepc binary from source in a FreeBSD 11.3 VM (the base for pfSense 2.4.5)
                                      and the Arm/Disarm light now does whatever I tell it to via ShellCmd.

                                      Flush with success I splashed out ยฃ12 on an Intel Q8200S on eBay and that arrived last week
                                      and I finally hit my first hurdle - the board doesn't boot with this chip, but will if I
                                      reinsert the E5700. So I just wanted to check that others have got this processor working with
                                      the xtm5_83.rom image? It's no real hardship if I can't get it working, it may just be a dudd
                                      Chinese-scavenged chip, but it would be the icing on the cake if I could get it going.

                                      Also - following the mantra of 'hope for success, plan for failure', I couldn't find the pinout of the SPI
                                      header anywhere in the forums, even though it was mentioned a few times. As I'm putting together a duplicate box
                                      for my brother this might come in handy, (though hopefully not). I've searched and googled but found nothing.
                                      Can anyone help with this info?

                                      Once again - thanks to everyone.

                                      1 Reply Last reply Reply Quote 0
                                      • stephenw10S
                                        stephenw10 Netgate Administrator
                                        last edited by

                                        It should work with the Q8200S. The board seems very accommodating in general. https://forum.netgate.com/post/427056 and https://forum.netgate.com/post/544654

                                        After camping ebay (for literally years ๐Ÿ˜‰ ) I have a Xeon L3110 in mine and that runs great.

                                        The SPI pinout is standard as far as I know. From the FW-7581 manual though:

                                        SPI-Pinout.png

                                        Steve

                                        D 1 Reply Last reply Reply Quote 0
                                        • D
                                          Dufflepod @stephenw10
                                          last edited by

                                          @stephenw10 Outstanding! Thanks for the info.

                                          1 Reply Last reply Reply Quote 0
                                          • A
                                            anoxy
                                            last edited by

                                            Hi,

                                            Sorry to disturbe the subject.

                                            I have bought a WatchGuard XTM 505 and I will change the processor and the RAM.

                                            About the processor, I have found a Pentium Dual Core E5300, does it fit with the XTM 505 ? Will it works?

                                            For the RAM, I read that we can add up to 8Go but I think 4Go is adequate ?

                                            I want to use all links at Gigabit speed, I have fiber that provide me 990mb/s download and 600mb/s in upload.

                                            I will add an SSD with PFSense.

                                            Do you think my config is good?

                                            Thanks!

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.