Watchguard Firebox M440
-
@stephenw10 said in Watchguard Firebox M440:
Hmm, it's probably a UEFI boot issue. I could believe it only boots UEFI from SATA. Not sure I ever tested that on the m400.
Do you have a spare CF card you can try the 2.3.5 Nano image on?
Steve
I have a Transcend 8GB Compact Flash card. So, I will try that.. What is the version I need to download and install on the CF?
-
This: https://nyifiles.pfsense.org/mirror/downloads/pfSense-CE-2.3.5-RELEASE-2g-amd64-nanobsd.img.gz
Though I just tested it on the m400 and it doesn't boot even from the CF slot. It probably is UEFI only which was in 2.4.
We have only been trying for a few days so far, it took far longer than that for some of the other stuff we now have access to.
However I agree this is not good target really. Certainly there are far easier things to install pfSense on. But if you wan a challenge this looks like it!There is more stuff we can try.
Steve
-
I’m up for the challenge. What’s next?
-
I got version 2.3.5 booting on the CF. Will upload the boot file.
-
Here is the boot file for version 2.3.5. Same results in that it only recognize the 3 interfaces.
-
Here is a better copy of the 2.3.5 log file.
-
Ok so that was the normal pfSense installed to CF? Not Nano by the looks if it.
Ok, so that at least proves it's not some odd driver regression. It seems more like a resource conflict of some sort though I don't see anything specific. I'll try to get that module built for 11.2.
Steve
-
@stephenw10 said in Watchguard Firebox M440:
Ok so that was the normal pfSense installed to CF? Not Nano by the looks if it.
Ok, so that at least proves it's not some odd driver regression. It seems more like a resource conflict of some sort though I don't see anything specific. I'll try to get that module built for 11.2.
Steve
Yes.. The normal pfSense installed to CF.. Please explain what you are building (module 11.2). When will it be available for me to test?
-
Hopefully it will be the igb kernel module that you can load in place of the in kernel driver but with debugging enabled.
It should be easy to build but it's been a while since I tried and I have to test it works at all locally before you try.
Steve
-
@stephenw10 said in Watchguard Firebox M440:
Hopefully it will be the igb kernel module that you can load in place of the in kernel driver but with debugging enabled.
It should be easy to build but it's been a while since I tried and I have to test it works at all locally before you try.
Steve
When will you have it available for testing? Anything else you want me to try?
-
Ok, so this works. But it is very verbose! Like it prints out a page of status info every second at the console.
0_1539553890564_if_igb.ko.txt
That is the replacement kernel module.Copy it to /boot/modules in the m440 and rename it
if_igb.ko
.Then add the following line to /boot/loader.conf.local:
if_igb_load="yes"
Then reboot.
Try to capture the console output covering the boot process. That should show it attempting to connect to the i354 NICs and why it's failing. You might have to disconnect the console once that happens because as I said it will continue to spam the console every second.
Steve
-
@stephenw10 said in Watchguard Firebox M440:
Ok, so this works. But it is very verbose! Like it prints out a page of status info every second at the console.
0_1539553890564_if_igb.ko.txt
That is the replacement kernel module.Copy it to /boot/modules in the m440 and rename it
if_igb.ko
.Then add the following line to /boot/loader.conf.local:
if_igb_load="yes"
Then reboot.
Try to capture the console output covering the boot process. That should show it attempting to connect to the i354 NICs and why it's failing. You might have to disconnect the console once that happens because as I said it will continue to spam the console every second.
Steve
Ok.. Will try it now.. Give me 30 minutes..
-
@stephenw10 said in Watchguard Firebox M440:
Ok, so this works. But it is very verbose! Like it prints out a page of status info every second at the console.
0_1539553890564_if_igb.ko.txt
That is the replacement kernel module.Copy it to /boot/modules in the m440 and rename it
if_igb.ko
.Then add the following line to /boot/loader.conf.local:
if_igb_load="yes"
Then reboot.
Try to capture the console output covering the boot process. That should show it attempting to connect to the i354 NICs and why it's failing. You might have to disconnect the console once that happens because as I said it will continue to spam the console every second.
Steve
I will be using WINSCP to copy the file to the M440 system...
-
Yeah, that's fine.
You don't really need to quote my whole post when you reply to me. There's only you and me here.
Doing so makes the thread waaaay longer.Steve
-
Added the module and updated the config file ... I don’t see anything verbosing on the console..
-
Hmm, you see it failing to load that, maybe an error at the beginning on the boot?
The module is built for pfSense 2.4.4 (FreeBSD 11.2). It won't load in 2.3.5.
Steve
-
I noticed this line in the boot log...
KDB: debugger backends: ddb.../if_igb.ko': input/output errors=[0x8+0x197280+0x8
Attached is the boot log....
-
Here is what I done so far based on your recommendation....
-
Hmm, only two possibilities I can see. I actually tested on a 2.4.5 snapshot but that's still build on FreeBSD 11.2.
Perhaps the file was borked somewhere by uploading/downloading via the forum:
[2.4.5-DEVELOPMENT][root@8860.stevew.lan]/root: sha256 /boot/modules/if_igb.ko SHA256 (/boot/modules/if_igb.ko) = d309d1b253ddf4a4444ab2c4fa16c71b2c880e7439f236a35395444edeb0db28
I don't see that KDB line so I'm guessing the file was broken somehow. Checking sha256 sum should show that.
Steve
-
Will check now...