Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Windstream gig fiber and pfsense

    General pfSense Questions
    3
    11
    100
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      batrams last edited by

      I have new Windstream gigbit fiber. The optical cable comes into my basement and connects to an Adtran 411 they provided, which has a single ethernet port.

      If I connect my Linux destokp to that ethernet port, I get a public IP via DHCP and all is well. Speed tests show around 900M both ways.

      If I instead connect my pfsense WAN port to that ethernet port, I do (usually) get an IP via DHCP, but i get horrible packet loss - like 50% or more.

      If I connect my pfsense WAN port to my good old spectrum cable modem, all is well. I get abot 500M down and 20M up as expected.

      Tried lower MTU but no change. Quite puzzling. Does anyone have suggestions or experience with this?

      1 Reply Last reply Reply Quote 0
      • B
        batrams last edited by

        I tried swapping the LAN and WAN interfaces in pfsense but it made no difference :(

        1 Reply Last reply Reply Quote 0
        • bmeeks
          bmeeks last edited by bmeeks

          First suspicion is that the auto-negotiation is failing and your pfSense NIC is defaulting to probably half-duplex operation. What brand of NIC is your pfSense box using as compared to that Linux desktop that works?

          Second obvious thing to check, although perhaps you are using the same cable for both the desktop test and pfSense, is that the network cable is good.

          However, my bet is on the auto-negotiation perhaps not working correctly with the NIC in the pfSense box.

          1 Reply Last reply Reply Quote 0
          • B
            batrams last edited by

            Thanks I'll check that when I try again.

            Linux box uses motherboard interface:
            product: RTL8111/8168/8411 PCI Express Gigabit Ethernet Controller

            pfsense:
            'RTL8169 PCI Gigabit Ethernet Controller'

            bmeeks 1 Reply Last reply Reply Quote 0
            • bmeeks
              bmeeks @batrams last edited by

              @batrams said in Windstream gig fiber and pfsense:

              Thanks I'll check that when I try again.

              Linux box uses motherboard interface:
              product: RTL8111/8168/8411 PCI Express Gigabit Ethernet Controller

              pfsense:
              'RTL8169 PCI Gigabit Ethernet Controller'

              Realtek NICs have a bad reputation in FreeBSD (which is the underlying OS that pfSense is based upon). If you have another Ethernet card you could try in the pfSense box, I would suggest giving that a go. Intel is probably the best supported, but even there older technology is best supported in FreeBSD. So the most cutting edge Intel NIC may not be supported well, or even at all.

              1 Reply Last reply Reply Quote 0
              • B
                batrams last edited by

                I think you were right - I overrode autodetect on my pfsense WAN interface and no more packet loss. Thanks!

                bmeeks 1 Reply Last reply Reply Quote 0
                • bmeeks
                  bmeeks @batrams last edited by

                  @batrams said in Windstream gig fiber and pfsense:

                  I think you were right - I overrode autodetect on my pfsense WAN interface and no more packet loss. Thanks!

                  Glad it worked in your case, but generally overriding auto-detect on Gig links is not optimal just so you are aware. If possible, you might want to consider finding an Intel NIC to stick in your firewall. There are several dual-port models available that work.

                  JKnott 1 Reply Last reply Reply Quote 0
                  • B
                    batrams last edited by

                    Yes I will. If you know of any specific models (old school pci slot) please advise. Thanks again.

                    1 Reply Last reply Reply Quote 0
                    • bmeeks
                      bmeeks last edited by

                      The old Intel PRO/1000 dual-port server NIC should work. You would probably have to find one on eBay from a reputable computer recycler/reseller. Watch out for knockoff counterfeits from China, though. If you really must have a PCI interface and can't use PCIe, that's going to narrow the field of choices considerably.

                      1 Reply Last reply Reply Quote 0
                      • JKnott
                        JKnott @bmeeks last edited by

                        @bmeeks said in Windstream gig fiber and pfsense:

                        Glad it worked in your case, but generally overriding auto-detect on Gig links is not optimal just so you are aware. If possible, you might want to consider finding an Intel NIC to stick in your firewall. There are several dual-port models available that work.

                        If you do override it, you must do so at both ends of the cable.

                        1 Reply Last reply Reply Quote 0
                        • B
                          batrams last edited by

                          I have no access to the Adtran ONT but what I did has fixed the packet loss. I will replace the interface however.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post

                          Products

                          • Platform Overview
                          • TNSR
                          • pfSense
                          • Appliances

                          Services

                          • Training
                          • Professional Services

                          Support

                          • Subscription Plans
                          • Contact Support
                          • Product Lifecycle
                          • Documentation

                          News

                          • Media Coverage
                          • Press
                          • Events

                          Resources

                          • Blog
                          • FAQ
                          • Find a Partner
                          • Resource Library
                          • Security Information

                          Company

                          • About Us
                          • Careers
                          • Partners
                          • Contact Us
                          • Legal
                          Our Mission

                          We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

                          Subscribe to our Newsletter

                          Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

                          © 2021 Rubicon Communications, LLC | Privacy Policy