Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG-3100: have all 32bit related issues been fixed?

    Scheduled Pinned Locked Moved IDS/IPS
    12 Posts 6 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Cabledude
      last edited by Cabledude

      Hey all,

      Used SG-3100's are relatively cheap nowadays. Because of the decent firewall and internet performance it is an interesting model: full pfSense features in a low power package.

      However, there have been topics about issues linked to the 32bit aspect of this design.

      Re: Snort won't start after upgrade to 21.02 on SG-3100

      I intend to use the appliance as a home router for OpenVPN, Suricata, pfBlockerNG, Avahi and maybe some other packages.

      Have all 32bit related issues been fixed now? Can I expect more of them as time passes?

      Thanks,
      Pete

      Pete
      Home: SG-2100 + UniFi + Synology. SG-1100 retired
      Parents: SG-1100 + UniFi + Synology
      Testing: SG-1100 w/ 120GB SSD via ext USB (eMMC dead). Works great

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @Cabledude
        last edited by

        @cabledude The issues with PHP PCRE and others were resolved in 21.05.1:
        https://docs.netgate.com/pfsense/en/latest/releases/21-05-1.html
        No issues at any of our clients.

        As for the future, I don't know that anyone can say. There aren't many other models that are 32 bit. But, Netgate did get these issues fixed on an EOL device so that's a nice result.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 1
        • C
          Cabledude
          last edited by Cabledude

          Thank you Steve. Does this mean an SG-3100 can run any package available today, reliably?
          I am using an SG-1100 and it has been running wonderfully reliably for over a year now. The sole reason I am looking into the 3100 is that it has a little more performance in firewall and internet speed. The other option would be a 4100, but that model is quite expensive (over 800 USD here in Europe) while I can get a 3100 for about 200.

          Pete
          Home: SG-2100 + UniFi + Synology. SG-1100 retired
          Parents: SG-1100 + UniFi + Synology
          Testing: SG-1100 w/ 120GB SSD via ext USB (eMMC dead). Works great

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @Cabledude
            last edited by

            @cabledude said in SG-3100: have all 32bit related issues been fixed?:

            Does this mean an SG-3100 can run any package available today, reliably?

            As far as I know, yes. We don’t run many besides Suricata/Snort, pfBlocker, and the APC packages. I seem to recall reading it can’t do ZFS ? but that’s not really operational. All ours were upgrades anyway.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            C 1 Reply Last reply Reply Quote 1
            • C
              Cabledude @SteveITS
              last edited by

              Thank you. Then maybe a 3100 could work for one or two years. I am still hoping we could be seeing a new ARM design, positioned above the 2100 but priced more moderately than the 4100.

              @steveits said in SG-3100: have all 32bit related issues been fixed?:

              All ours were upgrades anyway.

              Wondering what you mean by this? You are talking about 3100's you deployed, right? Did you upgrade hardware?

              Pete

              Pete
              Home: SG-2100 + UniFi + Synology. SG-1100 retired
              Parents: SG-1100 + UniFi + Synology
              Testing: SG-1100 w/ 120GB SSD via ext USB (eMMC dead). Works great

              S 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @Cabledude
                last edited by

                @cabledude My comment was in reference to ZFS which is now the default for new installs but IIRC not compatible with 32 bit ARM. When upgrading, it doesn’t reformat the disk.

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote 👍 helpful posts!

                R 1 Reply Last reply Reply Quote 0
                • R
                  rcoleman-netgate Netgate @SteveITS
                  last edited by

                  @steveits Correct. 3100 and 1000 aren't able to run ZFS.

                  Ryan
                  Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                  Requesting firmware for your Netgate device? https://go.netgate.com
                  Switching: Mikrotik, Netgear, Extreme
                  Wireless: Aruba, Ubiquiti

                  1 Reply Last reply Reply Quote 0
                  • M
                    mcury Rebel Alliance
                    last edited by

                    SG-3100 is a device that I like very much..
                    Specially the switch..

                    The only thing that is missing in my opinion is softflowd, which is not working.
                    Others complain about the telegraf,..

                    I use pfblockerng, acme, wireguard, nut, lots of vlans..

                    Exporting logs to graylog works great, but I don't like bandwidthd, darkstat and ntopng is too heavy..
                    So, only missing softflowd..

                    dead on arrival, nowhere to be found.

                    luckman212L 1 Reply Last reply Reply Quote 0
                    • luckman212L
                      luckman212 LAYER 8 @mcury
                      last edited by

                      @mcury What collector would you export your netflow to (if you had the option).

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        mcury Rebel Alliance @luckman212
                        last edited by

                        @luckman212 To Graylog, although I didn't test this netflow option in Graylog yet.
                        A few years ago I used nfsen/nfdump, but now softflowd is not working.

                        768bef6e-f5c7-433f-bdc9-c170e460ee0d-image.png

                        dead on arrival, nowhere to be found.

                        M 1 Reply Last reply Reply Quote 0
                        • M
                          michmoor LAYER 8 Rebel Alliance @mcury
                          last edited by

                          @mcury said in SG-3100: have all 32bit related issues been fixed?:

                          sed nfsen/nfdum

                          I have exported to GrayLog at one point. I just have no idea how to make the data useable, i.e. create pretty charts.

                          Firewall: NetGate,Palo Alto-VM,Juniper SRX
                          Routing: Juniper, Arista, Cisco
                          Switching: Juniper, Arista, Cisco
                          Wireless: Unifi, Aruba IAP
                          JNCIP,CCNP Enterprise

                          M 1 Reply Last reply Reply Quote 0
                          • M
                            mcury Rebel Alliance @michmoor
                            last edited by

                            @michmoor I'm exporting logs to it, but not netflow..

                            Using these extractors to parse the data: https://github.com/loganmarchione/Graylog_Extractors_pfSense

                            dead on arrival, nowhere to be found.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.