Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Plug SG-1100 being updated into LAN switch for Internet access?

    Scheduled Pinned Locked Moved General pfSense Questions
    19 Posts 3 Posters 685 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      NGUSER6947
      last edited by

      I have a 2nd SG-1100 that I need to reinstall the software on. Since the installer needs to be able to access the Netgate servers to obtain the image, can I connect this unit's WAN port to an open port on one of my switches?

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Yes.

        But... if you are restoring a config you may end up with a subnet conflict. The subnet you connect the WAN to may be the same as that set on the LAN.
        In that case you would need to change the LAN subnet while any updates run.

        N 1 Reply Last reply Reply Quote 0
        • N
          NGUSER6947 @stephenw10
          last edited by NGUSER6947

          @stephenw10 So on my original SG-1100, it failed during reinstallation. Error indicated is "pfSense partitioning. Installation aborted."

          This is during the file system creation.

          I assume this means the eMMC storage is worn out or damaged. Is this something that can be replaced by the factory or is it not worth doing (i.e. just get a replacement)?

          Also, in the interest of reducing write loads on my currently-running 1100, should I disable logging on the auto-created pfBlockerNG rules (or does disabling logging interfere with that package's operation)?

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @NGUSER6947
            last edited by Gertjan

            @NGUSER6947

            Here.

            edit :

            @NGUSER6947 said in Plug SG-1100 being updated into LAN switch for Internet access?:

            pfBlockerNG

            Even with minimal logging, if the resolver gets smacked with DNS requests, then pfBlockerNG will keep up the pace, and keep these log files /var/log/pfblockerng/ up to date = a lot of writes.
            After all, they are needed so it can create :
            879513da-37da-47ca-9aa1-b46ac823df55-image.png

            To really reduce the number of write cycles :

            1. No pfSense packages that need a lot of write cycles. For example, pfblockerng by itself does nothing. But wait .. add a lot of DNSBL and throw a lot of DNS requests at it, and it will make 'big' logs.
            2. Go RAM disk mode.

            Or : get a descent 'SSD' drive (if possible).

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            N 2 Replies Last reply Reply Quote 0
            • N
              NGUSER6947 @Gertjan
              last edited by

              @Gertjan Yeah I just spent an hour reading through some of these threads.

              Also I disabled IPv4 logging hoping that will help the other 1100 I'm running now live longer.

              I think I'm going to do the USB drive mod for the failed 1100 to get it going again.

              1 Reply Last reply Reply Quote 0
              • N
                NGUSER6947 @Gertjan
                last edited by

                @Gertjan Yeah, I only have the default DNSBL(s) enabled (the ones the package installer for pfBlockerNG installs).

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Yup using a USB drive to boot from is really the only option on the 1100 if the eMMC has failed.

                  N 1 Reply Last reply Reply Quote 1
                  • N
                    NGUSER6947 @stephenw10
                    last edited by NGUSER6947

                    @stephenw10
                    Samsung USB drive already ordered for the original 1100.

                    Back to my spare (now-active) 1100, I've disabled IPv4 logging but I still need to disable logging on the rules that pfBlocker created.

                    Disabling any of that logging won't prevent it from functioning, is that correct? I like seeing the reports showing what was blocked along with what LAN IPs are being targeted but I can live without that visibility if it reduces load on the eMMC.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      How much RAM do you have spare? By far the most significant thing you can do there to reduce write is enable RAM disks. But running pfBlocker in 1GB usually doesn't leave much. You might be able to do it if you have only a small set of lists.

                      N 1 Reply Last reply Reply Quote 0
                      • N
                        NGUSER6947 @stephenw10
                        last edited by NGUSER6947

                        @stephenw10 I only have 2 feeds enabled (Abuse Feodo Tracker and ADs_Basic).

                        Memory-wise, I'm seeing it run at around 30% used (of 957MB).

                        Looking at the RAM disk setup page, it appears it's not using much storage currently (if I'm reading it correctly, looking at 'Current usage' numbers) so the minimums should be fine?
                        b8743378-76de-4f6b-b526-cd4ab0a47d6f-image.png

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          You will probably need more than 60MB for /var. I usually set it to 120MB to start. If you try that I would monitor it for a few days to be sure it's not filing that when pfBlocker updates.

                          N 1 Reply Last reply Reply Quote 0
                          • N
                            NGUSER6947 @stephenw10
                            last edited by

                            @stephenw10 What would be the indications that it was filling up during an update? I.e. how do I monitor it?

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              You can see it on the disks widget on the dashboard:

                              Screenshot from 2025-05-27 15-03-42.png

                              N 1 Reply Last reply Reply Quote 0
                              • N
                                NGUSER6947 @stephenw10
                                last edited by NGUSER6947

                                @stephenw10 Ok, well I enabled the RAM disks.
                                5a4ee3ff-843e-4426-9421-f2ba279ec814-image.png

                                Interestingly, the Dashboard shows that only 60MB are being used for /var:
                                e29b963a-63e2-4c23-bccc-a136ad39d720-image.png

                                Update: I watched it during a pfBlocker update which just ran at Noon. It had been sitting at 17%, jumped up to a high of 73%, and seems to be staying there.

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  That's running 24.11?

                                  There was an issue setting the RAM disk size at one point. But if it's only using 73% at update that's good.

                                  N 1 Reply Last reply Reply Quote 0
                                  • N
                                    NGUSER6947 @stephenw10
                                    last edited by NGUSER6947

                                    @stephenw10 Yes, 24.11. I'll keep an eye on it but it seems to be stable at 73% (after going through 3 hourly updates).

                                    FWIW, I tried modifying the RAM disk size again for /var and restarting the device but with it set for 120MB it only creates a 60MB disk. Is there some flaw in the GUI interface or something else that limits it?

                                    Would it be beneficial to cut back on some of the log settings for pfBlocker?
                                    696a0a3a-42a8-4be5-b114-fac3bd175a74-image.png

                                    Like cut some of them down to 10,000 entries instead of 20,000?

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      Yes you can certainly reduce those if the logs start getting too large.

                                      That RAM disk issue is fixed in 25.03.

                                      N 1 Reply Last reply Reply Quote 0
                                      • N
                                        NGUSER6947 @stephenw10
                                        last edited by

                                        @stephenw10 So, after a few days /var is holding steady at 77% used. Would you recommend I hold tight until 25.03 is formally released (stable) so I can bump the RAM disk up to 120MB or should I update to the beta now?

                                        1 Reply Last reply Reply Quote 0
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by

                                          The beta is pretty stable. I'm running it as my edge here without issue. If you are running ZFS so you can roll back then I would try it.

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.