Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    SG-2100: ISP at 150Mbps and WAN at 100Mbps

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    17 Posts 3 Posters 4.1k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jimgm
      last edited by

      This past fall I received fiber from my ISP after being on 10Mbps ADSL. Initially they provided 100Mbps and everything was fine. They supplied a Calix ONT (GP1100G), and speed tests where close to 100Mbps. Sometime this spring they changed to 150Mbps, but I was still seeing 100Mbps on the LAN side of the sg-2100. I connected my laptop directly to the ONT and do in fact get 150Mbps. The sg-2100 seems to only negotiate to 100Mbps. I have tried a few different cables, but it does not seem to help.

      I have reviewed several other posts, but most are trying to get 1Gbps speed from a sg-2100. The speeds I am dealing with should be well within spec. No limiters are active, and I disabled suricata, but do have pfblocker running.

      Should I see a negotiated speed of 150Mbps on the WAN NIC? Or should be at 1000Mbps? I have also tried to set negotiation to 1000baseT which did not work. Only autonegotiation seems to work.

      Any ideas? Thank you for reading.

      keyserK 1 Reply Last reply Reply Quote 0
      • keyserK Online
        keyser Rebel Alliance @jimgm
        last edited by

        @jimgm Your WAN port should link at 1000Mbps in order for you to realize the 150Mbps your ISP provides. Ethernet is either 10, 100, 1000, 2500, 5000 or 10000 Mbps links speed capable (depending on the NICs)

        Love the no fuss of using the official appliances :-)

        J 1 Reply Last reply Reply Quote 0
        • J Offline
          jimgm @keyser
          last edited by

          @keyser OK, that's what I was thinking. So right now I am seeing 100baseTX <full-duplex> on the WAN interface. I found an old 1Gb 5-port switch in my pile I will put between the ONT and the SG-1100 and see what happens.

          keyserK 1 Reply Last reply Reply Quote 0
          • keyserK Online
            keyser Rebel Alliance @jimgm
            last edited by

            @jimgm said in SG-2100: ISP at 150Mbps and WAN at 100Mbps:

            @keyser OK, that's what I was thinking. So right now I am seeing 100baseTX <full-duplex> on the WAN interface. I found an old 1Gb 5-port switch in my pile I will put between the ONT and the SG-1100 and see what happens.

            Yes, that is the first and most correct test to determine if it is a link negotiation issue you are seeing

            Love the no fuss of using the official appliances :-)

            1 Reply Last reply Reply Quote 0
            • J Offline
              jimgm
              last edited by jimgm

              With the old 1Gb switch between, I now get 150Mbps download, but only 44Mbps upload. I can keep working that issue. It looks like the SG-2100 does not like negotiating with the Calix ONT at 1000baseT.

              I do have a PCEngines APU2 with purchased pfsense+ that I can reset and see if that negotiates with the ONT at some point if I can't figure out the asymmetry issue.

              Thanks, I have a plan now.

              stephenw10S 1 Reply Last reply Reply Quote 1
              • stephenw10S Online
                stephenw10 Netgate Administrator @jimgm
                last edited by stephenw10

                @jimgm said in SG-2100: ISP at 150Mbps and WAN at 100Mbps:

                I now get 150Mbps download, but only 44Mbps upload

                Check the Status > Interfaces page. Do you see any errors or collisions on the WAN NIC?

                Yes, the 2100 should easily pass that.

                J 1 Reply Last reply Reply Quote 0
                • J Offline
                  jimgm @stephenw10
                  last edited by

                  @stephenw10 The only errors seen are 88/0 and 0 collisions, which is probably from me connecting and reconnecting the cable. As it turns out, it seems cheap 1Gb switches are "cheap" I have one that works 150/44, the other will not negotiate with the Calix at 1Gb at all and runs at 55/38. At this point, I took the switches out and now have 100/100.

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Online
                    stephenw10 Netgate Administrator
                    last edited by

                    Hmm, curious.

                    You could reassign one of the LAN ports as WAN and see if that links at 1G. You should be able to see the link speed by just plugging it in momentarily. If it looks good then seperate one the ports to use: https://docs.netgate.com/pfsense/en/latest/solutions/netgate-2100/configuring-the-switch-ports.html

                    J 3 Replies Last reply Reply Quote 0
                    • J Offline
                      jimgm @stephenw10
                      last edited by

                      @stephenw10 That's a good idea. I just need to see what speed it negotiates at. I think I have one free port right now.

                      1 Reply Last reply Reply Quote 1
                      • J Offline
                        jimgm @stephenw10
                        last edited by

                        @stephenw10 So I just connected the ONT to the LAN1 interface and it negotiated at 1000baseT<full-duplex,master>. Now I have to remember how to switch this port in the WAN config which is now mvneta0. It has been a while since I set this up, going to take config backup now :).

                        J 1 Reply Last reply Reply Quote 0
                        • J Offline
                          jimgm @jimgm
                          last edited by

                          Well spoke too soon, looks like SG-2100 was not happy with constantly trying to figure out what I doing pulling the cable all of time. lost all IPv4, but still have IPv6. going to have to reset it.

                          J 1 Reply Last reply Reply Quote 0
                          • J Offline
                            jimgm @jimgm
                            last edited by jimgm

                            OK, well everything is back up again. I will look at that document and reconfigure the port and VLANs to see if I can get LAN1 port to function as WAN.
                            Thank you.

                            1 Reply Last reply Reply Quote 1
                            • J Offline
                              jimgm
                              last edited by

                              I have tried a bit this morning to get LAN1 assigned to the WAN interface, and I just cannot seem to get it configured to get an IP address. I followed the document using vlan 4081, configured the PVID to 4081 on LAN1, and pulled 1 (LAN1) from membership for vlan1. At this point, I should have an "isolated" LAN1 on its own vlan that I assign to the WAN interface. It does get link, although the speed says "Ethernet Other <full-duplex>" like the other internal switch ports, but I do not get an IP address from the ISP (they use DHCP).

                              Not sure what is going on now. I have always struggled with these internal marvell switches for some reason.

                              J 1 Reply Last reply Reply Quote 0
                              • J Offline
                                jimgm @jimgm
                                last edited by

                                OK, I think I found the issue. I didn't think I needed to add the port 5 as a member of vlan 4081. In reading more about the internal switch, port 5 is the uplink port, and the OS will not see it unless I add it as a tagged member of vlan 4081 ( yep just like the document tells you :) ).

                                I'll try this later today.

                                1 Reply Last reply Reply Quote 1
                                • J Offline
                                  jimgm @stephenw10
                                  last edited by

                                  @stephenw10 Well it took me a bit, but I have the LAN1 port setup as the WAN device, and now I am getting 150/150 as advertised. Thank you very much for the direction. The port shows speed as "Other <full-duplex>", but it seems it is 1000baseT now.

                                  I kind of wonder what the issue is with the WAN port and the Calix port, but this configuration works, and I only need three physical ports out of the router, so I can continue to use LAN1 interface. Most of my high traffic load is on my local office switch in a single vlan and doesn't need to traverse the router so no issues there.

                                  I guess I am going to have to test the two switches I used and see what going on with them as well.

                                  Thanks everyone!

                                  1 Reply Last reply Reply Quote 2
                                  • stephenw10S Online
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Nice. It might be some negotiation issue. If you have time you could setting a fixed speed on the WAN. At 1G that should never be required. But some devices behave in interesting ways!

                                    J 1 Reply Last reply Reply Quote 0
                                    • J Offline
                                      jimgm @stephenw10
                                      last edited by jimgm

                                      @stephenw10 I did try that a couple times to see what would happen, but it never gets a link.

                                      I did happen to go to the local ISP ( I live in a pretty rural area, and in a small town ), and was talking to them ( in person even ) about pining the Calix to 1000baseT, of course they are reluctant to make a one-off change, but did entertain the idea. I didn't want to push any more on it.

                                      There is a side effect of this configuration, in that suricata running on mvneta1 (default vlan 1) sees all inbound traffic and triggers on all of it even though the firewall blocks all inbound on the WAN. Probably due to port 5 (uplink) being untagged in the default vlan 0 group (tag 1). I'll probably just move everything off the default vlan and disable suricata on the mvneta1 interface.

                                      1 Reply Last reply Reply Quote 1
                                      • First post
                                        Last post
                                      Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                                      Privacy Policy · Cookie Policy