Successful Install on Watchguard Firebox X700!
-
Steve !
I have an idea. Maybe must I do installing pfSense on the CF card and running X700 with CF card and HDD. Only I don't know, can I move system pfSense from CF card –>on HDD? It's possible ?
Maybe I should change completely method and start from scratch? New install ? I should seek new (different) HDD ?I don't know why it just happened to me... It don't can be very hard. ;)
Log from my console:
miibus5: <mii bus=""> on re5 rlphy5: <realtek internal="" media="" interface=""> PHY 0 on miibus5 rlphy5: 10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, auto re5: [FILTER] isab0: <pci-isa bridge=""> at device 31.0 on pci0 isa0: <isa bus=""> on isab0 atapci0: <intel ich2="" udma100="" controller=""> port 0x1f0-0x1f7,0x3f6,0x170-0x177,0x376,0xff00-0xff0f at device 31.1 on pci0 ata0: <ata 0="" channel=""> on atapci0 ata0: [ITHREAD] ata1: <ata 1="" channel=""> on atapci0 ata1: [ITHREAD] cpu0 on motherboard pmtimer0 on isa0 unknown: <pnp0c01> can't assign resources (memory) atrtc0: <at realtime="" clock=""> at port 0x70-0x71 irq 8 pnpid PNP0b00 on isa0 atkbdc0: <keyboard controller="" (i8042)=""> at port 0x60,0x64 irq 1 pnpid PNP0303 on isa0 atkbd0: <at keyboard=""> irq 1 on atkbdc0 kbd0 at atkbd0 atkbd0: [GIANT-LOCKED] atkbd0: [ITHREAD] uart0: <16550 or compatible> at port 0x3f8-0x3ff irq 4 flags 0x10 pnpid PNP0501 on isa0 uart0: [FILTER] uart0: console (9600,n,8,1) ppc0: <ecp parallel="" printer="" port=""> at port 0x378-0x37f,0x778-0x77a irq 7 drq 3 pnpid PNP0401 on isa0 ppc0: Generic chipset (ECP/PS2/NIBBLE) in COMPATIBLE mode ppc0: FIFO with 16/16/16 bytes threshold ppc0: [ITHREAD] ppbus0: <parallel port="" bus=""> on ppc0 plip0: <plip network="" interface=""> on ppbus0 plip0: [ITHREAD] lpt0: <printer> on ppbus0 lpt0: [ITHREAD] lpt0: Interrupt-driven port ppi0: <parallel i="" o=""> on ppbus0 orm0: <isa option="" rom=""> at iomem 0xe0000-0xe0fff pnpid ORM0000 on isa0 unknown: <pnp0c01> can't assign resources (memory) RTC BIOS diagnostic error 20 <config_unit>Timecounter "TSC" frequency 1202731218 Hz quality 800 Timecounters tick every 1.000 msec IPsec: Initialized Security Association Processing. ata1: DMA limited to UDMA33, controller found non-ATA66 cable ad2: 38154MB <hts541040g9at00 mb2ia60a=""> at ata1-master UDMA33 GEOM: ad2: partition 1 does not start on a track boundary. GEOM: ad2: partition 1 does not end on a track boundary. GEOM: ad2s1: geometry does not match label (255h,63s != 16h,255s). Trying to mount root from ufs:/dev/da0s1a ROOT MOUNT ERROR: If you have invalid mount options, reboot, and first try the following from the loader prompt: set vfs.root.mountfrom.options=rw and then remove invalid mount options from /etc/fstab. Loader variables: vfs.root.mountfrom=ufs:/dev/da0s1a vfs.root.mountfrom.options=rw Manual root filesystem specification: <fstype>:<device> Mount <device> using filesystem <fstype> eg. ufs:/dev/da0s1a eg. cd9660:/dev/acd0 This is equivalent to: mount -t cd9660 /dev/acd0 / ? List valid disk boot devices <empty line=""> Abort manual input mountroot> ufs:ad2s1a Trying to mount root from ufs:ad2s1a WARNING: / was not properly dismounted Configuring crash dumps... No suitable dump device was found. Mounting filesystems... WARNING: R/W mount of / denied. Filesystem is not clean - run fsck mount: /dev/ad2s1a : Operation not permitted ** /dev/ad2s1a ** Last Mounted on / ** Root file system ** Phase 1 - Check Blocks and Sizes ** Phase 2 - Check Pathnames ** Phase 3 - Check Connectivity ** Phase 4 - Check Reference Counts ** Phase 5 - Check Cyl groups 1074 files, 36866 used, 10117329 free (161 frags, 1264646 blocks, 0.0% fragmentation) ***** FILE SYSTEM MARKED CLEAN ***** Can't stat /dev/da0s1b: No such file or directory Can't stat /dev/da0s1b: No such file or directory mount: /dev/da0s1b : No such file or directory readlink: not found grep: not found /etc/rc: /usr/sbin/pwd_mkdb: not found /etc/rc: /usr/bin/cut: not found /etc/rc: /usr/bin/grep: not found /etc/rc: /usr/bin/grep: not found /etc/rc: /usr/bin/wc: not found /etc/rc: /usr/bin/grep: not found /etc/rc: /usr/bin/cut: not found [: : bad number ___ ___/ f \ / p \___/ Sense \___/ \ \___/ Welcome to 2.0.1-RELEASE on the 'pfSense' platform ... /etc/rc: /usr/bin/grep: not found /etc/rc: /usr/bin/cut: not found Dump device does not exist. Savecore not run. Creating symlinks...ln: /tmp/tmp: No such file or directory mkdir: /tmp: No such file or directory chmod: /tmp/uploadbar: No such file or directory .grep: not found wc: not found awk: not found [: : bad number grep: not found wc: not found awk: not found [: : bad number /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found /etc/rc: /usr/sbin/clog: not found chmod: /var/log/*.log: No such file or directory ./etc/rc: /usr/bin/grep: not found /etc/rc: /usr/bin/wc: not found /etc/rc: /usr/bin/cut: not found .ldconfig: warning: /usr/lib: No such file or directory ldconfig: warning: /usr/local/lib: No such file or directory done. /etc/rc: /usr/bin/awk: not found [: -lt: unexpected operator /etc/rc: /usr/bin/cap_mkdb: not found /etc/rc: cannot create /tmp/php_errors.txt: No such file or directory /etc/rc: /usr/local/bin/php: not found /etc/rc: /usr/bin/nice: not found Launching the init system.../etc/rc: /usr/bin/touch: not found /etc/rc: /etc/rc.bootup: not found Starting CRON... cd: can't cd to /tmp done. /etc/rc: /etc/rc.start_packages: not found /etc/rc: /usr/local/bin/minicron: not found /etc/rc: /usr/local/bin/minicron: not found /etc/rc: /usr/local/bin/minicron: not found chmod: /tmp/.: No such file or directory Bootup complete rm: /booting: No such file or directory /etc/rc: /usr/local/bin/beep.sh: not found rm: /tmp/config.cache: No such file or directory Oct 29 11:41:25 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file orOct 29 11:41:25 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:41:56 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file orOct 29 11:41:56 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:42:26 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file orOct 29 11:42:26 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:42:56 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file or directory orOct 29 11:42:56 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:43:26 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file or directory Oct 29 11:43:26 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:43:56 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file or directory Oct 29 11:43:56 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:44:26 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file or directory Oct 29 11:44:26 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:44:56 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file or directory Oct 29 11:44:56 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:45:26 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file or directory Oct 29 11:45:26 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:45:56 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file or directory Oct 29 11:45:57 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:46:27 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file or directory Oct 29 11:46:27 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:46:57 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file or directory Oct 29 11:46:57 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:47:27 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file or directory Oct 29 11:47:27 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory Oct 29 11:47:57 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyu0: No such file or directory Oct 29 11:47:57 init: can't exec getty '/usr/libexec/getty' for port /dev/ttyv0: No such file or directory [/code] Pawel</empty></fstype></device></device></fstype></hts541040g9at00></config_unit></pnp0c01></isa></parallel></printer></plip></parallel></ecp></at></keyboard></at></pnp0c01></ata></ata></intel></isa></pci-isa></realtek></mii>
-
I'm happy !!! :-)
Victory !!! I have running system pfSense on the WatchGuard X700.My problem remove when I connected my HDD on ATA slot in My PC by means of adapter ATA (2,5") <–> ATA (3,5). Next step - as in first post.
Steve - THANK YOU from Your helping. I'm very happy, because I can make first configuration. Question: Can I find on forum any configuration instruction ?
P.S. My english language is bad. Sorry. ;-)
-
Ah so it was connected via usb when you installed before?
There are instructions in the wiki: http://doc.pfsense.org/index.php/Main_Page
What configuration do you want?Steve
-
Hi Steve !
Yes, first so it was connected via usb. And this was problem…
I want no special configuration: 1 WAN (4/2 Mbps with 5 used public IP) and 2 LAN.
LAN 1: Network in my home and office - because i have office in home. ;-)
LAN 2: Network for my friends and neighbors. Unfortunately I live in block...
LAN 3: DMZ for my 2-3 servers: 1 - my machine (HTTP, mail, ftp, mail, etc.) 2 - machine for my frends/neighbors (mail, ftp, etc.), 3 - DNS (chroot) and ftp for my best friend, hi is computer science specialist. This machine is for him backups.Networks LAN1 and LAN2 are NOT CONNECTED, but are have access to Internet.
LAN 3 - known...Pawel
-
Maybe better to discuss this in a new thread since this is now a general configuration problem not specific to the firebox. This thread is already too long! ;)
It doesn't look like a difficult config though.
Steve
-
Of course. I have a request to the Moderator: Do You move my last 2 entries to a new topic: "Configure 1xWAN, 2xLAN and 1xDMZ of 5 IP addresses" ?
Thank You. :)Steve - if you want help me understand pfSense rules - welcome to the new topic or my e-mail. Thank You for You fast helping. ;D
Pawel
-
Happy New 2013 Year!
Thank you for your help and kindness. At the beginning of 2013 I wish You all the best and fulfill their dreams. All the best!
Pablo
-
After upgrading from 2.0.1-RELEASE to 2.0.2-RELEASE the serial console stopped working again on my Firebox X700. The console shows the boot progress and then stops working after 'Bootup complete'.
In previous 2.0.x versions I used this solution.
After the upgrade to 2.0.2 the file "/usr/local/share/misc/serialbandaid.sh" was still available. The added lines to /etc/rc however, where gone. By simply adding the described lines again and a reboot the serial console works again! -
If you use this solution instead it will survive a firmware update:
http://forum.pfsense.org/index.php/topic,7458.msg241783.html#msg241783Also that is 'cleaner' since it doesn't involve editing any files or running scripts.
Steve
-
Thanks Steve! I thought I used that method before, but can't remind exactly… I will give it a new try.
-
Does anyone have any information on the max processor that these boxes will support? I know some have replaced the processor with 1.4 Pentium M or Celerons, has anyone gone higher?
If I'm going to buy a replacement, I might as well go as big as possible since these processors are so cheap.
Thanks
-
On the X-Core boxes you can only use Pentium 3 (or equivalent Celeron chip). The fastest P3 was 1.4GHz.
http://en.wikipedia.org/wiki/List_of_Intel_Pentium_III_microprocessors#.22Tualatin.22_.28130_nm.29I don't think anyone has ever tried one of the VIA Socket 370 CPUs. If those worked you would have the advantage of the on board encryption accelration (VIA Padlock):
http://en.wikipedia.org/wiki/List_of_VIA_C3_microprocessors#.22Nehemiah.22_.28130_nm.29Steve
-
jmcentire
Great post but you already know that :)
I have a WatchGuard Firebox X 1250e…I assume the motherboard are roughly the same.
I have a SATA 2.5 drive, I also have a 44 pin 2.5 hard drive that I want to 'adapt' to this box (I would prefer the SATA drive).
My question is... would/could you share where I could find the adapter(s), for either one??
Also could not find the caddy you recommend??
ChuckInAtl
-
I have a WatchGuard Firebox X 1250e…I assume the motherboard are roughly the same.
That would be an incorrect presumption. ;)
The X1250e is part of the X-Core-e series. See: http://www.watchguard.com/products/core-e/compare.asp?p1=x550e&p2=x750e&p3=x1250e
The relevant thread is here: http://forum.pfsense.org/index.php/topic,20095.0.html
Also see the wiki page: http://doc.pfsense.org/index.php/PfSense_on_Watchguard_Firebox#X-Core-eSteve
-
I currently have 2 WG FB X700 (both static IP) in production both running pfsense 2.03REL. The main office has dual WAN connection due to them having issues with Comcast going down now and then. Primary connection is Comcast and backup is AT&T setup for load balancing.
The satellite office has a single Comcast connection and rarely has any downtime. They currently connect through an IPsec connection with AES-128 encryption. I assume it would be using the SafeXcel 1141 card and I have the use glxsb option ticked on (should I turn this off?). Reading the docs http://doc.pfsense.org/index.php/PfSense_on_Watchguard_Firebox#X-Core now it appears it isn't using the card at all? I guess I should be using Blowfish encryption instead?
Lately I've been having issues with the IPsec VPN connection where it loses the connection and restarting the racoon service doesn't fix the issue. Would OpenVPN be more robust in reconnections?
My other issue is the old issue with the Web GUI not responding (thought this was fixed in 2.03). When this happens, I try the reset webconfigurator (option 11) through a SSH connection and I get the endless … screen.
Restarting the firewall on either end (I usually just pick the one where the Web GUI stops responding) appears to fix the GUI and VPN connection.
-
Certainly I have failed to find any evidence that the Safenet card is used. It's doesn't seem to work via the FreeBSD crypto framework which is how it should work. There may be some software that talks to it directly without the framework.
I would choose OpenVPN for a pfSense-to-pfSense tunnel but that's probably because I have more experience with that (which isn't saying much!). I do believe that OpenVPN tends to be slower if your hardware is the limiting factor as it may well be with X700s.
Steve
-
After my very successful re-flash of a x1250e last week I'm going to try to
resurrect a old X500 with pfSense.A quick read of the docs and page one of this thread seems to indicate that you
boot a live CD on a laptop and install directly to the CF (I assume mounted via USB). Is
that still the recommended option? And what size CF card is needed for 2.x pfsense? Or
can I just write an image to the CF card as is done for the X-core-E models?The docs appear to be a little sparse regarding these details :) :) :)
-
Just write the image to CF and boot it. :)
It should mostly be covered in the doc page: http://doc.pfsense.org/index.php/PfSense_on_Watchguard_Firebox#Installing_pfSense
Feel free to suggest any improvements in the related forum thread: http://forum.pfsense.org/index.php/topic,59821.0.htmlSteve
-
Just write the image to CF and boot it.
It does not say that anywhere that succinctly :) (The documentation is excellent, just missing that
small detail).No size restrictions like the x-core-e models? Can i use a 4gb?
-
There are no bios restrictions like the X-e boxes. Any card should boot.
The only thing to watch out for is the serial port quirk.Steve