Netgate SG-1000 microFirewall

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Messages - ashima

Pages: [1] 2 3 4 5 ... 9
General Questions / Re: rack setup
« on: January 06, 2018, 07:15:08 pm »

Hi merlin1,

           Since you have the hardware with 6 nic, you can use 3 of them for wan rest for lan. If you can arrange for managed switch (to do vlan tagging) you can create vlans. Then write rules to allow or disallow traffic. I can help you configure.


General Questions / Re: Cloning pfsense 2.4.2 harddisk
« on: January 02, 2018, 07:50:43 am »

   Thanks Jailer,

            So the new installer with guided ZFS install with pool type mirror did the trick. I tried my hand on a test machine with two 160 GB identical hdd acting as mirror.
     "zpool status"    shows  both the hardisks online.  I physically disconnected  one of the hdd, "zpool status" shows degraded. But pfsense boots properly and work flawlessly.

Now I introduced one more (new) disk at the same sata connector.  How do I replace the old hdd to new hdd in the same pool. I went through the manual page of zpool but nothing seems to work. I ended up goofing up the system and it failed to boot.

I am new to ZFS. Can any one guide what to do if one the hdd fails and I have to replace it with new hdd. Should I first disconnect the bad disk and introduce the new disk at the same sata controller or should I boot with three hdd. Can anyone help.

Thank you,

General Questions / Re: Cloning pfsense 2.4.2 harddisk
« on: December 29, 2017, 10:37:07 am »

Thank you once again Grimson. This is exactly what I was looking for.

Here is link of step by step guide for zfs pool in pfsense 2.4.

@Grimson is there anything I need to add ?

warm regards,

General Questions / Re: Cloning pfsense 2.4.2 harddisk
« on: December 29, 2017, 04:55:13 am »

Thank you Grimson for replying.
  I had already gone through those documents. But this box is going to a remote location. Basically the box is going to have two hardisks. Only the Master hardisk is connected. In case the master fails... the person at remote end will plug out master and plug in the clone hardisk.

I was able to do so with pfsense 2.3.4 using Acronis. But with 2.4, (with GPT) acronis is not able to copy the boot loader. I have tried with clonezilla also but no success. Does any one have any idea how to clone a hdd with GPT.

Thank you


General Questions / Cloning pfsense 2.4.2 harddisk
« on: December 29, 2017, 12:50:42 am »
Hi everyone,

      I have recently moved to pfsense 2.4.2. There are lot of packages installed on this box and also this box does an openvpn site to site connection with the head office. I was trying to clone the harddisk so in case of 1st hard disk failure, the user can just connect the secondary hard disk and it is up.

In earlier version of pfsense 2.3.2, I was able to clone the hardisk using acronis but now it clones the second hardisk but doen't boot from the there. Any suggestion on how to clone pfsense 2.4.2 .


Thank You Grimson.... It is working..

The following command helped....

gpart recover da1
 gpart set -a active da1


General Questions / Re: 2.4.2 not getting install on Intel 945 motherboard
« on: December 14, 2017, 07:25:39 am »
Thank you Grimson for replying.

I'll try those settings tomorrow.. and report back.


General Questions / 2.4.2 not getting install on Intel 945 motherboard
« on: December 14, 2017, 06:15:09 am »


    I have an old Intel 945 motherboard. I am trying to install pfsense 2.4.2 using usb mem stick. But it says Boot record not found.
The same pen drive is working on other systems.

I also tried installing  pfsense 2.4.2 through an iso installer (cd ) but again says No boot record found. However pfsense 2.3.2 through cd is installing perfectly on this board.

Is there any special BIOS setting required on this board for pfsense 2.4.2.

Any pointers ? It's slightly urgent...



Routing and Multi WAN / Re: Routing issue with AT&T?
« on: December 04, 2017, 08:23:11 pm »


       Just reboot pfsense it should start working. This happens if your lan ip series becomes wan ip series.... i mean I did the same ... rebooting resolved the issue.



Hi spice,

       You can leave the default gateway as it is. In your Firewall LAN rules add a rule before the default rule with gateway as loadbalancing gateway.

The default gateway is required if you are doing static routing.


Routing and Multi WAN / Re: 3 WAN with load balancing n failover
« on: December 04, 2017, 08:13:43 pm »

          Yes I have kept the weight settings as default. It was required if I do a load balance between WAN B(~9 Mbps) n WAN C (~5 Mbps).

Routing and Multi WAN / Re: 3 WAN with load balancing n failover
« on: December 02, 2017, 05:05:09 am »

    This is how I made it work finally.

Created a Gateway Group Grp1   ----     WAN  A      WAN B    WAN C
                                           Tier                 1                1             2

This is acting as load balance between WAN A n WAN B .... if WAN A/WAN B fails traffic goes through WAN B/WAN A respectively... if both fails traffic goes through WAN C.

I didn't create separate  Groups for load balancing and failover as suggested by pfsense official documentation.

Though I couldn't test load balancing as WAN A is down from last 10 days.

Thank You

Routing and Multi WAN / 3 WAN with load balancing n failover
« on: November 28, 2017, 12:50:43 am »

    I have 3 leased lines (11 Mbps, 9 Mbps, 5Mbps). I want to do following setup :

1) Load Balance WAN A + WAN B
2) Failover between WAN A and (Load balance between WAN B + WAN C with 2:1 weight) ie if WAN A fails traffic should load balance         between Wan B and Wan C.
3) Failover between WAN B and WAN C

To do so I have created Gateway group

1) WanAWanB   

         WanA    WanB
   Tier      1        1
Weight    1        1

2) WanAUP

          WanA     WanB    WanC
   Tier        1        2       2
Weight      1        2       1

3) WanBUp
            WanB     WanC
Tier          1        2

In Firewall LAN Rules

Allow all LAN Traffic through WanAWanB
Allow all LAN Traffic Through WanAUP
Allow all LAN Traffic through WanBUP

Is my setup correct. Any Suggestions

General Questions / Re: nginx = 504 Gateway Time-out / 502 Bad Gateway
« on: October 18, 2017, 01:45:57 am »

   I had a similar problem. Got it fixed by adding following line in /boot/loader.conf and rebooting


Hope this helps.


General Questions / Re: Migrate LAN to VLANs
« on: October 16, 2017, 08:02:16 am »


     You don't have to start from scratch. Just go to Firewall---> Rules----> LAN tab-->  copy the LAN rules and change the interface to VLAN.


Pages: [1] 2 3 4 5 ... 9