Netgate SG-1000 microFirewall

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - Smoothrunnings

Pages: [1] 2 3 4 5 ... 7
1
I guess the big question here is why?

Why do we need to increase the Firewall Maximum Table Entries from 200k (default) to 500k all of a sudden? I have been running pfSense a long time and have never had to make this change. So what changed all of a sudden?

It's great there is a solution but there isn't any real explanation as to why we have to change this value?

Thanks,

2
I have 63 of these alerts since the first on appeared on April 3rd, 2018.

There were error(s) loading the rules: /tmp/rules.debug:18: cannot define table bogonsv6: Cannot allocate memory - The line in question reads [18]: table <bogonsv6> persist file "/etc/bogonsv6"
@ 2018-04-08 14:20:27

I am using a WatchGuard XTM 5 Series, with a Q9450 QC CPU, 8GB of RAM, and 275GB SSD.
Memory usage is at 13%
CPU Usage 2%
Disk Usage 4%

I am using the following services:

Haproxy
LCDProc

The rest are standard:

DPinger
NTPD
Syslogd
Unbound

Please advise.

3
I am getting the following error when I boot the 32bit version of 2.3.x which I downloaded and flashed to my 4GB CF card.

ada0: <Xmore Industrial XM-CF-4G0-XIC52S(F) 081107S4> s/n 20110127AAAA80001666 detached
(ada0:ata0:0:0:0): Periph destroyed
Trying to mount root from ufs:/dev/ufs/pfSense [ro]...
mountroot: waiting for device /dev/ufs/pfSense ...
Mounting from ufs:/dev/ufs/pfSense failed with error 19.

Loader variables:
  vfs.root.mountfrom=ufs:/dev/ufs/pfSense
  vfs.root.mountfrom.options=ro

Manual root filesystem specification:
  <fstype>:<device> [options]
      Mount <device> using filesystem <fstype>
      and with the specified (optional) option list.

    eg. ufs:/dev/da0s1a
        zfs:tank
        cd9660:/dev/acd0 ro
          (which is equivalent to: mount -t cd9660 -o ro /dev/acd0 /)

  ?               List valid disk boot devices
  .               Yield 1 second (for background tasks)
  <empty line>    Abort manual input


Not sure if the image is broken on the downloads website, wonder if someone can offer some help?

Thanks,

4
2.4 Development Snapshots / Cannot log into console :(
« on: March 31, 2018, 10:00:11 am »
I can ping my GW (pfsense) and I can access the internet but when I try the WebGUI by IP either through http or https it tells me the system took too long to respond. I am using the latest 2.4 of pfSense.

I did once manage to get it work after several reboots but now its back to its ways.

Not sure how to get into this at this point. :(

I am using a WatchGuard XTM 5 series, QC 9450, 8GB of RAM, and 275GB SSD. Its been working fine after I installed 2.4 (latest non-beta build) but a some point its done something that its now not allow me to access the WebGUI but continues to allow traffic in and out of my network.

Appreciate your help!

Thannks

5
General Questions / Re: pfSense and Ubiquiti
« on: December 27, 2017, 08:16:05 am »
How many vpn users will you have that using radius to auth makes sense?  This is not a home setup I take it then?  Yeah Derelict is right what does the diagnostics auth section tell you?

I think I need to take a break from this fourm. Instead telling what I want or what I should do you should offer to help me to get there. This isn't directly at only you (Johnpoz) but everyone who has contributed to this thread what I want or should do. I have found myself having to fight a battle here which I should have to do.

Thanks,



6
General Questions / Re: pfSense and Ubiquiti
« on: December 26, 2017, 09:43:45 pm »
Is there a good walk through setting it up?

The stuff I have seen pre-dates pfSense 2.3.x and server 2008.

7
General Questions / Re: pfSense and Ubiquiti
« on: December 26, 2017, 03:41:17 pm »
What do you know about setting up pfSense 2.4.2 VPN (OpenVPN) using Windows 2016 NPAS for RADUIS?

I tried it once already and it didn't work out well.

Thanks,

8
General Questions / Re: pfSense and Ubiquiti
« on: December 26, 2017, 09:15:06 am »
the usg-3p could handle the 500/50 fine as long as it didn't turn the shaping which turns off the hardware offload.. If you left hardware offload on it handled the 500 without any issue..

If you want dpi, then just install the ntop package all the dpi you could want ;)  And pfsense also has layer 7 filtering back... with the snort package..
https://www.netgate.com/blog/application-detection-on-pfsense-software.html

It's not the same, I already have it installed. And I already have Ubuiqiti gear in my environment.

My environment now. The main switch on the backside and the UAP's are in the ceiling.
https://youtu.be/w8LTeGWgU8w


9
General Questions / Re: pfSense and Ubiquiti
« on: December 26, 2017, 08:43:38 am »
I am sorry to hear that you USG-3P couldn't hand your internet. My work friends own the USG-3P, I actually make fun of them not owning the Pro saying they aren't "PRO" enough! Anyhow one them has Rogers Gbit Fiber internet, granted switches max out at 1Gbit/sec the doesn't have any problems getting close to those speeds.

In the past when pfSense was version 2.3.x I was talking to guy on the USG forum who was trying to do what I looking to still do. He found that pfSense wasn't very good at it at the time and the only other firewall software that worked best was Sophos XG which he said was a walk in the park compared to doing it with pfSense. Now that we are on 2.4.x, and I have invested in my WatchGuard XTM 5 (put a faster CPU and 8GB of RAM in it) I would like to keep it a bit longer if that's possible. I have looked that Sophos XG documentation and for what I use pfSense for right now setting it up on the Sophos looks much easier than what I had to go through to get it setup this way. lol

I appreciate your offer on the USG-3P but it's not PRO enough for me. :P

And yes DPI is one of the things am interested in, and possibly VPN...but that's another project down the road.

Thanks,

10
General Questions / Re: pfSense and Ubiquiti
« on: December 25, 2017, 10:42:43 pm »
The USG is not anywhere near as capable as pfsense I'm afraid.

I have a USG, I install it and swap out the pfsense occasionally, then a day later put pfsense back in.

I have thought about using pfsense as the DHCP server, OpenVPN server, DNS server..... then USG do the rest.

Thanks for the info, but it doesn't really help me.

Thanks.

11
General Questions / pfSense and Ubiquiti
« on: December 24, 2017, 01:49:20 pm »
My network is mostly ubiquit except for my firewall which is a WatchGuard XTM (with 8GB of RAM and SSD) running pfSense 2.4 along with HAProxy.

I want the fuctionality of Ubiquiti and would like to buy a USG-Pro-4, i wonder if anyone has had some success connecting the two together, ideally I want (if possible) to put the USG first, and then let the internet traffic in/out go to the pfSense before hitting my network.

Thanks!!
 

12
Packages / Re: ntopng update?
« on: December 09, 2017, 07:41:20 am »
I am using pfSense v2.4.2, packages shows I have the latest ntopng installed v0.8.11, when I open ntopng I get a message that v3.2.0 is the latest version and I should download and update to it.

So is ntopng going to be updated in the pfSense packages anytime soon? It seems that v0.8.11 is fairly old if v3.2.0 is the latest.

Thanks

Go to your package manager and look at what you installed...you'll see as below...surprise!

I think you miss read my message maybe? How does 3.0.2 = 3.2.0?  :D ;) :P


13
Packages / ntopng update?
« on: December 08, 2017, 02:51:19 pm »
I am using pfSense v2.4.2, packages shows I have the latest ntopng installed v0.8.11, when I open ntopng I get a message that v3.2.0 is the latest version and I should download and update to it.

So is ntopng going to be updated in the pfSense packages anytime soon? It seems that v0.8.11 is fairly old if v3.2.0 is the latest.

Thanks

14
Installation and Upgrades / Upgrading to 2.4.0 from 2.3.4
« on: December 06, 2017, 07:24:25 pm »
I just want to know to if its safe to upgrade from 2.4.0 from 2.3.4 as I run HAProxy, LCDProc, and ntopng which I can't lose, especially HAProxy and all my 50 server settings.

Let me know,
Thanks,

15
Hardware / Re: Watchguard XTM 5 Series
« on: August 25, 2017, 10:57:26 pm »
On the WatchGuard XTM 5 motherboard do any of the pin-outs and or sockets support a VGA connector?

I have been looking on Google but nothing I see points to anyone investigating if a VGA connector can be connected to the motherboard or not.

Thanks,

Pages: [1] 2 3 4 5 ... 7