Want to downsize my pfsense box, Netgate SG-1000?

Page 4 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Red Squirrel

No Lifer
May 24, 2003
69,801
13,373
126
www.anyf.ca
Yeah been using the same MAC that is on the ISP provided router.

I changed the MAC to something else for troubleshooting now that I'm just trying to get an IP from the router and not the ISP. (don't want all the MACs to be the same). Still no go.

Current firewall gets a 192.168 IP fine from the ISP router and traffic goes through, new one jsut gets 0.0.0.0. Originally I was actually getting an IP from my ISP when I was connecting through the Asus router that has pass through but it would not pass traffic.
 

sdifox

No Lifer
Sep 30, 2005
98,966
17,384
126
Yeah been using the same MAC that is on the ISP provided router.

I changed the MAC to something else for troubleshooting now that I'm just trying to get an IP from the router and not the ISP. (don't want all the MACs to be the same). Still no go.

Current firewall gets a 192.168 IP fine from the ISP router and traffic goes through, new one jsut gets 0.0.0.0. Originally I was actually getting an IP from my ISP when I was connecting through the Asus router that has pass through but it would not pass traffic.


Have you tried rebooting the ont when you swap to the new firewall?

Never had the issue you are describing. You could also try a slightly older release like 2.4.2
 

Red Squirrel

No Lifer
May 24, 2003
69,801
13,373
126
www.anyf.ca
Have you tried rebooting the ont when you swap to the new firewall?

Yeah tried all that. Though the fact that it always works when I plug back the old firewall I don't think it's needed but I still tried it anyway.

Right now both are plugged into the ISP router (double NAT) and the old firewall works when the new one won't even get an IP anymore.
 

sdifox

No Lifer
Sep 30, 2005
98,966
17,384
126
Yeah tried all that. Though the fact that it always works when I plug back the old firewall I don't think it's needed but I still tried it anyway.

Right now both are plugged into the ISP router (double NAT) and the old firewall works when the new one won't even get an IP anymore.


Me think you got a lemon.
 

Red Squirrel

No Lifer
May 24, 2003
69,801
13,373
126
www.anyf.ca
That's my luck with this stuff. Probably what happened. I'll have to just repurpose this box for something else. ex: something that does not need to route traffic. Would make a decent HTPC, but my Raspbery Pi works fine for that already.

Probably too late to return it, I kinda waited long to start this project.

Going to try a reinstall for the 3rd time and for shits and giggles I'll swap the wan/lan interfaces around too.
 
Last edited:

sdifox

No Lifer
Sep 30, 2005
98,966
17,384
126
That's my luck with this stuff. Probably what happened. I'll have to just repurpose this box for something else. ex: something that does not need to route traffic. Would make a decent HTPC, but my Raspbery Pi works fine for that already.

Probably too late to return it, I kinda waited long to start this project.

Going to try a reinstall for the 3rd time and for shits and giggles I'll swap the wan/lan interfaces around too.


wasn't there a post about interface labelling issue? maybe that is it?
 

Red Squirrel

No Lifer
May 24, 2003
69,801
13,373
126
www.anyf.ca
wasn't there a post about interface labelling issue? maybe that is it?

I think it was for the 4 port version, I got the 2 port though I do wonder if it's doing some oddball stuff in the back end.

Though at some point I was actually getting an IP, it's just that it was not passing any traffic. Only arp requests.
 

Red Squirrel

No Lifer
May 24, 2003
69,801
13,373
126
www.anyf.ca
Yep got a port that's screwed. Now I can't connect to the web interface, but it's getting an IP. FML. This box is useless as a firewall then. There goes about $300.
 

killster1

Banned
Mar 15, 2007
6,205
475
126
Yep got a port that's screwed. Now I can't connect to the web interface, but it's getting an IP. FML. This box is useless as a firewall then. There goes about $300.
if you cant return you can still RMA it? /following reading your posts wish to buy a little box like this too, but realtek nic's doesnt sound good.
 

Red Squirrel

No Lifer
May 24, 2003
69,801
13,373
126
www.anyf.ca
Nope I think you only get like 30 days. The return option is gone now. no RMA or any other options. That's the downside with Amazon you're pretty much on your own after the return grace period.
 

killster1

Banned
Mar 15, 2007
6,205
475
126
Nope I think you only get like 30 days. The return option is gone now. no RMA or any other options. That's the downside with Amazon you're pretty much on your own after the return grace period.


nah i have returned this that are 4+ months old that wouldnt let me via website just did online chat or email etc and they even sent me a prepaid label.. maybe its the 1million (seems like) $$ i spend on amazon.
 

Red Squirrel

No Lifer
May 24, 2003
69,801
13,373
126
www.anyf.ca
There's no option to contact anyone. The window closed on may 18. I noticed if I go to seller feedback there is an option to contact Amazon but it's only for items that were fulfilled by Amazon. I think I'm pretty much out of luck. I'll have to find a use for it that only requires one NIC.

This blows, it's my luck to get DOA stuff all the freaking time.

I tried to use a USB nic that I had lying around, but it won't detect it. They arn't recommended anyway, but figured it would be worth a shot. I might try to just Ebay it for like $200 and disclose that one NIC is bad.

What a waste of a day this was.
 

mxnerd

Diamond Member
Jul 6, 2007
6,799
1,103
126
No matter what product you buy, you should test the box as soon as you received it.

Don't know why you have to wait so long to test a new box.

If DHCP didn't work, give the NIC a static IP.
 

Red Squirrel

No Lifer
May 24, 2003
69,801
13,373
126
www.anyf.ca
I just didn't get around to it till now. Was working when I ordered it. I had plugged it in and powered in on, and both link lights were on when I plugged a cable and I was able to get pfsense installed, just didn't get around to actually setting it up till now. This is really such a weird failure that it took a whole day of wasting time troubleshooting.

I can't do static on WAN, my ISP does not provide static IPs (I WISH. It would solve a lot of my other annoyances such as having to update firewall and other rules on my web server each time my IP changes).

When I switched the interfaces so that the "bad" interface is LAN, it was static but it was not passing TCP/UDP traffic. I could ping it, but could not do anything else.

I'm back fully connected to other firewall now. In this process I was also able to bypass the Asus router that was being used to do pass through. It was needed when I had TV service as the way TV service is provided is really weird, so that router has a custom firmware specificly for my ISP. But now that I only have internet I just had to setup WAN interface to use vlan 35 and I can plug straight into the ONT.

But yeah this blows, wasted my day on this, not to mention my money. Now to figure out what to do with this thing. I hear Photonicinduction is going to be making more videos soon.
 

sdifox

No Lifer
Sep 30, 2005
98,966
17,384
126
Amazon will still help with third party seller. Use the online chat
 

Red Squirrel

No Lifer
May 24, 2003
69,801
13,373
126
www.anyf.ca
I originally thought they had Intel nics myself, but you're right they are Realtek. During the setup phase when I was paying more attention to output I saw that they are indeed Realtek. Though these boxes are actually recommended for pfsense so that's weird it would give me so many issues.

So this is weird, I booted with a Linux Mint live CD, and now both nics work. I just don't get it.
 
Last edited:

Red Squirrel

No Lifer
May 24, 2003
69,801
13,373
126
www.anyf.ca
Good news after a bit of digging was able to get ahold of someone at Amazon and they decided to make an exception given the circumstances.

Also it looks like they actually changed the description of that listing. Used to say "pfsense" in the title indicating it was compatible with it.
 

mxnerd

Diamond Member
Jul 6, 2007
6,799
1,103
126
There are many issues with Realtek chips (on pfSense & FreeBSD, which pfSense based on).

You probably still need to deal with it even if you get a new box.

FreeBSD apparently is very picky since your box works under Linux Mint.


https://forum.netgate.com/topic/30212/realtek-8111e-driver-install-works

https://forum.netgate.com/topic/60796/realtek-8111e-drivers

compile realtek network driver for pfsense 2.4.x
https://gist.github.com/jovimon/524e116471f249626fd2ccd141f3fe05
 
Last edited: