background image

CHAPTER

THREE

GETTING STARTED

Tip:

Before configuring the pfSense appliance it is best to activate it by following the instructions at

https://www.

netgate.com/register/

.

The basic firewall configuration begins with connecting the pfSense appliance to the Internet. Neither the modem nor
the pfSense appliance should be powered up at this time.

Establishing a connection to the Internet Service Provider (ISP) starts with connecting one end of an ethernet cable to
the WAN port (shown in the

I/O Ports

section) of the pfSense appliance.

Warning:

The default LAN subnet on the firewall is

192.168.1.0/24

. The same subnet

cannot

be used on

both WAN and LAN, so if the subnet on the WAN side of the firewall is also

192.168.1.0/24

,

disconnect the

WAN

interface until the LAN interface has been renumbered to a different subnet.

The opposite end of the same ethernet cable should be inserted in to the LAN port of the ISP-supplied modem. The
modem provided by the ISP might have multiple LAN ports. If so, they are usually numbered. For the purpose of this
installation, please select port 1.

The next step is to connect the LAN port (shown in the

I/O Ports

section) of the pfSense appliance to the computer

which will be used to access the firewall console.

Connect one end of the second ethernet cable to the LAN port (shown in the

I/O Ports

section) of the pfSense appliance.

Connect the other end to the network connection on the computer. In order to access the web configurator, the PC
network interface must be set to use DHCP, or have a static IP set in the

192.168.1.x

subnet with a subnet mask

of

255.255.255.0

. Do not use

192.168.1.1

, as this is the address of the firewall, and will cause an IP conflict.

3.1 Initial Setup

The next step is to power up the modem and the firewall. Plug in the power supply to the power port (shown in the

I/O

Ports

section).

Once the modem and pfSense appliance are powered up, the next step is to power up the computer.

Once the pfSense appliance is booted, the attached computer should receive a

192.168.1.x

IP address via DHCP

from the pfSense appliance.

24

Summary of Contents for XG-7100

Page 1: ...Product Manual XG 7100 Netgate Sep 21 2018...

Page 2: ...2 XG 7100 Switch Overview 4 3 Getting Started 24 4 Connecting to Console Port 35 5 Additional Resources 42 6 Warranty and Support Information 43 7 Safety and Legal 44 8 BIOS Flash Procedure 52 9 Rein...

Page 3: ...Desktop System This Netgate appliance provides a powerful reliable cost effective solution Quick Start Guide The Quick Start Guide covers the first time connection procedures and will provide you with...

Page 4: ...N tagging as shown in XG 7100 Switch Overview Warning There is an Intel supplied driver issue which is noted in the Intel Release Notes for the C3000 preventing 1Gbps and 10Gbps copper modules from be...

Page 5: ...supply fan will continue to run Turning off the rocker switch on the back of the power supply will eliminate all power to the system The power button should be depressed 3 5 seconds to initiate a grac...

Page 6: ...ces are referred to as ETH1 ETH8 In addition to those 8 ports there are also three additional ports that operate behind the scenes PORT 0 PORT 9 ix2 and PORT 10 ix3 ETH1 ETH8 are gigabit switchports P...

Page 7: ...5 Gbps 2500 Base KX switch link to SoC CPU ix3 2 5 Gbps 2500 Base KX switch link to SoC CPU 2 2 Switch LAGG ix2 and ix3 switch uplink ports 9 and 10 are configured as a load balanced LAGG This provid...

Page 8: ...as an independent interface For example all of these configurations are possible ETH1 8 dedicated as a LAN switch ETH1 4 configured as a switch for LAN network A and ETH5 8 configured as a switch for...

Page 9: ...pecify whether a switchport should act as an access or trunk port it s also possible to disable 802 1q VLAN mode When this is done a third mode called Port VLAN Mode is enabled In this mode any and al...

Page 10: ...ever reach pfSense This can be useful if you want a device other than pfSense to act as the primary uplink for those connected clients Since WAN and LAN are assigned to lagg0 4090 and lagg0 4091 if Po...

Page 11: ...Information on switchport status and port names If 802 1q is enabled this section can also be used to specify the native VLAN ID for each port The Port VID defined will be used to tag inbound untagge...

Page 12: ...Product ManualXG 7100 Fig 2 Information on members of the switch LAG Fig 3 802 1q enabled default Fig 4 Port VLAN Mode 2 4 Configuring the Switch 10...

Page 13: ...Product ManualXG 7100 Fig 5 802 1q enabled default Fig 6 Port VLAN Mode 2 4 Configuring the Switch 11...

Page 14: ...AN child interface 4090 and 4091 are enabled instead VLANs Under VLANs the default WAN and LAN VLAN can be seen Additional VLAN networks that will be used by the switch should be defined here with lag...

Page 15: ...d as a LAN switch For this specific example I ll perform the WAN interface reassignment over console Re assigning the WAN can be done from the webGUI as well This is what the default interface assignm...

Page 16: ...eeded for this so enter n to continue Input ix0 as the new WAN interface name Input the same default LAN interface of lagg0 4091 for the LAN interface name and press Enter to complete the interface re...

Page 17: ...WAN interface The LAN interface is still configured the same as the default Next the switch will need to be updated so that ETH1 previously WAN acts the same as ETH2 8 This will be done from the webG...

Page 18: ...0 now You can either select on the row containing 4090 to delete this entry or click to remove port 1 as a member For this example I simply removed VLAN 4090 from the switch with Now edit the VLAN 409...

Page 19: ...Next update the PVID for ETH1 so that it uses VLAN 4091 rather than the old VLAN 4090 To do this click on the Ports tab and click on the 4090 Port VID to modify it Then click on Save 2 5 Switch Confi...

Page 20: ...the 4090 row to remove this VLAN interface 2 5 2 Two LAN switches In this scenario the LAN switch from the previous example will be split into two LAN switches A new LAN network should be created in...

Page 21: ...Product ManualXG 7100 Add enable and configure the VLAN interface under Interfaces Assignments 2 5 Switch Configuration Examples 19...

Page 22: ...gure the switch so that ETH1 4 use the new network To do this go to Interfaces Switches VLANs and click the Add Tag button Input the VLAN tag for the new network same as the VLAN ID configured in the...

Page 23: ...7100 Once this is done click the Save button The final result should look like this Lastly update the Port VIDs to use the new 4081 VLAN rather than 4091 on ETH1 4 and click Save 2 5 Switch Configura...

Page 24: ...rior to hitting pfSense Devices on this VLAN may come through on ETH8 but there may also be untagged client traffic First create the management VLAN of 4000 in pfSense using the same steps in the prev...

Page 25: ...alXG 7100 Untagged traffic on ETH8 will be assigned a VLAN ID of 4091 ETH8 and the uplinks will also accept traffic that has already been tagged with a VLAN ID of 4000 as well 2 5 Switch Configuration...

Page 26: ...vided by the ISP might have multiple LAN ports If so they are usually numbered For the purpose of this installation please select port 1 The next step is to connect the LAN port shown in the I O Ports...

Page 27: ...cating a problem with website security Below is a typical example in Google Chrome If this message or similar message is encountered it is safe to proceed At the login page enter the default pfSense p...

Page 28: ...l as http 192 168 1 1 3 6 Domain If an existing DNS domain is in use within the local network such as a Microsoft Active Directory domain use that domain here This is the domain suffix assigned to DHC...

Page 29: ...xt after filling in the fields as appropriate 3 8 Time Server Configuration 3 9 Time Server Synchronization Setting time server synchronization is quite simple We recommend using the default pfSense t...

Page 30: ...ss of the old firewall may be entered here if it can be determined This can help avoid issues involved in switching out firewalls such as ARP caches ISPs locking to single MAC addresses etc If the MAC...

Page 31: ...cally require a DHCP Hostname entry Unless the ISP requires the setting leave it blank 3 15 Configuring PPPoE and PPTP Interfaces Information added in these sections is assigned by the ISP Configure t...

Page 32: ...ivate networks The following inbound address Ranges are blocked by this firewall rule 10 0 0 1 to 10 255 255 255 172 16 0 1 to 172 31 255 254 192 168 0 1 to 192 168 255 254 127 0 0 0 8 100 64 0 0 10 f...

Page 33: ...1 0 24 IP addresses within the 172 16 0 0 12 RFC1918 private address block are the least frequently used We recommend selecting a block of addresses between 172 16 x x and 172 31 x x for least likelih...

Page 34: ...Configurator make the selection as highlighted The Dashboard display will follow 3 21 Backing Up and Restoring At this point basic LAN and WAN interface configuration is complete Before proceeding bac...

Page 35: ...Click Download Configuration and save a copy of the firewall configuration This configuration can be restored from the same screen by choosing the backup file under Restore configuration 3 21 Backing...

Page 36: ...here are times when accessing the console is required Perhaps GUI console access has been locked out or the password has been lost or forgotten See also Connecting to Console Port Connect to the conso...

Page 37: ...console through the serial interface Microsoft Windows no longer includes HyperTerminal in Versions 7 and up PuTTY is free and can be downloaded from http www chiark greenend org uk sgtatham putty do...

Page 38: ...play as shown below For the Connection type select Serial Set Serial line to the COM Port that is displayed in Windows Device Manager COM4 for this example and the Speed to 115200 bits per second the...

Page 39: ...e system console via this port 4 2 1 Install the Driver Install an appropriate CP210x USB to UART Bridge VCP virtual COM port driver on the workstation used to connect with the system if needed There...

Page 40: ...the Mini B connector on the system side completely With most cables there will be a tangible click snap or similar indication when the cable is fully engaged 4 2 3 Locate the Console Port Device The a...

Page 41: ...m Mac OS X screen ZTerm cu Windows PuTTY SecureCRT Do not use Hyperterminal FreeBSD screen cu The settings to use within the terminal program are Speed 115200 baud Data bits 8 Parity none Stop bits 1...

Page 42: ...t to use UTF 8 for character encoding 4 2 5 Troubleshooting No Serial Output If there is no output at all check the following items Ensure the cable is correctly attached and fully inserted Ensure the...

Page 43: ...See No Serial Output above Ensure the installed operating system is configured to activate the serial console Ensure the installed operating system is configured for the proper console e g ttyS1 in Li...

Page 44: ...l services html for more details 5 2 Netgate Training Netgate training offers training courses for increasing your knowledge of pfSense products and services Whether you need to maintain or improve th...

Page 45: ...T INFORMATION One year manufacturer s warranty Please contact Netgate for warranty information or view our Product Lifecycle page All Specifications subject to change without notice For support inform...

Page 46: ...onformity Disputes Applicable Law Site Policies Modification and Severability Miscellaneous Limited Warranty 7 1 Safety Notices 1 Read follow and keep these instructions 2 Heed all warnings 3 Only use...

Page 47: ...installation prior to connecting the equipment d Protective grounding earthing is provided by Listed AC adapter Building installation shall provide appro priate short circuit backup protection e Prot...

Page 48: ...oder st dtischen Entsorgungsdienste oder an den H ndler bei dem Sie das Produkt erworben haben 7 7 3 Espa ol La Directiva 2002 96 CE de la UE exige que los equipos que lleven este s mbolo en el propio...

Page 49: ...i p slu n mi ustanoven mi sm rnice 1999 5 ES 7 8 2 Dansk Danish Undertegnede NETGATE erkl rer herved at f lgende udstyr NETGATE device overholder de v sentlige krav og vrige relevante krav i direktiv...

Page 50: ...kipun 1999 5 EC 7 8 11 Italiano Italian Con la presente NETGATE dichiara che questo NETGATE device conforme ai requisiti essenziali ed alle altre disposizioni pertinenti stabilite dalla direttiva 1999...

Page 51: ...disposi es da Directiva 1999 5 CE 7 8 21 Rom na Romanian Prin prezenta NETGATE declara ca acest dispozitiv NETGATE este n conformitate cu cerint ele esent iale s i alte prevederi relevante ale Direct...

Page 52: ...ts located in Austin Texas or any other court having jurisdiction over you 7 11 Site Policies Modification and Severability Please review our other policies such as our pricing policy posted on our we...

Page 53: ...RODUCTS SERVICES INFORMA TION CONTENT MATERIALS PRODUCTS INCLUDING SOFTWARE OR OTHER SERVICES INCLUDED ON OR OTHERWISE MADE AVAILABLE TO YOU THROUGH THE PRODUCTS SERVICES RCL S OR ESF S SERVERS OR ELE...

Page 54: ...lation is complete a message will appear saying pfSense pkg Netgate_Coreboot_Upgrade installation successfully completed 5 Now that the package is installed navigate to System Netgate Coreboot Upgrade...

Page 55: ...appropriate console port options 6 The installer will automatically launch once the boot process completes and offer the choice of a Quick Easy Install Custom Install and several other options Select...

Page 56: ...Product ManualXG 7100 54...

Reviews: