background image

Security Gateway Manual

SG-1100

© Copyright 2020 Rubicon Communications LLC

Oct 21, 2020

Summary of Contents for SG-1100

Page 1: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC Oct 21 2020 ...

Page 2: ...CONTENTS 1 Out of the Box 2 2 How To Guides 20 3 References 55 i ...

Page 3: ...G 1100 Firewall Appliance and will provide the information needed to keep the appliance up and running Tip Before getting started we recommend downloading the PDF version of the Product Manual and the PDF version of the pfSense Documentation in case you lose Internet access Copyright 2020 Rubicon Communications LLC 1 ...

Page 4: ...le to the WAN port shown in the Input and Output Ports section of the Netgate appliance The other end of the same cable should be inserted into a port of the Cable or DSL modem The modem provided by the ISP should have multiple LAN ports Any port should work Next connect one end of a second Ethernet cable to the LAN port shown in the Input and Output Ports section of the Netgate appliance Connect ...

Page 5: ... of 192 168 1 1 please disconnect the Ethernet cable from the WAN port on your SG 1100 Netgate Security Gateway before proceeding You will need to change the default IP Address of the device during a later step in the configuration 1 From the computer log into the Web Interface Open a web browser Google Chrome in this example and type in 192 168 1 1 on the address bar Press Enter Fig 1 Enter the D...

Page 6: ...Security Gateway Manual SG 1100 Fig 2 Click Advanced and then Proceed to 192 168 1 1 unsafe Fig 3 Click Next Copyright 2020 Rubicon Communications LLC 4 ...

Page 7: ... set to America Chicago for US Central time 5 The WAN interface is the Public IP address the network will use to communicate with the Internet Use the following information for the WAN configuration page DHCP is the default and is the most common type of interface for home cable modems Default settings for the other items on this page should be acceptable for normal home users 6 Configuring LAN IP...

Page 8: ...Security Gateway Manual SG 1100 Fig 5 Change the Timezone and Click Next Fig 6 Default Settings Should be Acceptable Click Next Copyright 2020 Rubicon Communications LLC 6 ...

Page 9: ...vigation It also provides information on how to perform frequent tasks such as backing up the pfSense software and connecting to the Netgate firewall console 1 3 1 The Dashboard pfSense software is highly configurable all of which can be done through the dashboard This orientation will help to navigate and further configure the firewall Section 1 shows important system information such as the mode...

Page 10: ...Click Download configuration as XML and save a copy of the firewall configuration to the computer con nected to the Netgate firewall This backup or any backup can be restored from the same screen by choosing the backed up file under Restore Configuration Note Auto Config Backup is a built in service located at Services Auto Config Backup This service will save up to 100 encrypted backup files auto...

Page 11: ...Security Gateway Manual SG 1100 Fig 9 Re run the Setup Wizard Fig 10 Backup Restore Copyright 2020 Rubicon Communications LLC 9 ...

Page 12: ... has been locked out or the password has been lost or forgotten See also Connecting to the Console Port Connect to the console Cable is required Tip To learn more about getting the most out of your Netgate appliance sign up for a pfSense Training course or browse our extensive Resource Library 1 4 Input and Output Ports 1 4 1 Front Side Copyright 2020 Rubicon Communications LLC 10 ...

Page 13: ...n Other Front Ports 1x USB 2 0 left side 1x USB 3 0 right side 1 4 2 Rear Side From left to right 1 Power Connector 12VDC 2A Center Pin Positive Power Consumption 3 48W Idle 2 Micro USB Console Port 3 Recessed Reset Button performs a hard reset immediately turning the system off Warning A hard reset of the system could cause data corruption and should be avoided Halt or reboot the system through t...

Page 14: ...ions are not followed 2 There are no operator serviceable parts inside this equipment Service should be provided only by a qualified service technician 3 This equipment is provided with a detachable power cord which has an integral safety ground wire intended for connection to a grounded safety outlet a Do not substitute the power cord with one that is not the provided approved type If a 3 prong p...

Page 15: ...is product should be disposed of separately from regular household waste streams It is your responsibility to dispose of this and other electric and electronic equipment via designated collection facilities appointed by the government or local authorities Correct disposal and recycling will help prevent potential negative consequences to the environment and human health For more detailed informati...

Page 16: ...ion et le recyclage en bonne et due forme ont pour but de lutter contre l impact néfaste potentiel de ce type de produits sur l environnement et la santé publique Pour plus d informations sur le mode d élimination de votre ancien équipement veuillez prendre contact avec les pouvoirs publics locaux le service de traitement des déchets ou l endroit où vous avez acheté le produit Italiano La direttiv...

Page 17: ...9 5 EY oleellisten vaatimusten ja sitä koskevien direktiivin muiden ehtojen mukainen Français French Par la présente NETGATE déclare que l appareil Netgate device est conforme aux exigences essentielles et aux autres dispositions pertinentes de la directive 1999 5 CE Deutsch German Hiermit erklärt Netgate dass sich diese NETGATE device in Übereinstimmung mit den grundlegenden Anforderun gen und de...

Page 18: ...enzjali u ma provvedimenti o rajn relevanti li hemm fid Dirrettiva 1999 5 EC Norsk Norwegian NETGATE erklærer herved at utstyret NETGATE device er i samsvar med de grunnleggende krav og øvrige relevante krav i direktiv 1999 5 EF Slovensky Slovak NETGATE t mto vyhlasuje e NETGATE device sp a základné po iadavky a v etky príslu né ustanovenia Smernice 1999 5 ES Svenska Swedish Härmed intygar NETGATE...

Page 19: ...EVIEW OF AN ARBITRATION AWARD IS LIMITED HOWEVER AN ARBITRATOR CAN AWARD ON AN INDIVIDUAL BASIS THE SAME DAM AGES AND RELIEF AS A COURT INCLUDING INJUNCTIVE AND DECLARATORY RELIEF OR STATU TORY DAMAGES AND MUST FOLLOW THE TERMS OF THESE TERMS AND CONDITIONS OF USE AS A COURT WOULD To begin an arbitration proceeding you must send a letter requesting arbitration and describing your claim to the foll...

Page 20: ...fine limit construe or describe the scope or extent of such section Our failure to act with respect to a breach by you or others does not waive our right to act with respect to subsequent or similar breaches These terms and conditions set forth the entire understanding and agreement between us with respect to the subject matter hereof and supersede any prior oral or written agreement pertaining th...

Page 21: ...VE AND CONSEQUENTIAL DAMAGES UNLESS OTHERWISE SPECIFIED IN WRITING IN NO EVENT WILL RCL S OR ESF S LIABILITY TO YOU EXCEED THE PURCHASE PRICE PAID FOR THE PRODUCT OR SERVICE THAT IS THE BASIS OF THE CLAIM CERTAIN STATE LAWS DO NOT ALLOW LIMITATIONS ON IMPLIED WARRANTIES OR THE EXCLUSION OR LIMITATION OF CERTAIN DAMAGES IF THESE LAWS APPLY TO YOU SOME OR ALL OF THE ABOVE DISCLAIMERS EXCLUSIONS OR L...

Page 22: ...ndows available for download Mac OSX There are drivers available for Mac OSX available for download For Mac choose Mac OS X Universal Binary Driver Linux There are drivers available for Linux available for download Recent versions of many Linux distributions include this driver and will not require manual installation FreeBSD Recent versions of FreeBSD include this driver and will not require manu...

Page 23: ... with a title such as Prolific USB to Serial Comm Port If there is a label in the name that contains COMX where X is a decimal digit e g COM3 that value is what would be used as the port in the terminal program Mac OSX The device associated with the system console is likely to show up as dev cu usbserial Linux The device associated with the system console is likely to show up as dev ttyUSB0 Look f...

Page 24: ... Connection type to Serial Then set Serial line to the console port that was located above in Locate the Console Port Device and the Speed to 115200 bits per second Click the Open button and the console screen will be displayed PuTTY in Linux Open PuTTY from a terminal by typing sudo putty Next set the Connection type to Serial Then set Serial line to dev ttyUSB0 and the Speed to 115200 bits per s...

Page 25: ...Security Gateway Manual SG 1100 Fig 1 An example of using PuTTY in Windows Copyright 2020 Rubicon Communications LLC 23 ...

Page 26: ...tems Ensure the cable is correctly attached and fully inserted Ensure the terminal program is using the correct port Ensure the terminal program is configured for the correct speed The default BIOS speed is 115200 and many other modern operating systems use that speed as well Some older operating systems or custom configurations may use slower speeds such as 9600 or 38400 Ensure the operating syst...

Page 27: ...e the terminal program is configured for the correct speed for the installed operating system See No Serial Output Ensure the installed operating system is configured to activate the serial console Ensure the installed operating system is configured for the proper console e g ttyS1 in Linux Consult the various operating install guides on this site for further information If booting from a USB flas...

Page 28: ...he boot process very soon after initial boot 5 When prompted press any key to stop the autoboot process 6 Type run usbrecovery at the Marvell prompt and press Enter 7 Select the destination device by pressing Enter then confirm by pressing y and Enter Note The onboard eMMC flash memory is always mmcsd0 8 Wait for the installation to the eMMC to complete 9 Once the install has completed remove the ...

Page 29: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 27 ...

Page 30: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 28 ...

Page 31: ...ill work with untagged devices connected to them The LAN port could be used as a management port In normal operation the switch would only need to be connected to OPT with WAN and LAN disconnected 1 Connect to the LAN port on the SG 1100 2 From the pfSense webGUI menu navigate to Interfaces Switches 3 Go to the VLANs tab 4 Click on the button for VLAN group 3 Warning VLAN group 0 must remain in pl...

Page 32: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 30 ...

Page 33: ...ck Save When completed the Ports and VLANs configuration should reflect the screenshots below You can now connect a managed switch VLANs 4090 4092 must be trunked on the switchport of the managed switch to OPT with VLANs 4090 WAN 4091 LAN and 4092 OPT tagged to it If you need access to the WebConfigurator on LAN you can just connect a laptop to LAN and you should receive a DHCP lease unless DHCP S...

Page 34: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 32 ...

Page 35: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 33 ...

Page 36: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 34 ...

Page 37: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 35 ...

Page 38: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 36 ...

Page 39: ...l mount of the SG 1100 Note Remove the rubber standoff feet from the SG 1100 prior to attaching to the wall mount Do not remove the screws that are under the rubber standoff feet Tip Remember to save the SG 1100 MAC Address Serial Number and NDI located on the bottom of the system before attaching the SG 1100 to the wall Hang the wall mount with the cables hanging down Secure the cables to the hol...

Page 40: ...Security Gateway Manual SG 1100 Fig 4 Stretch the Silicone Band to the opposite side of the wall mount Copyright 2020 Rubicon Communications LLC 38 ...

Page 41: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 39 ...

Page 42: ...Security Gateway Manual SG 1100 Fig 5 Loop the silicone band under the opposite side of the wall mount Copyright 2020 Rubicon Communications LLC 40 ...

Page 43: ...Security Gateway Manual SG 1100 Fig 6 The silicone band should look like this Copyright 2020 Rubicon Communications LLC 41 ...

Page 44: ...Security Gateway Manual SG 1100 Fig 7 Tuck both sides of the silicone band under the wall mount Copyright 2020 Rubicon Communications LLC 42 ...

Page 45: ...teway Manual SG 1100 Fig 8 Place the SG 1100 over the silver aluminum standoffs on the wall mount and pull one side of the silicone band over the SG 1100 then the other Copyright 2020 Rubicon Communications LLC 43 ...

Page 46: ...Security Gateway Manual SG 1100 Fig 9 When mounted properly the SG 1100 should look like this Copyright 2020 Rubicon Communications LLC 44 ...

Page 47: ...Security Gateway Manual SG 1100 Fig 10 Note the silicone band under the SG 1100 when installed correctly Copyright 2020 Rubicon Communications LLC 45 ...

Page 48: ...Security Gateway Manual SG 1100 Fig 11 An SG 1100 wall mount kit correctly installed Copyright 2020 Rubicon Communications LLC 46 ...

Page 49: ...ng to configure or you will lose connectivity during this procedure 1 Open the pfSense WebGUI and log in 2 From the menu navigate to Interfaces Switches 3 Go to the Ports sub menu 4 Click on the Port VID for OPT Change the default value from 4092 to 4091 In the lower right hand corner click Save At this point Interfaces Switches Ports should look like the following 5 Click on the VLANs tab 6 Click...

Page 50: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 48 ...

Page 51: ...Click on the Add member button Enter Member 1 uncheck tagged and then click Save 10 Confirm the configuration matches the screenshots below Note Unlike software bridging traffic between ports 1 and 2 will never leave the switch chip so it will perform at switching speed You also cannot filter traffic between the two ports as pfSense will never see it just like with any other external switch Copyri...

Page 52: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 50 ...

Page 53: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 51 ...

Page 54: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 52 ...

Page 55: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 53 ...

Page 56: ...Security Gateway Manual SG 1100 Copyright 2020 Rubicon Communications LLC 54 ...

Page 57: ...iance and for other helpful resources make sure to browse our Resource Library https www netgate com resources 3 1 3 Professional Services Support does not cover more complex tasks such as CARP configuration for redundancy on multiple firewalls or cir cuits network design and conversion from other firewalls to pfSense software These items are offered as professional services and can be purchased a...

Page 58: ...ase only Please contact Netgate for warranty information or view our Product Lifecycle page All Specifications subject to change without notice For support information view our support plans See also For more information on how to use pfSense software see the pfSense Documentation and Resource Library Copyright 2020 Rubicon Communications LLC 56 ...

Reviews: