Download Print this page
Netgate SG-1100 Manual

Netgate SG-1100 Manual

Security gateway
Hide thumbs Also See for SG-1100:

Advertisement

Quick Links

Security Gateway Manual
SG-1100
© Copyright 2020 Rubicon Communications LLC
Oct 21, 2020

Advertisement

loading
Need help?

Need help?

Do you have a question about the SG-1100 and is the answer not in the manual?

Questions and answers

Summary of Contents for Netgate SG-1100

  • Page 1 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC Oct 21, 2020...
  • Page 2 CONTENTS 1 Out of the Box 2 How-To Guides 3 References...
  • Page 3 Security Gateway Manual SG-1100 This Quick Start Guide covers the first time connection procedures for the Netgate® SG-1100 Firewall Appliance will provide the information needed to keep the appliance up and running. Tip: Before getting started, we recommend downloading the...
  • Page 4 OUT OF THE BOX 1.1 Getting Started The basic firewall configuration begins with connecting the Netgate® appliance to the Internet. The Netgate appliance should be unplugged at this time. Connect one end of an Ethernet cable to the WAN port (shown in the...
  • Page 5 Warning: If your DSL or Cable Modem has a default IP Address of 192.168.1.1, please disconnect the Ethernet cable from the WAN port on your SG-1100 Netgate Security Gateway before proceeding. You will need to change the default IP Address of the device during a later step in the configuration.
  • Page 6 Security Gateway Manual SG-1100 Fig. 2: Click Advanced and then Proceed to 192.168.1.1 (unsafe) Fig. 3: Click Next © Copyright 2020 Rubicon Communications LLC...
  • Page 7 Tip: If your DSL or Cable Modem has a default IP Address of 192.168.1.1, change the IP Address of your SG-1100 Netgate Security Gateway to a different subnet, such as 192.168.2.1 with a subnet mask of 24 to avoid an IP Address conflict.
  • Page 8 Security Gateway Manual SG-1100 Fig. 5: Change the Timezone and Click Next Fig. 6: Default Settings Should be Acceptable. Click Next © Copyright 2020 Rubicon Communications LLC...
  • Page 9 This orientation will help to navigate and further configure the firewall. Section 1 shows important system information such as the model, Serial Number, and Netgate Device ID for this Netgate firewall.
  • Page 10 Click Download configuration as XML and save a copy of the firewall configuration to the computer con- nected to the Netgate firewall. This backup (or any backup) can be restored from the same screen by choosing the backed up file under Restore Configuration.
  • Page 11 Security Gateway Manual SG-1100 Fig. 9: Re-run the Setup Wizard Fig. 10: Backup & Restore © Copyright 2020 Rubicon Communications LLC...
  • Page 12 See also: Connecting to the Console Port Connect to the console. Cable is required. Tip: To learn more about getting the most out of your Netgate appliance, sign up for a pfSense Training course or browse our extensive Resource Library.
  • Page 13 Security Gateway Manual SG-1100 Ethernet Ports Interface Name Port Name Port Type Port Speed mvneta0.4090 RJ-45 1 Gbps mvneta0.4091 RJ-45 1 Gbps mvneta0.4092 RJ-45 1 Gbps Note: The ethernet ports are switched and configured by default on their own VLAN, see the Switch Overview more information.
  • Page 14 Security Gateway Manual SG-1100 1.4.3 Top Side Table 1: Indicators Status LED State Description Black Diamond Blink Fast pfSense® boot in progress Solid pfSense boot complete Blink Slow pfSense software upgrade is available Blue Square Active mPCIe activity (not supported)
  • Page 15 Security Gateway Manual SG-1100 1.5.3 FCC Compliance Changes or modifications not expressly approved by the party responsible for compliance could void the user’s au- thority to operate the equipment. This device complies with Part 15 of the FCC Rules. Operation is subject to the following two conditions: 1.
  • Page 16 1.5.7 Declaration of Conformity ˇ Cesky[Czech] NETGATE tímto prohla uje, e tento NETGATE device, je ve shod se základními po adavky a dal ími p íslu n mi ustanoveními sm rnice 1999/5/ES. Dansk [Danish] Undertegnede NETGATE erklærer herved, at følgende udstyr NETGATE device, overholder de væsentlige krav og...
  • Page 17 Alulírott, NETGATE nyilatkozom, hogy a NETGATE device, megfelel a vonatkozó alapvetõ követelményeknek és az 1999/5/EC irányelv egyéb elõírásainak. Íslenska [Icelandic] Hér me l sir NETGATE yfir ví a NETGATE device, er í samræmi vi grunnkröfur og a rar kröfur, sem ger ar eru í tilskipun 1999/5/EC. © Copyright 2020 Rubicon Communications LLC...
  • Page 18 Con la presente NETGATE dichiara che questo NETGATE device, è conforme ai requisiti essenziali ed alle altre disposizioni pertinenti stabilite dalla direttiva 1999/5/CE. Latviski [Latvian] Ar o NETGATE deklar , ka NETGATE device, atbilst Direkt vas 1999/5/EK b tiskaj m pras b m un citiem ar to saist tajiem noteikumiem. Lietuviškai [Lithuanian] NETGATE deklaruoja, kad šis NETGATE ı...
  • Page 19 Niniejszym, firma NETGATE o wiadcza, e produkt serii NETGATE device, spełnia zasadnicze wymagania i inne istotne postanowienia Dyrektywy 1999/5/EC. Português [Portuguese] NETGATE declara que este NETGATE device, está conforme com os requisitos essenciais e outras disposições da Directiva 1999/5/CE. Român ˘ a [Romanian] Prin prezenta, NETGATE declar˘...
  • Page 20 Security Gateway Manual SG-1100 1.5.9 Applicable Law By using any Products/Services, you agree that the Federal Arbitration Act, applicable federal law, and the laws of the state of Texas, without regard to principles of conflict of laws, will govern these terms and conditions of use and any dispute of any sort that might arise between you and RCL and/or ESF.
  • Page 21 Security Gateway Manual SG-1100 KIND ARISING FROM THE USE OF ANY PRODUCTS/SERVICES, OR FROM ANY INFORMATION, CON- TENT, MATERIALS, PRODUCTS (INCLUDING SOFTWARE) OR OTHER SERVICES INCLUDED ON OR OTHERWISE MADE AVAILABLE TO YOU THROUGH ANY PRODUCTS/SERVICES, INCLUDING, BUT NOT LIMITED TO DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, AND CONSEQUENTIAL DAMAGES, UNLESS OTHERWISE SPECIFIED IN WRITING.
  • Page 22 CHAPTER HOW-TO GUIDES 2.1 Connecting to the Console Port There are times when directly accessing the console is required. Perhaps webGUI or SSH access has been locked out, or the password has been lost or forgotten. This guide shows how to regain access directly through the console. 2.1.1 Install the Driver A Prolific PL2303 USB-to-UART Bridge driver is used to provide access to the console, which is exposed via the Micro-USB B port on the appliance.
  • Page 23 Security Gateway Manual SG-1100 Tip: Be certain to gently push in the Micro-USB B connector on the system side completely. With most cables there will be a tangible “click”, “snap”, or similar indication when the cable is fully engaged. 2.1.3 Locate the Console Port Device The appropriate console port device that the workstation assigned as the serial port must be located before attempting to connect to the console.
  • Page 24 Security Gateway Manual SG-1100 2.1.4 Launch a Terminal Program Use a terminal program to connect to the system console port. Some choices of terminal programs: Windows For Windows it is recommended to run or SecureCRT. An example of how to configure Putty is PuTTY in Windows below.
  • Page 25 Security Gateway Manual SG-1100 Fig. 1: An example of using PuTTY in Windows. © Copyright 2020 Rubicon Communications LLC...
  • Page 26 Security Gateway Manual SG-1100 Fig. 2: An example of using PuTTY in Linux. Terminal Settings The settings to use within the terminal program are: Speed 115200 baud, the speed of the BIOS Data bits 8 Parity none Stop bits 1 Flow Control Off or XON/OFF.
  • Page 27 1. Please open a support ticket General Problem and then select Netgate SG-1100 for the platform. Make sure to include the serial number in the ticket to expedite access. Once the ticket is processed, the latest stable version of the firmware will be attached to the ticket, with a name such as: pfSense-netgate-SG-1100-recovery-2.4.5-p1-RELEASE-aarch64.img.gz...
  • Page 28 Note: The onboard eMMC flash memory is always mmcsd0. 8. Wait for the installation to the eMMC to complete. 9. Once the install has completed, remove the memstick, and cycle the power (unplug the SG-1100 and plug it back in) to reboot the SG-1100.
  • Page 29 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 30 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 31 LAN ports will still work with untagged devices connected to them. The LAN port could be used as a management port. In normal operation, the switch would only need to be connected to OPT, with WAN and LAN disconnected. 1. Connect to the LAN port on the SG-1100. 2. From the pfSense® webGUI menu, navigate to Interfaces > Switches.
  • Page 32 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 33 Security Gateway Manual SG-1100 5. Check tagged for Member 1, then click Save. 6. Click on the button for VLAN group 2. 7. Click on the Add member button, Enter Member 1, check tagged and then click Save. 8. Click on the button for VLAN group 1.
  • Page 34 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 35 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 36 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 37 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 38 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 39 Fig. 3: Loop one side of the Silcone Band under the wall mount of the SG-1100 Note: Remove the rubber standoff feet from the SG-1100 prior to attaching to the wall mount. Do not remove the screws that are under the rubber standoff feet.
  • Page 40 Security Gateway Manual SG-1100 Fig. 4: Stretch the Silicone Band to the opposite side of the wall mount © Copyright 2020 Rubicon Communications LLC...
  • Page 41 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 42 Security Gateway Manual SG-1100 Fig. 5: Loop the silicone band under the opposite side of the wall mount © Copyright 2020 Rubicon Communications LLC...
  • Page 43 Security Gateway Manual SG-1100 Fig. 6: The silicone band should look like this © Copyright 2020 Rubicon Communications LLC...
  • Page 44 Security Gateway Manual SG-1100 Fig. 7: Tuck both sides of the silicone band under the wall mount © Copyright 2020 Rubicon Communications LLC...
  • Page 45 Security Gateway Manual SG-1100 Fig. 8: Place the SG-1100 over the silver aluminum standoffs on the wall mount and pull one side of the silicone band over the SG-1100, then the other © Copyright 2020 Rubicon Communications LLC...
  • Page 46 Security Gateway Manual SG-1100 Fig. 9: When mounted properly, the SG-1100 should look like this © Copyright 2020 Rubicon Communications LLC...
  • Page 47 Security Gateway Manual SG-1100 Fig. 10: Note the silicone band under the SG-1100 when installed correctly © Copyright 2020 Rubicon Communications LLC...
  • Page 48 Security Gateway Manual SG-1100 Fig. 11: An SG-1100 wall mount kit correctly installed © Copyright 2020 Rubicon Communications LLC...
  • Page 49 Security Gateway Manual SG-1100 2.5 Configuring the Switch Ports This optional guide shows the steps required to configure the LAN and OPT ethernet ports to be on the same VLAN. Note: When connecting to the webConfigurator, be sure you are NOT connected to the port you are going to configure or you will lose connectivity during this procedure.
  • Page 50 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 51 Security Gateway Manual SG-1100 Warning: VLAN group 0 must remain in place and VLAN groups 1-3 must include 0t as a member, in order to function properly. 7. Click Delete for Member 1, then click Save. 8. Click on the button on VLAN group 2.
  • Page 52 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 53 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 54 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 55 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 56 Security Gateway Manual SG-1100 © Copyright 2020 Rubicon Communications LLC...
  • Page 57 Netgate training has got you covered. https://www.netgate.com/training 3.1.2 Resource Library To learn more about how to use your Netgate appliance and for other helpful resources, make sure to browse our Resource Library. https://www.netgate.com/resources 3.1.3 Professional Services Support does not cover more complex tasks such as CARP configuration for redundancy on multiple firewalls or cir-...
  • Page 58 SG-1100 3.2 Warranty and Support • One year manufacturer’s warranty (optional second year warranty available at time of purchase only). • Please contact Netgate for warranty information or view our Product Lifecycle page. • All Specifications subject to change without notice...