Netgate 6100 pfsense Firewall Review

Поделиться
HTML-код
  • Опубликовано: 10 июн 2024
  • Netgate SG-6100 Manual
    docs.netgate.com/pfsense/en/l...
    Official Netgate Video on the SG-6100
    • Inside The Box: The Ne...
    My pfsense tutorials
    lawrence.technology/pfsense/
    SFP SFP+ SFP28 and Why You Need DAC in Your Rack!
    • SFP SFP+ SFP28 and Why...
    Connecting With Us
    ---------------------------------------------------
    + Hire Us For A Project: lawrencesystems.com/hire-us/
    + Tom Twitter 🐦 / tomlawrencetech
    + Our Web Site www.lawrencesystems.com/
    + Our Forums forums.lawrencesystems.com/
    + Instagram / lawrencesystems
    + Facebook / lawrencesystems
    + GitHub github.com/lawrencesystems/
    + Discord / discord
    Lawrence Systems Shirts and Swag
    ---------------------------------------------------
    ►👕 lawrence.video/swag
    AFFILIATES & REFERRAL LINKS
    ---------------------------------------------------
    Amazon Affiliate Store
    🛒 www.amazon.com/shop/lawrences...
    UniFi Affiliate Link
    🛒 store.ui.com?a_aid=LTS
    All Of Our Affiliates that help us out and can get you discounts!
    🛒 lawrencesystems.com/partners-...
    Gear we use on Kit
    🛒 kit.co/lawrencesystems
    Use OfferCode LTSERVICES to get 5% off your order at
    🛒 lawrence.video/techsupplydirect
    Digital Ocean Offer Code
    🛒 m.do.co/c/85de8d181725
    HostiFi UniFi Cloud Hosting Service
    🛒 hostifi.net/?via=lawrencesystems
    Protect you privacy with a VPN from Private Internet Access
    🛒 www.privateinternetaccess.com...
    Patreon
    💰 / lawrencesystems
    ⏱️ Timestamps ⏱️
    00:00 Netgate SG-6100
    03:37 Dissassembled SG-6100 & What's Inside
    05:52 Network Ports & Connections
    08:09 Pricing & Walmount Accessory
    10:09 Netgate SG-6100 Manual
    11:12 pfsense configuration
  • НаукаНаука

Комментарии • 194

  • @OT_55
    @OT_55 2 месяца назад +1

    Great review and led me to purchase the 6100 Base model a few years ago. A few days ago, the firewall wouldn't boot and isolated to the on-board eMMC had failed. From the video you can see there are M.2 slots to add a NVMe M.2 128 GB SSD and highly recommend that you do. Once you add one, it will be a pro model and easier to replace in case of a failure in the future. The Netgate website list the NVMe model that needs to be purchased, but I couldn't find any instructions or videos on how to install the NVMe SSD or configured for the 6100. I did find other videos or blogs on how to do it.

  • @RavingMad
    @RavingMad 2 года назад +16

    Dear Tom, keep up the great work. I've learned a lot from your videos. Although you have bias (since you are a human being afterall), you are one of the more humble RUclipsr and I love the way you break down and simplify the technical tidbits. Cheers.

  • @jimporter
    @jimporter 2 года назад +9

    It's amazing how many companies out there are still living in a world from 4-5 years ago where only medium-enterprise companies had gb or multi-gb pipes. FTTH is changing everything. Fibre is being installed here with speeds including 2gbps and 10gbps available and as competition increases these bigger speeds will start to migrate down the chain whether people need them or not. Looking to put in kit that won't constantly require changing out for a few years is proving difficult. Yes most people won't use these speeds properly now but as more people get access to them then things will change quickly.

  • @williamshenk7940
    @williamshenk7940 2 года назад +4

    Excellent tutorial and review. Thanks for pointing out the stream's information, which was quite enlightening.

  • @sstubbby
    @sstubbby 2 года назад +5

    btw. love your direction and stucture in your vids! You are a Professional! Thanks and keep the content comming!

  • @jasonisrael4842
    @jasonisrael4842 2 года назад +3

    I HAVE NO NEGATIVE COMMENTS ABOUT THIS VIDEO - GREAT JOB!

  • @hdtrejo
    @hdtrejo 2 года назад

    I know it's silly, but that screw type barrel connector is what sold me on the Netgate 2100. Good stuff Tom!

  • @bendono
    @bendono 2 года назад +2

    Excellent video. I was wondering when I'd see you review this device. I have the device on pre-order myself and am eagerly awaiting it.

  • @NetgateOfficial
    @NetgateOfficial 2 года назад +5

    Thanks for the review Tom!

  • @kennethray7319
    @kennethray7319 2 года назад

    I would never complain about you... you are awesome!!!

  • @michaelsims7728
    @michaelsims7728 2 года назад +2

    Yes!!! Been waiting for this

  • @chrismallia29
    @chrismallia29 2 года назад +16

    Would be great if it was also rack mountable

  • @ChristianMcDonald
    @ChristianMcDonald 2 года назад +2

    Enjoyed your review! Excellent work

  • @Enonymouse_
    @Enonymouse_ 2 года назад

    Thanks for the review, i've been looking at this recently.

  • @BenState
    @BenState 2 года назад

    Thanks for the tear-down mate.

  • @hmne1
    @hmne1 2 года назад +1

    At last i was Waiting for review

  • @dreadroberts7523
    @dreadroberts7523 2 года назад

    Really loving the Netgate 6100

  • @edwardsoares3838
    @edwardsoares3838 2 года назад +3

    Awesome timing! Looking to buy this one any day now.

    • @edwardsoares3838
      @edwardsoares3838 2 года назад +3

      @@ImTheKaiser Thankful for this review and appreciate your offer but it appears this unit suffers from some of the same SFP port limitations the 7100 I have does. I finally decided yesterday after this review to just buy the riser card for the 7100 so I can use just about any PCIE NIC I want to get around those limitations and finally put it into use after it sitting around for a year because I didn’t do my research first. They wouldn’t take it back at 31 days after taking forever on correspondence with me.

    • @fenilmanani
      @fenilmanani 2 года назад +2

      @@edwardsoares3838 can you please elaborate the SFP+ port limitations you mentioned?

    • @edwardsoares3838
      @edwardsoares3838 2 года назад

      @@fenilmanani Compatibility in general, lack of support for copper sfp, no 2.5gb sfp support and in some cases no 1gb sfp support. I would swear some of the documentation was added or changed after I got my unit. It is an original release I had sitting around longer than I had remembered, I’ve heard they replaced some boards for some with early issues and that is when they likely added and changed documentation to limit liability. It originally sat because it choked very fast on too many vlans, especially at reboot. Further testing at that point on decent dell xeon server with 32GB ddr4 had pfsense choking on vlans in general. It is the way the config loads and not hardware limitation. Was trying to deploy pfsense as gateway for PAN environments anywhere between 200-800 vlans each with own subnet and had to use MikroTik for that instead, better captive portal anyway and same reboot time with even 2000 vlans setup as the pfsense would take about 2 hours with 800 vlans to boot up if at all. For the home and typical office though pfsense all the way, even better than opnsense anyday. Just not suitable for edge cases even though most of these edge cases are becoming everyday use cases now. Hope they fix it sooner than later, worked closely with support and engineering at that time and it never felt like they knew the software well themselves which was weird, maybe the mono wall documentation is lacking…Pfsense does support enough vlans without choking for most use cases in general otherwise.

    • @alexbrown1050
      @alexbrown1050 Месяц назад

      @@edwardsoares3838 Hi, I'm in the market for a new router, what's this SFP port limitation?

  • @ejbully
    @ejbully 2 года назад

    HEY TOM - THANK YOU!!

  • @sambarrett3059
    @sambarrett3059 2 года назад +4

    That incredibly useful, I actually wanted a 10gb down to a switch, didn't realise the ports could be re assigned

  • @tsiou82
    @tsiou82 2 года назад

    Great review!

  • @_rchi_
    @_rchi_ 2 года назад

    THANKS FOR REMINDING ME TO COMPLAIN

  • @ysoymnk
    @ysoymnk 2 года назад +1

    Hi Tom. Thanks for the valuable video. Question re the storage. What's the purpose of the storage on this device? Cannot decide which model I should buy, basic or max. Thanks for your advice!

  • @daninmanchester
    @daninmanchester 2 года назад +5

    The other 10G products were overkill and out my price range. This seems like the perfect upgrade / replacement.
    My WAN is slow but I want faster inter-VLAN routing. To-date I have been using a thin client with SFP+ and then using VLANs in my switch for WAN etc.

  • @MactelecomNetworks
    @MactelecomNetworks 2 года назад +3

    Great review Tom

  • @4001Bob
    @4001Bob Год назад

    I purchased 2 Netgate 4100 for a client, I mentioned your name / company so hopefully they will give you "something" Thanks for the great videos and information...

  • @DavidCNavas
    @DavidCNavas 2 года назад +3

    Been waiting for this review -- I appreciate the real-world numbers. I do wish there was a more modern processor on this, but I sure do appreciate the 2.5G performance at least!
    I also wish they had included ears -- the dimensions are *roughly* 1U, and silicom-usa has rack ears, so I'm wondering why that wasn't done (heat? time? product differentiation?).
    Now we just need unifi to actually ship a 6E 2.5Gbe AP.... :)

    • @DavidCNavas
      @DavidCNavas 2 года назад

      I'm trying to decide if this is a good starter that'll last a year or two before we (finally?!) get a post-2017 processor. The alternatives I've found are a little power hungry/noisy. Mostly I'm just going to be needing cross-vlan routing rather than vpn perf. I probably don't *need* sfp+ routing speeds, but as I already have sfp28 locally, it feels like something I should at least consider.

  • @Fiskgjusen
    @Fiskgjusen 2 года назад +1

    Great review, thank you! Beautiful device. Also thanks for clearly stating in the beginning of the video that Netgate did not have any say in the content provided.

  • @corlan9767
    @corlan9767 2 года назад +3

    AWSOME VIDEOS! REALLY LOVE HOW DETAILED YOU ARE! 🤣
    I'm needing 10g fiber and 2.5g fiber, is the combo port capable of performing on at 2.5g network or do they only work at 1g?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад +1

      I don't think they support the 2.5G on the 10G port.

    • @0bsmith0
      @0bsmith0 2 года назад +1

      2.5 / 5 Gbps UTP sure, but fiber? That's not a thing. The combo ports are only 1 Gbps ports.

    • @corlan9767
      @corlan9767 2 года назад

      @@0bsmith0 that's a bummer thanks.

    • @mrmotofy
      @mrmotofy 2 года назад

      2.5Gb and 5Gb are kinda pointless and minimal compatibility. Go straight 10gb which has been a standard for years

  • @DJPenguino51
    @DJPenguino51 Год назад

    I obtained a 6100 and while it may be a bit overkill for my home network setup currently, I can grow into it more as time passes. Especially with the SFP 10G WAN ports should I ever get fiber in my area. Right now, it's just [coax] cable internet. And of course the firewall blows just about any wifi-router that you might buy at Best Buy, WalMart, or what have you out of the water for performance, flexibility, and scalability. My setup is cable modem > 6100 > Netgear 2.5G managed switch > Unifi 6 lite AP. Handlily outperforms the previous Asus routers I have had before. I also dig the VLAN setup, something that most store bought routers don't have.

  • @engrpiman
    @engrpiman 2 года назад +1

    I completely moved to DAC / fiber. I’ve had all kinds of strange issues with rj45 10g.

  • @wlshuford4585
    @wlshuford4585 2 года назад

    Tom, your pfsense videos have been the most helpful for a novice like myself. I am having a problem finding a solution to whether or not I can have another router behind my diy pfsense box on its own lan interface be given access to a public ip. I have Xfinity residential service and cannot get additional public ips. I have installed a Deeper Connect Mini DPN device on pfsense box nic igb3. Is it possible to for this to be done and if so, what is easiest method? There are a lot of people looking to answer this that are either installing Helium miners and/or Deeper Network devices, so it might be a great topic to cover in a RUclips video. I keep keep seeing this question on Discord and lots of different answers. DMZ, NAT 1:1, virtual ip, port forwarding etc but not any solutions for pfsense users. Thanks for the great tutorials.

  • @luciuswayne3425
    @luciuswayne3425 2 года назад +2

    One question about the SFP+: Netgate and you mentioned the two ports are for fibre and DAC only basically. I have a 10Gbps home internet connection and it uses HuaWei EchoLife HN8245q which only has RJ45.
    Now I would like to use 6100 for the setup. You mentioned there are ‘compatible’ modules that would work for 6100. Would mind sharing the models if possible? Or there are other solutions?

  • @YeOldeTraveller
    @YeOldeTraveller 2 года назад +1

    I'm sure this is in the Fine Manual, but what is the default configuration?
    I preferred the WAN, LAN, OPTn labeling.
    That anemic (and quite old in this case) CPUs is the biggest reason I have been buying my own hardware. Current device is a Protecli 6-port with an i5.
    This is interesting as I am wanting to move up from 1 GbE, but I like having the additional horsepower.

  • @neighborhoodtechgeek2954
    @neighborhoodtechgeek2954 2 года назад +1

    HORRAY! Caught a video!!! You put out great content by the way!

  • @Darkk6969
    @Darkk6969 2 года назад +3

    I agree the silkscreen of the ports should be port # and speed since they all can be reassigned anyway. Great looking product!!

  • @sceadugenga2120
    @sceadugenga2120 2 года назад +2

    What is the maximum throughput over PPPOE? For the sake of a few dollars I wonder why they didn't go for a newer chip.

  • @tcghunter9196
    @tcghunter9196 3 месяца назад

    So if you get the base model can you add the extra storage later? Either internally on board or use some external storage?

  • @nhojmedina22
    @nhojmedina22 2 года назад

    nice video tom helping us much

  • @BertMackFilm
    @BertMackFilm 2 года назад +4

    Is OPNsense compatible / possible with any of the Netgates? Excellent vid!

  • @WilliamHaggerty
    @WilliamHaggerty 2 года назад

    Would it be worth labelling them yourself with the internal names?

  • @rage_in
    @rage_in 2 года назад

    At the 00:06:55 mark you mention the copper SFP modules are not supported officially. Any chance you know of any that unofficially work?

  • @aminderpuri9392
    @aminderpuri9392 2 года назад

    Hi, great video. I was wondering if this device would be able to handle IPS/IDS snort all at the same time as I have read that online that it can't?

  • @solverz4078
    @solverz4078 2 года назад

    Are hardware firewalls another term for routers or is it just nearly all hardware firewalls are routers also

  • @normancummins4651
    @normancummins4651 6 месяцев назад

    Tom, I have AT&T 1G fiber, is it possible that this can replace my AT&T router?

  • @jamess1787
    @jamess1787 2 года назад +6

    CAPS LOCK ON ✅
    COMPLAINTS ❌
    GOOD VIDEO 👍

  • @pepeshopping
    @pepeshopping 2 года назад +3

    You MUST increase the TCP Window Size if you want to send/ack more than 1Gb/sec!!

  • @ryzenforce
    @ryzenforce 2 года назад +1

    Great review Tom! And I am glad there is a pair of discrete SPF+ connectors on that device now so you could start building more efficient networks and not having to bottleneck to your servers/services at 1Gbps. This is very a very neat device for Netgate. +1
    Edit: Also, no switch port on this model which is another big plus. I never really understood why Netgate put that on some of their models.
    Edit2: To be able to do 10Gbps in a single stream, you need to have your packets inspection go into dedicated ASICs and not rely on a multi-purpose CPU - although some could do it, but you need 4GHz+ per core for that which will start defeating the low-power benefit of those solid state appliances.

    • @BMcC78
      @BMcC78 2 года назад +1

      Switchports on these type of models is because it's not an enterprise grade device - it's more for a SOHO situation and not a datacenter.

  • @danielcottmain4035
    @danielcottmain4035 2 года назад

    Please excuse my lack of knowledge - can it have something like an Intel M2 wireless card installed then set up for multiple SSIDs some of which have direct VPN connection? (Thus negating the need for VPN setup on the device once the wireless password is used) Thank you

  • @davilajeremy
    @davilajeremy Год назад

    Do you have a video of setting up hardware ha? I would love to see that. Thanks in advance

  • @joellemorris5684
    @joellemorris5684 2 года назад +2

    thanks for another great tutorial!!! Can we bound WAN1 and WAN 2 together?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад +4

      Yes you can.

    • @joellemorris5684
      @joellemorris5684 2 года назад +1

      @@LAWRENCESYSTEMS Thanks. I don't own a PfSense box so i can't test things. I'm learning the differences between load-balancing and bonding before deciding what will fit my field situation, could you make a tutorial on how to bound 2 WANs together with a Netgate router?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад +2

      @@joellemorris5684 Already did ruclips.net/video/VULKulpXBYU/видео.html

  • @jrider85
    @jrider85 2 года назад +2

    It would be nice if it had the ability to be rack mounted.

  • @GillySqueeze
    @GillySqueeze 2 года назад +8

    Are we going to get a 2021 diy pfsense build with 10g ports

  • @luisenriquemelzer6124
    @luisenriquemelzer6124 2 года назад

    hi Lawrence, does the netgate 6100 have ecc ram?

  • @plrpilot
    @plrpilot 2 года назад +1

    Why would they silkscreen it that way? So frustrating. I AM glad they didn’t do that split chip crap here. I manage four of those of various sizes. They work fine, but are unnecessarily complex.

  • @KennethQvarfordt
    @KennethQvarfordt 2 года назад +9

    Thanks tom. If you're open to requests, I'd love to see a pfsense appliance that can handle single stream 10G. Basically what do you need to actually achieve that in a real world scenario. Preferably something with two PSU so there's a bit of redundancy in the mix as well.

    • @ryzenforce
      @ryzenforce 2 года назад +6

      When you need to 2 x PSU for a firewall, you probably need 2 firewall in HA instead which will accomplish more what true redundancy is all about.

    • @TheElderOne2003
      @TheElderOne2003 2 года назад

      @@ryzenforce exactly! And HA can be scaled up when you need more capacity or other reasons.

  • @johndroyson7921
    @johndroyson7921 2 года назад

    Question: you mentioned in one of your older pfsense build videos, that using an sfp+ 10gbe port would lock the speed at 10Gbps. Could that be resolved by using a transceiver that's capable/compatible with 1gbe, 2.5gbe, etc?

  • @lucasgautier8373
    @lucasgautier8373 2 года назад

    When my Protectli hardware fails - this looks like a viable replacement. More expensive, but a good value.

  • @aguycalledspacelord5495
    @aguycalledspacelord5495 2 года назад

    YOUR BIASED...I like it!

  • @Pabula
    @Pabula 2 года назад

    Thanks Tom for the review. Forgetting about 10GB, thinking purely on 1GB, can it run Suricata + Traffic Shaping/QoS + pftop/NTOPng and still sustain gigabit?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад

      Yes, unless you create crazy rules

    • @Pabula
      @Pabula 2 года назад

      @@LAWRENCESYSTEMS Thank you for the reply

  • @markvos2565
    @markvos2565 2 года назад

    With the testing you did, was that just routing without any NAT or Firewall rules in place?

  • @thomaspatterson6880
    @thomaspatterson6880 2 года назад +1

    Solid, stable and reliable device I've been using mine for over a year now

    • @ikkuranus
      @ikkuranus 2 года назад +5

      How? It just came out recently.

    • @thomaspatterson6880
      @thomaspatterson6880 2 года назад +1

      @@ikkuranus referring to brand in general, I've been using 3100

  • @AaronPace93
    @AaronPace93 2 года назад +2

    Really they should label the ports like “p1-p8” or whatever. But really thinking about upgrading my virtual instance at home with this. I been really wanting the 10G connectivity

    • @KhaledTheSaudiHawkII
      @KhaledTheSaudiHawkII 2 года назад

      I wonder why would you need a 10gbps connection at home

    • @AaronPace93
      @AaronPace93 2 года назад

      @@KhaledTheSaudiHawkII just for internal use. I segment out my networks with VRFs and that have to route through pfsense to get to different network segments

    • @0bsmith0
      @0bsmith0 2 года назад

      @@KhaledTheSaudiHawkII Why not?

    • @viaujoc
      @viaujoc 2 года назад +1

      In your home, it is more unlikely that you will get enough simultaneous streams to fill up a 10 gbps link. IMHO you would probably be better with a DIY firewall that has an AMD or Intel CPU with higher clock rate that would be able get you at least 5 gbps per stream. By building it yourself, you will probably end up paying the same amount as the 6100 anyway. If you don't plan on subscribing to Netgate commercial support, building your own appliance will not be a big issue and you will probably get more bang for your buck.

    • @KhaledTheSaudiHawkII
      @KhaledTheSaudiHawkII 2 года назад

      @@0bsmith0 Just curious. I have a 100mbps fiber optic line and I think it is plenty. I stream 4K content and play games online. Family is also on the same network. I was wondering about other scenarios where you would need anything north of 500mbps, and wanted to see if I’m missing something.

  • @lllongreen
    @lllongreen 2 года назад +3

    @ Lawrence. When do you think the Wireguard tutorial will be available?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад +3

      ¯\_(ツ)_/¯ When I finish some other projects. In the mean time watch this ruclips.net/video/bCNnP8FDSNA/видео.html

    • @lllongreen
      @lllongreen 2 года назад

      @@LAWRENCESYSTEMS looking forward to it !

  • @viaujoc
    @viaujoc 2 года назад +5

    I also disapprove the way that Netgate chose to name the ports on their appliances. A port is a port, an interface is an interface, these are completely different concepts. Their naming should not use the same vocabulary. Surely it is easier for beginners, but once you get to use more advanced features such as LAGG, VLAN, Bridge, then it just creates more confusion and can even lead to errors and longer outages. In my opinion, it would be fine to name the port with a simple number (ex: Port 1) or the system port name (ex: igb0). We can always add a label later on the appliance to identify the ports more conveniently.

    • @neofitsolovan1459
      @neofitsolovan1459 Год назад

      can you clarify for me if you are able to use these interraces (the lan ones) as routed interfaces? as in to assign ip addresses on them/tag vlans etc?

    • @viaujoc
      @viaujoc Год назад +1

      @@neofitsolovan1459 Yes you can use the LAN1 to 4 ports as routed interfaces. You can use them with untagged traffic and assign an IP address directly on them, or you can add VLAN tags to them an also use the sub-ports as routed interfaces in pfSense. As said in the Netgate 6100 manual, the LAN ports will actually be shown in pfSense as igc0, igc1, igc2 and igc3. If you add a VLAN to a port, you will end up with a virtual port such as igc0.99 where 99 is the VLAN number. You can then add an interface in pfSense, which is routed by detault, and bind it to that virtual port.

    • @neofitsolovan1459
      @neofitsolovan1459 Год назад

      @@viaujoc Thanks for clarifying. I'm comfortable with networking terminology (Cisco Enterprise World) but they are not very good at explaining things. Do you happen to know if on pfsense plus you are allowed to install all the packages you can install on CE? (eg openvpn, freeradius,etc)?
      thanks!

    • @viaujoc
      @viaujoc Год назад +1

      @@neofitsolovan1459 Yes, packages are the same in both Plus and CE editions. Netgate has not, as of today, made a value-added package repository for Plus customers. Most packages are open-source and maintained by seperate communities, so it would be very hard to close them and make them commercial only.

    • @neofitsolovan1459
      @neofitsolovan1459 Год назад

      @@viaujoc thank you

  • @ebrown405
    @ebrown405 2 года назад +2

    @Lawrence Systems -- I really like your review of the Netgate 6100 pfsense firewall. Thank you. I was wondering if you knew, off the top of your head, about ECC memory supported on it. Can it support ECC memory? I think it can but I didn't see it in the specs but I know the CPU can do it, just unsure if the motherboard chipset support will. And if so, in the 8gb single slot, does it support the same memory speed? I believe from the specs it as two memory slots on the motherboard. And I believe it says higher capacity memory DIMMs may run memory at slightly slower speeds, it's a trade off sometimes in terms of hardware capability. I'm aware you can't mix ECC and non ECC memory, it's one or the other. This is a fantastic device as is! I do want to replace my current consumer router in the future because of lack of security and slower performance at higher internet speeds.
    The reason I bring up ECC capabilities, and maybe some of your customers specific needs may have too, is because of higher cosmic rays reaching the earth's ground surface. Scientific studies have increasingly shown that cosmic rays and other energetic particles are breaching the earth's magnetic field due to Sun changes (think solar minimum, superflares, etc.). Bit flips will be more common according the research so resiliency in the future will be needed. I think the DDR5 memory spec with built in ECC and DFE will lead the way in the future, in addition to more capacity and speed than previous DDR4. In short, ECC and DFE is all about speed, capacity, and stability magic for DDR5 memory to run flawlessly.
    For those unfamiliar with DDR5's new DFE capability, I'll share with you this brief description of it from the website I've sourced. "At a very high level, decision feedback equalization (DFE) is a means to reduce inter-symbol interference by using feedback from the memory bus receiver to provide better equalization. And better equalization, in turn, allows for the cleaner signaling needed for DDR5’s memory bus to run at higher transfer rates without everything going off the rails." Source Anandtech.com

  • @johnthoithi2332
    @johnthoithi2332 2 года назад

    Great Firewall Device.
    One Issue I Have Is The Boot Load Corruption Of Files Once Their Is Power Interruption.
    Which Is Better UFS OR ZFS File System?
    The Device Comes With UFS As Default But Cannot Cope Well In An Environment Where Power Is Fluctuating

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад +1

      They all come zfs as the default now

    • @johnthoithi2332
      @johnthoithi2332 2 года назад

      @@LAWRENCESYSTEMS Hey Advice On The Best Migration Process From UFS TO ZFS, Video Link Or Writeup Link, I Will Appreciate.

  • @ahmetoooo
    @ahmetoooo Год назад

    is memory and ssd upgradable on this

  • @justinknash
    @justinknash 2 года назад +1

    What’s the point of 10G WAN if the LAN is only 2.5G if I want to put a Ubiquiti 10G switch behind this? Have to port bond (LAG) all 4 LAN posts to the UniFi switch. Silly, should have 10G LAN ports.

  • @aemonblackfyre4159
    @aemonblackfyre4159 2 года назад +3

    just a quick noob question. why does it have so many lan ports? wouldnt it be enough to just have one lan and one wan port... maybe two each for redundancy but whats the point of the other ports?
    is it just so you dont need vlans?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад +6

      VLAN's are nice but share bandwith with native and adjacent VLANs on that same port. Individual ports are nice for creating exclusive networks without the shared bandwidth issues.

    • @scottluebke5012
      @scottluebke5012 2 года назад +3

      Imagine you use this router for a business office snd you’re renting space to a couple other businesses. You can wire their switch to one of the various ports and create a dedicated and separate physical network. Like the OP said, VLANs are great but you’re also sharing a connection and at some point can saturate it especially with how much internet usage we do now. You can also configure these ports as switch ports. I have a customer who doesn’t even need a dedicated switch because the firewall has 8 ports on it.

    • @viaujoc
      @viaujoc 2 года назад +3

      Also, if you have a managed switch that only has 1 gbps ports, you can aggregate the 4 LAN ports in a LAGG and get a total bandwidth of 4 gbps with multiple streams, adding link redundancy in the process.

  • @hmne1
    @hmne1 2 года назад +1

    Cab you do tut how to connect ISP fiber internet directly to pfsense box

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад +1

      You plug it in and set the IP address and settings.

    • @hmne1
      @hmne1 2 года назад

      @@LAWRENCESYSTEMS this easy 🤔

    • @AyoolaBoyejo
      @AyoolaBoyejo 2 года назад

      @@hmne1 Yes, just like any other ports.

  • @OldNorsebrewery
    @OldNorsebrewery 2 года назад

    8 G of ram? Can you rund block list filtering? Snort? without running out of memory?

  • @Venix91
    @Venix91 2 года назад +1

    Uhm.. this has the exact same processor as the SG 7100.. I have a whole fleet of those and I've never been able to push more than 3gbps through the chip with iperf or mix traffic no matter how many parallel streams or interfaces I throw at it...
    I've even tested the internal fabric throughput by turning iperf3 back on itself by hitting localhost with 10 to 30 streams and I can only ever get 7gbps to localhost.. I've just accepted that that Xeon in the SG7100 is just bad. This is depressing.. my laptop will do 70 gigabit when I run iperf against localhost. I'm not sure if this is just a major bug with pfSense 2.4.5 or not, but it still sucks. And you can't even upgrade to pfSense Plus when you're using FRR because there's so many system breaking bugs (that are documented and not fixed yet) in the FRR package when using any of the pfSense Plus builds. 😑

  • @neofitsolovan1459
    @neofitsolovan1459 Год назад

    Can someone please clarify if you can assign IP addresses on the "discrete ports"? or tag/untag VLANs on them?

  • @tcallumg
    @tcallumg 2 года назад +2

    I would love one of these personally. Anything would be an upgrade from my use on a symmetrical gigabit line lol

  • @johnthoithi5052
    @johnthoithi5052 2 года назад

    Great Review Tom.
    Is There NETGATE SG6100 Datasheet Available For Download?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад +1

      shop.netgate.com/products/6100-base-pfsense

  • @TeflonBilly426
    @TeflonBilly426 2 года назад

    I'm considering upgrading my Atom C2758 based router so I can do 10GB routing, do you know if Netgate has a router that can do 10GB single-stream routing? Or can you say what level of processor can handle 10GB single-stream routing (say bulk file transfer between two systems on the LAN)? (Atom C3758, or C3958? Xeon D?)

    • @jimthompson971
      @jimthompson971 2 года назад

      TNSR rocks on this device

    • @mrmotofy
      @mrmotofy 2 года назад +3

      Use a 10Gb switch then transfers bypass the router so it's capability is irrelevant

  • @feastwithethan9412
    @feastwithethan9412 2 года назад

    Someone make a rap video on his hand movements. Fully sick man!

  • @geraldh.8047
    @geraldh.8047 2 года назад +1

    The 4 year old cpu is a bit of a disappointment, but probably ok since Intel has not really released much in the last 4 years 😅. 4x 2.5GbE ports is pretty forward thinking and modern though. Great new box, finally something modern from netgate, most other boxes they sell are a bit dated, especially the horrendous SG-3100 which features a 32bit-only arm cpu from 2011 and is still currently sold by netgate.

  • @neofitsolovan1459
    @neofitsolovan1459 Год назад

    so this box comes by default with pfsense+. Are you allowed to install packages such as freeradius, ovpn, ?

  • @BenState
    @BenState 2 года назад +2

    Please do a DIY hardware alternative to replicate? Im sure of us would love a semi-regular look at the alternative.

    • @BenState
      @BenState 9 месяцев назад

      @user-zm7qz5fq2d why not?

  • @jkotka
    @jkotka 2 года назад +1

    what was the MTU on the device ? with jumbo packets you should be able to get higher single stream speeds

    • @patrickhurley707
      @patrickhurley707 2 года назад

      Only for other devices that support jumbo frames.

  • @johngrear6506
    @johngrear6506 2 года назад +1

    Might be cool to label their ports XAN :-)

  • @tombruton
    @tombruton 2 года назад +1

    Does pfsense now have an option for vpn before login

  • @sam_sheridan
    @sam_sheridan 2 года назад

    We'll probably be able to get those in the UK in 12 months, odd how they've printed designated names on ports that can be reassigned.

    • @Hayd3nuff
      @Hayd3nuff 2 года назад +1

      You can pick these up from Amica Tech in the UK

    • @sam_sheridan
      @sam_sheridan 2 года назад

      Thanks I'm aware of Amica Tech, they also supply managed IT services etc.

  • @mrsalamander9246
    @mrsalamander9246 Год назад

    Is it recommended to use a separate switch with the 6100 or is ok to use the 4 LAN ports on the 6100 if I do not need more than 4 ports.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  Год назад

      those are logical ports so use a switch.

    • @DR19X
      @DR19X Год назад

      @@LAWRENCESYSTEMS Hi I am new to networking. can you please elaborate more on the logical port vs switch port? can these port be used similar to the ports on isp router?

    • @NF650i
      @NF650i 8 месяцев назад +1

      @@DR19X Yeah, you can. It isn't best practice but you can bridge the interfaces you want and it will work. But you'll have much better performance using a switch.

  • @Bigjonisklutch93
    @Bigjonisklutch93 2 года назад

    Hey there! I was curious if the 6100 can do inline ips mode with suricata or snort? I know it can run in legacy mode, but I don't want to block I just want to filter and manually block. Thanks!

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад

      I have not tested.

    • @Bigjonisklutch93
      @Bigjonisklutch93 2 года назад

      @@LAWRENCESYSTEMS would you be kind enough to give it a test? I have the sg-2100 currently and am unable to do inline. I do have an old computer with a dual intel nic which can do inline, but would like to buy a better solution. Thanks! 🙂

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад +1

      @@Bigjonisklutch93 Maybe eventually, if you want a faster answer ask in the Netgate Forums.

    • @Bigjonisklutch93
      @Bigjonisklutch93 2 года назад

      @@LAWRENCESYSTEMS duhh silly me thank you totally slipped my mind to ask there. Thank you sir!

  • @LackofFaithify
    @LackofFaithify 2 года назад

    Still C3558? What are the speeds of those after you get all your mitigations done, anyone know?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад

      What mitigations?

    • @pmsrodrigues
      @pmsrodrigues 2 года назад

      @@LAWRENCESYSTEMS OP probable means Intel CPUs security issues, such as Meltdown and Spectre, to name a few.

    • @leakcim1978
      @leakcim1978 2 года назад

      hello with an A2SDi-4C-HLN4F motherboard (C3558) with a 10gbs network card, is it possible to reach 10gbs or is there a software limitation?

  • @sstubbby
    @sstubbby 2 года назад +4

    Thanks Tom for the un-bias info! My opinion: A little disapointed with Netgate hardware. The SuperServer 5019D-4C-FN8TP has smoked SG-6100 out of the box. And cheaper. Thought they would have came up with something better; @ Price /Harware /LTE Compatability; as the SM SS

    • @geraldh.8047
      @geraldh.8047 2 года назад +9

      Well that’s a 60W tdp cpu compared to the 16W tdp cpu from the sg-6100, not really a fair comparison.
      Both are ancient though, the Atom from the sg-6100 was introduced 4 years ago, the skylake Xeon from the 5019d you mentioned was introduced 3 1/2 years ago. Both are utter crap by 2021 standards. Probably enough for routing though.

    • @sstubbby
      @sstubbby 2 года назад

      @@geraldh.8047 Agree

    • @mrmotofy
      @mrmotofy 2 года назад +2

      VERY different price points too. Gotta compare apples to apples

    • @sstubbby
      @sstubbby 2 года назад +1

      @@mrmotofy Yes and no. Apples 2 Apples yes. 10G Apples do not compare; but should. We could compair the "Older" Unifi XG Gateway; bad SW solution! This device could have been much better. As @Gerald H. mentioned. I choose my device because of LTE/10G hardware integration. No other optimale solution out there?

  • @ThePopolou
    @ThePopolou 2 года назад +1

    It's not clear what MTU the interfaces were set at. You're not going to get 10Gb without reconfiguring it.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад

      It was left at default and yes, you can get 10G at the default as I demonstrated in the video.

    • @ThePopolou
      @ThePopolou 2 года назад +1

      @@LAWRENCESYSTEMS Not optimal, no. You lost throughput on the default settings.

  • @fooey88
    @fooey88 2 года назад

    @ 0:26 🤣

  • @SinisterSpatula
    @SinisterSpatula 2 года назад +1

    So it seems this device is meant to serve 2.5Gbps to your clients with a 10Gbps uplink. Still an amazing leap forward but at this rate it seems like 10 Gbps home networking/broadband is going to arrive long after I'm dead. lol

    • @SinisterSpatula
      @SinisterSpatula 9 месяцев назад

      @@user-zm7qz5fq2dthanks for your insightful comment.

  • @DanielAwesomesauce
    @DanielAwesomesauce 2 года назад

    Can I install OPNSense on this thing?

  • @EthanWord
    @EthanWord 2 года назад +1

    INSERT HUGE COMPLAINT HERE

    • @EthanWord
      @EthanWord 2 года назад +1

      p.s. I haven't finished the video but you are clearly a shill ;)

  • @jeffreywolfe6313
    @jeffreywolfe6313 2 года назад

    GOOD JOB lol

  • @rusnyasosat
    @rusnyasosat 2 года назад

    Holy price hike, Batman!

  • @MaheshM-zz6ki
    @MaheshM-zz6ki 2 года назад +5

    At this price People can Buy Fortigate 40F and 60F UTM Bundle .

  • @kittysreview9055
    @kittysreview9055 2 года назад +1

    This is a good but slightly misleading review. The speed limitation is not a limitation of firewalls in general. Its more of a limitation of freebsd. Linux firewalls are not as gimped by stream count.
    Also, your Suricata process is NOT running in inline mode and you ran it with only the base included rules without full suite of ET rules enabled like 99% of people would in order to properly protect their network.
    Nothing against Netgate hardware but with Suricata now supporting VLANs natively without disabling hardware VLAN offloads, this firewall doesn’t have enough RAM to keep up a serious multi-VLAN enterprise environment. While I wholeheartedly support the price as PfSense is very highly capable, one can do much better by purchasing a used server that will perform exponentially better for the same or less money.
    QAT is of limited use since most users who need that level of IPSec throughput will just go the TNSR home/enterprise edition route or use Wireguard to get similar throughput as QAT accelerated IPSec without the need for on-die QAT or QAT expansion cards.

  • @pepeshopping
    @pepeshopping 2 года назад

    Not a great CPU. 2360 CPU Mark.
    I’ll just keep using the J4105/J4125 which are 2928 and 3036 CPU Mark.

  • @jimthompson971
    @jimthompson971 2 года назад +3

    It’s a Netgate 6100, not SG-6100

    • @viaujoc
      @viaujoc 2 года назад +1

      You are right. When releasing the 6100, Netgate also made other subtle changes in their product line.
      1. They removed the SG and XG prefixes from the model numbers. The SG-3100 is now the Netgate 3100, the XG-1541 is now the Netgate 1541 and so on...
      2. The 7100 desktop appliance was retired, leaving room for the 6100 that has the same processor and 10gb ports. The rackmount version is still the 7100 1U.

    • @jimthompson971
      @jimthompson971 2 года назад

      @@viaujoc Yes, I know. Thank you.

    • @viaujoc
      @viaujoc 2 года назад

      @@jimthompson971 You and I noticed it. But I am not sure how many people did.

    • @jimthompson971
      @jimthompson971 2 года назад +1

      @@viaujoc Everyone at Netgate. ;-)

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад +2

      Are you sure?? 😆 I fixed it in the thumbnail and in the title, now the hard part is removing that prefix from my head.