Good morning all, I need help. I am trying to get Cacheguard set up and running on my small network. Cacheguard is installed on a Beelink EQ14 Mini, with a N150, 16GB DDR4 500GB NVMe SSD and 2.5G Dual LAN.
My WAN is coming in from a cellular modem to firewall/router, to a switch and out to WAP running laptops and tv boxes, a Truenas Scale server with apps running, then desktop computers and printers. There will be other systems as I expand like security cameras and a promox computer lab.
I have tried following every setup guide I can find and reinstalled multiple times changing local ip addresses from system defaults to recommended in guides to mirroring my existing firewall. The only one I was able to access the web gui on is the default of 192.168.60.11 and only on one computer with the Cacheguard machine plugged directly into it. I have tried plugging my WAN into CG machine and the desktop without luck accessing the WAN and into my network in place of the other firewall appliance without success. It sees the WAN but does not show it as active and I do not see a way to activate it.
Thank you
Setup in a Home Network
Re: Setup in a Home Network
Hi,
Thank you for your post. There is something in your case that caught my attention: you can connect to the default internal CacheGuard IP address, which is 192.168.60.11/24. This IP address is proposed as an example during the first setup, and there is little chance that a user will have their LAN in that network. The same goes for the external IP address, which is 192.168.22.11/24 by default.
The first thing I would try is to run the
I need to know two things:
1. How is your cellular modem connected to your firewall/router? Is it connected using an Ethernet link, or is your firewall/router wireless on its WAN side?
2. Is your wireless modem bridged with your firewall/router, or is it connected using an IP network segment? If it is connected using an IP network, please provide the modem and firewall IP addresses and network mask.
The answers to these questions will help us guide you towards the right solution.
In all cases, CacheGuard Gateway needs to be connected to two distinct IP networks (it does not support bridging). In a simple network, the external interface should be connected to the WAN and the internal interface to the LAN (in your case, your WAP, which I hope has an Ethernet interface). The important part of this network topology is that these two networks must be distinct.
When running the setup command, enter the correct internal and external IP addresses according to your existing network IP configuration. The default gateway should be set to your Internet modem/box/router IP address, which I hope supports Ethernet and IP connectivity.
Thank you for your post. There is something in your case that caught my attention: you can connect to the default internal CacheGuard IP address, which is 192.168.60.11/24. This IP address is proposed as an example during the first setup, and there is little chance that a user will have their LAN in that network. The same goes for the external IP address, which is 192.168.22.11/24 by default.
The first thing I would try is to run the
command from the CLI to set the internal and external IP addresses according to your existing network.setup
I need to know two things:
1. How is your cellular modem connected to your firewall/router? Is it connected using an Ethernet link, or is your firewall/router wireless on its WAN side?
2. Is your wireless modem bridged with your firewall/router, or is it connected using an IP network segment? If it is connected using an IP network, please provide the modem and firewall IP addresses and network mask.
The answers to these questions will help us guide you towards the right solution.
In all cases, CacheGuard Gateway needs to be connected to two distinct IP networks (it does not support bridging). In a simple network, the external interface should be connected to the WAN and the internal interface to the LAN (in your case, your WAP, which I hope has an Ethernet interface). The important part of this network topology is that these two networks must be distinct.
When running the setup command, enter the correct internal and external IP addresses according to your existing network IP configuration. The default gateway should be set to your Internet modem/box/router IP address, which I hope supports Ethernet and IP connectivity.
Re: Setup in a Home Network
Hi,
My understanding of your network is represented by the diagram below. Am I right?
If so, you can see three network segments in this diagram, represented by three colors: red, green, and blue. To help us determine how CacheGuard should be integrated into your network, please provide the following information for each network segment:
* Network address (e.g. 192.168.1.0)
* Netmask (e.g. 255.255.255.0 or /24)
* IP addresses of each network device
Best regards,
My understanding of your network is represented by the diagram below. Am I right?
If so, you can see three network segments in this diagram, represented by three colors: red, green, and blue. To help us determine how CacheGuard should be integrated into your network, please provide the following information for each network segment:
* Network address (e.g. 192.168.1.0)
* Netmask (e.g. 255.255.255.0 or /24)
* IP addresses of each network device
Best regards,
Re: Setup in a Home Network
Another question: how do you plan to integrate CacheGuard into your network?
There are basically two possibilities:
1. Replace your existing firewall with CacheGuard:
CacheGuard would replace your current firewall and become the security gateway between your internal network and the Internet.
2. Keep your existing firewall and add CacheGuard:
You can keep your current firewall and add CacheGuard as an additional security layer in your network. In this case, both devices can provide firewall and security functions, with CacheGuard also handling features such as web traffic filtering, web antivirus, caching, and compression.
Knowing which option you have in mind will help us determine the most appropriate network configuration for your setup.
There are basically two possibilities:
1. Replace your existing firewall with CacheGuard:
CacheGuard would replace your current firewall and become the security gateway between your internal network and the Internet.
2. Keep your existing firewall and add CacheGuard:
You can keep your current firewall and add CacheGuard as an additional security layer in your network. In this case, both devices can provide firewall and security functions, with CacheGuard also handling features such as web traffic filtering, web antivirus, caching, and compression.
Knowing which option you have in mind will help us determine the most appropriate network configuration for your setup.
-
waterwrangler
- Posts: 3
- Joined: 04 Sep 2026 02:26
Re: Setup in a Home Network
Charles, that is how my network is set up with the exception of after the switch. Everything with the exception of TV's, laptops and phones are ethernet connections.
My existing firewall is xx.xx.74.1
switch xx.xx.74.40
WAP xx.xx.74.32
David, the firewall/router is connected via Ethernet. I can't remember but I believe it is in pass-though mode to not do anything other than pass the connection to the firewall/router. In order to confirm it needs a hard reset to access the web UI.
Cachguard will replace the existing firewall/router. I would like to run a DNS server and a VPN in addition to firewall and routing.
Thank you
My existing firewall is xx.xx.74.1
switch xx.xx.74.40
WAP xx.xx.74.32
David, the firewall/router is connected via Ethernet. I can't remember but I believe it is in pass-though mode to not do anything other than pass the connection to the firewall/router. In order to confirm it needs a hard reset to access the web UI.
Cachguard will replace the existing firewall/router. I would like to run a DNS server and a VPN in addition to firewall and routing.
Thank you
Re: Setup in a Home Network
If you plan to replace your existing firewall with CacheGuard, the implementation would be even easier. However, Charles asked you to provide us with your IP configuration for the three networks he mentioned, while you have provided information about only one network, and without mentioning the network mask.
I assume that these IP addresses are used on the green network. Can you confirm this? What is the network mask? Is it 255.255.255.0, or something else?
There is also one point that would be useful to clarify. The IP addresses you mentioned appear to be public IP addresses (routable on the public Internet). This may be intentional in your particular setup, but public IP addresses are not normally used on private networks. For security reasons, we have hidden them in your previous post. If these are indeed private network segments, you would normally use RFC 1918 private IP addresses, such as 192.168.x.x or 10.x.x.x.
To help us understand your network, could you please provide the following information?
Green network
We really want to help you, but without all the information we have requested, it will not be possible for us to properly understand your network and propose a suitable solution. We therefore kindly ask you to provide all the requested information so that we can move forward. We look forward to your answers and to working with you to develop a plan for replacing your current firewall with CacheGuard with minimum effort.
Best regards,
I assume that these IP addresses are used on the green network. Can you confirm this? What is the network mask? Is it 255.255.255.0, or something else?
There is also one point that would be useful to clarify. The IP addresses you mentioned appear to be public IP addresses (routable on the public Internet). This may be intentional in your particular setup, but public IP addresses are not normally used on private networks. For security reasons, we have hidden them in your previous post. If these are indeed private network segments, you would normally use RFC 1918 private IP addresses, such as 192.168.x.x or 10.x.x.x.
To help us understand your network, could you please provide the following information?
Green network
- Are the IP addresses you provided the ones used on this network?
- What is the network mask? For example, 255.255.255.0 (/24).
- What is the IP address and network mask used on the LAN side of your cellular modem?
- Is your WAP configured as a bridge or as a router?
- If it is a bridge, there is no separate blue network as represented in Charles's diagram.
- If it is a router, what are its IP address and network mask on the blue network?
- What IP address and default gateway are used by your endpoints (for instance, your laptop)?
- What is the brand and model of your WAP?
We really want to help you, but without all the information we have requested, it will not be possible for us to properly understand your network and propose a suitable solution. We therefore kindly ask you to provide all the requested information so that we can move forward. We look forward to your answers and to working with you to develop a plan for replacing your current firewall with CacheGuard with minimum effort.
Best regards,
-
waterwrangler
- Posts: 3
- Joined: 04 Sep 2026 02:26
Re: Setup in a Home Network
David, as I read I am understanding I made some mistakes out of ignorance setting up my previous firewall/router. The private IP addresses I chose were at random to be different than others without understanding what I was doing. As I understand more I think it is best to start from scratch and do it correctly rather than figure out the mess I have clearly made. As the two of you recommend, starting with 10.x.x.x within the RFC1918 seems like the best idea and I will set it up as directed by professionals, I am grateful to learn.
Green network
The network mask is 255.255.255.0 on everything at the moment and everything is on the IP’s I provided ie. x.x.74.1 being the router and everything else on my network being x.x.74.32, x.x.74.154, x.x.74.40 etc. Looking at the ISC DHCP leases it is hard to determine what is what and it sounds like to do it correctly we are changing them to 10.x.x.x anyway.
Red network
As far as I can tell the internal WAN is the WAN_GW is x.x.143.91. After looking online, I do not see where to view subnet mask on my existing firewall.
The WAP is just a access point with no routing function and the cellular internet modem is in passthrough mode. From what I am reading that is different from a bridge giving the firewall/router direct access to the internet and handling everything, dns, vpn,etc. The cellular modem is in passthrough mode which is the only option on that router/modems GUI. My WAP is a wireless access point only, it’s a TP-LINK TL-WA3001, my switch is a TP-LINK TL-SG108E.
To recap. Starting fresh with the IP address of your choosing, the internet comes into the firewall/router in passthrough mode, then to the switch, then to Ethernet to Desktop computer, NAS, printers and wireless access point to service wireless devices. I hope that I have answered your questions completely, I am doing my best to with the knowledge I have and am looking forward to getting this up and running properly.
Green network
The network mask is 255.255.255.0 on everything at the moment and everything is on the IP’s I provided ie. x.x.74.1 being the router and everything else on my network being x.x.74.32, x.x.74.154, x.x.74.40 etc. Looking at the ISC DHCP leases it is hard to determine what is what and it sounds like to do it correctly we are changing them to 10.x.x.x anyway.
Red network
As far as I can tell the internal WAN is the WAN_GW is x.x.143.91. After looking online, I do not see where to view subnet mask on my existing firewall.
The WAP is just a access point with no routing function and the cellular internet modem is in passthrough mode. From what I am reading that is different from a bridge giving the firewall/router direct access to the internet and handling everything, dns, vpn,etc. The cellular modem is in passthrough mode which is the only option on that router/modems GUI. My WAP is a wireless access point only, it’s a TP-LINK TL-WA3001, my switch is a TP-LINK TL-SG108E.
To recap. Starting fresh with the IP address of your choosing, the internet comes into the firewall/router in passthrough mode, then to the switch, then to Ethernet to Desktop computer, NAS, printers and wireless access point to service wireless devices. I hope that I have answered your questions completely, I am doing my best to with the knowledge I have and am looking forward to getting this up and running properly.
Re: Setup in a Home Network
Thanks for this additional information.
If your cellular modem is in pass-through mode, you would need to configure your CacheGuard external interface directly with your public IP address and network mask, and use the public IP gateway provided by your ISP as the default route. However, this assumes that you have a fixed public IP address and that your ISP allows you to manually configure this IP address on your firewall (and later on CacheGuard).
If your ISP supports only DHCP or another connectivity method such as PPPoE, I am afraid that connecting the CacheGuard external interface directly to your pass-through modem would not be an option. In that case, you would need to keep your existing firewall and deploy CacheGuard behind it. This is not necessarily a bad solution: you could delegate external routing and basic firewall functions to your existing firewall while using CacheGuard as an additional security layer, VPN server, and for its other functional advantages. Of course, this may make your network configuration somewhat more complex, but it also provides an additional layer of security.
At this stage, the most important thing we need to know is whether you have a fixed or dynamic public IP address. Once we know this, the rest of the configuration should be relatively straightforward.
It is also important to note that the latest CacheGuard-OS release at the time of writing (2.6.1) does not support DHCP configuration on its interfaces when deployed on-premise. However, this is something we can easily add to the OS, as DHCP configuration is already supported when CacheGuard-OS is deployed on public clouds such as AWS and Azure.
Configuring your network from scratch is a good idea, and I was also going to suggest it. However, I was first waiting for your confirmation regarding the public IP addresses you mentioned as being used on your LAN.
So, to move forward, could you please confirm the following:
1. Public IP address
Do you have a fixed public IP address, or is your public IP address assigned dynamically?
2. ISP configuration
If you have a fixed public IP address, does your ISP allow you to configure it manually on your current firewall or on CacheGuard? It is also worth noting that you can sometimes ask your ISP to provide you with a fixed public IP address if you do not already have one.
3. WAN configuration
If manual configuration is allowed, please provide:
Once we have this information, we should have everything we need to determine the appropriate CacheGuard network configuration.
If your cellular modem is in pass-through mode, you would need to configure your CacheGuard external interface directly with your public IP address and network mask, and use the public IP gateway provided by your ISP as the default route. However, this assumes that you have a fixed public IP address and that your ISP allows you to manually configure this IP address on your firewall (and later on CacheGuard).
If your ISP supports only DHCP or another connectivity method such as PPPoE, I am afraid that connecting the CacheGuard external interface directly to your pass-through modem would not be an option. In that case, you would need to keep your existing firewall and deploy CacheGuard behind it. This is not necessarily a bad solution: you could delegate external routing and basic firewall functions to your existing firewall while using CacheGuard as an additional security layer, VPN server, and for its other functional advantages. Of course, this may make your network configuration somewhat more complex, but it also provides an additional layer of security.
At this stage, the most important thing we need to know is whether you have a fixed or dynamic public IP address. Once we know this, the rest of the configuration should be relatively straightforward.
It is also important to note that the latest CacheGuard-OS release at the time of writing (2.6.1) does not support DHCP configuration on its interfaces when deployed on-premise. However, this is something we can easily add to the OS, as DHCP configuration is already supported when CacheGuard-OS is deployed on public clouds such as AWS and Azure.
Configuring your network from scratch is a good idea, and I was also going to suggest it. However, I was first waiting for your confirmation regarding the public IP addresses you mentioned as being used on your LAN.
So, to move forward, could you please confirm the following:
1. Public IP address
Do you have a fixed public IP address, or is your public IP address assigned dynamically?
2. ISP configuration
If you have a fixed public IP address, does your ISP allow you to configure it manually on your current firewall or on CacheGuard? It is also worth noting that you can sometimes ask your ISP to provide you with a fixed public IP address if you do not already have one.
3. WAN configuration
If manual configuration is allowed, please provide:
- The fixed public IP address
- The network mask
- The default gateway
Once we have this information, we should have everything we need to determine the appropriate CacheGuard network configuration.
Re: Setup in a Home Network
Thanks for this additional information.
Please find below an updated version of the diagram, revised to better represent your current setup.
If your ISP uses DHCP to provide your Internet connection, CacheGuard does not currently support obtaining a dynamic IP address from a DHCP server on its external interface. However, we can quickly implement DHCP client support on the external interface. DHCP support is already available when CacheGuard-OS is deployed on public clouds such as AWS and Azure, so extending this capability to on-premise deployments should be straightforward.
Most CacheGuard users are SMBs with business Internet connections that normally come with a router and/or a fixed public IP address. This is why DHCP and PPPoE connectivity on the external interface have not been a priority for us so far. However, your use case shows that this capability is important, and we will implement it in CacheGuard.
This would allow you to connect CacheGuard directly to your cellular modem in pass-through mode, without having to keep your existing firewall in front of CacheGuard.
The main limitation of using DHCP on the external interface is that some other features would become unavailable, such as High Availability through VRRP and multi-WAN support.
The approach you choose will help us determine the most appropriate final implementation for your particular setup. Just let us know which approach you would prefer, answer David's questions, and we will guide you from there.
Best regards,
Please find below an updated version of the diagram, revised to better represent your current setup.
If your ISP uses DHCP to provide your Internet connection, CacheGuard does not currently support obtaining a dynamic IP address from a DHCP server on its external interface. However, we can quickly implement DHCP client support on the external interface. DHCP support is already available when CacheGuard-OS is deployed on public clouds such as AWS and Azure, so extending this capability to on-premise deployments should be straightforward.
Most CacheGuard users are SMBs with business Internet connections that normally come with a router and/or a fixed public IP address. This is why DHCP and PPPoE connectivity on the external interface have not been a priority for us so far. However, your use case shows that this capability is important, and we will implement it in CacheGuard.
This would allow you to connect CacheGuard directly to your cellular modem in pass-through mode, without having to keep your existing firewall in front of CacheGuard.
The main limitation of using DHCP on the external interface is that some other features would become unavailable, such as High Availability through VRRP and multi-WAN support.
The approach you choose will help us determine the most appropriate final implementation for your particular setup. Just let us know which approach you would prefer, answer David's questions, and we will guide you from there.
Best regards,