Categories

  • 376 Topics
    1k Posts
    fractal_boyF
    @dgeist there is a bug on TNSR that prevents to learn neighbor mac while you have map enabled on the interface. The workaround is to configure static neighbor entry.
  • 122k Topics
    783k Posts
    S
    Forgive me for asking this once more, there has been discussion somewhere already, but I still look for a clever way to speed this up: I have to install 10 new boxes with pfSense-CE in the near future (once again). And I look for the most efficient way to do that. If I use the installer from a USB stick, I have to download the same stuff 10 times. This takes time: I sit in Europe, with a rather slow line (60 Mbit/s) ... and as mentioned elsewhere sometimes even the upgrades take a long time for me (we hadn't found the real issue). I think of using some kind of proxy for caching these downloads, maybe on my pfSense-Plus in my LAN or maybe with a docker container somehow. For Debian there is something like apt-cacher-ng ... something like that would be cool. Cloning and restoring the storage is too much action in my opinion. The second step is the configuration: each box gets an individual openvpn-tunnel-setup to a main site. Last time I set up all 10 or so tunnels on the first box, exported the whole config. Then I put it on the installer stick, restored at installation time (saves some steps) and then delete the unneeded tunnels via GUI (plus edited stuff like hostname and individual root-pwd). Not exactly super efficient, but OK: after the first phase I don't have to think much anymore, it gets repetitive and easier. I can do it that way this time again, but I am open to any clever suggestions! Something like ansible, with pfsensible: yes, but ... / as long as the boxes are here in my office they don't have individual and static IPs, so this adds complexity etc / IMO it's not the tool for that initial part of preparation.
  • 21k Topics
    130k Posts
    3um3le3ee3
    pfSense WG Peer Export v1.1.0 (Testing Preview) Please note that this release is specifically intended for testing and feedback purposes. As a preview build, I encourage users to report any issues encountered to help me stabilize the upcoming stable release. Reporting Issues If you run into bugs or have feedback, please report all issues on the [GitHub repository]. This helps me track and resolve problems much more effectively than forum replies. ️ Important: Backup Before You Update Before installing this update—or any package update on pfSense—always create a full system backup (Diagnostics > Backup & Restore). It is best practice to have a restore point you can revert to immediately if you encounter unexpected behavior. ️ Backup Your WireGuard Configuration In addition to a full system backup, I strongly recommend specifically exporting your current WireGuard peer list and tunnel configuration. https://github.com/3um3le3ee/pfSense-wireguard-peer-export
  • 43k Topics
    268k Posts
    opnwallO
    为方便社区插件安装,搭建了一个社区插件仓库,提供一些代理插件、工具软件的安装。 仓库地址 pfSense Community Repository
  • Information about hardware available from Netgate

    3k Topics
    21k Posts
    E
    If I send my config file to Netgate for conversion, I should remove any confidential information first. I can see this will include my ISP username/password (for PPPoE), the details of the admin user, and ssh keys. Have I missed anything obvious?
  • Information about hardware available from Netgate

    44 Topics
    211 Posts
    AriKellyA
    It looks like unified web management could be coming soon. It would be great if it means easier control and management of all web services in one place. Let's see if any companies announce more details about it!
  • Feel free to talk about anything and everything here

    4k Topics
    19k Posts
    V
    Hi guys, Not so long ago, I needed a feature to set rules for AD users. The captive portal wouldn't work for me because it requires too much authorization. I wanted an SSO-like approach, so I could just log into any PC, and pfSense would give me the right access. Then, when another user logs in, the access would adjust for them. I couldn't find this in any form, so I wrote this script: https://github.com/vladgames228/ad_pfsense_access Basically, it temporarily adds the PC where I logged in into a pfSense alias, and for this alias, I configure the rules. For me, this is a super useful basic feature, and I can't understand whether it's so specific that no one needs it except me, or if I'm being dumb and there is a different, right approach for this task. I want to continue working on this tool. now I need an API for updating the config, so before I begin doing this, I wanted to ask you: what do you think? Was there something similar? I don't want to reinvent the wheel.
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.