Categories

  • 391 Topics
    1k Posts
    P
    Feels like it’s been a while since this topic was brought up, and so much has happened since then. TNSR has really filled out but I’m sure there’s other features our users would love see in future releases. So with that said, please share your feature requests here and let’s see what we can do! —pfGeorge
  • 121k Topics
    775k Posts
    J
    @johnpoz Answering your questions: Most access switches carry a similar amount of traffic. But I'm curious: are there any switches, even one, that handle the least amount of traffic? The behavior is consistent across all of them: disconnecting any switch (regardless of which one) immediately stabilizes CPU usage and latency. How many cameras are we talking about? Even 4K cameras don't typically produce much bandwidth. You should usually only see something like 10 Mbps per camera. That's what I see with my 4K cameras. We have an average of 7,000 cameras. So, does the pfSense interface handle all the interVLAN traffic, or do you have multiple uplinks from your core switch? Two interfaces (link aggregated) from pfSense going to the core switch. Do you have ports available on your pfSense and core switch that you could use multiple uplinks to put the heavy interVLAN traffic on different physical interfaces? Pfsense still has available interfaces that we can use but it doesn't make sense to use other ports when it still uses the same resource Fully understanding the amount of intervlan traffic and between which vlans would be helpful in figuring out best solution or identifying an issue Inter-VLAN traffic is fairly high and fairly constant. The main flows are: PCs VLAN → Cameras VLAN (live view and playback) General client traffic between user VLANs and shared services There isn’t a single VLAN pair that spikes independently; rather, the combined inter-VLAN traffic across multiple VLANs seems to drive the load. All VLAN gateways currently reside on pfSense, so all inter-VLAN traffic is routed through it. How many clients are we talking total? What filtering are you doing between vlans - possible to maybe put the top talkers between each other on the same vlan.. For example cameras to nvr, that more than likely could be the same vlan - so none of that camera traffic flows across pfsense at all. Other then someone watching a stream off the nvr, etc. We're talking about approximately 90 clients, those who view the 7,000 cameras on display. All of these users are on a primary VLAN, VLAN210DATA. I just had an intermittent issue; the ping to the gateway dropped and then went back up, and the firewall's CPU usage also increased. [image: 1768731504026-a0cd2f5b-7195-4693-9f1d-4a7ef13d6a09-image.png] [image: 1768731560621-1c90b69a-b976-4fce-b79d-b6f54119425f-image.png] [image: 1768731583675-2b99d821-09ef-4ee1-ac73-3b09cbc13569-image.png] Any help or suggestions would be greatly appreciated. Thank you in advance.
  • 20k Topics
    129k Posts
    N
    @Draco Yes, it is a glitch I have also experienced during upgrade. I also had to reinstate the vip and everything worked fine. The rest must be browser caching. 192.168.254.100 is myvip See here [image: 1768711945507-c2f307c9-0657-45c2-9ed4-67869812990f-image-resized.png]
  • 43k Topics
    267k Posts
    micneuM
    @kira12 Du kannst einen weiteren Port als WAN definieren, der DHCP nutzt. Dann schließt du sie einfach mit dem WAN-DHCP-Port an dein Netzwerk an, und sie kommt ins Internet. Alternative 1 an den WAN_DHCP einen LTE/5G Router hängen und darüber die Updates ziehen Alternative 2 Mobilen/Travel Router an den WAN_DHCP und mit dem Handy Hotspot Verbinden, darüber dann die Updates ziehen (ich nutze jetzt dafür immer gerne die Reise Router von GL-iNet z.B. GL-BE3600) [image: 1768687869468-scr-20260117-tydx-resized.png] Zeig doch mal bitte dein WAN + LAN Interface konfiguration Wieviele interfaces hat deine Sense denn? Ich setze hier eine Netgate 6100 ein [image: 1768727653554-scr-20260118-jkad.png] ╔═══════════════════════════════════ pfSense+ ═══╗ ║ Netgate 6100║ ║ Netzwerk Block: 172.30.0.0/19║ ║ LAN Block: 172.30.0.0/20║ ║ VPN Block: 172.30.16.0/20║ ║ LAN: 172.30.3.0/24║ ║ Gäste (W)LAN (VLAN2): 172.30.2.0/24║ ║ IoT WLAN (VLAN4): 172.30.4.0/24║ ║ DynDNS über deSEC.io mit eigener Domain║ ║ VPN's:║ ║ 1 x S2S WireGuard FB 7490 (172.30.20.0/24)║ ║ 1 x S2S WireGuard FB 6591 (172.30.19.0/24)║ ║ 1 x pfSense S2S (Netgate 6100) IPSec║ ║ 1 x OpenVPN Road Warrior DCO (172.30.16.0/24)║ ║ 1 x WireGuard RA Hetzner (172.30.17.0/24)║ ║ 1 x WireGuard Road Warrior (172.30.18.0/24)║ ╚════════════════════════════════════════════════╝
  • Information about hardware available from Netgate

    3k Topics
    21k Posts
    itandgeneralI
    @chpalmer Yes, great idea. The 4U version of the DeskPi RackMate this is mounted on actually comes with a metal shelf for things like a cable or DSL modem. [image: DP-0047-06-06.jpg?v=1756792674]
  • Information about hardware available from Netgate

    44 Topics
    211 Posts
    AriKellyA
    It looks like unified web management could be coming soon. It would be great if it means easier control and management of all web services in one place. Let's see if any companies announce more details about it!
  • Feel free to talk about anything and everything here

    4k Topics
    19k Posts
    L
    I am way late to this thread... but I am so, incredibly, over netgate at this point. Trying to unbrick my SG1100 for the 4th time? 5th time? I am litearlly 0/5 on physical devices, every single one has bricked itself at some point, 2 of which needed RMA's. For the final time (getting a device ready for sale as I have moved entirely off netgate), the latest OS needs an internet connection to flash from a putty terminal?!?! This is in-sane. For anyone reading this in the future, just dump your netgate devices - the level of frustration these have caused me, my family, and my poor friends I recomended them to is unreal. /rant Netgate - do better. This is a disgrace to networking infrastructure.
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.