Subcategories

  • Discussions about Multi-Instance Management.

    37 Topics
    277 Posts
    K
    @skogs Same for me. I updated the Nexus pkg and my box is running without error concerning the serial number. Good .
  • Wireguard Back From The Past on Nexus

    1
    0 Votes
    1 Posts
    26 Views
    No one has replied
  • Nexus causing 99% CPU utilization on pfSense

    2
    1
    0 Votes
    2 Posts
    99 Views
    M
    Testing 26.07_2. It is now much , much better for me. I'll keep testing for a few days. Thanks, Netgate team!
  • SAML providers can't be deleted.

    6
    1
    0 Votes
    6 Posts
    260 Views
    F
    @marcosm Thanks now it works
  • unable to log in to nexus after recent update

    2
    0 Votes
    2 Posts
    82 Views
    T
    I reinstalled nexus and it now works. Ted Quade
  • CoreDNS Groups Prefix

    2
    0 Votes
    2 Posts
    108 Views
    Bob.DigB
    said in CoreDNS Groups Prefix: forcefully redirect all DNS queries I mean I would but the problem described here is still not tackled: https://forum.netgate.com/topic/201131/26.07-release-port-forward-is-missing-pass/11?_=1789294343778
  • Snort 3 on Nexus Breaks Routing

    1
    0 Votes
    1 Posts
    81 Views
    No one has replied
  • 0 Votes
    5 Posts
    215 Views
    M
    @phil_socket95 Thanks for the advice. IPv6 doesn't change the behavior, but I get your point; I'll simply take IPv6 out of the equation for now, as testing it is a hassle—it causes outages at times when CPU usage is high. Good point regarding RSS; I'll keep a closer eye on that. Another thing: after running further tests, I noticed the problem occurs under two different circumstances when ZTE is enabled: Restarting the pfnet-controller service and letting ThreatGate refresh the feeds for the first time (this takes at least 3 hours, as that is the minimum allowed interval); CPU usage spikes immediately after the refresh. Restarting the pfnet-controller service and changing the ThreatGate refresh interval to more than 24 hours to prevent a refresh; in this case, CPU usage increases gradually over time. I'll need to write up a new summary of all this when I have the time.
  • I think I missed something; Nexus Authentication

    10
    1 Votes
    10 Posts
    518 Views
    K
    @tkerr Proton Pass is working on my phone. I'll try again on the desktop. Might be some setting or blocker failure. ‍️
  • Nexus updates and release notes

    4
    3 Votes
    4 Posts
    174 Views
    W
    @pfGeorge Thanks for the heads-up, much appreciated!
  • Concerns about Nexus as the future default GUI

    5
    1 Votes
    5 Posts
    357 Views
    Bob.DigB
    Also it lacks personality.
  • [solved] Netgate Nexus is not supported on this sytem

    2
    0 Votes
    2 Posts
    238 Views
    Bob.DigB
    Solved with Nexus Version 26.07_1.
  • 0 Votes
    4 Posts
    205 Views
    M
    This should be fixed in the latest available Nexus version in 26.07.
  • Netgate Nexus coreDNS fails to start on Boot / Reboot

    3
    0 Votes
    3 Posts
    146 Views
    F
    @marcosm Thank you very much, I can confirm that this has resolved the issue. Mike
  • CoreDNS: add IPv6 DNS server results in "Invalid address or port"

    10
    1
    0 Votes
    10 Posts
    503 Views
    Bob.DigB
    Cool, my VM seems supported now. Even the other one.
  • Discussion of the New GUI design

    Moved
    57
    2
    0 Votes
    57 Posts
    4k Views
    T
    @SlackerDude if you see nothing helpful in the logs (Status->System Logs->Netgate Nexus), there could be a port conflict. If that isn't it, please share your logs and we'll look into it.
  • 1 Votes
    3 Posts
    178 Views
    J
    @jimp Thanks for the reply and looking into this. Messed around with this some more and it seems the key is that on the CoreDNS group for restricted clients you have to not define a DNS server. That way only the domains under FW get resolved. Otherwise if the group has a specified DNS server than everything gets resolved that isn't explicitly blocked. With this setup I also do not need to rely on the fallback to default. However, I have only been able to prove this from a DNS resolution standpoint because for some reason it seems like the traffic is not getting tagged with coredns_allow because my corresponding firewall rule for allowing the traffic does not match and I have checked it 5 times to ensure the rule is correct. It is basically allow TCP/UDP ANY ANY ANY ANY tagged:coredns_allow on the interface of the client in question. ZERO TRUST EGRESS is enabled and the client can only resolve the domains I put in group forward section and the IPs I get from a dig are exactly the same that curl then tries in my test. @264 pass in log quick on igc2.60 inet proto tcp from 192.168.77.41 to any flags S/SA keep state (if-bound) label "id=1788994054" label "tags=user_rule" label "descr=[COREDNS] allow coredns allowed internet hosts" ridentifier 1788994054 tagged coredns_allow Ultimately the firewall logs for the test traffic show it match for default deny on the interface. Seems to be quite similar to issue reported here https://forum.netgate.com/topic/201102/zero-trust-egress-with-coredns-can-t-get-it-working/ On another note, I had not fully considered one downside of using coreDNS allow listing like this which is that inheirently the firewall rules have to allow anything tagged coredns_allow so all clients subject to this, at least within the same group, end up being allowed to access all of the same domains. Not the end of the world, but I guess what Im really looking for as a feature request is CoreDNS backed aliases that could be used in firewall rules which hopefully this lays the ground work for someday. In the meantime I am still curious to get the tagged allow rules working like they are supposed to now. Running 26.07-RELEASE (amd64) on Netgate 4200.
  • IPv6 Invalid range?

    10
    2
    0 Votes
    10 Posts
    366 Views
    SteveITSS
    @Gertjan OK so then it's likely a "feature" that they block it if it's not the configured static subnet. Annoying in my very specific case but not a big issue.
  • Nexus UI BUG - Diagnostics -> DNS Lookups

    1
    4
    0 Votes
    1 Posts
    72 Views
    No one has replied
  • WOL Missing in Services

    3
    0 Votes
    3 Posts
    134 Views
    W
    I posted to the wrong forum initially.
  • No Nexus dashboard widget for services??!!

    2
    0 Votes
    2 Posts
    185 Views
    T
    @beerguzzle The services widget is coming soon (like a few days soon)! In the meantime you can go to Status -> Services to check. It looks like CoreDNS doesn't get a status so I will make a ticket to track that
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
Privacy Policy · Cookie Policy