• Adding Custom Configuration in Kea DHCP Server

    Pinned
    31
    4 Votes
    31 Posts
    29k Views
    I
    @marcosm Hey that actually worked, I get no error anymore with the client class defied in global config and just referencing it in the VLAN. Problem is now that the test condition doesn't seem to work, the mac address i put there will still get the Option 108. Any ideas?
  • HEADS UP: Be aware of Trusted Recursive Resolver (TRR) in Firefox

    Pinned
    85
    17 Votes
    85 Posts
    95k Views
    kiokomanK
    @Bob-Dig idk it's not my phone, if it's "Private DNS" settings than it was probably on by default, my family does not know what dot / doh is @johnpoz exactly
  • UnicodeDecodeError: 'utf-8' codec can't decode byte 0xac

    2
    0 Votes
    2 Posts
    134 Views
    BBcan177B
    @bschae1 we are working on a new upcoming release for devel and this should be resolved at that time.
  • vlan77 wont give dhcp ip

    4
    6
    0 Votes
    4 Posts
    882 Views
    publictoiletbowlP
    @KOM hi kom i forgot to change the vlan number in switchport option so when i change to 77 it works [image: 1783743322268-screenshot_2026-07-11_12-13-47.png]
  • Unbound DNS Resolver Periodically Non-Responsive

    21
    1
    0 Votes
    21 Posts
    5k Views
    M
    I can look into it further if steps are provided to reliably reproduce the issue. I use DoT with an ACME cert along with pfBlockerNG in python mode and haven't noticed any issues.
  • DNS blocks RFC1918 answers [SOLVED]

    3
    1 Votes
    3 Posts
    1k Views
    johnpozJ
    @Cabledude without details - hard to say what your doing. Do you even have rebind protection enabled. What is the fqdn you are doing query for that returns rfc1918. If you are asking some other ns other than pfsense? If you don't want to post in public - send it to me in a DM. It sure isn't going to be a ttl, rebind protection has been part of pfsense for years and years..
  • Kea DHCP6 registers static hosts in DNS incorrectly (pfSense+ 2025.7.1)

    10
    0 Votes
    10 Posts
    3k Views
    D
    @Gertjan Thanks, yes, but turning off Early Registration is totally fine. I would like my configuration to be as portable as possible, as it were, if you get my drift. Thanks again for confirming this bug...looks like a fix is possibly forthcoming in the October release. Fingers crossed.
  • Filterdns has stopped resolving hostnames in firewall aliases

    42
    1 Votes
    42 Posts
    21k Views
    P
    @NWOSwamp said in Filterdns has stopped resolving hostnames in firewall aliases: There is a workaround using pfBlockerNG described here: https://forum.netgate.com/topic/199641/psa-domain-name-based-aliases-filterdns-can-fail-silently-use-pfblockerng-instead Good call. A work around which uses this seams to work Leave all generic pfsense Alias definitions, associated port forwards and firewall rules using them as they are. For all alias containing at least one FQDN and more than one entries, for which you want the associated filter to not miss IP addresses (and you can not guarantee there will ever be any duplicates): create an equivalent alias in pfblockerNG (as described above). Give it the same name as the associated generic alias in pfsense (pfblocker will prepend "pfb_" to the name you specify) Clone the associated port forward / firewall rule. Type "pfb_" in front of the alias name & accept the full name pfsense provides in the drop down list. Save the new port forward / firewall rule. The end result is alias / port forward Provides rapid FQDN tracking response (but will miss an IP addresses after the duplicate count decreases). Provides an accurate IP address filter set (particularly for more important IP addresses which have been included for more than one reason) but is updated more slowly (hourly or less often) So not as clean as pfsense aliases actually working reliably, but it is a solution.
  • 0 Votes
    1 Posts
    561 Views
    No one has replied
  • Kea-dhcp Static Mapping DHCPv6 issue

    5
    0 Votes
    5 Posts
    2k Views
    M
    @Gertjan @Gertjan said in Kea-dhcp Static Mapping DHCPv6 issue: So you have 3.0.2 also. Aha! So that's something I was unaware of. No wonder Kea is such a pile of crap on CE - it's still using 2.6.2
  • Created a new template for monitoring Unbound with Zabbix

    3
    2 Votes
    3 Posts
    2k Views
    B
    @wheel5up is there a version of this without paywall?
  • 0 Votes
    10 Posts
    4k Views
    W
    @scottlindner So this worked for resolving the DDNS issues. The question is: why and what is the real fix?
  • DHCP clear lease option not working

    2
    0 Votes
    2 Posts
    1k Views
    J
    Not sure what other than restore configuration but the option is now back and working again. I tried the restore earlier and no help but logging out and trying again about 30mins later and now it's working again
  • 0 Votes
    7 Posts
    3k Views
    L
    @Gertjan and @giuliafw70, thank you both! Guest network has been stable several days now. Will reopen if it recurs.
  • 0 Votes
    7 Posts
    3k Views
    D
    I think I tracked it down. The SRV query appears to belong to the repository agent (pfSense-repoc). It's trying to find the closest or most available update mirror. I ran the following: pkg -d update The results showed pfSense stuck in a loop checking for system updates. Netgate's repository servers (pfsense-plus-pkg01 and pkg00) were actively rejecting your firewall's built-in client certificate at the application layer, throwing an HTTP 400 Bad Request. Because of this failure, the pkg tool mistakenly attempted to resume partial downloads using bad byte ranges, causing it to endlessly cycle between mirrors and throw erratic errors. Additionally, this update routine caused the firewall to query netgate.com as a relative name, resulting in the netgate.com.foo.org that I saw in the BIND logs. I resolved this as follows: rm -rf /var/db/pkg/repos/* Wipe out the corrupted metadata cache and clear the broken partial download states that were driving the infinite loop. pfSense-upgrade -cc Clean the internal upgrade utility cache. This forced the firewall to dump the stale SSL session tokens and request a fresh mutual TLS (mTLS) authentication challenge from Netgate's registration backend. -- Best regards
  • 0 Votes
    4 Posts
    2k Views
    johnpozJ
    @Feline not that I am aware no.. You able to do it with ntop pretty sure - but that wouldn't be doing it in pfsense state table - but in its own listing of traffic.
  • 0 Votes
    6 Posts
    3k Views
    M
    @marcosm , thanks, that fixed it: no dupes in unbound.conf in failover mode when the VIP and RA Subnet addresses are entered identically in the GUI. I don't know the exact release where the issue arose. My primary ISP has few outages nowadays. Failover definitely worked as recently as last year with similar (identical? ... can't recall) configs. That would have been on one or more of 24.11, 25.07, 25.11. Anyways, glad it's working now ... thanks again!
  • Kea DHCP does not give new IP addresses

    7
    0 Votes
    7 Posts
    5k Views
    stephenw10S
    Yup what are you testing in? That should be fixed in 2.8.1. You my have hit some edge case though.
  • Unique DNS to home Minecraft server.

    16
    0 Votes
    16 Posts
    6k Views
    N
    @Gertjan said in Unique DNS to home Minecraft server.: the LAN devices will never have access to this info. You told them top use another resolver = 1.1.1.1 and/or 1.0.0.1. Now you have to place your DNS override on '1.1.1.1' and '1.0.0.1' ... which is impossible In my distress I restarted pfsense. It has been working since then. I don't know what the problem was. The PTR record is now good, and it returns the correct IP address for the overwritten domain under both Windows and Linux. I am using the Community version and recently updated to the latest version, but I think this is impossible, but I can't say what could have caused the problem. Thank you very much to everyone for the constructive help and advice!!!!
  • KEA DHCP lease allocation and reclamation

    7
    0 Votes
    7 Posts
    3k Views
    E
    @cybis The referenced index.php and rfc8910.php only apply to captive portal so they won't help. It will be a while before the lease affinity issue is fixed in Kea and they likely have to fix it before pfSense adopts it. Even then, it will only be in the most recent release of pfSense so if you want to run CE, be prepared for a long delay. The longer you keep Kea running without a restart, the closer you are to a solution. Every Kea restart is a do over for IP allocation. You could also ensure your clients keep their leases active as in the static lease suggestion or long lease times that will survive the reboot but again, if they do ever timeout after a reboot, they have no affinity protection any more, even weeks later.
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.