Subcategories

  • Discussions and feedback related to this forum

    609 Topics
    3k Posts
    O
    When configured propertly Nginx.... For Netgate seems to be an issue
  • Community Hiring and For Hire postings related to jobs that require pfSense software skills

    28 Topics
    115 Posts
    w0wW
    @sef1414 Name it "run.sh", copy to pf and chmod according documentation https://docs.netgate.com/pfsense/en/latest/development/boot-commands.html#shell-script-option You will see messages in the system log like those quoted in the script after logger command.
  • Throughput test N3150N-D3V

    4
    0 Votes
    4 Posts
    2k Views
    PippinP
    Made time to test OpenVPN too. These tests where done from client to PFS to client. OVPN-Server: Remote Access (SSL/TLS+User Auth) udp tun tls static key 2048 Diffie Hellman 2048 Certs 2048 Encryption AES-256-CBC Auth digest SHA512 prng RSA-SHA512 32 fast-io tls-version-min 1.2 or-highest No hardware crypto selected No compression OVPN-Client export: dev tun persist-tun persist-key cipher AES-256-CBC auth SHA512 tls-client client resolv-retry infinite remote 192.168.11.200 1194 udp lport 0 verify-x509-name "OVPN-SERVER-CERT" name auth-user-pass ns-cert-type server comp-lzo no prng RSA-SHA512 32 tls-version-min 1.2 or-highest Clients connect with: Control channel: TLSv1.2 DHE-RSA-AES256-GCM-SHA384 2048 bit RSA PFS: System/ Advanced/ Miscellaneous - Cryptographic Hardware -> None VPN/ OpenVPN/ Servers/ Edit - Inter-client communication -> Allowed Command :iperf3 -c 10.0.10.3 -t 30 With above config: [ ID] Interval          Transfer    Bandwidth [  4]  0.00-30.01  sec  534 MBytes  149 Mbits/sec                  sender [  4]  0.00-30.01  sec  534 MBytes  149 Mbits/sec                  receiver Above + System/ Advanced/ Miscellaneous - Cryptographic Hardware -> AES-NI: [ ID] Interval          Transfer    Bandwidth [  4]  0.00-30.01  sec  530 MBytes  148 Mbits/sec                  sender [  4]  0.00-30.01  sec  530 MBytes  148 Mbits/sec                  receiver Above + OVPN-Server BSD cryptodev engine: [ ID] Interval          Transfer    Bandwidth [  4]  0.00-30.01  sec  523 MBytes  146 Mbits/sec                  sender [  4]  0.00-30.01  sec  523 MBytes  146 Mbits/sec                  receiver Above + add to client and server: sndbuf 524288 rcvbuf 524288 Which gave: [ ID] Interval          Transfer    Bandwidth [  4]  0.00-30.01  sec  538 MBytes  150 Mbits/sec                  sender [  4]  0.00-30.01  sec  538 MBytes  150 Mbits/sec                  receiver Above + no encryption cipher none auth none [ ID] Interval          Transfer    Bandwidth [  4]  0.00-30.01  sec  967 MBytes  270 Mbits/sec                  sender [  4]  0.00-30.01  sec  967 MBytes  270 Mbits/sec                  receiver I think the results for encryption and no encryption speak for themself. I don`t need big speeds for my home use but if someone has a idea for why enabling/disabling engine makes no difference, i would like to read it. What is this setting doing? For what does it apply? System/ Advanced/ Miscellaneous - Cryptographic Hardware -> AES-NI I did not test with that setting off and enabling only BSD crypto in OpenVPN Server, will do that next time.
  • How to figure out source of internet latency

    10
    0 Votes
    10 Posts
    3k Views
    K
    Run Ping Test. From the tools page, select Start, in the Ping Test (Real Time) box. This will advance you to a page indicating that all of the listed servers will be ping-ed twice per second and every thirty (30) seconds a report on your connection from A to F will be provided.
  • Can anyone help me pick a new switch?

    25
    0 Votes
    25 Posts
    6k Views
    F
    The Fastirons listed above have been replaced by the Fastiron FCX/SX series (maybe the ICX series as well, I'm more knowledgeable on their current carrier gear than I am edge switching), but expect $3,000 to $4,000 for base models and going up quickly from there. The stuff linked above for 30 bucks went for the same pricing when new years ago - if it makes you feel any better they're still actively updated, the firmware running on my GS was pushed out by brocade just a couple months ago
  • What's up with the "Community Edition" on the logo?

    Locked
    23
    0 Votes
    23 Posts
    7k Views
    C
    This has gotten way off topic and the politics has offended some, ending this thread here.
  • Backup pfSense via PHP + cURL

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Small fanless network device

    1
    0 Votes
    1 Posts
    714 Views
    No one has replied
  • 2.3 Firewall rules - I just noticed

    3
    0 Votes
    3 Posts
    1k Views
    D
    Now that's a handy little feature, especially when you go back to a box you've  been messin' with to get the rules right. Makes it easy to find all those spurious rules that do nothing at all in the end. 2.3 is a hit in my books so far, the 12 or so systems I've upgraded so far have been all smooth. Kudos for an excellent release  :D
  • PfSense Linux Port

    2
    0 Votes
    2 Posts
    1k Views
    H
    seems like a typo calling it a "linux router". but everything with a terminal is "linux" i guess
  • Looking for Linux System Admin that wants side work

    1
    0 Votes
    1 Posts
    660 Views
    No one has replied
  • Flash Fun

    1
    0 Votes
    1 Posts
    809 Views
    No one has replied
  • New Feature- Saving configuration temporary for sometime

    2
    0 Votes
    2 Posts
    913 Views
    P
    In pfSense terminology, you want to save the change (= update the config), press apply (for things that have an apply stage) to make it happen on the running system, then have another "confirm all is OK" button that you have to press within "x" minutes, otherwise the system reverts back to the previous config. That way you can wait a few minutes to see that you have not locked yourself out, and then press "confirm all is OK". If you get locked out then the system will revert back in a few minutes and (hopefully) you can get back in again. Mostly this sort of thing is great when you are messing with VPN settings on a remote box, using the VPN itself to make the changes.
  • Thank you for fixing bug #4387 international installer choices

    2
    0 Votes
    2 Posts
    863 Views
    C
    Thanks. It was one of those things that I saw and wondered "does anyone really care about this?" Glad to know someone does.  :)
  • New global mod in town - Not worth a message?

    10
    0 Votes
    10 Posts
    2k Views
    J
    Yes, Derelict is joining the team.  We only recruit the best. There is no need for Derelict to leave Vegas,  I was born and raised there, my father was born there, my grandfather moved there to work on Boulder/Hoover Dam.  My brother and mother are buried there.  My father, sister, aunt, nephews, nieces and cousins live in Vegas.  The Netgate warehouse was actually in Las Vegas for a couple years, not too far from where Derelict lives. In other words, al oeste Vegas es mi barrio. I threw down on the mod status because .. why not?  Dude works here (soon), he can be a force for even more good in the community.
  • OpenSSL and random numbers…

    1
    0 Votes
    1 Posts
    733 Views
    No one has replied
  • 2.3 upgraded flawlessly

    1
    0 Votes
    1 Posts
    780 Views
    No one has replied
  • Web Search Engines

    6
    0 Votes
    6 Posts
    1k Views
    K
    Forgot to add Yet!! :-)
  • PfSense Two-factor authentifaction

    21
    0 Votes
    21 Posts
    10k Views
    H
    development by copy-paste chaos Also known as full stackoverflow development.
  • Installation Newbee

    4
    0 Votes
    4 Posts
    1k Views
    P
    https://doc.pfsense.org/index.php/Installing_pfSense and lots of other docs at https://doc.pfsense.org/index.php/Main_Page
  • Recommendations for a connection monitor

    10
    0 Votes
    10 Posts
    3k Views
    KOMK
    For each host I'm checking (4 in my case), I created a batch file in the same folder as CheckHost with these contents: C:\Users\KOM\Software\NirCmd\nircmd.exe speak text "Google is not responding" 0 100 and save it as Google.bat.  Create other batch files to handle other hosts.  In CheckHost, I have an entry for Google DNS (8.8.8.8) and when down, I use Google.bat as the Start Program action.
  • There's no place like . . .

    1
    0 Votes
    1 Posts
    642 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.