Subcategories

  • Discussions and feedback related to this forum

    610 Topics
    3k Posts
    G
    @stephenw10 This is my final note since it seem you will always look at this as an endpoint. It doesn't appear, it actually is, the facts are the facts. Still, moderator usually have a way to remove posts and ban single users, not just the entire herd, or at least the ones use. Perhaps those are more advance, or perhaps netgate forums lack that functionality. I never said negate took this issue lightly, I was just looking for some feedback. I have seen this process many times and for the looks of it, pfsense CE is very much in maintenance mode. Just because netgate wants to be politically correct does not mean it is not. The fact are there and they are fallowing the same path as others did. Again, this subject is just becoming redundant and it is affecting other users in the forum.
  • Community Hiring and For Hire postings related to jobs that require pfSense software skills

    29 Topics
    117 Posts
    w0wW
    @sef1414 Name it "run.sh", copy to pf and chmod according documentation https://docs.netgate.com/pfsense/en/latest/development/boot-commands.html#shell-script-option You will see messages in the system log like those quoted in the script after logger command.
  • Advantages to Plus

    21
    0 Votes
    21 Posts
    3k Views
    RobbieTTR
    @rcoleman-netgate said in Advantages to Plus: As of yet... it has not been approved -- That's unfortunate but there could be business decisions behind it. Netgate does not engage that hard with the European market or make any real effort to market their products here in the UK. The UK distributers don't exactly push the products either; one of them actively avoids calls when it comes to Netgate hardware, whilst the other openly comments that Netgate prices are just too high when compared to those in the US market. Still, pfSense and Negate do have an established customer base here so perhaps resources may become available at some point to look at markets dogged by PPPoE vs FreeBSD. Upstream changes are more challenging but I remain convinced that more can be done with tuning behind the scenes, triggered by the end-user when they select the PPPoE option on the GUI. One thing for certain is that high-bandwidth PPPoE is being deployed rapidly in some countries - the problem is only getting bigger. ️
  • 2.5GB LAN and WAN with RTL8125BG cards

    14
    0 Votes
    14 Posts
    6k Views
    stephenw10S
    Doesn't look like the driver is loading. Make sure the two lines are correct in loader.conf.local. Check the console output from the boot loader. It should show the modules being loaded or some error if it's not.
  • How to best secure a guest network

    7
    0 Votes
    7 Posts
    962 Views
    RobbieTTR
    @michmoor said in How to best secure a guest network: How exactly do you prevent "illegal stuff" if you can't prevent them from getting to those sites if they are not respecting the provided DHCP DNS server settings? I do my level best to stop the horrors of child abuse, starting with a filtered DNS provider, down to filtering at the router. I know that the determined criminal could get around these things but at least I can demonstrate that I did all I could to prevent it and that I keep full usage logs so the police could try and find them, should they ever arrive at the door with a warrant. ️
  • 1 Votes
    12 Posts
    1k Views
    johnpozJ
    @mer Yea this is a arris S33, yeah your 44 seems more like what I have been reading.. But from testing been doing since post I am seeing my full speed upload.. And it seems to back off do to isp shaping.. It starts off say 65ish, and then backs down to 55 what I have been seeing the last 24 hours testing multiple times during the day and during prime time - say 5pm to 10pm for people in using the net.. There is no way isp is going to do anything if I call and say hey I am seeing the speed I should be getting but think my levels are a bit low ;) hehe I was concerned when it first came back up was seeing low.. But maybe it just took a bit to adjust in, etc.. But have been seeing good since then... And last night I had multiple users streaming off my plex and I was sending 40 up, which is the limit I have set in plex... So even real world testing I seem to be getting what paying for - so false alarm it seems. Thanks a lot for posting your levels.. So like just now tested, paying for 500/50 and seeing this - so can't complain [image: 1686321248691-speed.jpg] moving to the docsis 3.1 vs old docsis 3 sb6190 modem sure had a nice effect on download.. And tested real world via transfers from one of my servers in NL, and yeah seeing better download for sure..
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    1 Views
    No one has replied
  • pfsense CE is not being worked on , errta

    10
    1
    1 Votes
    10 Posts
    2k Views
    Dobby_D
    [image: 1685856432618-2.7-devel-to-realease.jpg] So I think after the 23.05 became a release it should be going on faster as the past time.
  • DNS Resolver with link/url

    5
    0 Votes
    5 Posts
    870 Views
    S
    @rgbinfinity said in DNS Resolver with link/url: In the browser, I will access www.bing.com.br, instead of going to this site, pfSense will redirect to www.google.com Only a web server can do that sort of redirection. A DNS override will override the IP used but if you want the browser to change to "www.google.com" that cannot be done via DNS. https://docs.netgate.com/pfsense/en/latest/packages/haproxy.html or similar proxy package might be able to do that, I've never used one as we just set up redirects on our web servers. (found https://stackoverflow.com/questions/28530087/how-to-redirect-url-with-haproxy )
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    2 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    8 Views
    No one has replied
  • How to Install a package that is in FreeBSD freshports.org

    1
    0 Votes
    1 Posts
    250 Views
    No one has replied
  • What is VLAN, why and how

    4
    0 Votes
    4 Posts
    620 Views
    Dobby_D
    @Sergei-0 said in What is VLAN, why and how: What do I risk? Do I manage firewall to each VLAN? Perhaps I need some links to good introduction materials. Like all other things you may be false configurating. If you have enough LAN port you may be connect devices there directly, if not you may be connect a switch to one or more ports, but if it comes to something like WiFi let us say you may be able to set up multiple SSIDs and on top each in its own VLAN, so they are running all over one LAN port but being separated each from another. I would say if enough port are there you should go buy routing and firewall rules, if not or it comes to WiFi with several SSIDs you should take VLANs for it. VLAN Configuration
  • Debian Install behind the Pfsense in DMZ

    3
    0 Votes
    3 Posts
    631 Views
    DigiguyD
    @viragomann Greatly appreciate the fast response! Will give it a go per your suggestion/recommendations. I also thought about setting up with dhcp then analyze it. Will keep on truckin!
  • [Solved] Draytek Vigor 166. Frequently dropped connection.

    23
    0 Votes
    23 Posts
    8k Views
    Y
    @youngy Just to round off this thread, I contacted Draytek again and they supplied two alternative firmware for the Vigor 166. One of them (r15597_791_9cf83135b_beta) has been running for > 2 days without a dropped connection. Fingers crossed, that's given me a usable modem. Thanks for all your contributions.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    2 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    2 Views
    No one has replied
  • CVE forum discussion categories?

    vulnerability
    20
    2
    1 Votes
    20 Posts
    3k Views
    JonathanLeeJ
    I got rid of some multiples in CURL and Strongswan by installing and uninstalling the package NUT again. NUT had some left over files from the last pfSense version. [image: 1684851839782-screenshot-2023-05-23-at-7.23.13-am-resized.png]
  • Convert .crt to .pem TLS 1.3 helppp

    11
    0 Votes
    11 Posts
    2k Views
    M
    @johnpoz said in Convert .crt to .pem TLS 1.3 helppp: Looking in my acme folder I see pem files hmmm, weird.. these are the files I copied from /tmp folder in pfsense once the certs were generated: ~/certs$ ls -lah total 44K drwxr-xr-x 3 root root 4.0K Apr 5 20:09 . drwxr-xr-x 8 pi pi 4.0K May 19 21:23 .. -rw-r--r-- 1 root root 3.7K Apr 5 20:07 ca.cer -rw-r--r-- 1 root root 5.6K Apr 5 20:07 fullchain.cer -rw-r--r-- 1 root root 1.9K Apr 5 20:07 mycert.cer -rw-r--r-- 1 root root 826 Apr 5 20:07 mycert.conf -rw-r--r-- 1 root root 1.1K Apr 5 20:07 mycert.csr -rw-r--r-- 1 root root 220 Apr 5 20:07 mycert.csr.conf -rw------- 1 root root 1.7K Apr 5 20:07 mykey.key Edit: Did you tick that option "Write Certificates" ? [image: 1684841658591-0649101d-a57e-4f69-bd83-f184917541cd-image.png]
  • Connecting a Netgate 4100 with a Ubiquiti Dream Machine

    3
    0 Votes
    3 Posts
    553 Views
    M
    @rcoleman-netgate Thanks. What I'm referring to is how they communicate. I have shut off DHCP and turned the firewall off on the Dream Machine since it's also a router and firewall. However, I'm unable to get out to the internet. I have LAN1 on the Netgate plugged into port 1 on the Dream Machine. I have LAN2 on the Netgate connected directly to the WAN port on the Dream Machine. Both LAN ports are on a different network but I still get reach the internet.
  • MultiSSID & VLAN Wifi Mesh?

    10
    1
    0 Votes
    10 Posts
    3k Views
    J
    @dobby_ Thank you for the information. It looks like I've been using the term Mesh in place of what I actually needed: efficient roaming. The unifi u6 Pros seem to allow for that to happen and from the looks of it I could change the RSSI settings myself. The Unifi U6 Pros, Unifi 8 POE switch, and pi4 + network controller is exactly what I needed. It was super easy to remove the 5x Netgear devices and drop in the Unifi devices with the same SSIDs and VLAN tagging. Thanks everyone!
  • Is it possible to serve time for Windows?

    11
    0 Votes
    11 Posts
    3k Views
    JonathanLeeJ
    This way it does not matter what requests it sends out the firewall responds [image: 1684180218241-19c8170c-fbb0-4529-aeee-02638e2ded94-image.png] Devices get requests sent to the firewall transparently, no more 1980s NTP protocol issues this way.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.