Subcategories

  • Discussions and feedback related to this forum

    610 Topics
    3k Posts
    G
    @stephenw10 This is my final note since it seem you will always look at this as an endpoint. It doesn't appear, it actually is, the facts are the facts. Still, moderator usually have a way to remove posts and ban single users, not just the entire herd, or at least the ones use. Perhaps those are more advance, or perhaps netgate forums lack that functionality. I never said negate took this issue lightly, I was just looking for some feedback. I have seen this process many times and for the looks of it, pfsense CE is very much in maintenance mode. Just because netgate wants to be politically correct does not mean it is not. The fact are there and they are fallowing the same path as others did. Again, this subject is just becoming redundant and it is affecting other users in the forum.
  • Community Hiring and For Hire postings related to jobs that require pfSense software skills

    29 Topics
    117 Posts
    w0wW
    @sef1414 Name it "run.sh", copy to pf and chmod according documentation https://docs.netgate.com/pfsense/en/latest/development/boot-commands.html#shell-script-option You will see messages in the system log like those quoted in the script after logger command.
  • BOTIM Stopped to work

    2
    0 Votes
    2 Posts
    981 Views
    stephenw10S
    If it was working fine previously behind some other SOHO router then the most common things to check are: It requires UPnP. pfSense includes UPnP but it's disabled by default as it's a security risk. pfSense randonmises the source port of outgoing traffic when it's NAT'd and some older applications (notably VoIP or VPN) cannot handle that correctly. See: https://docs.netgate.com/pfsense/en/latest/recipes/nat-voip-phones.html#disable-source-port-rewriting Steve
  • This topic is deleted!

    2
    0 Votes
    2 Posts
    10 Views
    No one has replied
  • pfSense + Layer 3 + Access Point

    pfsense switch access point vlans
    16
    0 Votes
    16 Posts
    5k Views
    johnpozJ
    @zipping8761 haha - I warned you, but it a good learning experience ;)
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    17 Views
    No one has replied
  • IPsec statusall | status Description Field

    2
    0 Votes
    2 Posts
    1k Views
    stephenw10S
    The config description fields are not part of the IPSec connection, they are not listed there. You can see them as comments in /var/etc/ipsec/swanctl.conf. Steve
  • zpool scrub cron job (Solved)

    4
    1
    0 Votes
    4 Posts
    2k Views
    V
    So I did some more digging around. In short it doesn't look like there is a Trim command for ZFS that I can see UFS does have Trim capability as found here... https://forum.pfsense.org/index.php?topic=113803.msg633795#msg633795 On this thread... https://forum.netgate.com/topic/102088/trim-for-ssd/17 At the bottom you'll find... @kpa said in Trim for SSD: All SSDs have automatic wear leveling. What TRIM does is to mark disk blocks that are no longer in use as empty so that the wear leveling has more free space to play with. If your disks are mostly empty the wear leveling will never come to a situation where the unused blocks become scarce and there's no reason to enable TRIM. Apparently thought Trim is enabled by default on zfs and can be confirmed with... sysctl -a | grep _trim
  • Switching used

    6
    0 Votes
    6 Posts
    2k Views
    ?
    Yep i think i misunderstood. I read TOR as TNSR. In some cases you will be off the need to use routers also inside of your LAN network and pending on your network topology and network Layer(s) it might be good to know where exactly you should connect your TSNR router. Although im still curious as to what switching infrastructure is used. It is pending on your network topology and/or network Layer design. as an example; 2 core switches (redundant) - Core Layer2 TOR Switch in each of the Racks - Distribution Layer Access switches (stacked in ring) - Access Layer This can be differing from design to design and also where all these racks and/or switches will be installed. example: IT Room (Server room) with Core Switches on each stage of the building one rack with stacks and ToR the stacks are connected to the ToR and the ToRs are connected to the Core switch(es)
  • So, what's your thoughts on this behaviour?

    Moved
    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S
    Hmm, well that doesn't sound good. Maybe consider a different hypervisor if that's your main firewall.
  • 5G Modem

    14
    0 Votes
    14 Posts
    2k Views
    NollipfSenseN
    @dobby_ I am a Mikrotik fan and use the new RB450x2 to manage my LAN with pfSense as edge (WAN). I'll research what you presented (Tailscale) as it sounds interesting, thank you for sharing. Discovered this about new package coming: https://www.youtube.com/watch?v=Fg_jIPVcioY
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    3 Views
    No one has replied
  • Signature?

    Moved
    12
    3 Votes
    12 Posts
    2k Views
    randomaustralianR
    Well my profile page changed and has a lot more options. i assume that because i am now the 5 reputation that @johnpoz mentioned. thanks for the rep points who ever gave them.
  • _Still_ confused about licensing

    Locked Moved
    9
    0 Votes
    9 Posts
    2k Views
    J
    And the price of a Coke at McDonalds was $1…until It wasn’t. "Enjoy a refreshing Coke at McDonald’s in extra small, small, medium and large for $1 on the $1 $2 $3 Dollar Menu." [image: 1657144561444-image-26-resized.png]
  • PFSense + Teardop (VPS) and OpenVPN

    5
    1
    2 Votes
    5 Posts
    2k Views
    D
    @ddbnj I have been assured it's not a pfsense issue, it's a me issue.
  • Unable to post question, flagged as Spam

    6
    5 Votes
    6 Posts
    1k Views
    C
    @rcoleman-netgate it has now posted thanks
  • This topic is deleted!

    4
    0 Votes
    4 Posts
    59 Views
  • Cellular behind cgnat - cloudflared argo tunnel solution?

    3
    0 Votes
    3 Posts
    1k Views
    D
    @zeroflow Thank you for the link. Has anyone successfully done this? I don't want to go down this tunnel first.
  • Question about Chromium and pfsense

    3
    0 Votes
    3 Posts
    1k Views
    S
    @stephenw10 Thanks for the reply back, I was going to grab the “site not found message” and post it but I upgraded over the weekend to version 102.0.5005.115-1 from 102.0.5005.61 and seems to be working for both AP and pfsense. After I upgraded I clearly I didn’t try it again but now it seems to be working . I guess we could mark this resolved, thanks for your interest in helping
  • unifi-pfsense not working

    3
    0 Votes
    3 Posts
    1k Views
    A
    @picia1990 You can also run the stand-alone controller app on a Linux, Windows or Mac computer, as needed. It doesn't have to run all the time, like a physical controller does, or on a dedicated machine. Looks like they are calling it "Network Application" now, under the software section, not network controller anymore... https://www.ui.com/download/unifi/
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    5 Views
    No one has replied
  • State of the Union (in pfSense land) - Opinions?

    Moved
    37
    0 Votes
    37 Posts
    7k Views
    M
    Great thread you started. Im still new to the pfsense product line having come from other vendors. In the beginning, i was frustrated that there was feature incompleteness when compared to other products but I have since changed my mentality a bit The obvious fact that it's free and there is paid support behind it makes me feel comfortable deploying Just understanding the use case for the product. I see pfsense as a router and firewall (L4) first and foremost. The VPN functionality when used in an "as-is" deployment is very good. The problems start to come in when you now have a business requirement that a 10+ year old firewall OS doesnt even have a feature set for. Need traffic visibility? Nope. Simple things like, which IP is the top talker between 8am - 4pm. No historical data is found. Sure you can use darkstat but cmon....its more of a hack and it provides no meaningful data. There is no application awareness despite what the marketing on the netgate site will tell you. OpenAppID rules have not been maintained on pfsense since 2017. The metadata conf is updated yes but not the text rules. I could go on but why bother. My hope is that the pfsense+ train is where the added functionality will appear. I know it's something that people dont want to hear but if they charge for it down the line but has feature completeness in key areas identified in this thread then ill pay. pfsense CE will continue to be free. As others have said on other forums and even here, it's a great product but one should only deploy in SMB scenarios. If your company has any I.T. budget then more than likely they are going with a named vendor.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.