• Gateway Failover and Failback Thresholds

    3
    0 Votes
    3 Posts
    299 Views
    P

    @viragomann
    Thank you, I was assuming this would be under Gateway Groups, time to do some reading now!

  • Clients behind WireGuard-connected travel router can't use personal VPNs

    1
    0 Votes
    1 Posts
    131 Views
    No one has replied
  • dpinger not reliable - ping request/replies

    9
    0 Votes
    9 Posts
    702 Views
    patient0P

    @siegmarb said in dpinger not reliable - ping request/replies:

    no, i did not set the id manually

    Ok, seeing the same on 2.7.2 (I'm on 25.03-BETA on prod), that's normal then.

  • Load balancing on an SG-2100 works but failover doesn't

    5
    0 Votes
    5 Posts
    410 Views
    A

    @SteveITS the issue of duplicate IP#s is one that I didn't see (or that didn't strike me as odd for some reason, but you would be right). I need to set this aside for a couple of days and maybe pick it up after I get some higher priority issues taken care of. Thx.

  • Cannot communicate off-LAN after upgrade to 24.03

    2
    0 Votes
    2 Posts
    255 Views
    K

    @kj32

    User error. I found some old notes that included this observation:

    "Lan gateway should be defined under System | Routing, not interface."

    Removed the spurious definition under interface, and now it works again.

  • Multi-Wan Comcast And Starlink - dpinger restarts every few minutes

    8
    0 Votes
    8 Posts
    746 Views
    S

    I am hoping this fairly ancient -5100 appliance holds on. It's been through a lot including several dead cable modems. However, physical intervention has to wait until my next in-person visit. I only have non-technical people on site (as indicated by the hard power off recovery).

    The site is in an area with buried cable and a high water table which is a recipe for disaster (eats a cable modem every 18 months) and explains the starlink back-up. We use tailscale so remote access is fairly tolerant of CGNAT and our windows DC / local users can phone home and network admin can remote in. When the comcast circuit is down I lose remote admin via the fqdn/public IP which is stressful as I'm reliant on tailscale coming up using starlink.

    As a first order trouble shooting step I'm stepping up a local VM as a tailscale client to give myself a back door if the netgate box becomes unreachable again and potentially to automatically attempt a pfsense reboot in the event of a sustained loss of connectivity.

    I will experiment with turning off gateway monitoring after that and watch for physical events. Next time I'm on site I'm going to insert a fiber media converter between the cable modem and the netgate (or it's successor if I can get the budget for it) to remove physical plug events from cable modem reboots and risk of electrical shocks on the wan port.

  • Configuring DMZ hosting for my new pfsense , on my home router

    21
    0 Votes
    21 Posts
    2k Views
    G

    @netblues And UPnP is also port forward.. just automagic. But as I said, never got it to work behind private IP using STUN. There is a feature request active to get a setting to allow UPnP to accept WAN with private IP though...

  • Installing pfsense without ISP router on Bridge-Mode

    12
    0 Votes
    12 Posts
    896 Views
    E

    If the OP needs remote access or host services, they should be using a VPN like Tailscale, which will traverse any level of NAT, including CGNAT

  • HA Setup

    11
    0 Votes
    11 Posts
    791 Views
    patient0P

    @laurens-DS said in HA Setup:

    The problem was I had WAN2 set up but nothing stuck in yet because I don't have a 2nd provider right now

    That is not the classic HA from the documentation. What you're want to do is HA with Multi-WAN.
    Have a read through Netgate doc: High Availability Configuration Example with Multi-WAN.

  • Problem with Forcing Asymmetric Traffic Through Specific Gateway

    7
    0 Votes
    7 Posts
    424 Views
    P

    @viragomann
    Hello,

    Thank you for your help. I changed the default routing to create an additional static route for this unique IP, in order to replace the subnet route. And for accesses that require it, I create policy-based rules.

    Have a very good day.

  • 0 Votes
    1 Posts
    128 Views
    No one has replied
  • Static Route Across Subnets?

    12
    0 Votes
    12 Posts
    696 Views
    D

    I finally got Ping working in Windows. Had to accept ANY source for Remote Address in Windows Defender Firewall for Private.Public Profile.
    And I am getting sub ms response times from the Pi to Windows (~0.56ms). So the route seems to be direct without any detours.

    Traceroute still fails, but that could be the ISP modem/router not allowing it.

    So, it appears ~75Mb/s is the best I can expect. 5x faster than before!!!

    Thanks Everyone!

    P.S. ICMP also needed to be added to the Firewall Rules in pfSense on the WAN interface to allow Pings through

  • [SOLVED] Need Help: Can't Reach Host from VPN Network

    3
    0 Votes
    3 Posts
    262 Views
    manjotscM

    @patient0 Thank you

  • 0 Votes
    9 Posts
    470 Views
    chpalmerC

    @ddbnj Awesome!

  • Traffic through Site to Site Wireguard between pfsense and opnsense

    4
    0 Votes
    4 Posts
    332 Views
    V

    @drmarian0
    Yes, the rule should work.

    Ensure that the policy routing rule on pfSense is applied. Is it configured for any protocol? If it's TCP only ping will not work.
    Enable logging, then try to access a public IP and check the log
    after.

    Or run a packet capture on OPNsense on the WG interface to verify that the upstream traffic is routed over the VPN.

  • Loss of IPV4 address on PPPoE interface after reboot

    6
    0 Votes
    6 Posts
    475 Views
    S

    @MrHedgehog With any luck, this will be fixed in the next release of Plus and CE:

    Redmine: https://redmine.pfsense.org/issues/16103

    Meanwhile, anyone who continues to experience this problem can manually patch /usr/local/bin/ppp-linkdown.

  • Multi WAN and multiple gateway issue

    5
    0 Votes
    5 Posts
    397 Views
    T

    @viragomann said in Multi WAN and multiple gateway issue:

    The proper rerouting is controlled by the reply-to tag. Did you disable it in System > Advanced > Firewall & NAT or in the rule by any chance?

    Not disabled.

    I didn't look closely enough when reviewing the state tables to see if WAN2 was referenced when WAN1 should have been.

    Hopefully it never happens again, but I have some things to look into if I ever come across this again. Thanks for discussing it with me!

  • Not getting DHCP lease from Netgear LB1120 LTE Modem Bridged

    28
    0 Votes
    28 Posts
    1k Views
    M

    @michmoor

    Yeah could be broken in many ways. I haven't used it for anything else. Thankfully I got another spare port.

  • OpenVPN and dual WAN

    8
    0 Votes
    8 Posts
    350 Views
    V

    @hillblock
    The problem in this thread is that the VPN endpoint is not the default gateway. In this case an outbound NAT rule enables you to access the local network.
    But the NAT has no impact on accessing the web GUI of pfSense, since this traffic doesn't doesn't go out on an interface.

  • 0 Votes
    4 Posts
    295 Views
    V

    @AlcMat
    Sniff the traffic to see if the masquerading rule works properly.

    If it's fine that's all you can do on pfSense. Then there might be something wrong on the Windows machine.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.