Subcategories

  • Bounties that have been completed and paid successfully

    37 Topics
    1k Posts
    ZedfulZ
    O o Thank You ! a PM is sent. This can be moved to "Completed Bounties".
  • Bounties that have been withdrawn by the original poster or that have expired due to lack of interest

    223 Topics
    3k Posts
    B
    I believe I’m having this issue, and have been for some time now. I always wondered why sometimes PPP would drop, and I’d drive out to site only to do a reboot and everything works. Sometimes I’d even have people put on site reboot for me, but it wouldn’t work. Is there any update on this issue? Below log is newest on top, so read in reverse. Feb 21 09:25:12 ppp 98216 [wan] IFACE: Down event Feb 21 09:25:08 ppp 98216 [wan] IPV6CP: LayerDown Feb 21 09:25:08 ppp 98216 [wan] IPV6CP: SendTerminateReq #38 Feb 21 09:25:08 ppp 98216 [wan] IPV6CP: state change Opened --> Closing Feb 21 09:25:08 ppp 98216 [wan] IPV6CP: Close event Feb 21 09:25:08 ppp 98216 [wan] IPCP: LayerDown Feb 21 09:25:08 ppp 98216 [wan] IPCP: SendTerminateReq #76 Feb 21 09:25:08 ppp 98216 [wan] IPCP: state change Opened --> Closing Feb 21 09:25:08 ppp 98216 [wan] IPCP: Close event Feb 21 09:25:08 ppp 98216 [wan] Bundle: Status update: up 0 links, total bandwidth 9600 bps Feb 21 09:25:08 ppp 98216 [wan_link0] Link: Leave bundle "wan" Feb 21 09:25:08 ppp 98216 [wan_link0] LCP: state change Opened --> Stopping Feb 21 09:25:08 ppp 98216 [wan_link0] LCP: peer not responding to echo requests Feb 21 09:25:08 ppp 98216 [wan_link0] LCP: no reply to 5 echo request(s) Feb 21 09:24:58 ppp 98216 [wan_link0] LCP: no reply to 4 echo request(s) Feb 21 09:24:48 ppp 98216 [wan_link0] LCP: no reply to 3 echo request(s) Feb 21 09:24:38 ppp 98216 [wan_link0] LCP: no reply to 2 echo request(s) Feb 21 09:24:27 ppp 98216 [wan_link0] LCP: no reply to 1 echo request(s
  • Commercial Support Available through the pfSense Portal

    Pinned Locked
    1
    0 Votes
    1 Posts
    4k Views
    No one has replied
  • Bounty board rules and guidelines - READ FIRST BEFORE STARTING A BOUNTY

    Pinned Locked
    1
    0 Votes
    1 Posts
    15k Views
    No one has replied
  • 0 Votes
    1 Posts
    8k Views
    No one has replied
  • Proposal to implement a Reverse Portal

    2
    0 Votes
    2 Posts
    232 Views
    J
    Rereading this I realize I didn't provide much context or frame the issue very well, and since I can't edit I'll post what the OP should have started with here. From the pfSense Docs: Captive Portal in pfSense software forces users on an interface to authenticate before granting access to the Internet. Where possible, the firewall automatically presents a login web page in which the user must enter credentials such as a username/password, a voucher code, or a simple click-through agreement. Users have made many requests for something similar, but for authorizing access into the intranet, instead of out to the internet. This is often called a "reverse portal". This would be useful for e.g. setting up MFA for wireguard vpn connections or requiring login to access a different segment of the local network. Unfortunately, despite being nearly identical in implementation, netgate explicitly states that their captive portal feature is not capable of acting as a reverse portal, aka authorizing access to the local intranet. One of the challenges with reverse portals is how to know when the user has disconnected and needs to reauthenticate. Here I propose a design where the user has to keep a browser tab with an open tcp connection (SSE with heartbeats) connected to the firewall to for the pass rule to be enabled; when the connection closes the pass rule is disabled and they will have to reauthenticate.
  • Bounty: $2000 for OpenMPTCProuter-like Functionality in pfSense

    15
    9 Votes
    15 Posts
    6k Views
    S
    @winkmichael Thanks so much. I'll look into it some more, but you were a great help. What I meant by a 0 point release is that is it basically an alpha or beta version until it reaches version 1.x This to me has historically been an indication that it shouldn't be deployed in mission critical spaces or commercial spaces, but good to hear it is very active and very reliable. thanks again
  • FQ_Codel IEEE pulse match rules/code/(applet?)/ $500

    4
    0 Votes
    4 Posts
    1k Views
    dennypageD
    @HLPPC said in FQ_Codel IEEE pulse match rules/code/(applet?)/ $500: Detection has to detect devices passing through managed switches to negotiate with the pSense, or correctly detect pulses while passing through pfSense in a bridge configuration to negotiate with a different device/router... Since auto-negotiation is not visible outside the two ends of the physical link, how would you expect this to work?
  • 0 Votes
    1 Posts
    321 Views
    No one has replied
  • ATT Uverse RG Bypass (0.2 BTC)

    555
    0 Votes
    555 Posts
    1m Views
    GPz1100G
    @jasonsansone I haven't tested the new pf versions yet. Will be starting my migration project in the next few weeks. The details are fairly self explanatory I thought. Basically openssl disables certain weaker ciphers. The config file re-enables them for the wpa_supplicant session. Depending on which wpa_supplicant is in use, this is either done simply through the wpa_supplicant.conf file (example at the end of the file), or through a config file for openssl that's referenced in the command line launching wpa_supplicant. @dreamdenizen Mac for wpa_supplicant doesn't have to be that of RG, or even RG where certs came from. What matters is the mac in wpa_supplicant.conf file match that of the wan interface mac requesting dhcp. Otherwise, you'll get eapol authentication, but never received an IP because of the mismatch.
  • Dpinger multiple targets - aka gwmond $2,500

    39
    1 Votes
    39 Posts
    14k Views
    R
    @dennypage said in Dpinger multiple targets - aka gwmond $2,500: I was referring to a traditional multi-wan situation in which you have two completely independent ISP connections, such as AT&T and Comcast. In this case you would want a monitoring target for WAN1 in the local region for ISP1, and a a monitoring target for WAN2 in the local region for ISP2 Ah sorry for the misunderstanding, besides the primary DIA WAN 1 connection, I also have a standard ISP connection for WAN 2. I get what you are saying though. Thanks for the help. I'll go with Cloudflare's IP for the time being until a solution like what was originally proposed can be implemented.
  • 0 Votes
    4 Posts
    1k Views
    L
    @dpsguard https://administrator.de/tutorial/freeradius-management-mit-webgui-6972997853.html
  • DNS and DHCP -> using different domains for each network - Bug #1819 - $150

    40
    0 Votes
    40 Posts
    16k Views
    M
    @johnpoz I agree on that, but multihoming is not why I have been supporting this tread. I would just like the subdomain/multible domain dns update to work. I would like to use dhcp to assign ip to my servers, and subsequently update dns (I admit I have not testet lately, but I still don't think dhcp/dns update allows for more that one domain).
  • I was told to post here...

    1
    0 Votes
    1 Posts
    471 Views
    No one has replied
  • Ignore me

    1
    0 Votes
    1 Posts
    454 Views
    No one has replied
  • 100 US dollars for working bhyve instructions on pfsense 2.2

    33
    0 Votes
    33 Posts
    20k Views
    N
    @viniciusferrao it's been a few years, but I followed this thread and ran into a similar issue that was ultimately due to hardware checksum offloading: https://docs.netgate.com/pfsense/en/latest/virtualization/virtio.html I wrote up a more complete post on the steps I took to get it working: https://n8henrie.com/2023/03/running-nixos-and-ubuntu-vms-on-pfsense-via-bhyve/, hope it's hopeful to someone!
  • Zerotier One as a package - $100USD

    100
    1 Votes
    100 Posts
    65k Views
    occamsrazorO
    So just for anyone who may have missed it.... While there's no news on the ZeroTier front, Netgate have now launched a package for Tailscale (a service providing similar functionality to ZeroTier) on pfSense that is very easy to set up and works very nicely. https://forum.netgate.com/category/89/tailscale
  • NTP - Add Peer - $100

    2
    0 Votes
    2 Posts
    2k Views
    C
    Thank you @viktor_g
  • 0 Votes
    120 Posts
    84k Views
    bingo600B
    @ethereal I was referring to the Raspberry Pi network interface , if you chose that for running ISC-DHCP-Server. Some might chose to get the cheaper "wireless only" Raspberry board. /Bingo
  • 0 Votes
    2 Posts
    1k Views
    P
    I didn't realize how dead this forum was when I posted. I guess this isn't going to happen. I'm going to try to find another solution instead of waiting for this to be fixed.
  • Temperature Fahrenheit /Celsius Option and Alarms

    25
    0 Votes
    25 Posts
    15k Views
    J
    Bump
  • Off-Topic: Captive Portal - Custom Portal development.

    Locked
    11
    0 Votes
    11 Posts
    4k Views
    J
    @charlesgardneryalantis Hi are you able to create self registration for captive portal?.. Need it ASAP.. If yes skype me on (jmiguel901)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.