• Terrapin SSH Attack

    Pinned
    33
    16 Votes
    33 Posts
    45k Views
    STLJonnyS
    @willowen100 It basically forces your ssh (on the Windows side) to utilize that encryption algorithm. You'll need to do that on any machine you ssh from. I'd have rather found a more elegant workaround (preferably on the pfSense side, so the mod only has to be done in one location), but this works in a pinch.
  • pfSense Hangouts are available on YouTube!

    Pinned Locked
    1
    5 Votes
    1 Posts
    17k Views
    No one has replied
  • Share your pfSense stories!

    Pinned Moved
    76
    0 Votes
    76 Posts
    72k Views
    V
    Mine may be typical, maybe not..... Took over a large sennior living facility with a pretty robust it infrastructure spread between 4 IT rooms, 23 access points, 12-14 switches, and 200 internal devices and 200 guest/resident devices, all being run by a Sonicwall TZ350. I had been wanting to reallign everything network wise for some time but the TZ had 2 ports that were failing. I had worked with ClearOS from back in the ClarkConnect days and started searching for something similar. I found PfSense and it just fit what I wanted to do. I tested it a bit on an old Athalon64x2 rig for proof of concept and had planned on installing on a mini pc or something, but I wanted 6 nics. Standing in my main IT room I looked down and in the bottom of the rack were 4 HP DL380s, 2 of which were decommissioned 2 years ago. It's such huge overkill for hardware that it's hard to explain, but who wouldn't want redundant power supplies, raid 60 with 25 drives and remote system monitoring through ILO? lol I spun one up and loaded PfSense and started tweaking. 2 weeks ago I switched over and have been working out gremlins since.. Overall it's gone well, just one snag that a couple members here have been very kind in helping me work out. Thank you to this page for all the help. [image: 1697753147328-pfsense1.png]
  • Can somebody help me get to Yamaha YNCA throug a pfSense?

    4
    0 Votes
    4 Posts
    69 Views
    M
    OK, weirder... According to the Plug-in programmer it's a simple TCP socket connection to port 50000 on the reciever. So then I really don't undrestand why I can't connect!
  • Netgate blocked my public IP on ACB

    16
    0 Votes
    16 Posts
    271 Views
    G
    @SarahBrown13 Actually after a few days of discussions and examinations on TAC and here in the forum, my IP was unblocked. The guys were great. Only the technician who first responded to TAC cut short immediately, showing no desire to go into detail nor help me, which annoyed me quite a bit.
  • pfSense 2.8.1 no packages updates - reason?

    6
    1 Votes
    6 Posts
    194 Views
    S
    @ramup said in pfSense 2.8.1 no packages updates - reason?: Hello Netgate Team, I have pfSense 2.8.1 in use. Is there a certain reason why installed packages do not receive an update? I noticed that on the GitHub pages there are newer package versions, e.g. Backup latest 0.6.3 but 0.6.4 available Lightsquid latest 3.0.7_5 but 3.0.9 available pfBlockerNG-devel latest 3.2.10 but 3.2.12_4 available squid latest 0.5.3 but 0.5.8 available WireGuard latest 0.2.9_5 but 0.2.11 available Package versions on GitHub don’t always match what’s available through the pfSense repo. Netgate usually holds back newer package releases until they’ve been tested specifically against the current pfSense branch. So even if upstream or GitHub shows a newer tag, it won’t appear in the GUI until it’s validated for 2.8.1.
  • Different service status using pfSsh.php after Upgrade to 2.8.1

    2
    0 Votes
    2 Posts
    33 Views
    tinfoilmattT
    Same behavior here. Presumably it's the result of some permissions hardending. A user not privileged to modify an elevated service should not be able to determine the status of said service.
  • fe80::1:1 for ipv6 track interface causes a problem with Apple TV box

    8
    1 Votes
    8 Posts
    87 Views
    JKnottJ
    @akochetkov said in fe80::1:1 for ipv6 track interface causes a problem with Apple TV box: I cannot use "Managed" configuration as some my devices do not support DHCPv6 (SLAAC only). That's why I use SLAAC. Android devices don't work with DHCPv6.
  • Anyone Here Using telMAX (Ontario, Canada)

    3
    0 Votes
    3 Posts
    61 Views
    G
    @JKnott tldr; Own network. AFAIK they are only available in certain select areas (Aurora, Newmarket, Stouffville, and parts of Markham/Richmond Hill) where they have their own Fibre network. So far I have been very happy. When I was getting set up, I found their customer service team a refreshing change from Bhell and Robbers. Teksavvy also had decent customer support as well. It was so refreshing to find support people that know enough to have a meaningful technical conversation. A big plus is that I get an ONT in bridge mode and I don't have to deal with the pathetic consumer crap that Bhell and Robbers slop out. Robbers has the audacity to force a hidden WiFi that supports services to other customers that can't be turned off-went as far as the office of the President to get it turned off, and when they said NO, I ditched them and never looked back. This hidden WiFi not only adds to WiFi congestion, but it is likely a long term health hazard because the modem is under the desk and within 2 feet of where I sit for hours on end. From what I can telMAX is great, latency about 4ms jitter 1-1.5ms, speed saturates my 1G network gear (although the connection is supposed to be 2G bidirectional (measured with speedtest.net) -hence I'm thinking about some hardware upgrades. The reason for my post is that I am wondering if there is a slight difference in the "first hop" after pfSense. I do have some delays/slow response that I'm pretty sure is caused by improper configuration or possibly hardware issues. I had similar (but slightly different) issues with Rogers/Teksavvy. So far haven't had the time to troubleshoot. I saw a Youtube on Wireshark a while back that gave me hope that I might be able to determine if the issue is inside or outside the firewall, but I need to take some time to go over it. May also be that I have IPv6 disabled as well. That's why I was hoping to find someone who may have looked into the finer points. </EndRamble>
  • Cant get "Malicious" feed to work on pfBlocker

    7
    2
    0 Votes
    7 Posts
    111 Views
    stephenw10S
    If it's actually a DNS list and not IPs/subnets then it doesn't create an alias like that. If it is IPs you should add it via the IPv4 feeds not DNSBL
  • Short hangs happening randomly a few times a day

    5
    0 Votes
    5 Posts
    110 Views
    GertjanG
    @Xantra said in Short hangs happening randomly a few times a day: I do have pfblockerng .... Depending on the number of DNSBL files you use, and the 'mode' you use, and the frequency of updating, pfblockerng can 'spike'. All the DNSBL have to be synced, and re downloaded if updates are avaible. Then they are all added together in on big file. Then this file is parsed, one line at the time, for white listing. Then this file is parsed, one line at the time, to check for double (or more) identical lines. Normally, this mode should be used : [image: 1764317053862-c14745f2-d037-4bba-81c5-5057cb30cd06-image.png] as the old Unbound mode used a lot of resources, and unbound had a hard time to restart (it has to read in the main DNSBL file into memory).
  • Lots of Errors in on lan and errors out on AP

    15
    0 Votes
    15 Posts
    253 Views
    johnpozJ
    @Omission0832 who said anyone has to know everything? Your question is not what my point about is - my point is the numbers are insignificant to be concerned about. For all we know they happened when a device was shutting down or booting up, or you had a spike in traffic that caused some errors. you might want to look at netstat -s or netstat -sI interface for more detailed breakdown of errors. But unless you see constant increase in errors or a high percentage of errors compared to total packets I wouldn't worry about see a few errors on an interface. something this is 0.000X of your total packets is nothing to be worried about
  • 0 Votes
    9 Posts
    207 Views
    stephenw10S
    Ah, nice! Yeah in retrospect those 5K byte packets in the pcap should have been a clue. I missed that.
  • 0 Votes
    3 Posts
    157 Views
    R
    @marcosm Hi - Just an update on this. It turned out it was the ena cleanup job that's what causing the CPU spike. CPU 0: 0.0% user, 0.0% nice, 100% system, 0.0% interrupt, 0.0% idle C PID LWP C PRI STAT %CPU TIME COMMAND 0 100154 0 -64 RLs 100.0 11:22.91 kernel/ena0 queue 0 cleanu -- So basically - ena drops out, and then the cpu gets in a deadlock kind of situation where the ena cleanup job is stuck on one CPU. Has anyone experienced this random ena failures on AWS - When it happens, there's not a lot of traffic pressure nor the CPU was under load etc...it just happens randomly
  • Cannot Achieve 10g pfsense bottleneck

    64
    0 Votes
    64 Posts
    3k Views
    P
    Try using multiple parallel streams. I've never managed to get full speed over 10G interfaces on any hardware. -P, --parallel # number of parallel client streams to run
  • SG6100 SWAP full and high CPU - tweak suggestions?

    8
    3
    0 Votes
    8 Posts
    202 Views
    dennypageD
    @alnico said in SG6100 SWAP full and high CPU - tweak suggestions?: Interesting, I will start to disable WAN interface and then turn off/on each one as you have suggested and see how it goes Given that your original post shows ntopng at 39 hours of cpu, I think everything else is probably minor in comparison. As a starter, I would suggest disabling ntopng completely while you evaluate the rest of the system. Btw, when you get around to re-enabling ntopng, it might be easier to simply reset ntopng as a starting point rather than going through the ntopng UI to find everything that has been turned on.
  • Broadcom Net Extreme E Dual 10GB Card (dell server Poweredge R740)

    2
    0 Votes
    2 Posts
    63 Views
    stephenw10S
    Sounds like something is linked at 1G. The ISP equipment might be trying to link at 2.5G and the NIC doesn't support it. Try running at the command line: ifconfig -vma to see how the NICs are linked now and what they are capable of. Run pciconf -lv to see the actual device and vendor IDs for the NICs.
  • if_pppoe problems with php-fpm causing loops. (resolved)

    86
    0 Votes
    86 Posts
    19k Views
    C
    @stephenw10 Had a brief ISP outage and if_pppoe auto recovered. :)
  • Console access with MacOS 26.1?

    11
    0 Votes
    11 Posts
    260 Views
    A
    @beerguzzle as I mentioned before and luckman mentioned above Serial2 just works without any tweaking.
  • Crash Report Netgate SG2100

    3
    0 Votes
    3 Posts
    71 Views
    stephenw10S
    Yup that. But basically make sure you're using python mode.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.