• Terrapin SSH Attack

    Pinned
    33
    16 Votes
    33 Posts
    44k Views
    STLJonnyS
    @willowen100 It basically forces your ssh (on the Windows side) to utilize that encryption algorithm. You'll need to do that on any machine you ssh from. I'd have rather found a more elegant workaround (preferably on the pfSense side, so the mod only has to be done in one location), but this works in a pinch.
  • pfSense Hangouts are available on YouTube!

    Pinned Locked
    1
    5 Votes
    1 Posts
    17k Views
    No one has replied
  • Share your pfSense stories!

    Pinned Moved
    76
    0 Votes
    76 Posts
    70k Views
    V
    Mine may be typical, maybe not..... Took over a large sennior living facility with a pretty robust it infrastructure spread between 4 IT rooms, 23 access points, 12-14 switches, and 200 internal devices and 200 guest/resident devices, all being run by a Sonicwall TZ350. I had been wanting to reallign everything network wise for some time but the TZ had 2 ports that were failing. I had worked with ClearOS from back in the ClarkConnect days and started searching for something similar. I found PfSense and it just fit what I wanted to do. I tested it a bit on an old Athalon64x2 rig for proof of concept and had planned on installing on a mini pc or something, but I wanted 6 nics. Standing in my main IT room I looked down and in the bottom of the rack were 4 HP DL380s, 2 of which were decommissioned 2 years ago. It's such huge overkill for hardware that it's hard to explain, but who wouldn't want redundant power supplies, raid 60 with 25 drives and remote system monitoring through ILO? lol I spun one up and loaded PfSense and started tweaking. 2 weeks ago I switched over and have been working out gremlins since.. Overall it's gone well, just one snag that a couple members here have been very kind in helping me work out. Thank you to this page for all the help. [image: 1697753147328-pfsense1.png]
  • New version of unbound; can’t update with “pkg upgrade”

    11
    0 Votes
    11 Posts
    107 Views
    tinfoilmattT
    @stephenw10 I was disappointed, too.
  • Unexpected alias behaviour - two ranges

    30
    0 Votes
    30 Posts
    397 Views
    stephenw10S
    Yes you should be able to run that in either place. Though I would run it on the real command line if possible in case it does something unexpected.
  • Are pfSense repos okay?

    1
    0 Votes
    1 Posts
    27 Views
    No one has replied
  • 0 Votes
    11 Posts
    172 Views
    A
    @w0w As I had feared and mentioned initially, in fact, the local USB upgrade did in fact resolve the issue [image: 1762275420776-4ba9679f-d1fa-47d6-9f08-c438624b1777-image.png] edit: I have not the reputation to give you the thumb
  • Cannot Achieve 10g pfsense bottleneck

    53
    0 Votes
    53 Posts
    1k Views
    A
    @Laxarus said in Cannot Achieve 10g pfsense bottleneck: disabled HT but this did not make any difference Did you configure the NIC queues down to 4 as well and tested SpeedShift at Package Level? The hwpstate_intel driver works quite well with Broadwell CPUs and does shown improvements (according to your post) towards 6Gbps on your Skylake CPUs. Compared to your previous posted results, this is an improvement of almost 1Gbps. How is the throughput if you disable the firewall (pfctl -d) and use pfsense as router only. NAT won't be available once you disable the firewall. You can re-enable by running pfctl -e and it will load your last ruleset. If you don't see any significant difference with firewall disabled, you can be at least sure, it's not the firewall ruleset slowing things down. What about the interface counter on that Ubiquiti switch, especially the ones for the 25gbps Uplinks - are there any error counter / drops shown?
  • 0 Votes
    7 Posts
    5k Views
    stephenw10S
    Mmm, that can be better I agree. You probably get better throughput that way. I have that modem though and have never seen an issue with it.
  • pfSense Install Error Message

    9
    0 Votes
    9 Posts
    129 Views
    D
    @stephenw10 No. Installed it in Hyper V rather than Virtualbox. Interestingly, I received the same MiB notifications on Hyper V, but a minute later the install continued instead of "freezing" as with Virtualbox.
  • Syslog service in pfSense v2.8.1 often stop itself

    62
    2
    0 Votes
    62 Posts
    10k Views
    stephenw10S
    Yes, that's the bug discussed here. The workaround rules will prevent it. https://redmine.pfsense.org/issues/16362#note-5
  • Strange gateway behavior after ISP did upgrade (monitor IP fixed it)

    7
    0 Votes
    7 Posts
    94 Views
    C
    @SteveITS Right, that's what I felt. I guess from now on I will be adding external IP's to monitor gateway.
  • pkg broken in 25.07.1?

    16
    1 Votes
    16 Posts
    6k Views
    stephenw10S
    You should always be able to run pkg commands by using pkg-static even if it gets updated. Was that not the case?
  • Netgate pfsense plus detected a crash report

    2
    1
    0 Votes
    2 Posts
    70 Views
    GertjanG
    @CatSpecial202 said in Netgate pfsense plus detected a crash report: Maximum execution time of 900 seconds exceeded in /usr/local/bin/usermgrpasswd on line 54 Most probably, as this /usr/local/bin/usermgrpasswd is called from /etc/rc.initial (afaik), you've seen during initial login the moment where you have to (?) change the admin password. If you leave that screen open for more then 900 seconds, a PHP time out will occur. In that case, no big deal. Maybe you changed the password already in the GUI ... I'd say - not being a security expert - as this can only happen when you already have access to pfSense, this wasn't important. Not some one from the 'out side'.
  • Error since applying patch for Redmine 460345

    4
    0 Votes
    4 Posts
    72 Views
    w0wW
    @Mission-Ghost This patch needs new filterlog binary, I think. This should be included in the 25.11.
  • Safety of using SFP Transceivers

    23
    0 Votes
    23 Posts
    2k Views
    P
    We run quite a few 10G RJ45 SFP in various Juniper & Cisco & Allied Telesys switches in our work lab with no heat issues. Most of them are between 30-40 DegC in a room with 22 ambient. It's definitely the SFP cages in lower end switches. You can get refurbished Juniper QFX-5100 or similar on eBay for << £400 these days, and will have no more heat issues.
  • Tool: pfSense configuration redactor

    pfsense firewall redaction python3
    1
    3 Votes
    1 Posts
    58 Views
    No one has replied
  • Netgear WAX610 multicast packets showing up on multiple VLANS

    10
    0 Votes
    10 Posts
    153 Views
    M
    @dennypage said in Netgear WAX610 multicast packets showing up on multiple VLANS: @Mission-Ghost said in Netgear WAX610 multicast packets showing up on multiple VLANS: I ran a packet capture with Wireguard on all my VLANs last night and found no IGMP packets on any except the Entertainment VLAN where they belong. I would not look for IGMP packets, I would look for ANY packets with source addresses outside the local subnet, whether they be point to point, multicast or broadcast packets. I did that too and had the same results; nothing outside of each subnet found. Just reported IGMP since that was what was on my mind from the origin thread.
  • Identify modified system files

    6
    1 Votes
    6 Posts
    122 Views
    GPz1100G
    Note, when I do modify anything, I always save a backup with a .orig extension. Just need to do a diff between the two to see the actual changes.
  • Syslog generating logfiles, not sending to remote server

    18
    0 Votes
    18 Posts
    243 Views
    GertjanG
    @justincm said in Syslog generating logfiles, not sending to remote server: on the syslog server I can see in netstat that port 10000 is open Nuance : netstat will show a process that is 'bound' = listen on that port. If all goes well, it the syslog collector port. That doesn't mean it will actually receive traffic on that port, as the system firewall can still block incoming traffic. Example : on pfSense : [25.07.1-RELEASE][root@pfSense.bhf.tld]/root: sockstat -4 | grep 'nginx' root nginx 28252 5 tcp4 *:443 *:* root nginx 28252 8 tcp4 *:80 *:* root nginx 28139 5 tcp4 *:443 *:* root nginx 28139 8 tcp4 *:80 *:* root nginx 27732 5 tcp4 *:443 *:* root nginx 27732 8 tcp4 *:80 *:* This tells me that nginx, the pfSense web server GUI listen on all (!!) existing pfSense interfaces, and that includes the WAN interface(s). This doesn't mean that I, and the entire world, can access the pfSense GUI from WAN, as WAN firewall rules won't allow this to happen.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.