<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[General pfSense Questions]]></title><description><![CDATA[Discussions about pfSense software that do not fit into one of the more specific categories below.]]></description><link>https://forum.netgate.com/category/38</link><generator>RSS for Node</generator><lastBuildDate>Sat, 09 May 2026 20:59:45 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/category/38.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 08 May 2026 19:44:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Unable to update repository pfSense (26.03)]]></title><description><![CDATA[I'm having the same issue :(
I was playing around with my install at home, and saw this error.
I thought I messed something up, so I reinstalled using the latest installer (netgate-installer-v1.2-RELEASE-amd64.iso).
This worked, but i'm still having errors and packages won't install :(
Probably something in the netgate infrastructure, let's hope that it works again tomorrow.
check_upgrade: "Updating repositories metadata" returned error code 1 @ 2026-05-08 22:22:27

Updating pfSense-core repository catalogue...
pkg: Failed to fetch https://pfsense-plus-pkg.netgate.com/pfSense_plus-v26_03_amd64-core/meta.conf: Problem with the local SSL certificate
pkg: Failed to fetch https://pfsense-plus-pkg.netgate.com/pfSense_plus-v26_03_amd64-core/meta.txz: Problem with the local SSL certificate
repository pfSense-core has no meta file, using default settings
pkg: Failed to fetch https://pfsense-plus-pkg.netgate.com/pfSense_plus-v26_03_amd64-core/data.pkg: Problem with the local SSL certificate
pkg: Failed to fetch https://pfsense-plus-pkg.netgate.com/pfSense_plus-v26_03_amd64-core/data.tzst: Problem with the local SSL certificate
pkg: Failed to fetch https://pfsense-plus-pkg.netgate.com/pfSense_plus-v26_03_amd64-core/packagesite.pkg: Problem with the local SSL certificate
pkg: Failed to fetch https://pfsense-plus-pkg.netgate.com/pfSense_plus-v26_03_amd64-core/packagesite.tzst: Problem with the local SSL certificate
Unable to update repository pfSense-core
Updating pfSense repository catalogue...
pkg: Failed to fetch https://pfsense-plus-pkg.netgate.com/pfSense_plus-v26_03_amd64-pfSense_plus_v26_03/meta.conf: Problem with the local SSL certificate
pkg: Failed to fetch https://pfsense-plus-pkg.netgate.com/pfSense_plus-v26_03_amd64-pfSense_plus_v26_03/meta.txz: Problem with the local SSL certificate
repository pfSense has no meta file, using default settings
pkg: Failed to fetch https://pfsense-plus-pkg.netgate.com/pfSense_plus-v26_03_amd64-pfSense_plus_v26_03/data.pkg: Problem with the local SSL certificate
pkg: Failed to fetch https://pfsense-plus-pkg.netgate.com/pfSense_plus-v26_03_amd64-pfSense_plus_v26_03/data.tzst: Problem with the local SSL certificate
pkg: Failed to fetch https://pfsense-plus-pkg.netgate.com/pfSense_plus-v26_03_amd64-pfSense_plus_v26_03/packagesite.pkg: Problem with the local SSL certificate
pkg: Failed to fetch https://pfsense-plus-pkg.netgate.com/pfSense_plus-v26_03_amd64-pfSense_plus_v26_03/packagesite.tzst: Problem with the local SSL certificate
Unable to update repository pfSense
Error updating repositories!

]]></description><link>https://forum.netgate.com/topic/200657/unable-to-update-repository-pfsense-26.03</link><guid isPermaLink="true">https://forum.netgate.com/topic/200657/unable-to-update-repository-pfsense-26.03</guid><dc:creator><![CDATA[bschapendonk]]></dc:creator><pubDate>Fri, 08 May 2026 19:44:17 GMT</pubDate></item><item><title><![CDATA[WAN disruptions with 802.1X Authentication Bridging]]></title><description><![CDATA[<p dir="auto">I am using <a href="https://docs.netgate.com/pfsense/en/latest/recipes/authbridge.html" target="_blank" rel="noopener noreferrer nofollow ugc">802.1X Authentication Bridging</a> in order to get my pfSense (Netgate 4200) directly connected to AT&amp;T. It's been working fine for 2 years.</p>
<p dir="auto">The other day my internet went down, I rebooted my router and when everything came back up, I started experiencing drops (1-2 seconds where I cannot ping anything outside my side of the router). <strong>These occur on a regular 40 second interval.</strong></p>
<p dir="auto">There are no logs in pfSense that correlate to this issue.</p>
<p dir="auto">I did see what seems to be a flicker on the port that connects the AT&amp;T RG (the bypassed RG) at the same time as the drops. When I remove the RG, the problem goes away (but I cannot leave it like that because it needs to re-authenicate me after a router reboot or any other timer it might have).</p>
<p dir="auto">I saw this on 25.x and now on 26.03 with no change in symptoms.</p>
<p dir="auto">Thoughts?</p>
]]></description><link>https://forum.netgate.com/topic/200656/wan-disruptions-with-802.1x-authentication-bridging</link><guid isPermaLink="true">https://forum.netgate.com/topic/200656/wan-disruptions-with-802.1x-authentication-bridging</guid><dc:creator><![CDATA[bplein]]></dc:creator><pubDate>Fri, 08 May 2026 15:14:43 GMT</pubDate></item><item><title><![CDATA[Custom ICAP to DLP]]></title><description><![CDATA[<p dir="auto">Is it possible to tweak ICAP settings and perform DLP content inspection using your own DLP server running as an ICAP server on the network?</p>
<p dir="auto">Thanks in advance.</p>
]]></description><link>https://forum.netgate.com/topic/200653/custom-icap-to-dlp</link><guid isPermaLink="true">https://forum.netgate.com/topic/200653/custom-icap-to-dlp</guid><dc:creator><![CDATA[abbu.rakesh]]></dc:creator><pubDate>Fri, 08 May 2026 05:50:57 GMT</pubDate></item><item><title><![CDATA[Acme certificate expiring notice after deletion]]></title><description><![CDATA[<p dir="auto">I used acme to create a duckdns certificate which i no longer need.<br />
i deleted the certificate, under certificate manager, but i keep getting notifications</p>
<pre><code>The following CA/Certificate entries are expiring:
Certificate: DuckDNS-xxxxxxx (68b14b77xxxxx): Expired 86 days ago @ 2026-05-06 03:01:00
The following CA/Certificate entries are expiring:
Certificate: DuckDNS-xxxxxxx (68b14b77xxxxx): Expired 87 days ago @ 2026-05-07 03:01:00
</code></pre>
<p dir="auto">Where is it coming from?</p>
]]></description><link>https://forum.netgate.com/topic/200648/acme-certificate-expiring-notice-after-deletion</link><guid isPermaLink="true">https://forum.netgate.com/topic/200648/acme-certificate-expiring-notice-after-deletion</guid><dc:creator><![CDATA[4o4rh]]></dc:creator><pubDate>Thu, 07 May 2026 11:43:47 GMT</pubDate></item><item><title><![CDATA[Pfsense crashing daily on protectli vault]]></title><description><![CDATA[@stephenw10 No worries, thanks for looking into this.
]]></description><link>https://forum.netgate.com/topic/200636/pfsense-crashing-daily-on-protectli-vault</link><guid isPermaLink="true">https://forum.netgate.com/topic/200636/pfsense-crashing-daily-on-protectli-vault</guid><dc:creator><![CDATA[kindlywasp]]></dc:creator><pubDate>Tue, 05 May 2026 17:39:42 GMT</pubDate></item><item><title><![CDATA[BSNMP causing massive memory use spikes since 26.03 update]]></title><description><![CDATA[I can confirm it is some kind of memory leak in BSNMPD. Both firewalls shows the BSNMPD process slowly but steadily allocating more and more memory. So this is very likely the same case/issue as the previously referenced thread. Let’s use that thread going forward and stop posting here :-)
]]></description><link>https://forum.netgate.com/topic/200635/bsnmp-causing-massive-memory-use-spikes-since-26.03-update</link><guid isPermaLink="true">https://forum.netgate.com/topic/200635/bsnmp-causing-massive-memory-use-spikes-since-26.03-update</guid><dc:creator><![CDATA[keyser]]></dc:creator><pubDate>Tue, 05 May 2026 16:37:49 GMT</pubDate></item><item><title><![CDATA[MFA for pfSense]]></title><description><![CDATA[@ortizat Kind of.  pfSense supports TOTP logins via the FreeRadius package.
]]></description><link>https://forum.netgate.com/topic/200632/mfa-for-pfsense</link><guid isPermaLink="true">https://forum.netgate.com/topic/200632/mfa-for-pfsense</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Tue, 05 May 2026 14:05:17 GMT</pubDate></item><item><title><![CDATA[Rogue DHCP Server]]></title><description><![CDATA[@JKnott said in Rogue DHCP Server:

then a request from the client and finally an acknowledge from the server.

Right. I guess I forgot (or never knew!) that the dhcprequest is also broadcast the first time. At lease renew it is unicast which is what you more normally see.
]]></description><link>https://forum.netgate.com/topic/200630/rogue-dhcp-server</link><guid isPermaLink="true">https://forum.netgate.com/topic/200630/rogue-dhcp-server</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Tue, 05 May 2026 06:18:17 GMT</pubDate></item><item><title><![CDATA[pfsense hardware failure(?)]]></title><description><![CDATA[@lkh your best bet is to attach keyboard and monitor, everytihng else is just guesswork. If you have not changed anything else in your infrastructure (switch, cables, etc.) then hardware failure is a likely scenario.
]]></description><link>https://forum.netgate.com/topic/200621/pfsense-hardware-failure</link><guid isPermaLink="true">https://forum.netgate.com/topic/200621/pfsense-hardware-failure</guid><dc:creator><![CDATA[patient0]]></dc:creator><pubDate>Sat, 02 May 2026 19:35:51 GMT</pubDate></item><item><title><![CDATA[RESOLVED - 26.03 - Failure updating ACME certificate]]></title><description><![CDATA[@Gertjan
Thank you!
The link you provided : https://github.com/acmesh-official/acme.sh/issues/6851
is the solution, so I created a new ‘Token’ with
domain:read
dns:read
dns:write
I put the ‘code’ in place of the other one, and miraculously, it's finally working now
[image: 1778154784906-0dacebe3-c924-49f0-abbd-992b82bd738e-image.png]
As for the second one, I’ve tried too many times and I’m stuck until tomorrow evening, but I’m confident because I’ve made the same changes
I know I’m repeating myself, but thank you again for all your help 
]]></description><link>https://forum.netgate.com/topic/200619/resolved-26.03-failure-updating-acme-certificate</link><guid isPermaLink="true">https://forum.netgate.com/topic/200619/resolved-26.03-failure-updating-acme-certificate</guid><dc:creator><![CDATA[SwissSteph]]></dc:creator><pubDate>Sat, 02 May 2026 06:06:53 GMT</pubDate></item><item><title><![CDATA[eed Help: Portal Account Not Provisioned &#x2F; Cannot Access Subscription]]></title><description><![CDATA[@Bruce11 if you know that you need a portal account (I wouldn't know what use that is) then maybe create a TAC support ticket?
https://www.netgate.com/tac-support-request
]]></description><link>https://forum.netgate.com/topic/200614/eed-help-portal-account-not-provisioned-cannot-access-subscription</link><guid isPermaLink="true">https://forum.netgate.com/topic/200614/eed-help-portal-account-not-provisioned-cannot-access-subscription</guid><dc:creator><![CDATA[patient0]]></dc:creator><pubDate>Thu, 30 Apr 2026 14:58:06 GMT</pubDate></item><item><title><![CDATA[I cannot get Dynamic DNS]]></title><description><![CDATA[@BlazeStar is your WAN marked as up in the 'Gateways' widget or under 'Status / Gateways'?
In the past people ran into similar issues when pfSense gateway monitoring thinks that the gateway is down.
And additionally: what monitoring IP is set for the WAN interface (System / Routing / Gateway)? Sometimes you can't use the ISPs gateway IP for monitoring of PPPoE connections since this IP is not ping-able. You would have to use another public IP, like 1.1.1.1 or 8.8.8.8 or 9.9.9.9.
]]></description><link>https://forum.netgate.com/topic/200610/i-cannot-get-dynamic-dns</link><guid isPermaLink="true">https://forum.netgate.com/topic/200610/i-cannot-get-dynamic-dns</guid><dc:creator><![CDATA[patient0]]></dc:creator><pubDate>Wed, 29 Apr 2026 18:41:06 GMT</pubDate></item><item><title><![CDATA[Wireguard using Proton configs and pfsense 2.7.2]]></title><description><![CDATA[I suggest following the Netgate docs for any steps related to pfSense. Unless Proton is using a custom WireGuard implementation I see no reason for there to be any compatibility issues. Part of what makes WireGuard configuration on pfSense more involved is the flexibility to support many scenarios. Granted an import/export feature like the OpenVPN service has would certainly be nice.
https://docs.netgate.com/pfsense/en/latest/recipes/wireguard-client.html
]]></description><link>https://forum.netgate.com/topic/200608/wireguard-using-proton-configs-and-pfsense-2.7.2</link><guid isPermaLink="true">https://forum.netgate.com/topic/200608/wireguard-using-proton-configs-and-pfsense-2.7.2</guid><dc:creator><![CDATA[marcosm]]></dc:creator><pubDate>Wed, 29 Apr 2026 03:33:03 GMT</pubDate></item><item><title><![CDATA[SSl certificates for all home network]]></title><description><![CDATA[@Gertjan yeah I think there are some ways to do acme via script via the new os server.. But I just installed my own, and its good til 2035 ;)
[image: 1778173237048-osserver.jpg]
]]></description><link>https://forum.netgate.com/topic/200605/ssl-certificates-for-all-home-network</link><guid isPermaLink="true">https://forum.netgate.com/topic/200605/ssl-certificates-for-all-home-network</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Tue, 28 Apr 2026 07:54:23 GMT</pubDate></item><item><title><![CDATA[Tftp-proxy between two subnets - reply blocked]]></title><description><![CDATA[Looks like it need to test this out with an updated system.  I'm still running 25.07.1
]]></description><link>https://forum.netgate.com/topic/200604/tftp-proxy-between-two-subnets-reply-blocked</link><guid isPermaLink="true">https://forum.netgate.com/topic/200604/tftp-proxy-between-two-subnets-reply-blocked</guid><dc:creator><![CDATA[opoplawski]]></dc:creator><pubDate>Mon, 27 Apr 2026 19:20:59 GMT</pubDate></item><item><title><![CDATA[pfsense plus - crypto Accelerator Wireguard &#x2F; OpenVPN &#x2F; IPsec]]></title><description><![CDATA[@tinfoilmatt said in pfsense plus - crypto Accelerator Wireguard / OpenVPN / IPsec:

If the FreeBSD driver supports them.

We see what you did there.

Well there are some newer CPUs with QAT that are not yet supported at all by the driver shipped in pfSense. So YMMV!
]]></description><link>https://forum.netgate.com/topic/200600/pfsense-plus-crypto-accelerator-wireguard-openvpn-ipsec</link><guid isPermaLink="true">https://forum.netgate.com/topic/200600/pfsense-plus-crypto-accelerator-wireguard-openvpn-ipsec</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Mon, 27 Apr 2026 07:45:34 GMT</pubDate></item><item><title><![CDATA[Is the FreeBSD Remote Code Execution Vulnerability fixed in 26.03?]]></title><description><![CDATA[Generally. yes, we review FreeBSD CVEs and assess whether or not they apply to pfSense. A lot (most?  ) do not apply since pfSense is a very cut down subset of the FreeBSD code.
]]></description><link>https://forum.netgate.com/topic/200592/is-the-freebsd-remote-code-execution-vulnerability-fixed-in-26.03</link><guid isPermaLink="true">https://forum.netgate.com/topic/200592/is-the-freebsd-remote-code-execution-vulnerability-fixed-in-26.03</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Sat, 25 Apr 2026 15:35:17 GMT</pubDate></item><item><title><![CDATA[Crash Dump - 1st time, how or where should I share ?]]></title><description><![CDATA[Hmm, it could be just that testing. The dmesg logs have no time stamps so it can be some time before the panic if nothing else is logged in between.
]]></description><link>https://forum.netgate.com/topic/200591/crash-dump-1st-time-how-or-where-should-i-share</link><guid isPermaLink="true">https://forum.netgate.com/topic/200591/crash-dump-1st-time-how-or-where-should-i-share</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Sat, 25 Apr 2026 15:17:10 GMT</pubDate></item><item><title><![CDATA[Fatal trap 12: page fault on pfSense 2.7.2]]></title><description><![CDATA[What does the backtrace in the crash report show?
]]></description><link>https://forum.netgate.com/topic/200583/fatal-trap-12-page-fault-on-pfsense-2.7.2</link><guid isPermaLink="true">https://forum.netgate.com/topic/200583/fatal-trap-12-page-fault-on-pfsense-2.7.2</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Fri, 24 Apr 2026 07:18:06 GMT</pubDate></item><item><title><![CDATA[Netgate 3100 - v25.11.1 - Sudden flood (228 messages A SECOND) of DHCPv6 syslogs]]></title><description><![CDATA[@stephenw10
I will not be able to get pcap as this is something that happened last week.
It occurred over a period of a few days, and our logging server locked-out the pfSense for exceeding the storage quota.
I will try to find what piece of office equipment was causing this.
I know very little about IPv6, but will enlist chatgpt to help me. 
]]></description><link>https://forum.netgate.com/topic/200574/netgate-3100-v25.11.1-sudden-flood-228-messages-a-second-of-dhcpv6-syslogs</link><guid isPermaLink="true">https://forum.netgate.com/topic/200574/netgate-3100-v25.11.1-sudden-flood-228-messages-a-second-of-dhcpv6-syslogs</guid><dc:creator><![CDATA[KB8DOA]]></dc:creator><pubDate>Wed, 22 Apr 2026 12:23:23 GMT</pubDate></item><item><title><![CDATA[NTP exposed to WAN by default]]></title><description><![CDATA[@dennypage said in NTP exposed to WAN by default:

specifying the listen by interface usually isn't necessary.

While I do agree here, I also think the ability to limit (when possible by the application/service) is a worth while security option to have. Should it be the number one priority - no prob not.  And since pfsense is a firewall, you do have complete control of who can talk to what service that might be running no matter what the service does for binding to IPs the device might have.
I mean quite often many services would be on device with only 1 interface anyway ;) So the ability to call out what specific interface/ip a service is bound to really becomes moot.  And it just makes it easier to setup to know that hey that service will listen to whatever IP the device has.
Back to the topic at hand, while ntp does out of the box listen on all IPs. Out of the box this would not be available via the wan no matter what IPs the service is actually listening on.  Seems the OP clearly was not using valid testing methods (nmap to a udp port) - where nmap in layman terms reports I can't tell there was no answer.
What I don't get is how you could interpret
(not open|filtered)
To you got a ntp response. Or any response at all.
Nor did they follow up with validation of what they thought they were seeing before jumping to the conclusion that somehow pfsense left this service open to the wan even with default deny on all interfaces out of the box.. The only sort of exception to this is while the lan also has default deny, out of the box a any any rule is created to ease setup.
]]></description><link>https://forum.netgate.com/topic/200569/ntp-exposed-to-wan-by-default</link><guid isPermaLink="true">https://forum.netgate.com/topic/200569/ntp-exposed-to-wan-by-default</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Tue, 21 Apr 2026 20:03:12 GMT</pubDate></item><item><title><![CDATA[Internal DNS only when VPN is up]]></title><description><![CDATA[@stephenw10 if so then means the they are available via public - so what is the point of the vpn? Just not understanding they are wanting to actually accomplish other than complexity.
If I want to resolve stuff on the other end of a vpn, I put in a domain override to go ask the the ns there for the domain at that site, done..
I am not understanding what exactly they are trying to accomplish here.. The use case makes no sense to me.
]]></description><link>https://forum.netgate.com/topic/200553/internal-dns-only-when-vpn-is-up</link><guid isPermaLink="true">https://forum.netgate.com/topic/200553/internal-dns-only-when-vpn-is-up</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sat, 18 Apr 2026 22:55:42 GMT</pubDate></item><item><title><![CDATA[ZFS Mirror replacing failed Drive]]></title><description><![CDATA[@stephenw10 Absolutely that was the first thing I did and I'm very glad I did to that or I would be in a right mess.
]]></description><link>https://forum.netgate.com/topic/200552/zfs-mirror-replacing-failed-drive</link><guid isPermaLink="true">https://forum.netgate.com/topic/200552/zfs-mirror-replacing-failed-drive</guid><dc:creator><![CDATA[VioletDragon]]></dc:creator><pubDate>Sat, 18 Apr 2026 20:53:42 GMT</pubDate></item><item><title><![CDATA[MTU on VLAN sub interface for WAN]]></title><description><![CDATA[@stephenw10 thank you, will test, currently running 26.03
]]></description><link>https://forum.netgate.com/topic/200548/mtu-on-vlan-sub-interface-for-wan</link><guid isPermaLink="true">https://forum.netgate.com/topic/200548/mtu-on-vlan-sub-interface-for-wan</guid><dc:creator><![CDATA[mikey_s]]></dc:creator><pubDate>Fri, 17 Apr 2026 15:18:13 GMT</pubDate></item><item><title><![CDATA[Netgate 6100 unstable since upgrade to 26.03]]></title><description><![CDATA[@dennypage yes, sorry, that is provided by HACS so you can ignore it.
]]></description><link>https://forum.netgate.com/topic/200547/netgate-6100-unstable-since-upgrade-to-26.03</link><guid isPermaLink="true">https://forum.netgate.com/topic/200547/netgate-6100-unstable-since-upgrade-to-26.03</guid><dc:creator><![CDATA[ChrisJenk]]></dc:creator><pubDate>Fri, 17 Apr 2026 13:31:51 GMT</pubDate></item></channel></rss>