• Terrapin SSH Attack

    Pinned
    33
    16 Votes
    33 Posts
    35k Views
    STLJonnyS
    @willowen100 It basically forces your ssh (on the Windows side) to utilize that encryption algorithm. You'll need to do that on any machine you ssh from. I'd have rather found a more elegant workaround (preferably on the pfSense side, so the mod only has to be done in one location), but this works in a pinch.
  • pfSense Hangouts are available on YouTube!

    Pinned Locked
    1
    5 Votes
    1 Posts
    13k Views
    No one has replied
  • Share your pfSense stories!

    Pinned Moved
    76
    0 Votes
    76 Posts
    66k Views
    V
    Mine may be typical, maybe not..... Took over a large sennior living facility with a pretty robust it infrastructure spread between 4 IT rooms, 23 access points, 12-14 switches, and 200 internal devices and 200 guest/resident devices, all being run by a Sonicwall TZ350. I had been wanting to reallign everything network wise for some time but the TZ had 2 ports that were failing. I had worked with ClearOS from back in the ClarkConnect days and started searching for something similar. I found PfSense and it just fit what I wanted to do. I tested it a bit on an old Athalon64x2 rig for proof of concept and had planned on installing on a mini pc or something, but I wanted 6 nics. Standing in my main IT room I looked down and in the bottom of the rack were 4 HP DL380s, 2 of which were decommissioned 2 years ago. It's such huge overkill for hardware that it's hard to explain, but who wouldn't want redundant power supplies, raid 60 with 25 drives and remote system monitoring through ILO? lol I spun one up and loaded PfSense and started tweaking. 2 weeks ago I switched over and have been working out gremlins since.. Overall it's gone well, just one snag that a couple members here have been very kind in helping me work out. Thank you to this page for all the help. [image: 1697753147328-pfsense1.png]
  • Periodic Panic on CE 2.8.0 - DHCP6 Client (I Think)

    5
    0 Votes
    5 Posts
    918 Views
    stephenw10S
    Ah, interesting. Yup AT&T expect to see their own router at the end of GPON/XPON and pfSense could well be doing something that doesn't play well. Obviously it still shouldn't panic like that. The panic appears to be caused by a race condition during removal of an IPv6 address. If the WAN was renewing a lease repeatedly that seems likely.
  • SSH inaccessibleupdate to version 25.07

    Moved
    21
    0 Votes
    21 Posts
    4k Views
    stephenw10S
    So you upgraded the secondary to 25.07 and it didn't hit the same issue?
  • if_pppoe ping works but dns doesn't?

    25
    0 Votes
    25 Posts
    4k Views
    stephenw10S
    It looks like the interface ends up with 2 public IPv4 addresses, is that expected? There are no large outgoing packets there at all. Something is clearly restricting it. Do you have that parent NIC assigned, for accessing the modem for example? It would be useful to prove you can send large packets on the NIC but outside the PPPoE. A pcap showing the same thing but using the mpd5/netgraph driver for PPPoE instead for comparison would be useful if you can get it.
  • Port Forwarding stopped working after upgrading to 2.8.0

    147
    0 Votes
    147 Posts
    12k Views
    stephenw10S
    What exactly are you counting as a leak test failure? If you're forwarding requests to Cloudflare then DNS tests will always show Cloudflare. It just might be local servers if the query isn't over the VPN.
  • PfSense 25.07.1 free radius error

    10
    0 Votes
    10 Posts
    1k Views
    stephenw10S
    Hmm, well it should start at boot. If it fails to start I'd expect some error to be logged.
  • Wireguard fails after reboot (2.8.0)

    40
    0 Votes
    40 Posts
    6k Views
    stephenw10S
    You could try an afterfilterchange shellcmd to trigger a script. That would be triggered when any tunnel comes up.
  • Crash report on CE 2.8.1

    9
    0 Votes
    9 Posts
    207 Views
    stephenw10S
    Hmm, OK. Not much to go on in that report unfortunately. If it does crash again comparing it would be useful. I'll see if anyone else sees anything I'm missing.
  • High CPU usage from egrep in pfSense+ v25.07.1

    17
    0 Votes
    17 Posts
    4k Views
    P
    @stephenw10 It's still showing a few simuleanteously, but every minute or so, not every other second like it was before.
  • pfsense OpenVPN Client with Multiple Connections/Tunnels

    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S
    You have to assign the OpenVPN client as a new interface so pfSense sees it as a WAN. It will then create a dynamic gateway for it you can use in a policy routing rule.
  • Troubleshooting WAN outage

    16
    0 Votes
    16 Posts
    3k Views
    stephenw10S
    Thanks for following up. Good result!
  • Is there a way to change pftop width in the GUI?

    1
    0 Votes
    1 Posts
    644 Views
    No one has replied
  • 0 Votes
    11 Posts
    423 Views
    stephenw10S
    Unlikely. The traffic handling for CP clients is identical in Plus.
  • crash dump 25.07.1

    2
    0 Votes
    2 Posts
    2k Views
    stephenw10S
    PHP Errors: [08-Sep-2025 00:01:03 America/New_York] PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 4096 bytes) in /usr/local/bin/kea2unbound on line 344 If you are using Kea, with DNS registration enabled, and pfBlocker with DNS-BL be sure to use Python mode to avoid the PHP memory limit. You can also increase the PHP max mem value in Sys > Adv > Misc. But that shouldn't be required if you're using Python mode.
  • Update Clarity

    25
    0 Votes
    25 Posts
    4k Views
    stephenw10S
    Oh yes there certainly are many users running VMs as edge on all hypervisors. I just wouldn't myself.
  • 25.7.1 package issue

    6
    0 Votes
    6 Posts
    4k Views
    S
    @hescominsoon said in 25.7.1 package issue: 25.07.1-RELEASE on both and yesw i access both in private mode which auto clears when i close the tab. Minor nitpick…Private/incognito tabs all share the same session so cookies/cache would clear when closing the window/all private tabs.
  • Switched to AT&T fiber, IPv6 tunnel broken

    44
    0 Votes
    44 Posts
    5k Views
    BiloxiGeekB
    @marcg I finally got the PD on the pfSense and I'm working through the reservations I had set to the tunnel so they get an reserved address within the PD. I had wanted to keep the tunnel from he.net but I never could get that working. If the BGW320 ever gets a different prefix I'll have to change any AAAA records at he.net's free DNS services. Won't be too difficult and I could script it through their API if it starts to happen often enough. I've had the same prefix for about a week now. Same IPv4 since I put the SG4200 online. I don't expect any changes but since I'm on the gulf coast it's somewhat likely that I could lose power and/or network for multiple days if a hurricane rolls through town. That could cause a change in the leases.
  • Order / Timing of Booting Modem and pfsense PC

    16
    0 Votes
    16 Posts
    498 Views
    N
    And 192.168.100.1 is part of the DOCSIS specification. That's because all cable modems run with this IP address.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.