• CARP VIPs or Other

    9
    0 Votes
    9 Posts
    480 Views
    M
    @viragomann said in CARP VIPs or Other: @mcury No, you need an interface IP and a CARP VIP in each VLAN. So the VLANs are defined on the lagg and you have to assign an interface and an IP to each on the primary and secondary. Then define the CARP VIP on each VLAN. Thanks for clarifying things for me viragomann
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    6 Views
    No one has replied
  • Load Balancer Query

    3
    0 Votes
    3 Posts
    232 Views
    Z
    @stephenw10 This is not pfsense specific, just a general NLB query. NLB > Unix vm's
  • 24.11 Firewall rules missing creation/modification date

    9
    0 Votes
    9 Posts
    727 Views
    stephenw10S
    Yup it's in the recommended patches list in the new patches package update.
  • Apply persistent standard log filter

    12
    0 Votes
    12 Posts
    701 Views
    GertjanG
    @LaUs3r Strange. I've created a "a;conf" with : !sshguard :msg, contains, ".*Exiting on signal.*" ~ ( No !, and I've added the ~ ) and restated the syslog daemon. No more [image: 1736423509794-a120a7e2-fd52-4575-a76d-9a05447f4ce2-image.png] for me.
  • The pfsense+ license has disappeared

    3
    0 Votes
    3 Posts
    354 Views
    stephenw10S
    If you send me your NDI in chat I can check it.
  • Egress traffic from LAN network not reaching WAN

    7
    0 Votes
    7 Posts
    340 Views
    stephenw10S
    Indeed! Even in that situation the gateway should not actually be on the LAN interface, just in the LAN subnet.
  • what could be the issue initial failure of duckduckgo

    10
    0 Votes
    10 Posts
    1k Views
    S
    Just add the following line to your DNS Resolver Custom options: local-zone: "duckduckgo.com" redirect [image: 1736366811328-7122c48a-ec9a-4c84-891f-223556326f35-image.png]
  • 0 Votes
    44 Posts
    6k Views
    stephenw10S
    Mmm, nothing terribly exciting there.
  • How to wake up monitor?

    2
    0 Votes
    2 Posts
    125 Views
    patient0P
    @coffeecup25 switching the monitor off and on may help. Or connecting a keyboard to pfSense and then press a key (not the reboot or shutdown key ;)).
  • pfSense behind ISP modem (Double NAT) trouble

    14
    0 Votes
    14 Posts
    1k Views
    C
    @Gblenn said in pfSense behind ISP modem (Double NAT) trouble: I kind of looks ok, although it's confusing to see that VID is listed as untagged for ports 1 - 10, which includes port 2. Perhaps it's a limitation of the UI, and I would have expected it to read 1, 3-10. Sicne you don't want any VID 1 traffic ending up on port 2... Are you sure you are actually seeing the devices picking up DHCP from pfsense or is it from the modem? I set port 2 to PVID 10 so the traffic from this port always falls into VLAN 10, I will try to disable this port for ID 1 however. Also I will do a pcap and report my results later.
  • Dev snapshot install?

    3
    0 Votes
    3 Posts
    156 Views
    stephenw10S
    We hope to have something sooner than that. But, as always, it depends how the development/testing goes.
  • Netgate 1100 bricked - any possibility to restore to factory?

    15
    0 Votes
    15 Posts
    784 Views
    stephenw10S
    When I did it I used a USB2 drive in the USB2 slot because when both drives are present it tries to boot from the USB3 slot first. You should be able to move it afterwards. It should at least recognise both drives in the boot messages if it is booting.
  • Access the GUI of a bridged modem with PPPoE and VLAN

    8
    0 Votes
    8 Posts
    317 Views
    stephenw10S
    Yes you should be able to access it be just assigning the VLAN parent interface and setting it in the same subnet as the modem admin page. As long as that doesn't conflict with any existing subnet on the firewall.
  • Awfully slow transfer speeds from remote NAS over ZeroTier

    12
    0 Votes
    12 Posts
    1k Views
    G
    @stephenw10 said in Awfully slow transfer speeds from remote NAS over ZeroTier: Yup good to know that about zerotier, I wouldn't have thought it was required. According to the documentation, it is not required for holepunching, but they do refer to challenges with symmetric NAT. https://docs.zerotier.com/corporate-firewalls/#:~:text=Default%20zerotier%2Done%20listening%20ports,ZeroTier%20hole%20punching%20to%20work)) @rheuer22 Perhaps try to set Static Port (Hybrid outbound rules), to see if that has a similar effect?
  • /mnt folder question

    11
    0 Votes
    11 Posts
    849 Views
    GertjanG
    @patient0 said in /mnt folder question: @Gertjan a bit further up stephenw10 wrote: I'm pretty sure the efi partition is mounted there to test at upgrade for example. ... that's why. That's why I replied ... it wouldn't mount in /mnt but somewhere in /mnt/somewhere/ That is, that is what I hope. Because, if not .... dono, that feels pretty dirty to me. What if I have a USB drive mounted (also) with my config.xml ? Anyway, just thinking out loud here.
  • How do I restart a service a minute or 2 after reboot?

    10
    0 Votes
    10 Posts
    518 Views
    P
    @SteveITS "sleep 60...." did it, thanks! Tested with a reboot and it did not sleep the reboot process either. Status > OpenVPN also shows the time (re)started correctly. Much appreciated and thanks to everyone for their help!
  • Migrating 24.03 to New Hardware

    3
    0 Votes
    3 Posts
    243 Views
    M
    @dacuda said in Migrating 24.03 to New Hardware: I originally was on CE, and took advantage of the free upgrade to plus when it was previously available. I was on the very similar boat and if you on free-upgrade (CE -> Plus) then tac-support won't do it. I was told that free upgrade is tied to the H/W, hence cannot be transferred. -S
  • chown use

    13
    0 Votes
    13 Posts
    874 Views
    patient0P
    @JonathanLee I'm sure someone with longer and deeper understanding of pfSense will be able to answer that.
  • Pfsense config becomes randomly corrupted on change

    7
    1 Votes
    7 Posts
    478 Views
    stephenw10S
    Hmm, odd. The routes should be added by the daemon when it connects as long as they are defined in tailscale as I understand it. But, yes, the tailscale interface is not expected to ever be assigned. It is not bypassed by the interfaces check at boot so will throw an error.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.