• Android phone tethering

    3
    0 Votes
    3 Posts
    1k Views
    JKnottJ
    @zoltrix You might also get an IPv6 address, as IPv6 is a mandatory part of 4G & later. However, this depends on your carrier. Mine, Rogers, does it properly and tethered devices get an address. Another company (work phone) does a lousy job. However, since the phone doesn't provide prefix delegation, pfsense can't pass IPv6 on to the LAN.
  • NTPd which interfaces

    6
    0 Votes
    6 Posts
    746 Views
    A
    @stephenw10 ... ah I see. Thanks everyone, BRgds/Alan
  • Replacing failed router, how to restore config?

    Moved
    9
    0 Votes
    9 Posts
    860 Views
    RyanMR
    @stephenw10 sent you the IP address in a PM/chat. Thank you for trying this.
  • php error

    4
    0 Votes
    4 Posts
    560 Views
    stephenw10S
    You shouldn't have to. And even if you did it would probably just exhaust the new limit in a case like that. You need to locate the process that is running incorrectly if this is an ongoing problem. Steve
  • One VLAN, no connetion data

    22
    0 Votes
    22 Posts
    2k Views
    DenverDesktopsSupportD
    Nope. All is good. Thank you "all" for the assistance and quick response.
  • Show users logged in

    2
    0 Votes
    2 Posts
    245 Views
    stephenw10S
    Not in the webgui other than filtering the system logs. Steve
  • No more Internet access since yesterday afternoon.

    7
    0 Votes
    7 Posts
    751 Views
    stephenw10S
    If you ping 1.1.1.1 from a client on LAN and then look for that in the state table you should see something like this: [image: 1642770844568-screenshot-from-2022-01-21-13-12-52.png] So a state allowing it in on LAN and another state allowing it out on WAN and also NATing the source to the WAN IP (also a private IP in my example). Steve
  • Gateway dpinger errors

    3
    0 Votes
    3 Posts
    415 Views
    N
    @stephenw10 I never noticed any network interruption. I will check the link you sent, thanks.
  • 0 Votes
    3 Posts
    427 Views
    N
    @nollipfsense thanks! It seems better now. Comparing some traceroutes it looks like it was an issue after my ISP but before Netgates servers.
  • One or two CPUs?

    5
    0 Votes
    5 Posts
    711 Views
    L
    @stephenw10 It's a little confusing. I looked up the non V2 and the V2. Mine are 2.20Ghz at 95W. BX80621E52660.
  • 0 Votes
    3 Posts
    435 Views
    stephenw10S
    You cannot yet view backups except via the pfSense webgui. However you can use ACB on another pfSense instance to fetch a backup as long as you have the acb key and encryption pass phrase. Steve
  • userland calling deprecated sysctl, please rebuild world

    25
    0 Votes
    25 Posts
    2k Views
    stephenw10S
    Nice find.
  • Host OverRide for UnFi APs

    47
    0 Votes
    47 Posts
    8k Views
    stephenw10S
    Ah, well similar deal if the VPN client is routing all your traffic over the VPN.
  • Block most ports

    3
    0 Votes
    3 Posts
    474 Views
    stephenw10S
    Do you mean outgoing connections? You can allow only the ports you need. You will find there are a lot of ports you didn't realise you needed for most environments. Steve
  • Route traffic out and back in

    3
    0 Votes
    3 Posts
    482 Views
    stephenw10S
    Yeah, DNS override or NAT reflection: https://docs.netgate.com/pfsense/en/latest/recipes/port-forwards-from-local-networks.html Steve
  • AWS pfSense+ Loopback interface

    8
    0 Votes
    8 Posts
    842 Views
    stephenw10S
    Yes, the AWS AMI deploys with mobile IPSec configured but disabled. It has that VIP set to allow mobile IPSec clients to use it for DNS. Steve
  • Traffic Graphs

    6
    1 Votes
    6 Posts
    701 Views
    stephenw10S
    It's always by an interface perspective. How else could it be?
  • OPT1 needs LAN DNS access

    109
    0 Votes
    109 Posts
    20k Views
    L
    @johnpoz LOl, correct :). Thanks very much for all of your input. Even if I am not able to commit it all to memory, I have these threads to come back to when I'm stuck.
  • Weird DHCP server issue.

    9
    0 Votes
    9 Posts
    913 Views
    stephenw10S
    Clear those alerts and reload the filter in Status > Filter Reload to make sure the current ruleset is loading. Those pfBlocker errors are quite common at boot though and not usually a problem. Steve
  • Do the OpenSSH 7.9 CVEs apply to pfSense?

    6
    0 Votes
    6 Posts
    750 Views
    johnpozJ
    @skilledinept said in Do the OpenSSH 7.9 CVEs apply to pfSense?: -to see how readily is info like this available to scanner. you could turn off the banner, Not sure if pfsense allows for that in the gui? But if your allowed to talk to the ssh and try and negotiate a connection to "auth" you would still be able to get info like what algos and ciphers are possible. You could edit the sshd conf directly, but that would just get reverted on update, etc. Security scanners can be very useful - and fun even. But a lot of what they report really needs to be taken with a grain of salt, if not a whole freaking tablespoon of it ;) But it did do its job - it got you curious, and looking into, and now you prob make for a more secure setup even if what it had reported wasn't really valid ;)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.