• Terrapin SSH Attack

    Pinned
    33
    16 Votes
    33 Posts
    37k Views
    STLJonnyS
    @willowen100 It basically forces your ssh (on the Windows side) to utilize that encryption algorithm. You'll need to do that on any machine you ssh from. I'd have rather found a more elegant workaround (preferably on the pfSense side, so the mod only has to be done in one location), but this works in a pinch.
  • pfSense Hangouts are available on YouTube!

    Pinned Locked
    1
    5 Votes
    1 Posts
    14k Views
    No one has replied
  • Share your pfSense stories!

    Pinned Moved
    76
    0 Votes
    76 Posts
    66k Views
    V
    Mine may be typical, maybe not..... Took over a large sennior living facility with a pretty robust it infrastructure spread between 4 IT rooms, 23 access points, 12-14 switches, and 200 internal devices and 200 guest/resident devices, all being run by a Sonicwall TZ350. I had been wanting to reallign everything network wise for some time but the TZ had 2 ports that were failing. I had worked with ClearOS from back in the ClarkConnect days and started searching for something similar. I found PfSense and it just fit what I wanted to do. I tested it a bit on an old Athalon64x2 rig for proof of concept and had planned on installing on a mini pc or something, but I wanted 6 nics. Standing in my main IT room I looked down and in the bottom of the rack were 4 HP DL380s, 2 of which were decommissioned 2 years ago. It's such huge overkill for hardware that it's hard to explain, but who wouldn't want redundant power supplies, raid 60 with 25 drives and remote system monitoring through ILO? lol I spun one up and loaded PfSense and started tweaking. 2 weeks ago I switched over and have been working out gremlins since.. Overall it's gone well, just one snag that a couple members here have been very kind in helping me work out. Thank you to this page for all the help. [image: 1697753147328-pfsense1.png]
  • Syslog service in pfSense v2.8.1 often stop itself

    1
    0 Votes
    1 Posts
    20 Views
    No one has replied
  • Port Forwarding stopped working after upgrading to 2.8.0

    152
    0 Votes
    152 Posts
    14k Views
    stephenw10S
    Anycast is a routing method for sending traffic to the nearest servers using the same IP. So here when you connect to 1.1.1.1 it goes to the closest servers. And when you connect to it over a VPN it goes to the closest servers to the other end of the VPN. That's important because if you check the resolve location it appears to be close the VPN location which is your source IP. Differences there can be used to detect connections using a VPN.
  • What is it? 25.11.a.20250916.0600

    8
    0 Votes
    8 Posts
    484 Views
    S
    @dennypage said in What is it? 25.11.a.20250916.0600: Dev build for 25.11: https://forum.netgate.com/post/1225827 The .a is an alpha release AFAIK.
  • ACB backup - issues with network interface config and package restore

    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S
    Mmm, it does seem like a bug. I'm surprised there isn't something open for it. I'll try to replicate it here and open something.
  • AI Copilot suggestion

    1
    0 Votes
    1 Posts
    164 Views
    No one has replied
  • Any updates on plans to make an arm64 image available?

    2
    0 Votes
    2 Posts
    358 Views
    S
    @rcfa They support ARM on Amazon: https://docs.netgate.com/pfsense/en/latest/solutions/aws-vpn-appliance/ I have no insight into Netgate's plans of course, but so far ARM support has been for Plus so I don't expect a CE ARM version if that's what you're asking.
  • curl backup fails sometimes with unexpected eof while reading

    1
    0 Votes
    1 Posts
    234 Views
    No one has replied
  • Subnet Mask Update

    5
    0 Votes
    5 Posts
    957 Views
    ARAMP1A
    @stephenw10 said in Subnet Mask Update: You need to set the subnet mask on everything static in the subnet. You probably still have somethings set to /24 creating route asymmetry when they try to use their gateway instead of sending directly. Everything appears to be working correctly now. I think this was it. I have an UnRaid server that I thought I changed the subnet mask but it didn't change. Actually have to stop the array and change it. After doing this, I'm back in business!
  • DNS resolver log-queries not working in 25.07

    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S
    You can just set the log level to query info in the Unbound advanced setting tab.
  • Pfsense crashed after upgrading from 2.7.2 to 2.8.1

    4
    0 Votes
    4 Posts
    2k Views
    stephenw10S
    Safest way is to backup the config from https://<your-firewall-ip>/diag_backup.php. Edit it then restore the config. That way pfSense will refuse to import it of you have typo'd something. Look in the config for the widgets section like: <widgets> <sequence>system_information:col1:open:0,disks:col1:open,interfaces:col2:open:0,services_status:col2:open:0,gateways:col2:open:0,snort_alerts:col2:open:0</sequence> <period>10</period> <gateways-0> <descr><![CDATA[Gateways]]></descr> <display_type>both_ip</display_type> <gatewaysfilter>WAN_DHCP6</gatewaysfilter> </gateways-0> </widgets> Remove the disks widget. So there I would remove: disks:col1:open, But the widget should be fine with just a ZFS mirror. What do you see from?: zfs list; mount -p; geom disk list;
  • if_pppoe ping works but dns doesn't?

    27
    0 Votes
    27 Posts
    6k Views
    stephenw10S
    Ok that will be useful. Also see if you can try running a dtrace whilst sending a failing large ping. So you'll need two ssh sessions open it, for the trace and for the ping. In the dtrace session run: dtrace -n 'fbt::if_inc_counter:entry / arg1 != 0 && arg1 != 2 && arg1 != 5 && arg1 != 6 / { printf("%s type %d count %d", ((struct ifnet*)arg0)->if_xname, arg1, arg2); stack(); }' Then send some large pings in the other session that should work but fail. Stop the dtrace with ctl+c after a few pings and see what's shown.
  • IPv6 Link Local in Interface Status

    4
    0 Votes
    4 Posts
    460 Views
    tinfoilmattT
    @azalea said in IPv6 Link Local in Interface Status: On the other hand, the OPT1 interface status display, NDP table display, and ifconfig execution results all show that the OPT1 interface (IPv6) is linked to "fe80::XXXX:XXXX:XXXX:XXXX%pppoe1 From the Wikipedia article: Even if a single address is not in use in different zones, the address prefixes for addresses in those zones may still be identical, which makes the operating system unable to select an outgoing interface based on the information in the routing table (which is prefix-based). [In this specific case, your WAN interface's link-local address of fe80::[EUI-64]/128 is the 'prefix' being referred to here] In order to resolve the ambiguity in textual addresses, a zone index must be appended to the address. [ . . . ] As multiple interfaces may belong to the same zone (e.g. when connected to the same network), in practice two addresses with different zone identifiers may actually be equivalent, and refer to the same host on the same link. fe80::[identical EUI-64]%ppoe0 and fe80::[identical EUI-64]%em0 are obviously not mutually exclusive addresses, even if both or neither are active at any given time on a given link. And the zone index in general can obviously refer to both, a physical or a logical network interface. The same goes for fe80::[identical EUI-64]%ppoe1 and fe80::[identical EUI-64]%em1 on the OPT1 interface. Agreed no problem here, just thought-provoking discussion (at least for me!) of an interesting IPv6 feature.
  • Periodic Panic on CE 2.8.0 - DHCP6 Client (I Think)

    5
    0 Votes
    5 Posts
    3k Views
    stephenw10S
    Ah, interesting. Yup AT&T expect to see their own router at the end of GPON/XPON and pfSense could well be doing something that doesn't play well. Obviously it still shouldn't panic like that. The panic appears to be caused by a race condition during removal of an IPv6 address. If the WAN was renewing a lease repeatedly that seems likely.
  • SSH inaccessibleupdate to version 25.07

    Moved
    21
    0 Votes
    21 Posts
    6k Views
    stephenw10S
    So you upgraded the secondary to 25.07 and it didn't hit the same issue?
  • PfSense 25.07.1 free radius error

    10
    0 Votes
    10 Posts
    3k Views
    stephenw10S
    Hmm, well it should start at boot. If it fails to start I'd expect some error to be logged.
  • Wireguard fails after reboot (2.8.0)

    40
    0 Votes
    40 Posts
    8k Views
    stephenw10S
    You could try an afterfilterchange shellcmd to trigger a script. That would be triggered when any tunnel comes up.
  • Crash report on CE 2.8.1

    9
    0 Votes
    9 Posts
    260 Views
    stephenw10S
    Hmm, OK. Not much to go on in that report unfortunately. If it does crash again comparing it would be useful. I'll see if anyone else sees anything I'm missing.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.