• Terrapin SSH Attack

    Pinned
    33
    16 Votes
    33 Posts
    45k Views
    STLJonnyS
    @willowen100 It basically forces your ssh (on the Windows side) to utilize that encryption algorithm. You'll need to do that on any machine you ssh from. I'd have rather found a more elegant workaround (preferably on the pfSense side, so the mod only has to be done in one location), but this works in a pinch.
  • pfSense Hangouts are available on YouTube!

    Pinned Locked
    1
    5 Votes
    1 Posts
    17k Views
    No one has replied
  • Share your pfSense stories!

    Pinned Moved
    76
    0 Votes
    76 Posts
    72k Views
    V
    Mine may be typical, maybe not..... Took over a large sennior living facility with a pretty robust it infrastructure spread between 4 IT rooms, 23 access points, 12-14 switches, and 200 internal devices and 200 guest/resident devices, all being run by a Sonicwall TZ350. I had been wanting to reallign everything network wise for some time but the TZ had 2 ports that were failing. I had worked with ClearOS from back in the ClarkConnect days and started searching for something similar. I found PfSense and it just fit what I wanted to do. I tested it a bit on an old Athalon64x2 rig for proof of concept and had planned on installing on a mini pc or something, but I wanted 6 nics. Standing in my main IT room I looked down and in the bottom of the rack were 4 HP DL380s, 2 of which were decommissioned 2 years ago. It's such huge overkill for hardware that it's hard to explain, but who wouldn't want redundant power supplies, raid 60 with 25 drives and remote system monitoring through ILO? lol I spun one up and loaded PfSense and started tweaking. 2 weeks ago I switched over and have been working out gremlins since.. Overall it's gone well, just one snag that a couple members here have been very kind in helping me work out. Thank you to this page for all the help. [image: 1697753147328-pfsense1.png]
  • Short hangs happening randomly a few times a day

    4
    0 Votes
    4 Posts
    57 Views
    S
    @Xantra I’d watch top to see what it shows while it’s happening. System logs? Connection drop? CPU spike?
  • Lots of Errors in on lan and errors out on AP

    10
    0 Votes
    10 Posts
    120 Views
    O
    @pwood999 thanks. I'll start there. But wouldn't it be from the AP to the LAN?
  • Cant get "Malicious" feed to work on pfBlocker

    5
    2
    0 Votes
    5 Posts
    41 Views
    tinfoilmattT
    @FrankZappa Force Update | Reload All. If that doesn't do it, I'd follow the procedure noted under Firewall / pfBlockerNG / General / Keep Settings to clear and re-download all lists.
  • 0 Votes
    3 Posts
    141 Views
    R
    @marcosm Hi - Just an update on this. It turned out it was the ena cleanup job that's what causing the CPU spike. CPU 0: 0.0% user, 0.0% nice, 100% system, 0.0% interrupt, 0.0% idle C PID LWP C PRI STAT %CPU TIME COMMAND 0 100154 0 -64 RLs 100.0 11:22.91 kernel/ena0 queue 0 cleanu -- So basically - ena drops out, and then the cpu gets in a deadlock kind of situation where the ena cleanup job is stuck on one CPU. Has anyone experienced this random ena failures on AWS - When it happens, there's not a lot of traffic pressure nor the CPU was under load etc...it just happens randomly
  • pfSense 2.8.1 no packages updates - reason?

    5
    1 Votes
    5 Posts
    139 Views
    stephenw10S
    Not necessarily. It's just why you are seeing newer code and it's not in 2.8.1 yet. Things get tested in head first.
  • 0 Votes
    8 Posts
    134 Views
    L
    Finally, it works and it's kinda embarrassing: I figured that it needed to have something to do with the Jumbo packets What seems strange to me was that I needed to reboot if I changed the jumbo packet settings in order to have it be applied Then I checked the driver version. As I was using the Windows Update for drivers as well, I did not expect any surprise. Well, I was surprised. Driver was from 2020. When I installed the latest version and set the Jumbo packet to 9014, it was instantly applied and I could access the pfSense GUI again I only can assume that the driver somehow was installed during the Win11 migration few weeks back. I usually access my pfSense via a dedicated admin VM running Linux. Therefore I did not realize that I was not able to access it from my other PC I use "standard" / main tasks. HAPPY AGAIN
  • Cannot Achieve 10g pfsense bottleneck

    64
    0 Votes
    64 Posts
    3k Views
    P
    Try using multiple parallel streams. I've never managed to get full speed over 10G interfaces on any hardware. -P, --parallel # number of parallel client streams to run
  • SG6100 SWAP full and high CPU - tweak suggestions?

    8
    3
    0 Votes
    8 Posts
    149 Views
    dennypageD
    @alnico said in SG6100 SWAP full and high CPU - tweak suggestions?: Interesting, I will start to disable WAN interface and then turn off/on each one as you have suggested and see how it goes Given that your original post shows ntopng at 39 hours of cpu, I think everything else is probably minor in comparison. As a starter, I would suggest disabling ntopng completely while you evaluate the rest of the system. Btw, when you get around to re-enabling ntopng, it might be easier to simply reset ntopng as a starting point rather than going through the ntopng UI to find everything that has been turned on.
  • Broadcom Net Extreme E Dual 10GB Card (dell server Poweredge R740)

    2
    0 Votes
    2 Posts
    41 Views
    stephenw10S
    Sounds like something is linked at 1G. The ISP equipment might be trying to link at 2.5G and the NIC doesn't support it. Try running at the command line: ifconfig -vma to see how the NICs are linked now and what they are capable of. Run pciconf -lv to see the actual device and vendor IDs for the NICs.
  • Netgate blocked my public IP on ACB

    14
    0 Votes
    14 Posts
    180 Views
    tinfoilmattT
    @Gertjan Don't get me wrong, it's a useful script. Was a pure shot in the dark.
  • if_pppoe problems with php-fpm causing loops. (resolved)

    86
    0 Votes
    86 Posts
    19k Views
    C
    @stephenw10 Had a brief ISP outage and if_pppoe auto recovered. :)
  • Console access with MacOS 26.1?

    11
    0 Votes
    11 Posts
    172 Views
    A
    @beerguzzle as I mentioned before and luckman mentioned above Serial2 just works without any tweaking.
  • Crash Report Netgate SG2100

    3
    0 Votes
    3 Posts
    53 Views
    stephenw10S
    Yup that. But basically make sure you're using python mode.
  • All traffic stopped, looks a bug to me!

    13
    0 Votes
    13 Posts
    146 Views
    stephenw10S
    I mean there is a bug there but it's known. The Realtek hardware is such that there is little motivation for devs to fix it. And the newer Realtek NICs are better anyway. But, yes, if you see that watchdog error from the re(4) driver then definitely try the alternative driver.
  • WAN port not getting an IP address

    5
    0 Votes
    5 Posts
    65 Views
    L
    Update: Thanks everyone for your replies! I reset pfsense to factory defaults, went through the setup again and somehow the web gui worked this time around. I then simply configured the wan to PPPoE and added the credentials. Everything seems to be working fine now.
  • 25.07 ran for 24 hours and then ????

    5
    0 Votes
    5 Posts
    429 Views
    B
    I tried the upgrade again a few months later and it worked fine. This time I made sure to power off the VMs and power on. No idea really.
  • Dual WAN DHCP Issues

    16
    9
    0 Votes
    16 Posts
    408 Views
    P
    @stephenw10 That worked, thanks.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.