• Terrapin SSH Attack

    Pinned
    33
    16 Votes
    33 Posts
    44k Views
    STLJonnyS
    @willowen100 It basically forces your ssh (on the Windows side) to utilize that encryption algorithm. You'll need to do that on any machine you ssh from. I'd have rather found a more elegant workaround (preferably on the pfSense side, so the mod only has to be done in one location), but this works in a pinch.
  • pfSense Hangouts are available on YouTube!

    Pinned Locked
    1
    5 Votes
    1 Posts
    17k Views
    No one has replied
  • Share your pfSense stories!

    Pinned Moved
    76
    0 Votes
    76 Posts
    69k Views
    V
    Mine may be typical, maybe not..... Took over a large sennior living facility with a pretty robust it infrastructure spread between 4 IT rooms, 23 access points, 12-14 switches, and 200 internal devices and 200 guest/resident devices, all being run by a Sonicwall TZ350. I had been wanting to reallign everything network wise for some time but the TZ had 2 ports that were failing. I had worked with ClearOS from back in the ClarkConnect days and started searching for something similar. I found PfSense and it just fit what I wanted to do. I tested it a bit on an old Athalon64x2 rig for proof of concept and had planned on installing on a mini pc or something, but I wanted 6 nics. Standing in my main IT room I looked down and in the bottom of the rack were 4 HP DL380s, 2 of which were decommissioned 2 years ago. It's such huge overkill for hardware that it's hard to explain, but who wouldn't want redundant power supplies, raid 60 with 25 drives and remote system monitoring through ILO? lol I spun one up and loaded PfSense and started tweaking. 2 weeks ago I switched over and have been working out gremlins since.. Overall it's gone well, just one snag that a couple members here have been very kind in helping me work out. Thank you to this page for all the help. [image: 1697753147328-pfsense1.png]
  • ACB host (acb.netgate.com) not reachable from pfSense

    6
    0 Votes
    6 Posts
    54 Views
    stephenw10S
    If it's their own DNS servers they may be filtering something....
  • How do I disable RAM drive for /var /tmp?

    4
    0 Votes
    4 Posts
    1k Views
    T
    @jimp God bless you man! Ran into this issue too -- turned on RAM disk and specified 80/120 MB for tmp/var and even though I have 4GB total RAM pfSense showed warnings through VGA that the disk is full and it cannot write to tmp or var (I'm not savvy in this hi-end IT stuff). viconfig and some search on how to use it saved me from reinstalling pfSense, thank you ))
  • Wireguard Start Delayed - How to delay filter loading

    7
    0 Votes
    7 Posts
    84 Views
    4
    @stephenw10 it's 50/50. but if they don't then i have to stop and restart the service
  • How can I route all HTTP traffic on a specific interface to a single URL

    3
    0 Votes
    3 Posts
    26 Views
    S
    @SteveITS Shoot. I forgot about the SSL. So maybe just HTTP. I'm sure I can find plenty of gag URLs that aren't behind a certificate. Heck, I could even just host the content, but I like the idea of just having a pile of URLs that rotate randomly
  • DNS Resolver: Query Name Minimization Default Value

    netgate-docs
    3
    0 Votes
    3 Posts
    39 Views
    E
    @Bob.Dig I should clarify, that is the description inside pfSense, which seems to be opposite the documentation.
  • Frequent Crashing (Page Fault) After Upgrade to 2.8.0 From Latest 2.7

    92
    0 Votes
    92 Posts
    8k Views
    R
    So, for anybody keeping score, I finally got this deployed to production last weekend. So far this couldn't have gone smoother. Aside from a few users messing up OTP with VPN logins everything seems to have worked fine on PFSense's new home. HA works, FW rules work, NAT all seems to work. PFBlocker is doing its thing, OpenVPN seems as good if not better than our old AnyConnect setup from Cisco. Very impressed with the solution I have here after a week. Servers are not even breathing hard and handling our traffic fine. Really happy to get this behind me and to see PFSense work so well for us. As for any crashes, so far there have been none. I'm worried this is something to do with the environment I was building this in. Everything is set to capture another crash if it happens but for now, I am just in wait and see mode. Thanks everyone for their input. Really appreciate all the guidance. Hopefully all this still yields something useful. Will let you know.
  • 0 Votes
    2 Posts
    28 Views
    S
    @Enso_ In the simple case, no. Yes you can edit the config file. Just be sure not to do a search and replace in case the NIC strings are used in an encoded string. If you're not using complicated VLANs you should be able to just restore in the web GUI and it will ask you to assign the interfaces. Save, then apply to reboot. (note if it doesn't work it will stop on boot to ask at the console to reassign interfaces)
  • if_pppoe ping works but dns doesn't?

    36
    0 Votes
    36 Posts
    10k Views
    stephenw10S
    Not yet, but the lead developer on this is away for a bit and it may need hi input. A second data point here would be very useful I agree.
  • Packets go through, logging is set, but no logs of the traffic

    7
    0 Votes
    7 Posts
    58 Views
    stephenw10S
    Hmm, OK. Check the actual ruleset in /tmp/rules.debug. Do you see your custom rule? Does it have 'log' set?
  • Syslog service in pfSense v2.8.1 often stop itself

    59
    2
    0 Votes
    59 Posts
    9k Views
    stephenw10S
    No sorry that was at the previous poster. The workaround rule won't work for traffic to syslog-ng locally.
  • Unable to create internal certificate (CA not detected)

    9
    2
    0 Votes
    9 Posts
    69 Views
    stephenw10S
    The valid from and to dates are correct though? A CA that was, for some reason, no longer valid would be hidden. You might try exporting the CA and examining it in a cert viewer to check for anything obviously wrong.
  • 1 Votes
    1 Posts
    33 Views
    No one has replied
  • Does pfsense have a old outdated SSHD version, and how to update it?

    13
    0 Votes
    13 Posts
    319 Views
    stephenw10S
    Nice! Thanks for testing.
  • Sending pfSense Logs over TLS to Fluent Bit server

    syslog rsyslog tls logs syslog-ng
    2
    0 Votes
    2 Posts
    53 Views
    stephenw10S
    Hmm, using syslog-ng as a proxy of sorts is what I've done in the past to make this work. Otherwise you could try the STunnel package: https://docs.netgate.com/pfsense/en/latest/packages/stunnel.html But using a VPN is probably more stable long term. Nothing custom required for that.
  • solved: suddenly getting latency with t-mobile home internet

    5
    2
    0 Votes
    5 Posts
    96 Views
    stephenw10S
    Hmm, that's interesting. I wouldn't expect larger packets to make any difference there.
  • if_pppoe problems with php-fpm causing loops. (resolved)

    83
    0 Votes
    83 Posts
    16k Views
    fireodoF
    @stephenw10 said in if_pppoe problems with php-fpm causing loops. (resolved): Not yet. The issue is more complex that initially thought. Enabling the pppoe encapsulation there prevents it crashing out but it never matches any traffic. Thanks for the Info & explanation!
  • Direct connection says host is down

    19
    1
    0 Votes
    19 Posts
    264 Views
    stephenw10S
    Hmm, now I'm confused. Your screenshot above shows two igb NICs. That's a 1G Intel NIC. It can't link at 10G. Are you using different NICs there now? I expect the idrac to show the real hardware MAC for each port. The internals only vtnet ports should show a MAC generated by Proxmox.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.