• Intel X710-T4L Not Supporting 2.5G or 5G

    8
    0 Votes
    8 Posts
    682 Views
    stephenw10S

    Hmm, that would be interesting. Is it reported anywhere? Different PCI ID?

  • SMTP Notifications for low disc space

    6
    0 Votes
    6 Posts
    243 Views
    stephenw10S

    Unfortunately not. The redmine site pre-dates much of the current Netgate infrastructure.

  • If you could have 1 feature added - what would it be?

    9
    1 Votes
    9 Posts
    364 Views
    B

    Some more IPv6 things to learn / play with.

    Better dhcpc6 status information (the PD_PREFIX is only printed once in the logs when debugging is enabled) Option to use a PD_PREFIX "template" in other configuration fields (eg rules/wireguard) instead of hardcoding a IPv6 address in those. (might already be possible for rules?) Make IPv6 the primary stack vs IPv4 (UI / design / thinking wise) NAT64 / 464XLAT support so that IPv6 only networks are possible (Should be feasible for most big OS'es, expect Windows although CLAT support for non WWAN interfaces was announced, no timeline yet tho) Better (UI) way to handle manual DNS registrations (IPv4/6) versus automatic DHCP ones (no need for DHCPv6 in my use case, SLAAC is great and the latest Windows 24H2 works with RDNSS on dual-stack)
  • How do I setup Pfsense as a transparent firewall with IPS?

    8
    0 Votes
    8 Posts
    687 Views
    stephenw10S

    @jshoe It could be either if filtering is on the member interfaces.

    I would probably move filtering to the bridge interface and apply it there for logical simplicity.

  • Changing LAN Interface Network Port

    25
    0 Votes
    25 Posts
    2k Views
    C

    @stephenw10 I was able to figure it out.

    There was a problem on my Netgear switch. Old MTU and VLANs were not removed.

  • Cox Fiber - just setting up...

    5
    0 Votes
    5 Posts
    345 Views
    stephenw10S

    You don't have to put the modem in bridge mode. But doing so avoids double NAT which is preferred.

  • Recent Display Issue with Chrome (Edge works fine)

    4
    0 Votes
    4 Posts
    139 Views
    stephenw10S

    In what pfSense version?

    It's failing to load the font awesome characters. A force refresh or clearing the cache usually fixed that.

  • Any useful notification triggers exist in pfSense ?

    4
    0 Votes
    4 Posts
    388 Views
    C

    @Gertjan Thanks!

  • IPv6 DDNS not working with 6rd

    5
    0 Votes
    5 Posts
    377 Views
    C

    @stephenw10 Straightforwardly, AFAICT (see below). This configuration is translated straight from my working OpenWRT configuration, double-checked, etc. For he.net, hostname and username are the same (the domain to use). The 'Interface to monitor' dropdown only has WAN and my other LAN interfaces, no special separate interface for 6rd.

    Even if these details were wrong, I would expect to see something other than 'Couldn't connect to server' in the logs. It seems like there is some deeper issue preventing the DDNS handler from even contacting the he.net server.

    Screenshot 2024-07-01 at 9.24.05 AM.png

    Screenshot 2024-07-01 at 9.24.12 AM.png

  • pfSense not responding to icmp ping from switch

    20
    0 Votes
    20 Posts
    900 Views
    johnpozJ

    @stephenw10 sdwan company we used for few customers at last gig used the documentation network...

    192.0.2.0/24

    For the tunnels to make didn't overlap with sites of the customer network.

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    3 Views
    No one has replied
  • rule error There were error(s) loading the rules: /tmp/rules.debug

    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S

    Do you have a wireguard connection still? A wireguard interface?

    If not you should remove (or disable) those rules with that alias in them.

  • cyberstudent with basic questions about interface configurations

    61
    0 Votes
    61 Posts
    6k Views
    JonathanLeeJ

    @JKnott COOL!!

  • Not receiving down emails multi-wan in failover config in 24.03 SG1100

    17
    0 Votes
    17 Posts
    638 Views
    M

    @stephenw10 said in Not receiving down emails multi-wan in failover config in 24.03 SG1100:

    Wow there's no Ethernet when it's acting as a router? That sucks.

    Some other router in between then might be your only option then. Two gateways with the same address is a conflict and can never work correctly. The only exception to that is for PPPoE links because they are point to point connections. Butt even then some things will misbehave.

    I think I misspoke; the Ethernet apparently does work when their router is enabled and from some more reading it appears it does use the SL router's DHCP to serve a different IP address range to the Ethernet in the 192.168.1.0/24 set. Ok, yay. In bypass mode, the SL router's DHCP server is disabled and the dish's own 192.168.100.1 address is served to the pfSense. From the dish, so pfSense gets the same IP from each dish.

    It certainly does suck, though, because I still want the WiFi completely off. I have my own access points and the SL WiFi will pollute the airwaves with traffic that is useless to me. I'll have to keep looking to see if there's a way to shut off WiFi without bypass mode, so I can keep the SL DHCP server delivering different IP addresses than the dish range. So far it doesn't seem so.

    Starlink as a company behaves as if it were founded by a control freak. Strange.

    While they have built a groundbreaking and well-functioning service in many respects, their terrestrial consumer-facing engineering seems to be where they assign the unpaid summer interns.

    I appreciate your help and attention. Best regards.

  • Unknown 10.x.x.x address

    17
    0 Votes
    17 Posts
    1k Views
    stephenw10S

    Mmm, indeed. If you really need UPnP then lock it down to only known devices.

  • 0 Votes
    3 Posts
    385 Views
    C

    I ordered two of these and put them in my Netgate 6100 Max with TNSR and they are not recognized. Running 22.10 software. Does it need an update?

    Well, after reading the reddit post and seeing this comment - It’s a 10G module, so it won’t connect at 1G or 2.5G - I found my problem. I was testing to a 1 Gig port on a Cisco switch. Moved it to a 10G port on server as a temporary workaround and its up now.

  • NO CARRIER on Protectli NIC

    7
    0 Votes
    7 Posts
    325 Views
    dennypageD

    @stephenw10 Given that the interface status is "no carrier" I don't think there is a physical connection to either a host or a switch.

  • pfSense Todo Widget

    1
    3 Votes
    1 Posts
    183 Views
    No one has replied
  • Interface has license all over it

    9
    0 Votes
    9 Posts
    409 Views
    S

    @stephenw10
    That's good news. Just don't want the issue to carry over and get in a bind.

  • System - Certificates using an ICA or CA generated by pfSense

    6
    0 Votes
    6 Posts
    312 Views
    P

    i agree with backing up any of the files that are changed.

    The openssl.cnf file edits was something I did not see many topics within this forum.

    As I was comparing a signed CSR using a customer ICA/CA generated from the pfSsense web UI against ACME, I wanted to ask this question.

    The signed certificate has an intended use within Cockpit within a number of server (not connected to the internet). Naturally the environment will have a different CA generated.

    While the signed CSR from pfsense works well for Apache, Nginx, HAproxy, etc, other applications were not as accepting. I did add my ICA/CA chain to the server's OS. This lead to me to check out the options in the openssl itself (to see what pfSense uses).

    Thank you for the responses. I was going to attempt to edit the openssl.cnf and try that.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.