• Obtaining global IP after a power outage

    4
    0 Votes
    4 Posts
    322 Views
    stephenw10S

    From that many versions back I would just reinstall to 2.7.2 and restore the config.

    But what IP does it get? A private IP from the modem?

    You can set the dhcp client to reject leases from the modem server IP to prevent that. Cable modems will comonly hand out their own leases until the line syncs.

    Steve

  • VLAN not getting to VM

    4
    0 Votes
    4 Posts
    434 Views
    stephenw10S

    I expect it to be in the Hyper-V setup. Though the NIC itself would probably need to be in promiscuous mode to pass tagged and untagged traffic. The Guest VM shouldn't see the VLAN tagging at all. Though you could probably set that up in a few different ways.

    I don't run Hyper-V so I can't help you with it directly.

  • pfsense plus: get support end date from command-line?

    2
    0 Votes
    2 Posts
    220 Views
    stephenw10S

    You can see that data in /var/db/support.json. That should get updated every 24hrs.

  • Finally adguard local server working)))

    1
    0 Votes
    1 Posts
    163 Views
    No one has replied
  • Pfsense Software, WireGuard VPN

    2
    0 Votes
    2 Posts
    391 Views
    G

    @Ratfink Connecting two sites with Wireguard VPN is absolutely doable, and you don't even need fixed IP's for it to work.

    When you say you have 5 fixed IP's from your ISP, I'm kind of assuming you have your office at your house? Meaning they are both connected to the same fibre? Otherwise, if they are at very different locations, is it still the same ISP?
    In terms of getting the IP's on the respective pfsense machines, I assume you know how or have instructions from the ISP to do this. Might be MAC based if DHCP for example...

    Anyway, running pfsense on repurposed HW is very common and can be done "barebone" or virtualized. So you shouldn't have any problems getting to to work on your rack servers, hopefully.

    So step one is of course getting both machines up and running. And since they will be for different sites and connected via VPN you must make sure to use different LAN subnets on them. Like 192.168.1.0/24 on one and 192.168.2.0/24 on the other.

    Once you have them up and running you can follow a guide like one of these to set up wireguard.
    Even though you have fixed IP's it might be a good idea to get two domains, unless you already have that.

    https://www.youtube.com/watch?v=2oe7rTMFmqc
    Youtube Video

  • Slow PfSense Speed. or maybe is me.

    18
    0 Votes
    18 Posts
    2k Views
    stephenw10S

    Nice. 👍

  • Poor 10gbps WAN throughput

    42
    0 Votes
    42 Posts
    3k Views
    G

    @keyser said in Poor 10gbps WAN throughput:

    @Gblenn Did you knwo you can do this:
    https://answers.microsoft.com/en-us/windows/forum/all/how-can-i-prevent-automatic-updating-a-specific/9967b1cf-dc6f-495d-82be-4ab3f3207ff1

    Thanks for the tip but that is not the issue, and it didn't help. Every time after a shut down and start of the PC I cap out at 2-2.5 in speedtest (only download however).

    What is interesting however, is that I now tested with iperf and get the full 9.44 Gbit... so what is it that speedtest does differently, or fast.com for that matter?

  • configure unifi with pfsense

    24
    0 Votes
    24 Posts
    3k Views
    P

    @zaibi12345 said in configure unifi with pfsense:

    1 unifi dream machine pro controller with 20 access points connected with it, In lab if more than 400 users get connect, it got crashed all connected users faced disconnectivity. 1200 users is actual limit as advised by unifi support team.
    actually we need to connect more than 2000 users at a time and 5 controllers is not a solution

    I use a self hosted controller https://help.ui.com/hc/en-us/articles/360012282453-Self-Hosting-a-UniFi-Network-Server

    Easily installed via this script https://community.ui.com/questions/UniFi-Installation-Scripts-or-UniFi-Easy-Update-Script-or-UniFi-Lets-Encrypt-or-UniFi-Easy-Encrypt-/ccbc7530-dd61-40a7-82ec-22b17f027776

    Which I run on a Debian VM under Proxmox on a Mini PC also running pfsense as a VM.
    For your application, being more generous with the hardware would be sensible. https://lazyadmin.nl/home-network/unifi-controller/ and https://techspecs.ui.com/unifi/cloud-keys-gateways/cloud-key-enterprise

  • Nmap error

    8
    0 Votes
    8 Posts
    635 Views
    stephenw10S

    And that nmap error was triggered in that time period?

  • Verizon CR200a in ip passthrough?

    74
    0 Votes
    74 Posts
    10k Views
    E

    @stephenw10 Thanks so much for all your time and patience, but I finally admitted defeat and gave up. I canceled the Verizon service today and will be returning the gateway device shortly.
    I'd love to track down the gremlins and eventually switch away from my horrible DSL provider, but the trial I was on was about to expire, and I was out of time to screw with it for now.
    Maybe one day I'll try it again, possibly with T-Mobile home internet, which I think it also in my area. I've heard they will be making it easier to 'bridge' their gateway device soon, so that might be an option.
    I really do appreciate all your help, sorry we couldn't come up with a real solution!

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    12 Views
    No one has replied
  • Invalid gateway on install

    5
    0 Votes
    5 Posts
    468 Views
    stephenw10S

    You don't have to set .1 as the gateway. It still has to be the real gateway IP. The subnet simply has to contain both the host and gateway IPs.

    The next Installer version should be very soon.

  • Port forwarding for Synology on Openvpn address

    2
    0 Votes
    2 Posts
    150 Views
    stephenw10S

    pfSense is the router at the main house?

    What's the other end of the OpenVPN tunnel?

    You shouldn't need any port forwards if routing between the two ends of the tunnel is working.

    @ajaypatel26 said in Port forwarding for Synology on Openvpn address:

    I can connect the backup nas to my home router and get 192.168.10.10 I can work ok but the backup task not working.

    What exactly is working OK there?

    Steve

  • SG-1100 package manager, search for available no work

    23
    0 Votes
    23 Posts
    1k Views
    stephenw10S

    @rsicard said in SG-1100 package manager, search for available no work:

    Now how much is this going to cost me to upgrade?

    Nothing. There is no cost involved here. All Netgate hardware includes Plus upgrades for the life of the device.

  • Unable to delete alias - firewall thinks its in use

    6
    0 Votes
    6 Posts
    609 Views
    stephenw10S

    Hmm, possibly you changed the IPSec filtering mode? That can hide tabs for VTI or IPSec interfaces.

  • Crash Dump

    14
    0 Votes
    14 Posts
    1k Views
    stephenw10S

    Hmm, nothing terribly exciting there. Sure seems like it must be OpenVPN doing something. 🤔

  • Firewall log TCP -S

    10
    0 Votes
    10 Posts
    436 Views
    stephenw10S

    @johnpoz said in Firewall log TCP -S:

    curious let see if you get any hits on those ;)

    Probably depends on what types of clients are behind the firewall. I'd certainly expect some hits on some of those.

  • Netgate doc regarding bufferbloat settings

    4
    0 Votes
    4 Posts
    204 Views
    A

    @Antibiotic Ok , finally I think found correct settings with VPN interfaces. Waveform measuring looks like incorrectly upload speed, Ookla speed test show me correct
    1GB upload speed and 1GB download. Have A+))) , without Limiters have B or C. Tested grade on all inerfaces with VPN and without VPN only clear WAN. All looks good grade A+ tested also with a proxy squid also A+. This my final settings Limiters as from official docs and floating rule as below:

    Screenshot_4-6-2024_151052_192.168.10.1.jpeg

  • Pfsense crashed - stuck on reboot

    11
    0 Votes
    11 Posts
    464 Views
    stephenw10S

    No it shouldn't lock up the system entirely. You might end up blocking all ICMP traffic depending on how the limiter is configured. That could potentially block gateway monitoring etc.

  • trouble adding LAN2 & LAN3 interfaces (assignments)

    4
    0 Votes
    4 Posts
    329 Views
    johnpozJ

    @Greg2100 said in trouble adding LAN2 & LAN3 interfaces (assignments):

    Not very intuitive!!!

    For people inexperienced with managed switches, then yeah there is a bit of a learning curve.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.