• SG-2100 Network Interfaces Question

    15
    0 Votes
    15 Posts
    2k Views
    M

    @JonathanLee said in SG-2100 Network Interfaces Question:

    Happy new year everyone

    Happy new year to everyone !! =)

    Going to meet my friend now, Mr. Jack Daniels.. Nice guy.. hehe

  • Sophos XG230 Rev2 Netgate Device ID

    5
    0 Votes
    5 Posts
    581 Views
    M

    @stephenw10

    Indeed they are. Will decide which Sophos appliance I’m sticking with.

    Seen a 2nd hand Netgate 7100 that I am keeping my eye on.

  • After update to 2.7.2, auto-update checker is hopping update branches

    8
    0 Votes
    8 Posts
    800 Views
    stephenw10S

    Yes this is a known issue. It's really only cosmetic but can be confusing. https://redmine.pfsense.org/issues/15019

    Yes if you really need to I can remove your NDI so it stops seeing Plus as an available upgrade.

  • NEWBIE - VLAN / L2TP / OpenVPN - Not Working?

    2
    0 Votes
    2 Posts
    321 Views
    stephenw10S

    L2TP over IPSec can work: https://docs.netgate.com/pfsense/en/latest/recipes/l2tp-ipsec.html

    That's a long list of failures. 😉 We'd need to get more info about any one to know more.

  • pfSense & concurrent users

    18
    0 Votes
    18 Posts
    2k Views
    johnpozJ

    @AMSUIT said in pfSense & concurrent users:

    i did a test with the local website using the Firewall as intermediate, and faced the same problem!

    Where did you state that? You stated this

    i had done a test with the same Moodle platform locally in our LAN (with no pfSense in the middle) and it works fine with concurrent 109 students

    Ok I see now where you redirected it through pfsense.. How exactly did you do that? Locally pfsense would be involved in talking to some website on your own local network and if just routed to a different segment it wouldn't nat. You setup nat reflection?

  • Add Upstream SSL Intercepting Proxy Certificate

    4
    0 Votes
    4 Posts
    660 Views
    stephenw10S

    There is a checkbox to add the CA to the system when you import it if required:
    Screenshot from 2023-12-31 18-31-58.png

    However in this situation I would add the proxy IP to pfSense specifically so it doesn't need to have that CA.
    https://docs.netgate.com/pfsense/en/latest/config/advanced-misc.html#proxy-support

    Steve

  • Migrating from Sophos UTM Home Use License

    10
    0 Votes
    10 Posts
    2k Views
    M

    @jeffshead
    That is correct. Snort/Suricata operates outside the firewall so to speak so it cannot inspect ssl traffic. There is no mechanism within pfsense to decrypt a flow and send to an engine to inspect. This largely,in my opinion, makes the threat prevention aspect of pfsense quite useless. It would be more useful to have your endpoint mitigation tools on the clients do the protection.

  • Separate LANs unable to see each other

    12
    0 Votes
    12 Posts
    944 Views
    JonathanLeeJ

    @lkh allow windows firewall to approve ping you shouldn’t need to disable defender. Make one rule in windows firewall to approve pings.

  • After update to 2.7.1, Bad Gateway: Nginx

    Moved
    9
    0 Votes
    9 Posts
    2k Views
    stephenw10S

    You might be able to use a driver for the specific hardware rather than the cdce driver. It's possible some specific driver gained support for that hardware in 2.7.1/2.7.2 and that's what changed.

  • High CPU and load very high after updating to 2.7.1 and 2.7.2

    12
    1 Votes
    12 Posts
    3k Views
    C

    I did do that when testing last weekend and I can confirm that with a factory default config the CPU usage and load was greater on 2.7.1 and 2.7.2. This is not an issue with the hardware, or any specify post installation configuration. This is an issue with the base system running 2.7.1 and 2.7.2 on this hardware. is there some log or debug level that i can get you output for that might allow you to narrow down the issue so that I can get this box back to running at normal utilization?

  • host website from home with Dynamic IP

    2
    0 Votes
    2 Posts
    323 Views
    johnpozJ

    @kdmiller61 the request wouldn't be dynamic. And you don't really need a client on some other pc on your network.. Pfsense can keep your IP updated to the dynamic service you are using.

    It supports no-ip
    noip.jpg

    Or it prob supports whatever other ddns service you were using.

    All a ddns does is point to your internet IP, the IP on pfsense wan normally unless pfsense is behind a nat router.

    Just create your normal port forward rule using your wan address as the destination. This built in alias will know if pfsense wan IP changes. And just forward this to whatever IP behind pfsense.

  • 0 Votes
    3 Posts
    741 Views
    Sergei_ShablovskyS

    @stephenw10 said in Congestion control choose (BBR2, QUICK, RACK, CDG) for music streaming:

    Unless you're streaming music from or on pfSense itself (which you shouldn't be!) then it makes no difference what pfSense is using for those.

    Of course, streaming are from separate servers set.

    The only exceptions to that might be if you're proxying the traffic in pfSense or perhaps routing the stream over a TCP VPN.

    In this moment - stream traffic not proxying.

    Additionally most streaming is UDP anyway.

    Let me correct You: more and more services nowadays using TCP and QUICK.

    But:
    ——
    For instance, Netflix and Amazon Prime use TCP as transport layer protocol, while YouTube has adopted both UDP and TCP protocols.
    ——

  • PfSense Error

    2
    0 Votes
    2 Posts
    540 Views
  • unable to resolve mask.icloud.com

    2
    0 Votes
    2 Posts
    425 Views
    M

    Old forum post led me in the right direction.
    I have forgotten that in pfBlocker there is an option in SafeSearch to block DoH/DoT.
    Unchecked apples relay names and reloaded. Everything works.

  • PPPoE and HW

    6
    0 Votes
    6 Posts
    626 Views
    E

    I am currently in that same process, but I have been using pfsense with captive portal and freeradius for authentication for 8 years. I have a little more than 1800 clients and I am about to switch to pppoe with limiters, in the tests it has worked excellently. I have segmented by area with VLANS so these will continue. In this way, I reduce the need to have a pppoe server with a high number of users. I have to run a PPPoE server for each VLAN or interface.

  • Lost connectivity after exiting CARP maintenance

    5
    0 Votes
    5 Posts
    490 Views
    A

    @SteveITS

    Thank you, I will re-examine the logs and see if for any reason it appears I was in one of the two cases. I will test as well again entering and exiting the maintenance mode.

    Andrea

  • FreeRadius password types

    3
    0 Votes
    3 Posts
    550 Views
    Austin 0A

    @kiokoman Thank you

  • RIPE Atlas Probe (hardware, v.4) periodically dropped connections

    1
    0 Votes
    1 Posts
    266 Views
    No one has replied
  • [SOLVED] DNS & Ping work from LAN, but nothing else does

    15
    0 Votes
    15 Posts
    4k Views
    C

    @remlei @EveningStarNM
    Scoured the interwebs and could not get my home lab working . Same symptoms as you and this fixed it !! Only signed up for the forum to thank you haha

  • Configuring NUT as a network server (SNMP)

    2
    0 Votes
    2 Posts
    1k Views
    dennypageD

    @jeff3820 See Notes on remote access to NUT in the second post of the NUT support thread, and the section Notes on Synology at the end of the post.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.