• Newb question for CityFibre PPPOE on pfsense (in UK)

    2
    0 Votes
    2 Posts
    744 Views
    stephenw10S

    Yes, you would create a VLAN 911 on the WAN NIC and then create the PPPoE connection on that VLAN. Should work fine.

    Steve

  • Blank Web Configurator after upgrade from 22.9 to 23.05.01

    13
    0 Votes
    13 Posts
    1k Views
    stephenw10S

    Hmm, that all look good. I can see that NDI chekcing in and it's being validated.

    After running that pkg-static update still fails?

    Try pkg-static -d update to see more error output.

  • DNS - Unable to reverse lookup internet address

    14
    0 Votes
    14 Posts
    789 Views
    johnpozJ

    @michmoor I believe that is for clients IPs.. I don't currently have squid or squid reports or anything installed, guess I could to take a look. But anything you google for squid PTR all comes up talking about the client IP.

    from back in the day, when I ran proxies for living ;) we almost always blocked direct IP access, and only specific ones were whitelisted. Not sure why a proxy would want to look up PTRs when you normally block direct IP access, etc. ;)

    But for clients, you could use client names in rules that allow, deny etc. So since client IPs might change you might want to do ptr on client IPs to know if its specific client based on its name.

  • Kernel keeps throwing messages

    10
    0 Votes
    10 Posts
    931 Views
    bmeeksB

    @Remember said in Kernel keeps throwing messages:

    @bmeeks Any update on if/when this will be fixed so we can start using it?

    This problem was fixed back in August of 2021. If you are running the current Suricata package on pfSense you should not be seeing this errror. The current package version is 6.0.13 on RELEASE versions of pfSense CE and Plus, and version 7.0.0 on the DEVELOPMENT snapshots of pfSense CE and Plus.

  • weird network behavior after switching from mikrotik

    6
    0 Votes
    6 Posts
    678 Views
    NollipfSenseN

    @homeauto Mikrotik has nothing to do with your problem and I'll agree with Bingo600 that your issue(s) seem to suggest or related to NAT.

  • [Solved] pfSense-repoc-static: invalid signature

    2
    0 Votes
    2 Posts
    574 Views
    T

    I use a new activation key from netgate and that helped get past this.

  • Pfsense 2.6 to 2.7 upgrade - remove Realtek driver?

    11
    0 Votes
    11 Posts
    2k Views
    stephenw10S

    The location of the module installed by the package is the same. You should not have to change the loader values.

    The version of the pkg in 2.7 is 1.98.

  • pfSense v.2.6 crashes and reboot

    10
  • Rate Limit by Attempts Per Time

    9
    0 Votes
    9 Posts
    1k Views
    J

    @stephenw10

    OK I see ...

    This is slightly different from the rate limit I use in UFW or Firewalld ...

    In which the state auto resets.

    One assumes that as long as the limit of 4 in 30 seconds isn't exceeded the host isn't written and therefore will never require deletion with the Chron Job.

    I suppose maybe set the limit a little higher to resolve accidents - but leave the 1 hour Chron job -

    I did think of using my usual Fail2Ban - but I think this will work well as the SSH is protected with MFA any robot will immediately be blocked after hitting it so fast, and the times taken after lock to unlock will make any brute force practically beyond impossible - the MFA would stop em when they don't have the second device which is push notification so --- impossible. virtually.

    Thanks for your input

  • wifi deco doesnt work any more, need help

    13
    0 Votes
    13 Posts
    2k Views
    stephenw10S

    Check the pfSense DHCP status or logs. If there's a link there it can be handing a lease to itself.

  • pfsense plus updating issues.

    3
    0 Votes
    3 Posts
    397 Views
    J

    @stephenw10 i just went ahead and reinstalled this morning. i appreciate the reply.

  • 0 Votes
    6 Posts
    302 Views
    S

    @BassStation70 yep. PfB can’t spoof HTTPS certs with valid certs so your browser will show the warning.

    Re: still working, could be DNS caching on your device, or a list update, etc.

  • pfsense 2.7 crash report

    4
    0 Votes
    4 Posts
    374 Views
    stephenw10S

    Ah, it looks exactly like this: https://redmine.pfsense.org/issues/14685

    So try a few rounds of fsck as mentioned there. Or switching to ZFS would also prevent it.

    Steve

  • Speed issues

    2
  • System Advanced >Networking

    24
    0 Votes
    24 Posts
    2k Views
    G

    @Gertjan @stephenw10

    Yes, to both of you guys. I was tired and just trying to get things done. I made a backup in the UI and it was larger than I had thought it would be.

    Wanted to thank all of you for your help, and let you know I was/am not meaning to be rude. I wasn't able to get on yesterday, as my central air went out and as I don't have just over $12k to replace it, I had to do what I could to get it running again. Took about 7 straight hours.

    As for my firewall, I have not messed with it anymore, as I just haven't had the time. I cannot reproduce the issue, so I cannot submit it as a bug report. I am sure it is something stupid I did, while up all night after playing COD or something like that. When I first got my box, I had only the basic understanding of python, very basic, and had forgotten most of php, and the networking I did was 20 plus years ago. So it's been a bit of a challenge for me. You all have been VERY helpful, and again, thank you!

  • Automatic connection does not work

    4
    0 Votes
    4 Posts
    295 Views
    stephenw10S

    Hmm, so it tries to connect via em0 before it has an IP and fails. Then retries successfully?

  • Network Failure

    Moved
    3
    0 Votes
    3 Posts
    429 Views
    stephenw10S

    That's what you would see if the device loses it's default route or has an invalid default route.

    Check Diag > Routes when it happens.

    Make sure the default gateway in System > Routing > Gateways is set to WAN and not automatic.

    Steve

  • Register DHCP WAN address with unbound?

    18
    0 Votes
    18 Posts
    1k Views
    GertjanG

    @NollipfSense said in Register DHCP WAN address with unbound?:

    I found it best also to have a real domain (often a $10/yr cost)

    Exact.
    And it comes with a free bonus : free certificates.

  • Some issues with Starlink bypass mode

    24
    0 Votes
    24 Posts
    8k Views
    ?

    Checked the connection last night and this morning again, confirmed it's still good. So, I believe this was the issue 100%.

    Glad I can go home with no worries. Thanks guys.

  • Multiple lan subnets (NO VLANS)

    18
    0 Votes
    18 Posts
    2k Views
    johnpozJ

    @Khoomn oh so you won't be using the dumb switches then?

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.