• miniUPnPd not working since 23.09 (worked in 23.05.1)

    27
    1 Votes
    27 Posts
    4k Views
    R
    you have to add a rule in wan to allow... [image: 1712860779613-65762eb4-ba3f-4ff2-9d7a-5d305d84084a-image.png] ## External Network ext_ifname=igc0 ext_perform_stun=yes ext_stun_host=198.100.144.121 ext_stun_port=3478 ## Internal Network listening_ip=bridge0 ipv6_disable=yes allow 1024-65535 192.168.1.0/24 1024-65535 deny 0-65535 0.0.0.0/0 0-65535 bitrate_down=512000 bitrate_up=1024000 ## UPnP Settings anchor=miniupnpd enable_natpmp=yes enable_upnp=yes secure_mode=yes min_lifetime=120 max_lifetime=86400 system_uptime=yes notify_interval=60 clean_ruleset_interval=600 packet_log=yes uuid=fb241e30-9c00-11ee-xxxxxxxxxxx serial=CA0A9DD5 [image: 1712861019539-db87680c-23fb-4b12-b5c4-4d1bdbc68a67-image.png]
  • Remove Orphan Package Entry

    5
    0 Votes
    5 Posts
    606 Views
    R
    @panzerscope I had to go back to a previous configuration. I know I could have edited the config file, but I had a recent config and that fixed t he problem. I did have success in the past with a reinstall, but it doesn't always work.
  • Pfsense upgrade from 2.6.0 to 2.7.0

    6
    0 Votes
    6 Posts
    649 Views
    stephenw10S
    ovpnc3 is a client interface. It would be named ovpns3 if it were a server. However the issue here is probably because one side is set as net30 topology and the other side is set as subnet. Both should be subnet in recent versions of OpenVPN really. Net30 is the older default.
  • Pfsense + Upgrade Offered on CE Dashboard

    6
    0 Votes
    6 Posts
    309 Views
    M
    @stephenw10 said in Pfsense + Upgrade Offered on CE Dashboard: If it's really a problem I can manually remove your NDI. But that doesn't scale! No that's fine thanks. As long as it's expected behaviour then it's good
  • Problem with several services

    10
    0 Votes
    10 Posts
    669 Views
    B
    @Dobby_ Hi again Everything was like you show - but with the risk of sounding like a broken recored if squid is being fased out what is the point? bookie56
  • pfSense HAproxy system adjustments need a shell command

    2
    0 Votes
    2 Posts
    222 Views
    stephenw10S
    @dhenzler said in pfSense HAproxy system adjustments need a shell command: tune.ssl.default-dh-param Does that exist without a value? Or with a value too low? What do you have set for it here? [image: 1712718079014-screenshot-from-2024-04-10-04-00-44.png] Steve
  • Solved: PHP error in Boot Environments

    9
    0 Votes
    9 Posts
    741 Views
    T
    @stephenw10 I will attempt to find.
  • pfsense connect to unify express

    8
    0 Votes
    8 Posts
    796 Views
    stephenw10S
    You don't have to run a controller at all, the AP can be configured from a phone app. But there are some features that do require a controller running so most users do.
  • DNS/DHCP stop working suddenly

    59
    0 Votes
    59 Posts
    9k Views
    M
    @stephenw10 Just an update for you stephen. ATT offered to replace the att gateway (router). I didn't think it would help/hurt so i ended up replacing it. Ill be.... Its been stable for well over a week. Replacing ATTs equipment ended up solving the "issue". Why? I dunno. Why did a bad gateway ended up crashing my 6100? I dunno. Its fixed tho..... yay.
  • FreeRadius Configured with Unifi (3 Access Points)

    5
    0 Votes
    5 Posts
    664 Views
    C
    @stephenw10 thanks, I happened to come across that last night and it works good.. my only concern is when I updrade to a 6ghz band access point then I would need to move over to wpa3 and that does not support PPSK (as far as I know). I am just trying to see what method should I move forward with.
  • PFSense 2.7.2 SquidGuard Service State: Stopped

    1
    0 Votes
    1 Posts
    125 Views
    No one has replied
  • pfSense+ trial

    2
    0 Votes
    2 Posts
    589 Views
    S
    @teicors On AWS Plus is licensed per hour, above the VM cost. So right, if you don't like it you can terminate it.
  • What is the meaning of this dpinger log entry?

    8
    0 Votes
    8 Posts
    1k Views
    dennypageD
    @DominikHoffmann said in What is the meaning of this dpinger log entry?: What does this mean For future reference, see here. As @stephenw10 noted, the issue is that your immediate gateway (default route) is not reachable. A much more basic problem than what IP you decide to ping. As for choosing a target, I usually recommend performing a traceroute to 1.1.1.1 or 8.8.8.8, to help choose a target inside your ISP's infrastructure: traceroute -I 1.1.1.1 Look for an address that is a hop or two inside your ISPs infrastructure and has fairly consistent response times. YMMV.
  • Netgate 1100 becoming unresponsive intermittently

    4
    0 Votes
    4 Posts
    276 Views
    D
    @stephenw10: Thanks very much! Excellent point!
  • Netgate 7100 NAT/routing poor performance issue

    15
    0 Votes
    15 Posts
    690 Views
    T
    @stephenw10 THANK YOU VERY MUCH for helping me analyze this weird issue and what finally lead me to solution! Your support and input was amazing! Thank you!
  • Interfaces has wrong suffix in URL

    5
    0 Votes
    5 Posts
    545 Views
    stephenw10S
    Yes.
  • Moved Pfsense firewall from Virgin Media to Community Fibre

    8
    0 Votes
    8 Posts
    955 Views
    stephenw10S
    Nope, it only blocks connections coming into the WAN sourced from a private IP address: # block anything from private networks on interfaces with the option set block in log quick on $BT from 10.0.0.0/8 to any ridentifier 12006 label "Block private networks from BT block 10/8" block in log quick on $BT from 127.0.0.0/8 to any ridentifier 12007 label "Block private networks from BT block 127/8" block in log quick on $BT from 172.16.0.0/12 to any ridentifier 12008 label "Block private networks from BT block 172.16/12" block in log quick on $BT from 192.168.0.0/16 to any ridentifier 12009 label "Block private networks from BT block 192.168/16"
  • Delete LAN Interface, Keep VLANs

    5
    0 Votes
    5 Posts
    706 Views
    planedropP
    Thank you everyone, I figured it was safe to do so but wanted to ask before I committed, much appreciated! And yes @keyser I am not talking about removing ix0, just the assignment for it. @Jarhead I could go this route but I'd rather just remove it TBH.
  • Problems with all floating rules setup?

    11
    0 Votes
    11 Posts
    935 Views
    G
    @stephenw10 I'll get that submitted tonight. Thanks for talking through this with me.
  • slow guid from IP local network

    19
    0 Votes
    19 Posts
    1k Views
    stephenw10S
    For example using the Network tool in Firefox shows how long it took to open the page and which components took time: [image: 1712318757853-screenshot-from-2024-04-05-13-04-54.png] Other browsers have similar tools.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.