• Nprobe on pfSense - experiences?

    7
    0 Votes
    7 Posts
    1k Views
    keyserK
    @dennypage Hi Denny Really great that you are willing to put this effort into providing more options with NtopNG on pfSense. I already have a licensed NtopNG Enterprise Embedded running on a Raspberry Pi 4 collecting flows from Softflowd and a licensed nProbe Pro embedded I have (Portmirror on switch). I have been testing the difference between flows recorded by SoftflowD on pfSense and Nprobe Pro (portmirrored LAN to pfSense). The difference is HUGE. NProbe does a lot of DPI analysis + records all DNS queries and fills alll that in as flow metadata to NtopNG. So in the UI you can the client sessions with domainnames instead of IP addresses and a lot of trafficanalysis of the sessions. So it is much easier to dissect/analyze what happened in the nProbe flows than from SoftflowD. I record this to a Clickhouse server on the same Pi. Runs great, and gives me 180 days history of all flows back in time. I have decided to forego running the NtopNG package on pfSense as it cannot be licensed and work fully featured. I realize that one could perhaps avoid the licensing cost of a nProbe (And a port switchmirror) by setting up nTopNG like you suggested, but its a “heavy” package with lots of discwrites for nothing compared to nProbe. So I’ll stick with the nProbe Embedded as the deluxe flow generator, and look forward to testing the built-in pf flow exporter in 24.03 as the poormans flow solution. But your work is still very much appreciated, and I’m sure it will be very well recieved in the community
  • php scripting and PHP shell broken after update

    4
    0 Votes
    4 Posts
    300 Views
    P
    @bmeeks why the PHP shell i reach from menu point 12 does not give any hints? All the examples given in the help commands don't work. As this is the place, where I tested my scripts, I expected to get information about changes there. Thanks for your link, I will dig from there.
  • Intermittent reboots

    9
    0 Votes
    9 Posts
    745 Views
    stephenw10S
    It shouldn't be possible for anything external to reboot it. You might see a lo of logs or disconnections. Or potentially it could stop passing traffic entirely but it would still remain up. Or panic and log that.
  • PHP Fatal error on a newly wiped 1541, the FW shuts down without warning.

    9
    0 Votes
    9 Posts
    1k Views
    D
    @Gertjan How did you solve this error? I'm struggling with it on a couple of appliances
  • adguard type setup?

    5
    0 Votes
    5 Posts
    773 Views
    X
    @stephenw10 Understood. Was more looking to follow his process and I would download manually and install
  • SSL certificate from IONOS?

    4
    0 Votes
    4 Posts
    659 Views
    stephenw10S
    Because when you test from inside the firewall that traffic never hits the forwarding rules. https://docs.netgate.com/pfsense/en/latest/recipes/port-forwards-from-local-networks.html
  • pfSense advanced settings: System/Advanced/Networking

    4
    0 Votes
    4 Posts
    759 Views
    stephenw10S
    Tunables for FreeBSD will generally apply in pfSense but may not improve performance. On the page the default values should be fine for igc.
  • Pfsense PPPoE Server and Dhcp option 43.

    4
    0 Votes
    4 Posts
    563 Views
    stephenw10S
    Well it would have to be a value that can be set in mpd5 since that's what the PPPoE server uses. As a test you could try adding values to the conf file for the server in, for example, /var/etc/pppoe1-vpn/mpd.conf. You would need to manually kill the process and restart it like: /usr/local/sbin/mpd5 -b -d /var/etc/pppoe1-vpn -p /var/run/pppoe1-vpn.pid -s poes poes If you are able to find a value that works there most of that is created in /etc/inc/vpn.inc Steve
  • New commit and merge in FreeBSD source code of MAP-E

    20
    0 Votes
    20 Posts
    2k Views
    T
    @Patch yes, seeing the link for the earlier FR, I went to comment on that but couldn't as it was closed, hence the new FR with a link to the previous one. Not sure if that's the "right" way of doing it, but just wanted to bring it to their attention. I'm hoping that if the new FreeBSD has it built-in, it requires minimal development on the pfSense side to include it as a feature - just a few Web UI tweaks?
  • New install on NUC12 - lots of missed packets and slow upload

    20
    0 Votes
    20 Posts
    2k Views
    stephenw10S
    Nice! Yeah we've seen ASPM cause all sorts of issues.
  • Cloudflare + BIND9 + pfSense DNS over TLS

    21
    0 Votes
    21 Posts
    2k Views
    F
    I found this post and this is exactly what I want to do. https://serverfault.com/questions/1034535/pfsense-dns-port-forwarding Instead of setting NAT reflection to Enable (Pure NAT) I tried setting Enable (NAT + Proxy) and I'm able to see result when I dig with my domain x.x.com. Unfortunately, I'm still unable to connect to DoT from my Android phone.
  • 0 Votes
    8 Posts
    586 Views
    B
    @stephenw10 Thank you @viragomann 's solution worked directly connecting to the firewall hardware console using video cable, keyboard and mouse. Thank you again!
  • Abysmal Performance after pfSense hardware upgrade

    69
    0 Votes
    69 Posts
    16k Views
    8
    Ordering the Rackmount version shortly and I'll test restoring one component at a time to see if the interrupts persist, or at what point they may increase.
  • random mac and VPN Ip

    19
    0 Votes
    19 Posts
    1k Views
    N
    @stephenw10 unless they work for the ISP of the Feds.. Anyhow.. My fasting recipe 1/8 cup honey 1 banana 1/2 pint fresh blue berries 1/2 pint fresh red grapes with seeds 1 skinned Golden delicious apple no seeds 1/2 pint great value frozen fruit blend. 1/2 pint great value frozen tropical blend top off with Eureka spring water,, blend into a smoothie.. and get your crown on.. :)
  • Port 53 (DNS)

    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S
    Yes by default the server set in general settings don't do anything. pfSense resolves directly (Unbound in resolving mode) and clients are passed the local interfaces address to query against that. Do you see blocked traffic in the firewall logs? Your rule probably isn't matching as you intended it to.
  • suppress message -> ISC DHCP has reached end-of-life

    24
    0 Votes
    24 Posts
    2k Views
    TacyonT
    @JonathanLee - nope ... 2.7.2 CE from Dec of last year.
  • Rare kernel panic on 23.09.1-RELEASE (amd64), non-Netgate HW

    4
    0 Votes
    4 Posts
    368 Views
    stephenw10S
    Hmm, as you say the llinfo arp messages have obscured anything that might give us a clue. Really not much to go on there. The backtrace shows a general memory error but that could be hardware or software. Is that the first time it has happened? Did it happen after upgrading to 23.09.1?
  • How to set static ip on DHCP device with no control access?

    3
    0 Votes
    3 Posts
    480 Views
    stephenw10S
    Yup use a static mapping: https://docs.netgate.com/pfsense/en/latest/services/dhcp/ipv4.html#static-mappings
  • pf ipv4 syslog-ng parser available

    1
    1 Votes
    1 Posts
    189 Views
    No one has replied
  • DHCP renew on WAN not working

    4
    0 Votes
    4 Posts
    624 Views
    keyserK
    @mtis This issue might also be caused by the ISP requiring DHCP renew requests to be QOS marked or VLAN Priority tagged. I have a french ISP that requires all DHCP frames to Priority 6 vlan tagged - otherwise they just don’t reply to the frames. Do you have any chance of doing a packet capture of the ISP’s CPE doing DHCP discover and renew? Then you could see what they might be doing (if not just requiring renews to be broadcasted).
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.