• pfSense - OpenVPN + Avahi = Not Working

    20
    0 Votes
    20 Posts
    3k Views
    fogF
    Also DNS-SD (see http://dns-sd.org) doesn't work when connecting with OpenVPN and forwarding to the client correct DNS suffix name. I've setup my internal DNS server to publish many of my service on my LAN ... but them not get discovered on iOS.
  • cant find one host on my PFsense

    2
    0 Votes
    2 Posts
    303 Views
    stephenw10S
    If it's a static IP then it does not have to reach out for dhcp. If there have not been any connection to it inside the arp expire time it will not show. If you ping it from the firewall it will show again in the tabel. You can add that as a static dhcp lease even if it's not using dhcp so pfSense knows about it. If you have Unbound resolving static leases you can use it's hostname dircetly. Steve
  • Watchguard Firebox X750e - Vert slow internet speed ..

    2
    0 Votes
    2 Posts
    463 Views
    stephenw10S
    Does it still have the original Celeron CPU in it? You won't see 900Mbps through that. somewhere in 500-600Mbps range is more likely. I assume you mean 150Mbps not 150MB? Bits per second not Bytes? Since that would be over 1G.... That hardware is 32bit. It has not been able to run a current version of pfSense for several years. Whatever version you have on there is obsolete, you should think about upgrading. Steve
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    12 Views
    No one has replied
  • Layer 2 Tunnel over Layer 3 (IPSec/GRE/GIF)

    31
    0 Votes
    31 Posts
    7k Views
    stephenw10S
    It wouldn't make any difference in terms of the dhcp server. I would use routed IPSec there if the other router supports it if only because there are issues with GRE/IPSec in pfSense which it's better to avoid. And you definitely want to use encryption. Steve
  • Support pfSense/Netgate with gold subscription (again)

    3
    0 Votes
    3 Posts
    259 Views
    B
    My Amazon smile donations go towards FreeBSD
  • Master Firewall is not accessible until slave is rebooted

    2
    0 Votes
    2 Posts
    311 Views
    stephenw10S
    Do you mean the CARP VIPs remain master on the secondary node? And backup on the primary node? The primary may have demoted itself if an interface went down. Check the advskew value in the ifconfig output. Steve
  • Solved: pfSense as bhyve guest only gives 60Mbit instead 200+

    33
    0 Votes
    33 Posts
    3k Views
    stephenw10S
    Nice catch.
  • wifi disconnects when changing settings

    14
    0 Votes
    14 Posts
    884 Views
    stephenw10S
    Mmm, that's fun!
  • Torrent kills PFSense DELL R210II Box

    disconnections nic pfsense torrent unresponsive
    4
    0 Votes
    4 Posts
    1k Views
    GertjanG
    @nds2k said in Torrent kills PFSense DELL R210II Box: I shall try that when once other family members are not using the network. If you know what device is using the torrent, and you have a ISP router in front of your pfSEnse, you could hook up that device only without taking your network down. @nds2k said in Torrent kills PFSense DELL R210II Box: Noted! You didn't know that most ISP's do not like at all the usage of P2P protocols as they are used for distributing very legal info like Windows updates and the like, and also less legal files like ripped DVD etc ? If the destination IP is from these "Windows updates" servers, then the content isn't blocked, of course.
  • Automatic Backups from previous owner

    5
    0 Votes
    5 Posts
    656 Views
    stephenw10S
    @diegus83 said in Automatic Backups from previous owner: I decided "I should try that now while it is not an emergency instead of when I break something and the internet stops working" I approve of this decision.
  • What would cause my server to show UDP port scans coming from my VLAN IP?

    4
    0 Votes
    4 Posts
    580 Views
    stephenw10S
    Yes, unless you have outbound NAT configured on that interface. Check the state table for that states on that interface. Steve
  • A few questions about logging and reporting tools

    4
    0 Votes
    4 Posts
    661 Views
    stephenw10S
    Yes exporting syslog and netflow data is the way to go for that. Long term data is not intended to be held in pfSense directly.
  • freeradius package + ad + mfa

    3
    0 Votes
    3 Posts
    554 Views
    P
    @stephenw10 yeah. let's say i have an openvpn user that comes from ad. can i utilize the freeradius to add mfa to it?
  • 0 Votes
    14 Posts
    3k Views
    stephenw10S
    Do you see it being routed in packet captures or the state table when you try to reach 1.1.1.1? Where does it fail?
  • Can't connect from site A to site C

    20
    0 Votes
    20 Posts
    2k Views
    C
    Got it working finally. For this I reset everything to default and started again from scratch. And both options now works. If I do it via NAT it works. And if I change this to a static route in the destination network (so without NAT) it also works. I think I have the same configured as before. But apparently something was wrong before, because now it works. Thank you all for your input and suggestions.
  • hide false positive blocked/rejected firewall entries

    9
    0 Votes
    9 Posts
    932 Views
    NogBadTheBadN
    @imthenachoman said in hide false positive blocked/rejected firewall entries: My FW rules are very prescriptive. My last FW rule rejects everything that a previous rule doesn't allow. I was talking about your WAN rules, your screenshot is the LAN or one of the LAN interfaces isn't it as you're doing DNS redirects to the firewall. If you really want to understand whats hitting the firewall send the logs to a syslog server, then look at the data, I send mine to my Synology NAS and can export out if needed to Excel.
  • Port Redirection internal vs external

    9
    0 Votes
    9 Posts
    1k Views
    R
    @tabmow It's really easy to use, which is why i opted to use it myself, i also don't need another VM or Docker container running when the PfSense box can do this along with the LE certs Do keep in mind HA only works at TCP level, so if you wanted to proxy anything non HTTPS, you might have issues
  • 1Gbit Symmetrical Upload Slows to 80Mbps

    6
    0 Votes
    6 Posts
    700 Views
    G
    @stephenw10 Although not ideal, after getting login credentials to the ISP provided router, I moved everything behind their device (which is a calix gigacenter 844e-1 which is actually not a bad device) and speeds are running normal with no weird latency when upload was seemingly capped. Their device provides the option to place my pfsense box in a DMZ, so this allows me to open ports (ie 443) and route things like I need to. I really wanted to figure out why it was acting the way it was directly connecting the the ONT box, but I'll roll with this for now as it seems there is something upstream that is hampering devices that aren't isp devices. Thanks for the information from both of you guys.
  • FreeBSD vnet jails no comms

    freebsd vmware jail vnet
    2
    0 Votes
    2 Posts
    898 Views
    T
    As always is the case, I resolved this minutes after posting. It's quite an obscure setting but I needed to also enable Security --> Forged Transmits in the vSwitch. https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.vsphere.security.doc/GUID-7DC6486F-5400-44DF-8A62-6273798A2F80.html
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.