• DNS resolver not starting

    20
    0 Votes
    20 Posts
    2k Views
    W
    OK, thanks a lot. I will reduce the RAM size.
  • Setup NAT for VOIPMuch

    9
    0 Votes
    9 Posts
    782 Views
    stephenw10S
    Mmm, OK reviewing that I guess that even though you have not set static source ports specifically you have set the source port to match and the translated source port to the same value which will effectively make it static. That's the wrong way to do it though. Setting the source IP as any will catch traffic that should not be NAT'd and break things. You should set OBN to hybrid mode and then add one rule only with the source IP as the internal phone and static source set. Steve
  • Switching providers and pfSense configuration

    15
    0 Votes
    15 Posts
    1k Views
    gtjG
    @stephenw10 said in Switching providers and pfSense configuration: Draytek has a g.fast modem coming out that will likely be cheaper and better since the MT992 is locked down. No diag info. If they are actually offering FTTH in your area it's a whole different ball game though. Steve I'll have a look at that option. Thank you once again!
  • Checking for open ports ?

    19
    0 Votes
    19 Posts
    1k Views
    DerelictD
    Packet captures generally don't lie.
  • RAM disk on upgrade from 2.4.4 to 2.4.5p1 and kernel memory

    5
    0 Votes
    5 Posts
    497 Views
    E
    Thank you for the explanation; makes sense. In essence the RAM disk allocation has moved from a "thin" provision to a "thick" provision. And yes, I know the disks are considerably larger than I need, especially since I send everything to a remote syslog, and the local logs are capped. I did it because I have a lot more RAM in the system than I really need, and was still wondering what extra data and/or graphs I could capture. If I ever find a need to run something that needs RAM I will reduce these values as needed.
  • Network setup help needed.

    4
    0 Votes
    4 Posts
    476 Views
    DerelictD
    Then you don't have the proper provisioning to route the subnets to interfaces behind a router. https://docs.netgate.com/pfsense/en/latest/firewall/additional-ip-addresses.html#multiple-ip-subnets It doesn't sound like you are 100% on what it is you have there. I would read that first link in its entirety.
  • Update Automatically

    2
    0 Votes
    2 Posts
    371 Views
    stephenw10S
    There is no setting for that in the GUI because generally speaking it's a terrible idea. There are a few threads here on the forum discussing it but highhly recommend you don't read them! Automatically updating without reading the release notes etc opens you up to the possibility of the firewall updating and rebooting at some inconvenient point. And at worst failing to reboot because of some required manual step that didn't happen. Now imagine how bad that might be is you're remote from the firewall and using it for VPN etc.... Subscribe or check the blog to get update announcements: https://www.netgate.com/blog/ Steve
  • pfSense for 2 LANs

    21
    0 Votes
    21 Posts
    3k Views
    G
    @stephenw10 said in pfSense for 2 LANs: Yup, you can't do that in pfSense. Then I would setup pfSense between the switch and CentOS and configure is as routed only, no NAT, do CentOS can see the real source IP of clients. And to avoid double NAT which is bad in general. Steve Yea, that's what @viragomann suggested me. Next week I'll buy a new switch VLAN capable and do this. Thanks for now.
  • Who Maintains this Package/How Do I File a Bug Report

    12
    0 Votes
    12 Posts
    450 Views
    stephenw10S
    VBox on a desktop works well for a test like this. I used it for years until I got Proxmox setup. Steve
  • barnyard is no longer exist

    2
    0 Votes
    2 Posts
    161 Views
    DaddyGoD
    @anis_ferchichi said in barnyard is no longer exist: barnyard Hi, Recommend to your attention (from @bmeeks) : https://forum.netgate.com/topic/154632/attention-barnyard2-users-for-snort-or-suricata-please-read-this-notice?_=1606476384817
  • Double throughput with Bridge, Lagg or other?

    21
    0 Votes
    21 Posts
    2k Views
    stephenw10S
    Ah, good to hear. Thanks for reporting back.
  • WireGuard release 1.0.0

    vpn wireguard
    6
    0 Votes
    6 Posts
    1k Views
    J
    @jimp Yes would love this feature as wel. Tested it and works really fast en easy to setup. Timeline even for beta release would be great. OpenVpn has so much overhead, and just does not meet the speed requirements with low(er) end hardware.
  • Renew DHCP IP

    12
    0 Votes
    12 Posts
    809 Views
    JKnottJ
    @stephenw10 For me, just unplugging and reconnecting the WAN cable was enough to cause the change. The last time my prefix changed was almost 2 years ago, when there was a problem with the CMTS at my ISP.
  • Peaks and stops...

    10
    0 Votes
    10 Posts
    518 Views
    imWACCoI
    @stephenw10 P.S. in case I did not imply it, Thank you for helping me. If you're ever in Illinois, I'll buy you a $drink
  • stopping an IP address or MAC address from internet access

    15
    0 Votes
    15 Posts
    1k Views
    stephenw10S
    Yes, I understand. The goal of resetting the state table after enabling the rule is to understand whether the rule is not matching the traffic or you are not killing the required states when you kill them individually. It's probably the latter since it's very easy to use a filter expression against the state table that cannot be used the kill states. Steve
  • freeradius limit speed per user

    18
    0 Votes
    18 Posts
    4k Views
    stephenw10S
    Opened a feature request: https://redmine.pfsense.org/issues/11102 Add a comments there if more is needed. Steve
  • Weird WAN Issue

    2
    0 Votes
    2 Posts
    318 Views
    A
    Also just an FYI. I ran a file check 4 times and it came back clean everytime. It appears if I run a file check then reboot. PFSense will reboot just fine and obtain an IP. But if I don't run a file check, more often then not. It will not obtain an IP until I reboot like 4-8 times in a row.
  • SG3100 , 100% CPU filterlog and syslog

    2
    0 Votes
    2 Posts
    362 Views
    stephenw10S
    I have seen that before if the firewall is under significant DDoS attack. It logs every blocked connection by default but you can disable that by unchecking Log firewall default blocks in Status > System Logs > Settings. Or by adding your own block rule on WAN without logging enabled. That leaves other blocked traffic still available for troubleshooting. What are you seeing in the logs currently? Steve
  • Plex-ExpressVPN

    2
    0 Votes
    2 Posts
    541 Views
    stephenw10S
    It's probably because you're sending all your traffic across the VPN, including the registration from the plex server. You probably want to exclude the plex server from the policy routing so it just uses the WAN directly. Steve
  • Where are log files system / openvpn / firewall saved?

    7
    0 Votes
    7 Posts
    819 Views
    GertjanG
    @ramses-sevilla said in Where are log files system / openvpn / firewall saved?: Do you know where are saved all log files? Here : [image: 1606133392678-4adabe7f-662f-4121-a70f-79ea8df481e5-image.png] Or here : /var/log/ ( as any othor unix/linix/freebsd/openbsd/etc OS) Note that : @kiokoman said in Where are log files system / openvpn / firewall saved?: 2.4.5 use a binary circular log format known as clog to maintain a constant log size without the need for rotation is a silent hint that explains the need of a quick Google lookup. Or reading the pfSense manual. As https://docs.netgate.com/pfsense/en/latest/monitoring/logs/manage.html or https://docs.netgate.com/manuals/pfsense/en/latest/the-pfsense-documentation.pdf page 139
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.