• disable on boot check of config.xml

    4
    0 Votes
    4 Posts
    325 Views
    stephenw10S
    USB Ethernet devices are renamed ue0, ue1 etc, yes. It's not desirable to stop checking for them though. That is a physical interface. If it is assigned in the config and not present on the system the firewall should stop and ask the user how to proceed. Not doing so ends up in an unknown situation or potentially something worse like if you had multiple ue interfaces and one is unplugged you could start sending private traffic out of the remaining one if that became a different interface. The other interfaces in that list are those that built on top of a different physical NIC and may not have been created yet at the time of the check like ppp or vpns. There is no good way to handle this unfortunately. If the modem is in Ethernet mode you have to do something like this to avoid boot failure. If it's in PPP mode pfSense has no problem with the interface or device disappearing but the speed is limited to 3.5G (ish). It would be great to be able to use one of the other methods like MBIM but there is no driver in FreeBSD, yet. https://man.openbsd.org/umb.4 Steve
  • FTP Client problem

    ftp client
    33
    0 Votes
    33 Posts
    5k Views
    stephenw10S
    Um... yeah that would not have helped at all in this case. Traffic to any ftp server was already allowed and passing. Steve
  • pfSense for Squid with only one interface

    4
    0 Votes
    4 Posts
    343 Views
    stephenw10S
    Because the proxy allows traffic on those ports? You can always block it on the firewall. Steve
  • pfSense problems tonight with access

    7
    0 Votes
    7 Posts
    960 Views
    M
    @jashaw30 that's all you've ever needed since that changed that you no longer need to use their kit. dhcp-client-identifier "woteveryouwanr@skydsl|woteveryouwant"
  • Is connecting a factory defaulted router a potential vulnerability?

    7
    0 Votes
    7 Posts
    836 Views
    GrimsonG
    For connecting new devices I have separated two ports on my switch into a single dedicated VLAN. So I connect the new devices to one of these ports and patch the Ethernet connection of one PC to the other port, this way they are in their own L2 and can't impact the network. Another solution is to use a Laptop and connect a new device there first for setup purposes. Just don't connect a device with unknown/conflicting settings to your production network.
  • Need to enable Rules to allow UniFi based Captive Portal Page?

    12
    0 Votes
    12 Posts
    5k Views
    C
    @gertjan said in Need to enable Rules to allow UniFi based Captive Portal Page?: If you pass some time with the acme package you could learn it to obtain a free of cost (that is money, not your time) wild card cert. Hey thank you for this info will look at the package for sure.
  • Load Balancer and reflection.

    2
    0 Votes
    2 Posts
    302 Views
    stephenw10S
    It's possible to workarounbd this using outbound NAT on the internal interface but it's ugly: https://www.netgate.com/docs/pfsense/book/loadbalancing/troubleshooting-server-load-balancing.html#unable-to-reach-a-virtual-server-from-a-client-in-the-same-subnet-as-the-pool-server Steve
  • Pfsense using for ISP with openBGPD

    4
    0 Votes
    4 Posts
    437 Views
    chrismacmahonC
    No, I can let you know we have assisted several ISP's at the support desk.
  • Dynamic dns for local (not exterior) ip?

    8
    0 Votes
    8 Posts
    863 Views
    JKnottJ
    @johnpoz said in Dynamic dns for local (not exterior) ip?: @jknott said in Dynamic dns for local (not exterior) ip?: I think this forum needs an emoticon for "WTF?". Hehehe I agree - what do you think this would look like exactly? [image: 1549052899360-wtf.png] Yep, that's exactly what we need.
  • pfSense hangs randomly every 10-20th day, please help troubleshoot

    13
    0 Votes
    13 Posts
    2k Views
    T
    +1 on blaming Realtek NICs. I built a machine in the past two years that had Realtek NICs (horrible oversight on my part). Put pfSense on the box and it locked up randomly requiring a reboot to resolve the issue. No log entries or anything else. I also put VMware ESXi onto the same box and had it purple screen a few times (even with injecting an in-line patch to support the NICs). IMHO, newer Realtek NICs can hang your box w/o logging issues in the OS. Avoid at ALL costs.
  • Where's the bottleneck?

    8
    0 Votes
    8 Posts
    865 Views
    johnpozJ
    No problem - great that you mention such an issue for sure. Now back to our original programming ;) Can you put in some details of how your doing the speed testing - and maybe now you should retest since its not impossible that the virus/whatever was eating up some cycles/bandwidth edit: Seems I confused you with the OP hehehe... Thanks for the PM to mention that.. So we are still waiting for the details of the OP and how they did their testing. @Raffi_ so what are you running pfsense on and are you seeing your full bandwidth.. Is it gig? ;)
  • negate_networks Empty Table

    2
    0 Votes
    2 Posts
    242 Views
    jimpJ
    It's a default table that is usually populated with local networks that need to bypass policy routing (e.g. LAN to LAN2/DMZ type traffic). It could be empty if you only have one local interface, or if you don't use policy routing.
  • pfsense WAN on private network

    7
    0 Votes
    7 Posts
    2k Views
    S
    @penguin-nut said in pfsense WAN on private network: Disable hardware checksum offload FYI, documented at https://www.netgate.com/docs/pfsense/book/config/advanced-networking.html?highlight=xen#hardware-checksum-offloading
  • Cannot delete "incomplete" device from arp table.

    13
    0 Votes
    13 Posts
    5k Views
    D
    @jknott I'm not going to jump the gun but I think I found it. I'm using Home Assistant for my home automation and inside it I have setup trackers for devices. I ping the devices and if they do not respond I send a message to my phone telling which device is down. In my code I was still pinging those old IP's. Lets hope that was it. Thank you so much for your help.
  • 2.3 release needed for testing

    Locked
    19
    0 Votes
    19 Posts
    1k Views
    ?
    @selianto pfSense 2.3.x is End of Life. As such, we do not offer older releases for download, nor do we support them. If you have an urgent upgrade project, you should consider a Netgate Global Support subscription. The Support team may be able to assist with the upgrade in a way that does not require having to use an outdated image. If you would like more information about a Netgate Global Support subscription, please email sales@netgate.com or if you need help now, you can find our different Netgate Global Support subscriptions here: https://netgate.com/support
  • [Authentication] Password with special character gets rejected?!

    8
    0 Votes
    8 Posts
    1k Views
    8
    Okay. Thanks for the explanation.
  • How long entry should be found in the logs

    8
    0 Votes
    8 Posts
    908 Views
    chudakC
    @jimp Very confusing but ok, thx ! Case to have real syslog server
  • Hostname of pfsense is attached to openvpn file

    2
    0 Votes
    2 Posts
    236 Views
    jimpJ
    There is no way to exclude the hostname, it does this to ensure the filenames are unique between firewalls, so if you connect to multiple firewalls, the filenames are not the same. I'm not sure it makes much difference for the hostname in that context, whether or not you want it to show "pfsense" there or another hostname is up to you.
  • Can't allocate llinfo

    6
    0 Votes
    6 Posts
    3k Views
    jimpJ
    The most common time I see this is when my cable connection renews DHCP and switches to a different subnet. Some states are still pointing at the old gateway which is no longer valid, thus the error. I suspect a similar issue happened there, probably as @heper said, it came from the cable modem. Lots of cable modems will hand you a private address if you lose upstream sync.
  • Port Forwarding

    28
    0 Votes
    28 Posts
    3k Views
    johnpozJ
    Do your sniff, diag packet capture on your lan interface... Do you see the syn to your ftp server private IP... If you do not see an answer its not pfsense that is your problem. Here I just setup a port forward for ftp (21) and can you see me shows closed.. [image: 1548858567386-ftprst-resized.png] See how my client on 192.168.2.11 sent a RST... Basically he said to F off ;)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.