• LAN Clients can Ping out, but nothing else

    16
    0 Votes
    16 Posts
    2k Views
    RicoR
    Glad you have it working now. -Rico
  • BT Youview plays for a few minutes then stops

    19
    0 Votes
    19 Posts
    2k Views
    stephenw10S
    Yes, you can see it was blocking IGMP traffic on the IPTV interface so adding that floating rule will pass it. You don't need to pass all IGMP traffic on every interface though. I wouldn't expect to need it on WAN at all. You don't need 'any' destination there either. It's always better to pass only the traffic you need. Still seems odd that it appears to be using the source IP of the interface it's arriving at.... Steve
  • pfSense 2.5 Release Date News

    84
    4 Votes
    84 Posts
    39k Views
    kiokomanK
    @jknott i prefer to do this way [image: 1607514887517-immagine.jpg] you can't use host override for IOT device with embedded 2001:4860:4860::8888 i don't use dns of pfsense and i don't use ntp from pfsense i need to redirect to a bind9 dns server and it was only an example
  • PfSense hangs/restarts intermittently...

    9
    0 Votes
    9 Posts
    979 Views
    G
    Well, over 24 hours, and rock solid since replacing RAM. Even restored the config file from newer pfSense, not skipped a beat. Thanks for the help guys.
  • Multi WAN and Multi LAN

    5
    0 Votes
    5 Posts
    579 Views
    Hoto CocoaH
    @bob-dig Thanks for support!
  • How to modify the Nginx tmeout?

    2
    0 Votes
    2 Posts
    343 Views
    stephenw10S
    Does it always fail for that cert? You have something unresolvable set there? Failing after 60s seems reasonable I doubt increasing that value will help. Steve
  • Set up mixed IPv4 and IPv6 traffic?

    26
    0 Votes
    26 Posts
    3k Views
    P
    @jknott Good to know. I appreciate all your help so far. Once (if) I decide to proceed with this, I might have to come back to get more assistance...
  • pppoe server more than 255 users?

    4
    0 Votes
    4 Posts
    728 Views
    jimpJ
    The limit is set by pfSense, I am not aware of a limit in mpd. But again, it hasn't been tested so you're pretty much on your own there. It isn't intended for that many users, but it may work.
  • Block Facebook but Allow Messenger

    2
    0 Votes
    2 Posts
    303 Views
    stephenw10S
    You can try filtering it in DNS but I'm not sure if Facebook Messenger will work without being able to resolve facebook.com. Steve
  • Can't acess Microsoft urls or Xbox App on PC

    2
    0 Votes
    2 Posts
    344 Views
    stephenw10S
    Are the URLs in question resolving? Do you have any other packages installed besides pfBlocker? What error do you see when you try to visit one of these URLs? Steve
  • 0 Votes
    4 Posts
    1k Views
    stephenw10S
    Ah, yes, if it tries to boot and finds the assigned interface missing then you will see problems. I would not normally expect a panic though. An Ethernet connected external modem will give far better results pretty much every time. Steve
  • pfSense change the URL

    7
    0 Votes
    7 Posts
    1k Views
    W
    @stephenw10 If I call the URL from another PC on another network in another city, the problem is not there. And it doesn't even exist if I call the URL from a smartphone. I only have it from multiple PCs in THIS network, under pfSense. So that's something here in this office. I don't know where, but it's here. OK, I close the thread. I try to reinstall everything.
  • Secondary DNS Server

    8
    0 Votes
    8 Posts
    3k Views
    GertjanG
    @leungda said in Secondary DNS Server: Why not using the pfsense as a SLAVE server. Because https://forum.netgate.com/topic/133593/bind-setup-pfsense-as-slave-dns-server/8?_=1607327341512 I'll add a why not more : bind, as any other daemon type process, bind uses config files. And like servers daemons like apache2, nginx, postfix etc : it's close to impossible to build a GUI around them. You wind up doing what's been done for the last 3 or 4 decades : edit the config files with a text editor. Typically, you'll be needing 3 SSH open during editing : One where you edit the config files - bind has config many files, zone files. One to restart or reload bind9, and one where you 'tail' the bind log file(s). Typically, these log files are split in debug, xfer, dnsssec, debug, query, etc. Ones set up correctly, you'll be fine for some time. You have two choices : bind does everything for your pfSense, working as a resolver for pfSense, and your LAN's and slave DNS name server for your domain name. Or you make a mix : unboud listens only to the LANs and pfsense local host, and have bind bind to the WAN IP, port 53. I guess it is possible - with actually ONE restriction : you have to know bind. My own slaves run on a VPS that exists for only that reason : for DNS and mail backup server. I've been using https://freedns.afraid.org/ a long time as a second (third, actually) but had to remove them : as I'm using Letsencrypt, freedns.afraid.org is to slow to update (execute the XFER upon NOTIFY) so acme failed to renew my certs. What happens is that I ask mostly for wild card certs, which implies two records being pushed (using nsupdate) to the master DNS. When this happens, the master sends out after each record update a NOTIFY to the slaves. The first XFER initiated by the salves happens quickly, but then - @freedns - some rate limiting kicks in, the second records gets XFERred much kater, making the Letsencryptcheck fail. In the past, Letsencryptchecked just one name server, which could be the master answering, or the slave, making the chance bigger to succeed. These days, master and all the slaves are checked.
  • Very slow login to dashboard++

    17
    0 Votes
    17 Posts
    2k Views
    GertjanG
    @bla said in Very slow login to dashboard++: that one of the DNS servers being used Keep in mind : you don't have to enter during setup any DNS server. The resolver already knows where the 13 original main 'root' servers are, as these are build into the code. No need to pas on your DNS info elsewhere.
  • IoT Devices on WPA2 Enterprise network

    4
    0 Votes
    4 Posts
    2k Views
    NogBadTheBadN
    @jwj I don't think the Unifi kit support 802.1x and any form of WPA on the same network segment even if the SSID is different. I'm with @johnpoz on the guest WiFi and QR codes.
  • 0 Votes
    12 Posts
    2k Views
    S
    @pagger i disable my WAN ipv6 and everything is solved .
  • Pfsense questions from a newb

    5
    0 Votes
    5 Posts
    587 Views
    johnpozJ
    Yeah knew that was going to happen.. Could tell from the IP.. I don't think we have 1 legit user from there.. It's just spam.. Your googlefu in finding the threads they are coping from is better than mine - I searched and could not find where they had copy pasted from.
  • Issues with Netgate SG-1100 over FTTH (Bell Canada)

    13
    0 Votes
    13 Posts
    1k Views
    stephenw10S
    Hmm, odd. That should be identical to re-assigning it as WAN.
  • 0 Votes
    3 Posts
    579 Views
    I
    @heper I see. Interesting. I'll see if I can find the poll. I mean if folks are willing to pay a premium for Unifi gear, you'd think they'd be willing to buy cheaper (but just as good) gear and pay more for pfSense. I know I would. Interesting.
  • Cisco AnyConnect VPN behind a pfSense 2.4.5

    14
    0 Votes
    14 Posts
    2k Views
    A
    @johnpoz Hello and thanks Yes I only had TCP port 443 outbound from my work VLAN and after adding UDP all is better. I'll VPN into work and update that wiki page
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.